Privacy Policy

Last updated: 31 July 2026

The short version. AscAuto never asks for or stores your Apple ID password. It authenticates to Apple with an App Store Connect API key (.p8) that you issue and can revoke at any time, encrypted at rest with AES-256-GCM. The marketing site sets no cookies and builds no cross-visit profile. You can have your account and its data deleted by emailing support@ascauto.org.

Who this covers

This policy covers the AscAuto marketing site at ascauto.org, the application at app.ascauto.org, and the API at api.ascauto.org. Contact for any privacy question, including access and deletion requests: support@ascauto.org.

What we collect

1. Visiting ascauto.org

The site uses first-party, cookie-free page counting. When you load a page, the browser sends the path and referrer to our own server. We store those together with a daily visitor hash derived from the date, your IP address, your user agent and a server-side secret. The hash rotates every day and cannot be reversed to an IP address, so it lets us count visitors for a single day without identifying anyone or tracking you across days. There are no cookies, no persistent identifiers, no advertising or analytics third parties, and no cross-site tracking. Standard web-server logs are also produced by the hosting infrastructure.

2. Waitlist and contact form

If you join the waitlist we store your email address. If you send the contact form we store the name, email address and message you submit, so we can reply. Nothing here is sold, rented, or used for advertising.

3. Using the product

We do not collect your Apple ID password. There is no flow in the product that asks for it, and no field that stores it.

Who processes data for us

These are the third parties involved in running the service. They receive only what their function requires.

How long we keep things

Your choices

Email support@ascauto.org to get a copy of your data, correct it, or have your account and its data deleted. You can revoke AscAuto's Apple access yourself at any time by revoking the API key in App Store Connect, and its GitHub access by uninstalling the GitHub App. Depending on where you live you may have additional statutory rights (access, rectification, erasure, portability, objection); we honour those requests through the same address.

Security

Secrets are encrypted at rest with AES-256-GCM. Every query in the application is scoped to the authenticated account, so one tenant cannot read another's data. Traffic is HTTPS-only with HSTS. Database and internal services are not exposed to the public internet.

Children

AscAuto is a developer tool intended for people running an Apple Developer Program membership. It is not directed at children and we do not knowingly collect data from them.

Changes

If this policy changes materially we will update the date at the top and, for account holders, say so by email. Questions: support@ascauto.org.