Privacy Policy
Last updated: 11 August 2026
Introduction
AppSmash ("we", "our", "us") is operated by Brian Lee Houston, a sole trader based in Australia. AppSmash is a revenue-analytics and copycat-monitoring dashboard for app developers, available at appsmash.tech. This policy explains what information we handle, why, and the choices you have.
Information we collect
Your account. We collect your email address, which is used to sign you in (we send one-time sign-in links instead of storing passwords) and to send the emails described below. Signing in sets a session cookie so you stay logged in.
Your workspace. The workspace name and reporting currency you choose, and settings you save (such as copycat watch terms).
Store credentials. To import your reports we store the credentials you connect: an App Store Connect API key, and/or a Google sign-in authorization (described in the next section). Credentials are encrypted the moment they arrive and can never be viewed again by anyone — including us and our own web server. You can replace or delete them at any time, and revoke them at the store's end at any time.
Your report data. The sales, revenue, and download reports we fetch from Apple and Google on your behalf. These are your business figures — daily totals by app, country, and currency. They do not identify your customers, and we never receive your customers' names, emails, or payment details.
Copycat results. Public app-store listings (name, developer, icon, link) that match your watched app names.
Server logs. Like nearly every website, our servers keep standard access logs (including IP addresses) for security and troubleshooting. We do not use analytics frameworks, tracking pixels, or advertising trackers anywhere on the site.
Google user data
If you connect Google Play with Google sign-in, we request two things from your Google account:
- Read-only access to Google Cloud Storage (
devstorage.read_only) — used solely to download the Play report files Google publishes in your developer reports bucket. We read only the bucket you tell us; the permission cannot modify anything in your account. - Your email address — used solely to show you which Google account is connected.
The sign-in produces a token, which we store with the same encryption as every other credential and use only to fetch your reports on a schedule. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your permission (for support), for security purposes, or to comply with applicable law.
AppSmash's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke AppSmash's access at any time from your Google account permissions page, or by removing the connection in your dashboard — which deletes the stored token immediately.
We send two kinds of email: sign-in links (required to use the service) and optional copycat match alerts — sent only when new matches appear, with a working unsubscribe link in every message. We don't send marketing email.
Third-party services
We use a small number of services to operate AppSmash, each receiving only what its job requires: Apple's App Store Connect API and Google's APIs (fetching your reports, as described above), Amazon Web Services (delivering and receiving email), the European Central Bank's published exchange rates via the Frankfurter API (currency conversion — no personal data involved), and app-store search services for copycat sweeps (these receive watched app names only). We do not sell or share your information with anyone for advertising or marketing.
Data storage and security
All traffic to appsmash.tech is encrypted in transit (TLS). Store credentials and Google tokens are additionally encrypted at rest with public-key encryption, arranged so the web-facing part of our system can store credentials but can never read them back — only an isolated internal worker can, and only to fetch your reports. Report data is stored in our database, scoped to your workspace.
Retention and deletion
Removing a store connection deletes the stored credential immediately. If you want your workspace and its imported data deleted, email us at the address below and we'll remove it. Server and email logs are kept briefly for security and then rotate out.
Children's privacy
AppSmash is a business tool, is not directed at children under 13, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. Changes appear on this page with an updated revision date.
Contact us
Questions about this policy or your data: privacy@appsmash.tech.