Privacy Policy

Last updated: 25 July 2026

This Privacy Policy explains how RejectRadar ("we", "us") collects and processes personal data when you use rejectradar.app and related services (the "Service"). By creating an account or submitting an App Store package, you agree to this policy.

1. Who we are

RejectRadar provides human App Store submission consulting (Launch Approval Shield / Pre-Flight audits). We are not affiliated with Apple Inc. or Google LLC.

Privacy contact: privacy@rejectradar.app

2. Data we collect

Account data

Name, email address, password hash, and role (customer, reviewer, or admin).

App Store submission packages

Information you provide for an audit, which may include: app name, bundle ID, categories, age rating, listing copy, keywords, privacy and support URLs, monetization model, App Review contact details, screenshots, app icons, TestFlight links and notes, and review notes.

Demo / review credentials

Demo usernames and passwords you supply so reviewers can sign into your TestFlight build. These are encrypted at rest. After your report is delivered, we wipe encrypted demo credentials from the submission record.

Saved apps

If you use My Apps, we store profiles you choose to save so you can reuse metadata across audits. You can edit or delete them in your account.

Payment data

Payments are processed by Stripe. We store payment metadata such as Stripe customer ID, Checkout session / payment IDs, amounts, plan, and paid timestamps. We do not store full card numbers on our servers. Stripe's privacy policy applies to card data they process.

Reports and findings

Review findings, scores, PDF reports, and related artifacts generated for your jobs. Reviewers may also record operational notes needed to complete the audit.

Technical and usage data

Basic logs needed to operate the Service (e.g. authentication events, job status changes, error logs). We do not sell advertising profiles.

3. How we use data

  • Provide, operate, and improve the Service
  • Install and test your TestFlight build and produce consulting reports
  • Process payments, refunds under the First-Pass Guarantee, and subscriptions
  • Authenticate accounts and prevent abuse
  • Send transactional email (e.g. report ready, billing notices) when configured
  • Comply with legal obligations

Automated tooling may draft assist notes for human reviewers (e.g. metadata heuristics). Final customer-facing reports are signed off by a human checker. We do not use your app binaries or demo credentials to train public AI models for unrelated products.

4. Legal bases (EEA/UK)

Where GDPR/UK GDPR applies, we process data on these bases:

  • Contract — to deliver audits you purchase
  • Legitimate interests — security, fraud prevention, service improvement (balanced against your rights)
  • Legal obligation — tax, accounting, or regulatory requirements
  • Consent — where we ask for it (e.g. optional marketing, if offered)

5. Sharing

We share data only as needed to run the Service:

  • Stripe — payments, invoices, Customer Portal
  • Infrastructure / email providers — hosting, database, and transactional email when enabled
  • Human reviewers — company checkers or contractors under confidentiality obligations, solely to perform your audit
  • Legal — if required by law or to protect rights and safety

We do not sell your personal data. Agency white-label PDFs are generated for you to share with your clients under your own relationship with them.

6. Retention

  • Demo credentials — wiped after report delivery (or sooner if you ask and the job is closed)
  • Job packages, findings, PDFs — retained while your account is active and for a reasonable period afterward for support, disputes, and the First-Pass Guarantee, unless you request deletion sooner where legally allowed
  • Payment records — retained as required for accounting and tax
  • Account — until you delete it or request erasure, subject to legal holds

7. Security

We use encryption for demo credentials at rest, access controls for reviewer consoles, and HTTPS in transit. No method of storage or transmission is 100% secure; you are responsible for using dedicated review accounts and not sharing production secrets beyond what Apple App Review would need.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your data, and to object to certain processing. Contact privacy@rejectradar.app. You may also lodge a complaint with your local supervisory authority.

In-product controls: edit/delete saved apps under My Apps; manage payment methods via Billing (Stripe Customer Portal).

9. International transfers

We may process data in the EU/EEA, UK, or United States via our processors. Where required, we use appropriate safeguards (e.g. Standard Contractual Clauses) with those providers.

10. Children

The Service is for developers and businesses, not for children under 16. We do not knowingly collect personal data from children.

11. Changes

We may update this policy. Material changes will be reflected by the "Last updated" date on this page. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Related

See also Terms of Service and Disclaimer.