Smartappreview

Privacy Policy

Last updated: July 21, 2026

Smartappreview ("we", "us", "our") provides a service that fetches publicly available app store reviews and analyzes them into ranked themes for app owners. This Privacy Policy explains what information we collect, why, who we share it with, and the choices and rights you have.

The data controller responsible for this processing is Mykyta Titov, operating Smartappreview. Full legal-entity and contact details are in our Impressum. We are based in Germany, so EU/GDPR concepts (controller, processor, legal basis) apply to us directly, not just as a courtesy to visitors.

1. Information we collect

  • Account information: your email address, and, if you sign in with Google, the name, email, and profile picture Google provides during OAuth consent. That Google-provided data is stored by our authentication provider, Supabase, as part of its own authentication records; it is not duplicated into our own application database beyond your email address.
  • Payment information: processed entirely by Lemon Squeezy, our merchant of record. We never receive or store your card number or other full card details. We only receive confirmation of payment, your email, and high-level metadata (e.g. plan type, last four digits and brand of the card used, subscription status) back from Lemon Squeezy.
  • Usage data: the App Store/Google Play URLs you submit, the reports generated for you, and product-analytics events (e.g. that a report was requested, completed, or shared) tied to your internal account ID rather than your email or name.
  • Public review content: the 1–3★ reviews we fetch from Apple's and Google's public review feeds for the apps you analyze. We do not collect or store reviewer usernames: only star rating, review text, review date, app version, and (where available) a "helpful/thumbs up" count. It is possible, though we don't expect it to be common, that a reviewer voluntarily included their own name, contact details, or other personal information inside the free-text body of a review they posted publicly; we have no practical way to detect or filter that, since we treat review text as opaque content to be quoted verbatim, never paraphrased.
  • Technical & security data: IP address and request metadata, used transiently for rate-limiting and abuse/bot prevention (via Upstash, with short time-boxed retention windows) and for Cloudflare Turnstile's bot-detection challenge on our sign-up form.
  • Analytics & error data: aggregated, account-ID-keyed product usage analytics (via PostHog, server-side) and aggregated site-visit analytics (via PostHog, client-side but cookieless; see Section 11, Cookies), plus error/crash reports (via Sentry), used to keep the Service reliable. Error reports can incidentally include technical context such as your account ID, a report ID, or the URL you were on when an error occurred.

2. How we use information, and our legal bases

  • To provide the Service (generate and deliver your reports, manage your account, subscription, and billing): necessary to perform our contract with you (GDPR Art. 6(1)(b)).
  • To send transactional email (signup confirmation, password reset, report-ready notifications, review-count-watch alerts, and, only if you've opted in, a weekly digest): necessary to perform our contract with you, or based on your consent for the opt-in weekly digest, which you can withdraw at any time from Account settings or via the unsubscribe link in any digest email.
  • To monitor, secure, and improve the reliability of the Service (error monitoring, rate-limiting, bot mitigation, aggregated product analytics): our legitimate interest in operating a secure, reliable product (GDPR Art. 6(1)(f)), balanced against your privacy interests; none of this involves cross-site tracking or advertising.
  • To comply with legal obligations (e.g. responding to lawful requests from authorities, tax and accounting record-keeping): GDPR Art. 6(1)(c).

We do not use your account data to train the AI models used for review analysis, and we do not sell your personal information to anyone, in the ordinary meaning of "sell" and also as that term is defined under the CCPA/CPRA (Section 9).

3. Third-party service providers (sub-processors)

We share data with the following providers, solely to operate the Service on our behalf:

  • Supabase (USA/EU infrastructure): database hosting and authentication.
  • Vercel (USA): application hosting.
  • Lemon Squeezy (USA): payment processing, acting as merchant of record.
  • Anthropic (USA): receives scraped public review text, star ratings, and the target app's public name/category to generate the theme analysis in your reports. Anthropic does not receive your email, name, or account identifiers, and does not train its models on this data.
  • Resend (USA): transactional email delivery, including Supabase Auth's own signup/password-reset emails, which are sent through Resend's infrastructure.
  • PostHog (USA/EU): product analytics (server-side, account-ID-keyed) and cookieless site-visit analytics (client-side).
  • Sentry (USA): error and crash monitoring, including a client-side SDK that can transmit error events directly from your browser.
  • Inngest (USA): background job orchestration for report generation, weekly digests, and scheduled reconciliation tasks; user IDs, emails (for email-sending steps), and report content pass through Inngest's infrastructure as part of running these jobs durably.
  • Upstash (USA): short-lived, IP-keyed rate-limiting counters.
  • Cloudflare (global): bot mitigation (Turnstile) on our sign-up form.
  • Google: if you choose "Sign in with Google", Google acts as your identity provider for that sign-in.

Each processes data only as necessary to provide their respective service to us, under their own privacy, security, and (where applicable) data processing terms.

