Privacy
What ASOgenic collects, what it never sees, and who it shares data with.
What we collect when you sign in
Signing in with Google or with an email and password (through Firebase Authentication) gives us your name, email, and avatar image URL, where the provider supplies them. We store those to show them back to you and to know which keys are yours. We never see your password (Firebase handles that) and never see anything else from your Google account: no contacts, no other account data.
What we collect when you create a key
Just the label you give it. The platform key itself is shown to you exactly once, in your browser, right after it's created or rotated. We never store it, not even encrypted: our database holds only the key's id, its label, and who created it.
Cookies
One session cookie, so you stay signed in. It's required for the app to work and carries no tracking payload.
Google Analytics is not enabled on this deployment.
Who we share data with
This dashboard and the MCP server your keys actually authenticate against are two separate running services, both built by us. We keep them separate on purpose: your App Store Connect credentials never pass through this dashboard, only to your own MCP client and the MCP server directly.
- The ASOgenic MCP server receives your key's label and issues the key itself. It never receives your App Store Connect credentials through this dashboard, only through your own MCP client.
- Firebase Authentication (Google), which handles the actual sign-in and gives us your verified identity.
- Paddle, our payment processor, if you upgrade a key. Paddle collects your payment details directly; we never see your card number, only whether a payment succeeded.
Deleting your data
Revoking a key deletes its record immediately. To delete your account entirely, including your sign-in identity, contact us.
Questions about this page: [email protected].