Data and security
How ASO Agent protects the credentials and data from your connected store and ad accounts, and how to revoke access.
Updated September 30, 2026
We treat your data and your connected accounts with care. This article summarises how connections are secured and how you stay in control.
Your passwords stay with you
- App Store Connect connects with a Team Key (Issuer ID, Key ID and private key file) that you create.
- Google Play Console connects by authorizing with Google. We store only the access Google grants us.
- Apple Ads connects with API credentials created with Read Only access.
In every case, we never store your Apple or Google account password.
Encrypted credentials
The credentials and authorizations for your connections are stored encrypted, and we treat key material as sensitive data. Data exchanged between your browser, connected services and ASO Agent is encrypted in transit.
Read-only where possible
Apple Ads credentials are created with read-only access, and access to your Google Play reports bucket is read-only. Some features — such as publishing metadata or uploading screenshots — need write access to your store account, which is why App Store Connect asks for a key with Admin permissions.
Revoke access at any time
- In ASO Agent: go to Settings → Connections, click the delete icon on a connection and confirm. This removes the connection and any data synced through it.
- At the source: you can also revoke the key in App Store Connect or Apple Ads, or remove ASO Agent's access from your Google account.
Payments
Payments are processed by Stripe. You manage your payment details in the Stripe billing portal via Manage billing.
Questions
For anything else about how we handle your data, contact us.
What's next?
Was this page helpful?
Still stuck? Contact support