Privacy Policy
Last updated: April 12, 2026
1. Introduction
This Privacy Policy explains how ASO Copilot (Kiryl Sadko, conducting business as an individual entrepreneur, "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you access our website, register for an account, use our product, or interact with us in any other way. It applies to all visitors, registered users, trial users, paying customers, and anyone who contacts us for support.
By using ASO Copilot, you acknowledge that you have read and understood this policy. If you do not agree with this policy, you should discontinue use of our services.
2. Who We Are
ASO Copilot is an AI-assisted SaaS platform for App Store Optimization, offering tools for keyword research, metadata generation, content suggestions, and related workflows for mobile app publishers, developers, and marketing teams.
The data controller responsible for your personal data is:
Kiryl Sadko
Indywidualna działalność gospodarcza (sole trader)
pl. Plac Mechaników 3, 05-800 Pruszków, Poland
NIP: 8992968363 · REGON: 526067095
3. Contact Information
For questions, requests, or concerns relating to this Privacy Policy or the handling of your personal data, please contact us at:
Email: [email protected]
We do not operate a telephone customer service line. All privacy enquiries and data subject requests are handled by email.
4. What This Policy Covers
This policy covers personal data processed in connection with: (a) your use of the ASO Copilot website and any publicly accessible pages; (b) account registration and authentication; (c) use of the ASO Copilot application, including all features, workflows, and AI-assisted tools; (d) billing, subscription management, and transaction processing; (e) support communications and correspondence; and (f) any other direct interaction between you and ASO Copilot.
This policy does not cover the practices of third-party websites or services linked from our platform. We encourage you to review the privacy policies of those services independently.
5. Categories of Personal Data Collected
We may collect and process the following categories of personal data:
- Identity and account data: name, email address, username, and authentication credentials.
- Billing and payment data: subscription tier, billing email, payment method type, and transaction records. Full card details are handled exclusively by our payment processor.
- Usage and activity data: features accessed, workflow configurations, session metadata, interaction logs, and product usage patterns.
- Device and technical data: IP address, browser type and version, operating system, referral source, and device identifiers.
- Customer content and workspace data: app metadata, keyword inputs, project configurations, instructions submitted to AI workflows, and any other content you create or upload within the product.
- AI inputs and outputs: prompts, instructions, submissions to AI-assisted workflows, and generated outputs.
- Support and communications data: the content of messages you send to us, including support requests, feedback, and correspondence.
- Cookies and tracking data: as described in Section 14.
We do not intentionally collect special category data (such as health, racial, religious, or biometric data). Please do not submit such data through the product.
6. Sources of Data
We receive personal data from the following sources:
- Directly from you: when you register, configure your account, use the product, or contact us.
- Automatically: through your use of the website and application, including server logs, session data, and cookies.
- From third-party providers: authentication providers and payment processors may share relevant account or transaction data with us in connection with your use of those integrations.
7. How and Why Data Is Used
We use personal data for the following purposes:
- To create and manage your account and authenticate your identity.
- To deliver, operate, and maintain the ASO Copilot service and all its features.
- To process payments, manage subscriptions, and administer billing.
- To improve, develop, and optimize the product, including by analyzing usage patterns and identifying areas for enhancement.
- To provide customer support and respond to your communications.
- To send transactional communications related to your account (e.g. invoices, service notices, security alerts).
- To send marketing or product communications where you have opted in or where we have a legitimate interest, subject to your right to opt out.
- To detect, prevent, and investigate fraud, abuse, security incidents, and unauthorized access.
- To comply with applicable laws, regulations, and legal obligations.
- To enforce our Terms of Service and other agreements.
- To carry out internal business operations including auditing, reporting, and financial administration.
We may also use aggregated or de-identified data — which cannot reasonably be used to identify you — for analysis, research, service improvement, and business intelligence purposes without restriction.
8. Legal Bases for Processing
Where applicable law requires a legal basis for processing personal data (including under the GDPR and similar frameworks), we rely on the following bases, mapped to the purposes described in Section 7:
- Performance of a contract (Art. 6(1)(b) GDPR): processing necessary to provide the service you have signed up for — including account creation and management, feature delivery, billing, and fulfillment of support requests.
- Legitimate interests (Art. 6(1)(f) GDPR): we process data where we have a legitimate interest that is not overridden by your rights and interests. Specific legitimate interests we rely on include: fraud detection and prevention; security monitoring and abuse prevention; improving and developing the product through analysis of usage patterns; enforcing our terms; administering our business operations including auditing, reporting, and financial administration; and, for existing customers, direct marketing of our own similar products and services. For each purpose for which we rely on legitimate interests, we maintain an internal Legitimate Interests Assessment (LIA) documenting our balancing exercise. You may request information about our LIA by contacting us. Where we rely on legitimate interests, you have the right to object (see Section 20).
- Legal obligation (Art. 6(1)(c) GDPR): processing required to comply with applicable laws, regulations, tax obligations, or lawful orders from competent authorities.
