ReviewOps is in active development and not yet available for production use.

Privacy Policy

Last updated: July 19, 2026

1. Who We Are

ReviewOps (“we”, “us”) operates a SaaS product that monitors app store reviews and delivers notifications to user-configured destinations. ReviewOps is operated by an individual sole proprietor based in the United States, who is the data controller for the personal data described in this policy for GDPR purposes. Contact: [email protected].

ReviewOps is directed to and intended for customers in the United States, and is not offered or marketed to individuals in the European Economic Area (EEA) or the United Kingdom. The GDPR and UK GDPR provisions in this policy — legal bases, EEA/UK data-subject rights, and international-transfer terms — apply only to the extent a resident of the EEA or UK nonetheless uses the Service and that law applies to the processing. California residents’ rights under the CCPA/CPRA apply regardless.

2. What We Collect, and Why

We identify the purpose and legal basis (GDPR Art. 6) for each category:

  • Account data — email address, display name, and a unique account identifier. Purpose: operating your account. Basis: contract.
  • Authentication data — passkey public keys and credential metadata (device type, creation date), one-time email sign-in codes (expire after 10 minutes), and session records including the IP address and browser user agent of each sign-in, shown to you on your Security page so you can spot unfamiliar sessions. ReviewOps has no passwords. Purpose: sign-in and account security. Basis: contract and legitimate interest (account security).
  • Billing data — subscription status, plan, and billing metadata from our payment processor. We do not see or store your credit card details. Purpose: billing. Basis: contract.
  • App configuration — the app store IDs, countries, and notification destinations (e.g. Slack webhook URLs) you configure. Purpose: providing the Service. Basis: contract.
  • Operational telemetry — structured logs, error events, and aggregate usage analytics. Email addresses are redacted from log output before storage; analytics are cookieless and not linked to your account (see the Cookie Policy). Purpose: diagnosing problems and preventing abuse. Basis: legitimate interest.
  • Support communications — emails you send us. Purpose: responding to you. Basis: legitimate interest.

3. Review Content (Data About People Who Are Not Our Users)

The Service processes publicly available app store reviews, which can include a reviewer’s display name and any personal information the reviewer chose to include in their review text. We obtain this content from public Google Play and Apple App Store listings, not from the reviewers themselves.

  • Purpose: delivering review monitoring, notifications, and analysis to our users. Basis: legitimate interest in processing information the reviewer has made public.
  • Individual notification to each reviewer would be disproportionate (GDPR Art. 14(5)(b)); this section serves as our public disclosure.
  • AI features (theme classification, sentiment analysis, semantic search, translation, and review Q&A) run on models hosted on our own infrastructure. Review content is not sent to third-party AI providers.
  • Our Acceptable Use Policy prohibits users from exploiting review data to identify, contact, or harass reviewers.
  • If you are a reviewer and want your data removed from our systems, email us — note that removing content from the app store itself is controlled by Google/Apple, not us.

4. Third-Party Subprocessors

ReviewOps runs on infrastructure the operator owns and manages directly in the United States; there is no third-party cloud hosting provider. We engage a small number of third-party services for specific functions. A subprocessor is a distinct legal entity that processes personal data on our behalf. Self-hosted software running on our own infrastructure (including our AI models, analytics, and error tracking) is not a subprocessor.

  • Lemon Squeezy — billing, Merchant of Record, subscription lifecycle emails. Their checkout runs on their domain and is governed by their privacy policy.
  • SMTP2GO — transactional email delivery (sign-in codes, account operations, security alerts).
  • Slack — user-configured notification destinations. You control which webhook URLs we send to, and what workspace they belong to.
  • Cloudflare — network security and content delivery in front of the Service; processes visitor IP addresses in transit.

5. Privacy by Design

User data at rest is protected by full-disk encryption, and all connections between internal services (database, message broker) use TLS. Backups are encrypted before leaving the host. Database access is scoped per service (least privilege). Email addresses are redacted from application logs before ingestion, and error reports are scrubbed of emails and credential-bearing URLs. ReviewOps is passwordless — sign-in uses passkeys or one-time email codes, so there is no password database to breach.

6. Your Rights

If you are in the EU/UK, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Lodge a complaint with your national data protection authority

Self-service: your account’s Privacy page provides a one-click data export (a machine-readable archive covering your profile, configurations, memberships, and authentication metadata — satisfying access and portability), and the Delete accountpage permanently erases your account and owned organizations. (If you own a team organization that still has other members, you must transfer ownership or remove the members first, so a shared workspace can’t be destroyed by accident.) Profile data can be corrected in place. For anything else, email [email protected].

California residents (CCPA/CPRA): you have the right to know, correct, and delete personal information we hold about you, exercisable through the same mechanisms above, without discrimination. We do not sell or share personal information as those terms are defined in the CCPA, and we do not use or disclose sensitive personal information beyond what is necessary to provide the Service.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not use it to train AI models.

7. Data Retention

  • Account data: retained until you delete your account, then removed along with your owned organizations and configurations.
  • Sessions: expire after 30 days of inactivity; revocable immediately from your Security page.
  • Sign-in codes: expire after 10 minutes.
  • Application logs (including audit events): 30 days.
  • Billing webhook events: purged 90 days after processing.
  • Data-export archives: download links expire after 15 minutes; the archives themselves are deleted automatically after 7 days.
  • Review content: public app store reviews are shared infrastructure and are retained while any user monitors the app they belong to. They are not tied to your account and are unaffected by account deletion.

8. International Transfers

ReviewOps is operated from and hosted in the United States, and all first-party processing takes place there. If you use the Service from the European Economic Area (EEA), the United Kingdom, or elsewhere outside the United States, your personal data is transferred to and processed in the United States.

For personal data of EEA/UK residents, we protect that data with the safeguards described in Privacy by Design above — encryption in transit and at rest, least-privilege access, and log redaction. Some subprocessors (notably Lemon Squeezy and Cloudflare) also process data in the United States under their own data processing agreements incorporating Standard Contractual Clauses or an applicable adequacy decision.

9. Children

ReviewOps is a business tool, is not directed to children, and may not be used by anyone under 16. We do not knowingly collect personal data from children; if you believe a child has created an account, contact us and we will delete it.

10. Security Incidents

If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required by GDPR Art. 33, and we will notify affected users without undue delay when the breach is likely to result in a high risk to their rights (Art. 34).

11. Changes to This Policy

Material changes will be announced via email and a notice on the Service before taking effect. The “last updated” date at the top reflects the current revision.

12. Contact

For privacy inquiries, email [email protected].