Security
Connecting your store accounts means trusting us with keys to your apps. Here's how we look after them.
- Read-only by default
- Stayshipped asks for the least access that works: an App Store Connect key with the Developer or Customer Support role, a Google Play service account with view-only permissions, and a GitHub App you install on the repositories you pick, or a read-only access token for one Bitbucket repository. Bitbucket tokens that can write are refused, and a Google Play key missing a permission is named when you connect it. Apple doesn't let us see a key's role, so we ask for a Developer key.
- Keys are encrypted and never shown again
- Store keys are encrypted with a key unique to your organisation, which is itself protected by Google Cloud KMS. They're only decrypted in memory while a sync runs. They're never logged, never returned by the API, and never sent to an AI model.
- Your data stays in the EU
- The database runs in Frankfurt and files are stored with EU jurisdiction.
- AI without training on your data
- Review grouping and fix tasks use AI providers under terms that exclude training on customer data. Reviewer names and personal details are removed before anything reaches a model.
- Accounts
- Two-factor authentication for everyone, and owners can require it across their organisation. Deleting your account destroys your store keys immediately.
- If something goes wrong
- We follow a written incident response plan, and tell affected customers within 72 hours of confirming a breach.
- Sub-processors
- The companies that process data for us, what for and where, are listed on the sub-processors page.
Found a vulnerability? Email security@stayshipped.com.