Skip to content

Security

Connecting your store accounts means trusting us with keys to your apps. Here's how we look after them.

Read-only by default
Stayshipped asks for the least access that works: an App Store Connect key with the Developer or Customer Support role, a Google Play service account with view-only permissions, and a GitHub App you install on the repositories you pick, or a read-only access token for one Bitbucket repository. Bitbucket tokens that can write are refused, and a Google Play key missing a permission is named when you connect it. Apple doesn't let us see a key's role, so we ask for a Developer key.
Keys are encrypted and never shown again
Store keys are encrypted with a key unique to your organisation, which is itself protected by Google Cloud KMS. They're only decrypted in memory while a sync runs. They're never logged, never returned by the API, and never sent to an AI model.
Your data stays in the EU
The database runs in Frankfurt and files are stored with EU jurisdiction.
AI without training on your data
Review grouping and fix tasks use AI providers under terms that exclude training on customer data. Reviewer names and personal details are removed before anything reaches a model.
Accounts
Two-factor authentication for everyone, and owners can require it across their organisation. Deleting your account destroys your store keys immediately.
If something goes wrong
We follow a written incident response plan, and tell affected customers within 72 hours of confirming a breach.
Sub-processors
The companies that process data for us, what for and where, are listed on the sub-processors page.

Found a vulnerability? Email security@stayshipped.com.