Android Release Notes Creator Android Release Notes Creator
Features How it works Benefits Contact

Privacy Policy

Last updated: September 2026  ·  Effective for all users of App Store Manager and appstoremanager.net.

The Android Release Notes Creator is a feature of App Store Manager — the all-in-one platform for iOS and Android app store metadata management by I WANT AN ELEPHANT UG. This Privacy Policy applies to both androidreleasenotes.com and appstoremanager.net.

Last updated: September 2026  ·  This policy applies to appstoremanager.net (marketing site) and app.appstoremanager.net (the SaaS application).

Overview

I WANT AN ELEPHANT UG (haftungsbeschränkt), Pelargusstrasse 5, 70180 Stuttgart, Germany ("we", "us") is the data controller for personal data processed through this website and the App Store Manager SaaS platform.

This policy explains what personal data we collect, on what legal basis, for what purposes, how long we retain it, who we share it with, and what rights you have. It covers both the marketing website (appstoremanager.net) and the application (app.appstoremanager.net).

The Service is intended for business users (app developers, app publishers, development agencies). It is not directed at consumers or persons under 18 years of age.

Section 1 — Data We Collect and Why

1.1 Account & registration data

When you create an account we collect:

  • Name and email address
  • Company name and billing address (for invoice generation)
  • Password (stored as a one-way hash — we never see or store your plain-text password)

Legal basis: Art. 6(1)(b) GDPR — necessary for the performance of the contract. Retention: for the duration of the account plus 10 years after closure (statutory commercial record-keeping obligation, §257 HGB).

1.2 Billing & payment data

Subscription payments are processed exclusively by Stripe, Inc. We do not store full card numbers, CVV codes, or bank account details. We retain a Stripe customer ID, subscription status, and invoice history (including billing address and VAT number if provided).

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligation — tax records). Retention: 10 years from invoice date (§147 AO).

1.3 App store credentials

To submit content to Apple App Store Connect and Google Play Console on your behalf, you provide API credentials — such as Apple API keys or Google Play service account JSON keys. These are:

  • Stored encrypted at rest in our Firebase Realtime Database (Google Cloud, EU region europe-west1)
  • Used exclusively to perform actions you request (uploads, exports, metadata submissions)
  • Never shared with any third party except as technically required for the API calls to Apple/Google
  • Deleted within 30 days of account closure

Legal basis: Art. 6(1)(b) GDPR — necessary for service delivery. Retention: for the duration of the account; deleted within 30 days of closure.

1.4 App metadata & content

When you use the Service you create and store app metadata (titles, descriptions, keywords, release notes), screenshots, app preview videos, and translations. This content is stored in Firebase (Google Cloud, EU region europe-west1) and Firebase Storage.

Legal basis: Art. 6(1)(b) GDPR — core service delivery. Retention: for the duration of the account plus a 30-day grace period after cancellation, then deleted.

1.5 Usage & service data

We collect data about how you use the Service: feature usage, upload history, translation character consumption, error logs, and API call logs. This data is used for billing, enforcing plan limits, improving the Service, and diagnosing technical issues.

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in service improvement). Retention: 12 months rolling for logs; aggregated analytics retained indefinitely.

1.6 Team member data

If you invite team members to your account, we store their email addresses and permission settings. Invited users are bound by these Terms through your acceptance on their behalf as account owner.

Legal basis: Art. 6(1)(b) GDPR. Retention: until removed from the account or until account closure.

1.7 Website visitor data (marketing site)

When you visit appstoremanager.net, Firebase Hosting and Google Analytics may collect standard server log data: IP address, browser type and version, pages visited, referrer, and timestamps. This data is used for security, fraud prevention, and aggregate traffic analysis.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website security and analytics). Google Analytics is only activated after explicit consent (see Section 3). Retention: server logs — 30 days; Analytics data — configured to 14 months in GA4.

1.8 Contact form data

When you contact us via the contact form or email, we collect your name, email address, and message content to respond to your enquiry and maintain a record of the communication.

Legal basis: Art. 6(1)(a) GDPR (your consent, given at form submission) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Retention: 3 years from last contact.

