Privacy
Last updated 21 July 2026. AsoHarbor is operated by
Efe Budak, based in Ireland, who is the
data controller for the information described here.
What we collect
- Your email address. It is your account identifier, and
it is where sign-in links and digests go.
- The IP address of sign-in requests. Stored on the
sign-in link record and used only to rate-limit abuse of the send path.
- What you configure: the apps, keywords, countries, and
competitors you choose to track.
- Billing state, if you subscribe: a Stripe customer
reference, your plan, and its renewal date. We never see or store
your card details; Stripe handles the payment page itself.
What we do not do
No analytics, no advertising, no third-party trackers, no profiling, and no
selling or sharing of your data with anyone for their own purposes. The site
sets exactly one cookie, asoharbor_session, which keeps you
signed in. There is no cookie banner because there is nothing optional to
consent to.
Why we are allowed to hold it
Under the GDPR we rely on two legal bases:
- Performance of a contract: your email address, what you
configure, and your billing state. Without these there is no account and
nothing to send you.
- Legitimate interest: the IP address on sign-in requests,
used to stop people abusing the sign-in email path. The interest is keeping
the service usable and our email sender reputation intact, and the data is
a single address on a short-lived record.
Who processes it, and where
We use a small number of providers to run the service, each with access
only to what their job needs:
- Fly.io hosts the application, in Amsterdam.
- Supabase hosts the database, in Frankfurt.
- Resend delivers email, so it processes your address and
the contents of the messages we send you.
- Stripe handles payments and holds your card details
under its own privacy policy.
Your account data and everything you configure stay inside the European
Economic Area. Resend and Stripe are US companies, so sending you an email
or taking a payment involves a transfer outside the EEA; both commit to
standard contractual clauses or equivalent safeguards in their data
processing terms, which is what we rely on for those transfers.
We also query Apple's public iTunes Search API to collect App Store
rankings and listing data. Those requests contain no personal data about
you: they ask about apps and keywords, not people.
How long we keep it
- Account data stays until you delete it.
- Sign-in links expire 15 minutes after they are issued
and are single use. The record of the request, including its IP address,
is what the rate limits are counted from.
- Sign-in sessions last 30 days, and you can end them all
at once from Settings.
- App Store data (rankings, listing changes) is about
public apps rather than about you, is shared across everyone tracking the
same app, and is kept as a historical record.
Your rights
The GDPR gives you the right to access your data, to have it corrected or
erased, to restrict or object to how we use it, and to receive a copy in a
portable form. In practice:
- Erasure is a button. Settings has a delete-account
button that removes your account and the data tied to it. It is immediate
and cannot be undone.
- Stop the emails: every digest has an unsubscribe link,
and Settings has the same switch. Sign-in links are not marketing and are
only ever sent when someone asks for one.
- Anything else (access, correction, a portable copy, or
an objection): email efebudakapps@gmail.com and
we will deal with it within one month.
You also have the right to complain to a data protection authority. Ours is
the Irish Data Protection Commission,
dataprotection.ie, and you can
also complain to the authority where you live.
Changes
If this policy changes materially we will say so on this page and update the
date above. Questions go to
efebudakapps@gmail.com.