We have reviewed each provider's data processing terms and, where the provider offers a separate Data Processing Addendum, accepted it. For providers whose GDPR Art. 28-compliant processor obligations are instead incorporated by reference into their standard terms of service (the common approach for most SaaS infrastructure vendors), we rely on those terms rather than a separately countersigned document.

4. International data transfers

Most of the providers listed above are based in, or process data in, the United States. When we or they transfer personal data of EU/UK/Swiss individuals outside the EEA/UK, we rely on the transfer mechanism each provider makes available, typically the EU Standard Contractual Clauses and/or (for providers that hold it) certification under the EU-U.S. Data Privacy Framework, as the safeguard required under GDPR Art. 44-49. If you'd like more detail on a specific provider's transfer mechanism, contact us and we'll do our best to point you to their current documentation.

5. Data retention

We retain your account data for as long as your account is active, and report/review snapshots for as long as the report exists, until you delete it or your account. Deleting your account (Section 7) triggers an immediate, permanent deletion of your reports, review snapshots, themes, entitlements, and profile record, and cancels any active subscription. We currently run our database on Supabase's Free plan, which does not provide automatic backups or point-in-time recovery, so there is no rolling backup copy of your data for deleted records to age out of; deletion removes the data from our database immediately and completely. If we later move to a paid Supabase plan with backups enabled, we will update this section to describe that backup-rotation window.

6. Your rights (GDPR & equivalent laws)

Subject to the conditions and exceptions in applicable law, you have the right to:

  • Access the personal data we hold about you, and get a copy of it.
  • Rectify inaccurate or incomplete personal data.
  • Erase your personal data: self-service via account deletion (Section 7), or by request.
  • Restrict or object to certain processing based on our legitimate interests.
  • Data portability: receive certain data you provided to us in a structured, commonly used, machine-readable format. Report/theme data is already self-service exportable as CSV from within the product; for a copy of your broader account data, email us and we will provide it within 30 days.
  • Withdraw consent at any time, where processing is based on consent (e.g. the opt-in weekly digest), without affecting the lawfulness of processing before the withdrawal.
  • Lodge a complaint with a supervisory authority: in Germany, the data protection authority (Landesdatenschutzbehörde) responsible for our registered address, or the authority in your own EU/EEA country of residence. A directory of German state authorities is available via bfdi.bund.de.

To exercise any of these rights, email legal@smartappreview.com. We will respond within the timeframe required by applicable law (generally one month under GDPR, extendable by two further months for complex requests).

7. Account deletion

You can delete your account at any time from Account settings. Doing so permanently deletes all of your reports, review snapshots, themes, and entitlements, and cancels any active subscription. This action cannot be undone.

8. Automated processing

We use an AI model (Anthropic's Claude) to cluster public review text into themes. This analysis is performed on app-review content, not on personal data about you as the account holder, and does not produce any automated decision with legal or similarly significant effects on you within the meaning of GDPR Art. 22.

9. California & other U.S. state privacy rights

If you are a California resident, the CCPA (as amended by the CPRA) gives you the right to know what personal information we've collected about you, to request its deletion, to correct inaccuracies, to opt out of the "sale" or "sharing" of personal information, and to not be discriminated against for exercising these rights. We do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months. To exercise any of these rights, email legal@smartappreview.com from the email address on your account (or have an authorized agent contact us on your behalf); we will verify your request using the email address tied to your account.

If you are a resident of another U.S. state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Utah, or others as they take effect), we extend comparable access, correction, deletion, and opt-out rights to you on request, to the extent required by the law of your state.

10. Security

We use technical and organizational measures appropriate to the risk, including encrypted connections (HTTPS/TLS) end-to-end, a restrictive Content Security Policy, access controls on our database, and rate-limiting/bot-mitigation on sensitive endpoints. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Cookies

We use a small number of strictly necessary cookies: a session cookie (via Supabase Auth) that keeps you signed in, and a security cookie set by Cloudflare Turnstile on our sign-up form to help distinguish real signups from bots. Neither requires opt-in consent under applicable ePrivacy law, since both are necessary for functionality/security you've requested rather than for tracking or advertising. We do not use any advertising cookies. We do run a client-side analytics script (PostHog) to count site visits and see which countries they come from, but it runs in a cookieless mode: instead of storing an ID in your browser, PostHog computes a privacy-preserving, one-way hash server-side from your IP address and browser type plus a salt that rotates daily and is then deleted, so it sets no cookie and cannot be used to track you across sites. See our full Cookie Policy for details, including what happens once you're redirected to Lemon Squeezy's own checkout page.

12. Children's privacy

The Service is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child under 16 has provided us with personal information, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above, and, where required by law, we will provide more prominent notice or seek renewed consent.

14. Contact

Questions about this policy, or want to exercise any of the rights above? Reach us at legal@smartappreview.com. For our full legal-entity details, see our Impressum.

Privacy Policy | Smartappreview