1.9 Social login (Google, X / Twitter, GitHub)

When you register or sign in to the Service using a social login provider — Google, X (formerly Twitter), or GitHub — you authorise that provider to share certain profile data with us via OAuth 2.0. We receive and store only the data required to create and identify your account:

  • Google: name, email address, and Google account ID
  • X (Twitter): display name, username (handle), and X account ID
  • GitHub: name, primary email address (if public or granted), and GitHub user ID

We do not receive your social provider password. We do not post to your social accounts. We do not request write permissions. The social provider's own privacy policy governs data they process on their end:

Legal basis: Art. 6(1)(b) GDPR — necessary to create and manage your account. Retention: for the duration of the account plus 30-day grace period. You can unlink a social provider at any time in your account settings; unlinking does not delete your account.

Section 2 — Legal Bases Summary

Processing activityLegal basis (GDPR Art. 6)
Account creation & service deliveryArt. 6(1)(b) — contract
Social login (Google, X, GitHub)Art. 6(1)(b) — contract
Billing, invoicing, tax recordsArt. 6(1)(b) + Art. 6(1)(c) — contract + legal obligation
Service improvement & logsArt. 6(1)(f) — legitimate interest
Google Analytics (website)Art. 6(1)(a) — consent (cookie banner)
HubSpot live chatArt. 6(1)(a) — consent (cookie banner)
Contact form responsesArt. 6(1)(a) — consent
Legal claims & complianceArt. 6(1)(c) — legal obligation

Section 3 — Third-Party Processors (Sub-processors)

We use the following third-party services to deliver and operate the Service. Each is engaged under a Data Processing Agreement (DPA) where required by GDPR.

Google LLC — Firebase & Google Cloud (Infrastructure)

The Service runs on Firebase (Hosting, Realtime Database, Cloud Functions, Authentication, Storage), all deployed to the EU region europe-west1 (Belgium). Your app data, credentials, metadata, and account data are stored in this region. Firebase Cloud Functions process data as part of service delivery (API submissions to Apple/Google, translation requests).

Data processed: all service data as described in Section 1. Transfer basis: EU-US Data Privacy Framework (adequacy decision, Jul 2023) where applicable; EU-region processing otherwise. — Firebase Privacy

Stripe, Inc. — Payment Processing

All subscription payments are processed by Stripe. We do not handle card data. Stripe receives your billing name, billing address, and payment instrument details directly. Stripe is certified under the EU-US Data Privacy Framework.

Place of processing: United States (EU-US DPF) and Ireland (Stripe's EU entity). — Stripe Privacy Policy

Microsoft Corporation — Azure Cognitive Services (Machine Translation)

When you use the machine translation feature, the text content of your app metadata (titles, descriptions, keywords) is sent to Microsoft's Azure Translator API for translation. Microsoft processes this text solely to return a translation; it is not used to train models or for any other purpose per Microsoft's data processing terms.

Data processed: app metadata text you submit for translation. Place of processing: EU data residency configured. — Microsoft Privacy Statement

Apple Inc. & Google LLC — App Store APIs

When you submit content (metadata, screenshots, app previews) through ASM, the data is transmitted to Apple App Store Connect and/or Google Play Console using the API credentials you provide. Apple and Google are independent data controllers for data you submit to their platforms. Their privacy policies govern that processing.

Apple Privacy Policy  ·  Google Privacy Policy

Google LLC — Google Analytics 4 (Website analytics, consent-gated)

We use Google Analytics 4 (GA4) to analyse aggregate website traffic on appstoremanager.net. We implement Google Consent Mode v2: analytics storage is set to denied by default and only activated after you click "Accept" on the cookie banner. No GA4 cookies are set if you decline. GA4 collects pseudonymous identifiers, page views, and interaction events.

Data retention in GA4: configured to 14 months. Transfer basis: EU-US Data Privacy Framework. — Google Privacy PolicyBrowser Opt-Out

HubSpot, Inc. — Live Chat (consent-gated)

We use HubSpot to provide a live chat widget on appstoremanager.net. The HubSpot script is only loaded after you click "Accept" on the cookie banner. If you decline, no HubSpot script is loaded and no HubSpot cookies are set. If you use the chat widget, HubSpot may collect your name, email address, and chat conversation content.

