Privacy Policy

Effective: 1 August 2026

This policy explains how MB Viksva, a small partnership (mažoji bendrija) established in the Republic of Lithuania (“we”, “us”), processes personal data in connection with StoreReplies (the “Service”). Contact for all privacy matters: appstorereplies@gmail.com.

1. Our two roles

For data about you — your account, billing status, settings, and correspondence — we are the controller.

For app-store review data — reviews of your apps, which may include reviewer nicknames and any personal data reviewers chose to write — we act as your processor: we retrieve and process that data on your instruction to provide the Service. You are responsible for having a lawful basis to process your apps’ review data.

2. What we collect

We use no advertising trackers, run no ad campaigns, and never sell or share data for advertising. Analytics cookies are the only non-essential cookies we set, they are off unless you switch them on, and they run only on our public marketing pages.

3. Cookies and similar technologies

When you first visit our public pages we ask for your choice. Until you actively consent, no analytics cookies are set and nothing is loaded from Google’s servers — we do not merely disable the cookies, we do not request the script at all. Strictly necessary cookies are exempt from consent under art. 5(3) of the ePrivacy Directive.

CookieSet byPurposeCategoryExpires
__sessionStoreRepliesKeeps you signed in to the dashboard.Strictly necessary14 days
sr_consentStoreRepliesRemembers the cookie choice you made here, so we stop asking.Strictly necessary6 months
_gaGoogle AnalyticsDistinguishes one visitor from another to count visits.Analytics — consent only2 years
_ga_*Google AnalyticsKeeps track of a single browsing session.Analytics — consent only2 years

Where analytics runs. Google Analytics is loaded only on our public pages (home page, sign-in, and these legal pages). It is never loaded inside the signed-in dashboard, because dashboard addresses contain our customers’ app identifiers and we will not disclose those to a third party.

What we tell Google. We use Google Consent Mode v2 with advertising signals (ad_storage, ad_user_data, ad_personalization) set to denied permanently — there is no setting that turns them on. Google Analytics 4 does not log or retain IP addresses; they are used only in transit to derive an approximate location. We have not enabled Google Signals, advertising features, or data sharing with other Google products. Google acts as our processor for this data.

Changing your mind. Select “Cookie settings” in the footer of any public page at any time. Withdrawing consent is as easy as giving it: we stop loading analytics immediately and delete the _ga cookies from your browser. Withdrawal does not affect the lawfulness of processing before you withdrew. You can also block or delete cookies in your browser settings, and we honour the Global Privacy Control signal automatically — if your browser sends it, we record a refusal without even showing you the banner.

4. What we use it for, and the legal bases

5. AI processing

To generate reply drafts and translations we send the following to Google Vertex AI (Gemini models, Google Cloud): the review’s text, title, rating, language, and storefront country; your tone settings (voice, app description, signature, phrases to avoid); your edits to a draft; and — only if you enable “learn from my past replies” — up to a handful of replies you previously published, as style examples. Reviewer names or nicknames are never sent to the AI.

Under Google Cloud’s terms, this data is not used to train Google’s models. We may change the specific model versions at any time. AI suggestions are always subject to your review unless you explicitly enable auto-publish for narrowly defined cases. We make no automated decisions producing legal or similarly significant effects about any person.

6. Who else receives data (subprocessors)

We do not sell personal data and do not share it with anyone else except where required by law.

7. International transfers

Data is stored on Google Cloud infrastructure in the United States. Transfers from the EEA rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses as implemented by our providers.

8. Retention

9. Security

Data is encrypted in transit and at rest. Store credentials live only in Google Secret Manager with least-privilege access; the application is designed never to write credentials — or errors that might echo them — to databases or logs. Access to production is limited to the operator.

10. Your rights

Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests, and withdraw consent at any time. Write to appstorereplies@gmail.com — we respond within one month. You can also lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI) or your local supervisory authority.

If you are a reviewer whose review appears in a developer’s StoreReplies account, note that the review is public data from the app store; direct removal requests to the store, and rights requests concerning a developer’s use of it to that developer (the controller), or to us and we will pass them on.

11. Children

The Service is for professional use and not directed at children. We do not knowingly collect data from anyone under 16.

12. Changes

We may update this policy; material changes will be announced by email or in-app notice at least 14 days in advance. The effective date above always reflects the current version.