Privacy policy
Last updated 1 October 2026
Mobile Apps Stats (“we”, “us”) is operated by [Your company or legal name], [Registered business address]. This policy explains what we collect when you use Mobile Apps Stats, why, who we share it with, and how you can have it deleted. For questions, contact [privacy@yourdomain.com].
What we collect
Your account. Your name, email address and a one-way hash of your password (we never store the password itself). For each signed-in device we keep a hashed session token, the browser’s user-agent string and when it was last used, so you can stay signed in and so sessions can be revoked.
Your workspace. Its name, its members and their roles, and the settings you choose, such as your reporting currency.
Your Google connections. When you connect a Google account we store the address of that account, the permissions it granted, and a refresh token that lets us read your reports. Refresh tokens are encrypted (AES-256-GCM) before they are stored. We also store the identifiers needed to find your reports: Google Ads customer IDs, your AdMob publisher ID and your Google Play reports bucket name.
Your app and report data. Daily figures read from your Google accounts: Google Ads cost, impressions, clicks and conversions per campaign; AdMob earnings, impressions, clicks and requests per app; Google Play in-app purchase totals per app, day, product and currency; and Google Play install, uninstall, store-listing and crash counts per app. We store daily totals only. We do not store individual orders or any information about the people who buy or use your apps. We also read your apps’ public Google Play store pages (title, icon, rating, download range) and, where permitted, their current release version.
Sync records. A log of each data refresh, including any error messages returned by Google, so you and we can see when and why a refresh failed.
Technical data. To protect sign-in and sign-up from abuse we briefly hold your IP address in memory to count attempts; it is not written to our database. Our hosting provider’s web server may record IP addresses in its access logs.
How we use Google user data
We request these Google permissions, and use them only to read the reports and settings shown to you in Mobile Apps Stats:
- Google Ads (adwords): to read campaign cost and performance. We never create, change or pause campaigns.
- AdMob (admob.readonly, admob.report): to read your apps and earnings reports.
- Google Play (devstorage.read_only, androidpublisher): to read the sales and statistics reports in your Play reports bucket, and your apps’ release information. We never publish, change or upload anything.
- Your email address (userinfo.email): to show which Google account a connection belongs to.
Mobile Apps Stats’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not use it to train AI or machine-learning models, and no person at [Your company or legal name] reads it except with your permission, to investigate a problem you reported, where needed for security, or where the law requires it.
Why we use it
- To provide the service you signed up for: importing, combining and showing your figures.
- To send you emails the service needs, such as confirming your address, invitations and password resets.
- To keep the service secure and working, and to diagnose problems.
If you are in the EU, UK or a similar jurisdiction, our legal basis is performing our contract with you, and our legitimate interest in keeping the service secure.
Who we share it with
We do not sell personal data. We share it only with the providers that run the service for us:
- Google, whose APIs we call with your permission to read your reports.
- [Your hosting provider, e.g. DigitalOcean, AWS], which hosts our servers and database.
- [Your email provider, e.g. Postmark, Amazon SES], which delivers our emails.
We also fetch public currency exchange rates, which involves sending no personal data. We may disclose data where the law requires it.
Cookies
We use a single cookie, which keeps you signed in. It is strictly necessary, expires after 30 days, and is not readable by scripts. We use no analytics, advertising or tracking cookies.
How long we keep it, and deleting it
We keep your data while your account or workspace exists. You can delete it yourself at any time:
- Delete a workspace from its Settings page. Its apps, figures, settings and sync history are deleted immediately, and its Google connections are revoked with Google.
- Delete your account from your Account page. This also deletes any workspace you are the only member of.
- Disconnect a Google account from the Connections page, or revoke access from your Google account settings.
Deleted data may remain in backups for up to [N] days before those backups are overwritten. Expired sessions and password links are purged automatically.
Your rights
You can access, correct or delete your personal data, object to or restrict how we use it, and ask for a copy of it. Most of this you can do yourself in the app; for anything else, email [privacy@yourdomain.com] and we will respond within 30 days. You may also complain to your local data protection authority.
Security
Passwords are hashed with scrypt, Google refresh tokens are encrypted, session and password links are stored only as hashes, and each workspace’s data is kept separate. No system is perfectly secure; if we become aware of a breach affecting your data we will tell you without undue delay.
Children
Mobile Apps Stats is a business tool and is not intended for anyone under 16.
Changes
If we change this policy we will update the date at the top, and tell account holders by email before a significant change takes effect.
See also our Terms of service.