Skip to content
ASO Agent
Browse all articles

Data and security

How ASO Agent protects the credentials and data from your connected store and ad accounts, and how to revoke access.

Updated September 30, 2026

We treat your data and your connected accounts with care. This article summarises how connections are secured and how you stay in control.

Your passwords stay with you

  • App Store Connect connects with a Team Key (Issuer ID, Key ID and private key file) that you create.
  • Google Play Console connects by authorizing with Google. We store only the access Google grants us.
  • Apple Ads connects with API credentials created with Read Only access.

In every case, we never store your Apple or Google account password.

Encrypted credentials

The credentials and authorizations for your connections are stored encrypted, and we treat key material as sensitive data. Data exchanged between your browser, connected services and ASO Agent is encrypted in transit.

Read-only where possible

Apple Ads credentials are created with read-only access, and access to your Google Play reports bucket is read-only. Some features — such as publishing metadata or uploading screenshots — need write access to your store account, which is why App Store Connect asks for a key with Admin permissions.

Revoke access at any time

  • In ASO Agent: go to Settings → Connections, click the delete icon on a connection and confirm. This removes the connection and any data synced through it.
  • At the source: you can also revoke the key in App Store Connect or Apple Ads, or remove ASO Agent's access from your Google account.

Payments

Payments are processed by Stripe. You manage your payment details in the Stripe billing portal via Manage billing.

Questions

For anything else about how we handle your data, contact us.

What's next?

Was this page helpful?

Still stuck? Contact support

Type to search, or press ⌘I to ask the AI assistant.

↑↓ navigate↵ openesc close