Place of processing: United States (EU-US DPF). — HubSpot Privacy Policy

Section 4 — International Data Transfers

Our core infrastructure (Firebase) is hosted in the EU (europe-west1, Belgium). For services operating from the United States (Google Analytics, HubSpot, Stripe), transfers are covered by the EU-US Data Privacy Framework adequacy decision adopted by the European Commission on 10 July 2023, under which these providers are certified. For any transfers not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) as the transfer mechanism.

Section 5 — Cookies

We use cookies on appstoremanager.net. A cookie is a small text file stored in your browser. The table below lists every cookie set by our website.

Cookie namePurposeDurationSet byRequires consent
iwae-acceptCookiesStores your Accept choice to suppress the banner on return visits365 daysappstoremanager.netNo (functional)
iwae-declineCookiesStores your Decline choice to suppress the banner on return visits365 daysappstoremanager.netNo (functional)
_ga, _ga_*Google Analytics 4 — pseudonymous visitor and session trackingUp to 2 yearsGoogle LLCYes — Accept only
__hs_*, hubspotutkHubSpot live chat — visitor identification and chat sessionUp to 13 monthsHubSpot, Inc.Yes — Accept only

To withdraw cookie consent, click "Decline" on the banner or clear the iwae-acceptCookies cookie in your browser. The consent banner will reappear on your next visit. You can also use the Google Analytics opt-out browser extension.

Section 6 — Your Rights Under GDPR

As a data subject under GDPR you have the following rights. To exercise any of them, contact us using the details in Section 9.

Right of access (Art. 15): You may request a copy of all personal data we hold about you, together with information about how it is processed.

Right to rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.

Right to erasure / "right to be forgotten" (Art. 17): You may request deletion of your personal data where there is no overriding legal ground for retention (e.g. statutory retention obligations may prevent immediate deletion of billing records).

Right to restriction of processing (Art. 18): You may request that we restrict processing of your data in certain circumstances (e.g. while a dispute about accuracy is resolved).

Right to data portability (Art. 20): Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, machine-readable format.

Right to object (Art. 21): You may object at any time to processing based on our legitimate interests (Art. 6(1)(f)). We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to withdraw consent (Art. 7(3)): Where processing is based on your consent (e.g. cookies, contact form), you may withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal.

Rights related to automated decision-making (Art. 22): We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you.

Right to lodge a complaint: You have the right to lodge a complaint with the supervisory authority. The competent authority for I WANT AN ELEPHANT UG is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de

Section 7 — Data Retention

Data categoryRetention periodBasis
Account & profile dataDuration of account + 30-day grace periodContract
App metadata & assetsDuration of account + 30-day grace periodContract
API credentialsDuration of account + 30 days after closureContract
Invoices & billing records10 years from invoice date§147 AO / §257 HGB
Service & error logs12 months rollingLegitimate interest
Website server logs30 daysLegitimate interest
Google Analytics data14 months (GA4 setting)Consent
Contact form messages3 years from last contactConsent / legitimate interest

Section 8 — Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity. We will notify affected users via email or a prominent notice on the website at least 30 days before any such transfer, and will ensure the new controller either maintains equivalent protections or obtains fresh consent where required.

Section 9 — Changes to This Policy

We may update this Privacy Policy from time to time. For material changes (e.g. a new processor, a new purpose, or a change of legal basis), we will notify active users by email at least 14 days before the change takes effect. Minor clarifications may be made without notice. The "Last updated" date at the top of this page always reflects the current version. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

Data Controller & Privacy Contact

Data Controller

I WANT AN ELEPHANT UG (haftungsbeschränkt)
Pelargusstrasse 5, 70180 Stuttgart
Amtsgericht Stuttgart, HRB 774060
support​[at]​appstoremanager.net

Privacy Contact

Matthias Krause
matthias​[at]​iwantanelephant.com

For data subject requests (access, erasure, portability, objection, restriction), please use our contact form or the email addresses above. We will respond within 30 days as required by Art. 12 GDPR.

🍪 We use cookies We use Google Analytics (page view statistics) and HubSpot (live chat support). Both set cookies and process data on servers in the USA. Declining disables both. Privacy Policy
Decline
Accept