Privacy Policy
Effective: 1 August 2026
This policy explains how MB Viksva, a small partnership (mažoji bendrija) established in the Republic of Lithuania (“we”, “us”), processes personal data in connection with StoreReplies (the “Service”). Contact for all privacy matters: appstorereplies@gmail.com.
1. Our two roles
For data about you — your account, billing status, settings, and correspondence — we are the controller.
For app-store review data — reviews of your apps, which may include reviewer nicknames and any personal data reviewers chose to write — we act as your processor: we retrieve and process that data on your instruction to provide the Service. You are responsible for having a lawful basis to process your apps’ review data.
2. What we collect
- Account data — your Google sign-in identity (email address, user ID) and a session cookie.
- Store credentials — service-account keys / API keys you upload to connect apps. Stored encrypted in Google Secret Manager, never written to logs or the database, used only to call the store APIs, destroyed on disconnect.
- Review data — reviews of your connected apps as exposed by Google Play and the App Store: rating, text, language/country where available, reviewer nickname, and any existing developer reply. Also aggregate ratings and app-stability metrics (crash and ANR rates) — these are aggregates and contain no personal data.
- Drafts and replies — AI-drafted reply suggestions, translations, your edits, and the replies you publish.
- Billing data — handled by Stripe as merchant of record. We receive your plan and subscription status, never your card details.
- Correspondence — any support email you send us.
- Website usage data — only if you consent to analytics cookies: the public pages you visit, the site or search that referred you, approximate location derived from your IP address, and general device/browser type. Collected via Google Analytics 4 and described in section 3.
We use no advertising trackers, run no ad campaigns, and never sell or share data for advertising. Analytics cookies are the only non-essential cookies we set, they are off unless you switch them on, and they run only on our public marketing pages.
3. Cookies and similar technologies
When you first visit our public pages we ask for your choice. Until you actively consent, no analytics cookies are set and nothing is loaded from Google’s servers — we do not merely disable the cookies, we do not request the script at all. Strictly necessary cookies are exempt from consent under art. 5(3) of the ePrivacy Directive.
| Cookie | Set by | Purpose | Category | Expires |
|---|---|---|---|---|
| __session | StoreReplies | Keeps you signed in to the dashboard. | Strictly necessary | 14 days |
| sr_consent | StoreReplies | Remembers the cookie choice you made here, so we stop asking. | Strictly necessary | 6 months |
| _ga | Google Analytics | Distinguishes one visitor from another to count visits. | Analytics — consent only | 2 years |
| _ga_* | Google Analytics | Keeps track of a single browsing session. | Analytics — consent only | 2 years |
Where analytics runs. Google Analytics is loaded only on our public pages (home page, sign-in, and these legal pages). It is never loaded inside the signed-in dashboard, because dashboard addresses contain our customers’ app identifiers and we will not disclose those to a third party.
What we tell Google. We use Google Consent Mode v2 with advertising signals (ad_storage, ad_user_data, ad_personalization) set to denied permanently — there is no setting that turns them on. Google Analytics 4 does not log or retain IP addresses; they are used only in transit to derive an approximate location. We have not enabled Google Signals, advertising features, or data sharing with other Google products. Google acts as our processor for this data.
Changing your mind. Select “Cookie settings” in the footer of any public page at any time. Withdrawing consent is as easy as giving it: we stop loading analytics immediately and delete the _ga cookies from your browser. Withdrawal does not affect the lawfulness of processing before you withdrew. You can also block or delete cookies in your browser settings, and we honour the Global Privacy Control signal automatically — if your browser sends it, we record a refusal without even showing you the banner.
4. What we use it for, and the legal bases
- Providing the Service (ingesting reviews, drafting, translating, publishing, alerting) — performance of a contract (GDPR art. 6(1)(b)).
- Security, abuse prevention, and service improvement — legitimate interests (art. 6(1)(f)).
- Product emails you asked for — consent (art. 6(1)(a)), withdrawable any time.
- Website analytics — consent (art. 6(1)(a), and art. 5(3) ePrivacy for storing the cookie), withdrawable any time from the footer.
- Accounting and legal obligations — legal obligation (art. 6(1)(c)).
5. AI processing
To generate reply drafts and translations we send the following to Google Vertex AI (Gemini models, Google Cloud): the review’s text, title, rating, language, and storefront country; your tone settings (voice, app description, signature, phrases to avoid); your edits to a draft; and — only if you enable “learn from my past replies” — up to a handful of replies you previously published, as style examples. Reviewer names or nicknames are never sent to the AI.
Under Google Cloud’s terms, this data is not used to train Google’s models. We may change the specific model versions at any time. AI suggestions are always subject to your review unless you explicitly enable auto-publish for narrowly defined cases. We make no automated decisions producing legal or similarly significant effects about any person.
6. Who else receives data (subprocessors)
- Google Cloud / Firebase — hosting, database, secret storage, AI (region: us-central1, USA).
- Stripe — payments, as merchant of record.
- Resend — transactional alert emails.
- Google Analytics — website usage statistics on public pages, only with your consent.
- Google Play & Apple App Store APIs — retrieving reviews and publishing your replies, using your credentials.
We do not sell personal data and do not share it with anyone else except where required by law.
7. International transfers
Data is stored on Google Cloud infrastructure in the United States. Transfers from the EEA rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses as implemented by our providers.
8. Retention
- Store credentials — destroyed immediately when you disconnect an app.
- Review data, drafts, and snapshots — deleted when you disconnect the app or delete your account.
- Account data — kept while your account exists. Deleting your account also removes your support messages sent from the same address.
- Payment records — held by Stripe, our payment processor, for the period tax and accounting law requires. Deleting your account cancels the subscription and removes our copy, but we cannot erase Stripe’s financial record of a completed payment.
- Analytics data — event-level data is retained by Google Analytics for no longer than 14 months, Google’s maximum for this data.
- Replies already published on a store are public and outside our control — deleting data here does not remove them from the store.
9. Security
Data is encrypted in transit and at rest. Store credentials live only in Google Secret Manager with least-privilege access; the application is designed never to write credentials — or errors that might echo them — to databases or logs. Access to production is limited to the operator.
10. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests, and withdraw consent at any time. Write to appstorereplies@gmail.com — we respond within one month. You can also lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI) or your local supervisory authority.
If you are a reviewer whose review appears in a developer’s StoreReplies account, note that the review is public data from the app store; direct removal requests to the store, and rights requests concerning a developer’s use of it to that developer (the controller), or to us and we will pass them on.
11. Children
The Service is for professional use and not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes
We may update this policy; material changes will be announced by email or in-app notice at least 14 days in advance. The effective date above always reflects the current version.