Privacy Policy for StoreFast
Effective Date: October 2, 2026
StoreFast (https://storefast.app) is run as a sole proprietorship in Massachusetts, United States. This policy explains what we collect, why we collect it, and what you can do about it.
1. What we collect
We only collect what we need to run StoreFast for you:
- Early access list. If you join it, we keep your email address and when you signed up.
- Account details. When you sign in with GitHub or Google, we get your name, email address and profile picture from them. When you sign in with an email link, we get your email address.
- Sign-in and security data. For each session we keep your IP address, your browser type and when the session started and ends. We also count requests per IP address for a short time to stop abuse.
- Store credentials. When you connect a store account, such as Microsoft Partner Center, we keep the credentials you give us. They’re encrypted before they’re stored, they’re only opened to talk to the store for you, and they’re never shown to you or anyone else again.
- Your app content. Packages you upload, release notes you write, and the translations StoreFast makes for you.
- Store data. From Partner Center we fetch your apps, downloads, installs, ratings, reviews and certification results. We also keep a copy of the text of each app’s live listing, so we can match its languages and earlier release notes, and a short writing style profile made from that text. Reviews are written by your app’s users and can include whatever they chose to write.
- API keys. We keep each key’s name, its first few characters, what it’s allowed to do and when it was last used. We only store a one-way hash of the key itself, never the key, so we can’t show it again.
- AI usage. We count how many AI requests each account makes per day, so we can apply the daily limit.
- Cost records. For each AI request we keep its type, the app it was for and how many tokens it used, and we count how many emails we send each account per day. We use these to keep track of what StoreFast costs to run.
- Billing details. We keep your plan, its status, when it renews, and Stripe’s IDs for your subscription. Stripe shares order details with us, such as your name, email address, billing address and the last four digits of your card. We never see your full card number.
- Usage and errors. We use product analytics (PostHog) to see how StoreFast is used and to get reports when something breaks: which pages you visit, steps like connecting a store or submitting an update, and error details. It is tied to an internal account ID, never your name or email, and stores nothing on your device. We also record some sessions as a replay of the page, so we can see where people get stuck. Anything you type is hidden in those replays, and so are your email, your Partner Center IDs and API keys.
2. How we use it
We use your data to sign you in, publish your apps, translate release notes and reviews, show you your stats and reviews, send you sign-in links and emails about your account, keep StoreFast secure, handle billing, and fix and improve the product.
We also email you about your apps: new reviews once a day, when an update goes live or fails certification, download milestones, and warnings before your Partner Center key expires or when StoreFast can’t reach Partner Center. You can turn each of these off in Settings or with the link at the bottom of each email.
We don’t sell your data, we don’t show ads, and we don’t use your data or your app content to train AI models.
3. Cookies
We use one essential cookie to keep you signed in. When you sign in, we also set a functional cookie, better-auth.last_used_login_method, that remembers which sign-in method you used last so the sign-in page can mark it. Product analytics doesn’t set cookies or store anything on your device. We don’t use advertising or cross-site tracking cookies.
4. Who we share it with
We use a few service providers to run StoreFast. They only get the data they need to do their part:
- Cloudflare hosts StoreFast, stores our database and uploaded packages, and sends our emails.
- Cloudflare Workers AI, reached through Cloudflare AI Gateway, runs the AI model that translates release notes and reviews and writes the writing style profile. It receives the text being translated or studied. Cloudflare says it doesn’t use this content to train models. AI Gateway may keep logs of these requests, which we use to watch for errors and costs.
- Stripe, through its Managed Payments service. Stripe’s company Sold through Link, LLC is the merchant of record for your payment. It collects your payment details, billing address and tax information directly and uses them under its own privacy policy (stripe.com/privacy) and Link’s terms.
- PostHog, for product analytics and error reports, hosted in the EU. We use it only to understand and improve StoreFast, never for advertising.
- Microsoft, when we publish your apps or fetch your apps, stats and reviews from Partner Center. The same goes for any other store you connect.
- GitHub and Google, if you choose to sign in with them.
- Gravatar, if you sign in with an email link. Your browser asks Gravatar for your profile picture using a one-way hash of your email address.
5. How long we keep it
We keep your data only as long as we need it:
- Account data, store data and API key records stay for as long as you have an account. Disconnecting a store deletes its apps and their data.
- Uploaded packages are deleted once they’re sent to the store, when you discard an update, or after 30 days, whichever comes first.
- Translated release notes are cached for up to 30 days so the same text isn’t translated twice.
- Daily AI usage counts are deleted after 7 days.
- Cost records, meaning each AI request’s type, app and token count and the daily email counts, are deleted after 90 days.
- Session records expire on their own.
- If you delete your account, we delete your data within 30 days, except billing records we have to keep for tax and legal reasons.
6. Your rights
You can ask us to show you the data we have about you, correct it, export it or delete it, or take you off the early access list. Email hello@storefast.app and we’ll reply within 30 days. Depending on where you live, such as the EU, the UK or California, you may have extra rights under local law, and we’ll honor them.
7. Security
Data is encrypted in transit, store credentials are encrypted at rest, API keys are only stored as hashes, and access to production systems is limited to the people who run StoreFast. No system is perfectly secure, so if we ever learn of a breach that affects you, we’ll tell you.
8. Where data is processed
StoreFast is run from Massachusetts, United States. We and our providers may process your data in the United States and other countries.
9. Children
StoreFast isn’t meant for children under 13, and we don’t knowingly collect their data.
10. Changes
If we change this policy, we’ll update the date at the top. If the change is important, we’ll also email you.
11. Governing law
This Privacy Policy is governed by the laws of the Commonwealth of Massachusetts, United States.
Questions? Email hello@storefast.app.