- Consent (Art. 6(1)(a) GDPR): where we rely on consent — for example, for certain marketing communications to non-customers or for non-essential cookies — you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
9. Account and Profile Data
When you register for ASO Copilot, we collect the information necessary to create and secure your account, including your email address and authentication credentials. Authentication is handled through a third-party authentication provider. We retain account data for as long as your account is active and for a reasonable period thereafter to accommodate account recovery, legal compliance, and dispute resolution.
10. Billing and Transaction Data
Billing and payment processing is handled by our third-party payment processor. We do not store full payment card details on our systems. We retain billing records — including subscription history, invoice amounts, and transaction identifiers — as needed for financial administration, tax compliance, fraud prevention, and legal obligations. Billing data may be retained beyond account deletion to satisfy financial reporting requirements.
11. Usage, Device, Log, and Analytics Data
We automatically collect technical and usage data when you interact with our website and application. This includes server logs (IP address, request timestamps, HTTP status codes), browser and device information, session identifiers, feature interaction logs, and navigation patterns. This data is used for security monitoring, abuse prevention, system reliability, debugging, and improving the quality and performance of the service.
We do not currently use third-party analytics tools. If we introduce such tools in the future, they will process data on our behalf under appropriate data processing agreements and this policy will be updated accordingly.
12. Customer Content, Workspace Data, Inputs, and Outputs
You may submit content to ASO Copilot in the course of using the service, including app metadata, keyword lists, workflow configurations, instructions, and other inputs. This content is stored and processed to deliver the service features you use.
Customer content remains yours. We do not claim ownership over content you submit. We process it solely to operate and improve the service, prevent abuse, and fulfill legal obligations. We do not sell customer content.
You are responsible for ensuring that any content you submit does not violate the rights of third parties or applicable law. Do not submit sensitive personal data belonging to others unless you have a lawful basis for doing so.
Business customers — controller and processor roles: where you use ASO Copilot in a professional or business capacity and any content you submit relates to personal data of your own end-users or third parties, you act as a data controller in respect of that data and we act as a data processor on your behalf. In such cases, our processing of that data is governed by a data processing agreement between us, which incorporates appropriate technical and organizational safeguards. To request our standard Data Processing Agreement (as required under GDPR Art. 28), please contact us at [email protected] . You must not use the service to process personal data of others in a context that requires a DPA without first executing one with us.
13. AI-Related Processing
ASO Copilot uses artificial intelligence and machine learning models to power certain features, including keyword suggestions, metadata generation, content drafting, and related workflow automation. When you use these features, the prompts, instructions, and content you submit may be processed by AI systems — including models provided by third-party AI infrastructure vendors — in order to generate outputs.
The following disclosures apply to AI-assisted functionality:
- Third-party AI model providers may be involved in processing your inputs and generating outputs. Their handling of data is subject to their own terms and privacy practices. A list of our current AI infrastructure providers is available on request at [email protected] .
- We may use aggregated, de-identified, or anonymized usage data — including interaction patterns and non-personal workflow metadata — to improve our service and AI-related features, where lawfully permissible.
Automated decision-making and profiling: certain features of ASO Copilot use automated processing — including AI models — to analyze inputs and generate outputs such as keyword suggestions and metadata drafts. These outputs are provided as recommendations only and do not constitute automated decisions producing legal or similarly significant effects on you within the meaning of Article 22 of the GDPR. All outputs require your review and active decision before use. If you have questions about the logic involved in a specific automated feature, please contact us.
EU AI Act (Art. 50) transparency: where the Service uses AI systems that interact with you as a natural person, we will inform you at or before the point of interaction that AI is involved in generating those outputs. For the full scope of our AI transparency obligations and user responsibilities, see §10 of our Terms of Service.
14. Cookies and Similar Technologies
We and our third-party service providers use cookies, local storage, and similar tracking technologies on our website and application. Only strictly necessary cookies are currently in use; we will update this policy and seek your consent before introducing any non-essential cookies.
Current cookies in use:
| Name / Prefix | Provider | Purpose | Duration |
|---|---|---|---|
__clerk_*, __session |
Clerk (auth provider) | Authentication, session management, and security (strictly necessary) | Session / up to 1 year |
Local Storage keys (clerk-*) |
Clerk | Client-side session state for authentication (strictly necessary) | Until cleared |
- Analytics cookies: we do not currently use analytics cookies. If we introduce analytics tools in the future, we will update this policy and, where required by applicable law, seek your consent before placing any such cookies.
- Marketing cookies: we do not currently use marketing or advertising cookies. If this changes, we will update this policy and, where required by applicable law, seek your consent before placing any such cookies.
You may control cookie preferences through your browser settings. Disabling authentication cookies will prevent you from accessing the service. Where required by law, we will request your consent before placing non-essential cookies. To withdraw consent for any non-essential cookies (if introduced), you may update your preferences through the consent mechanism we will provide at that time.
15. Sharing and Disclosure of Data
We do not sell your personal data. We may share your data in the following circumstances:
- Service providers and subprocessors: we share data with trusted third-party vendors who process data on our behalf to deliver the service (see Section 16).
- Legal compliance: we may disclose data if required to do so by applicable law, regulation, court order, or lawful request from a government or regulatory authority.
- Protection of rights: we may disclose data where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of ASO Copilot, our users, or others.
- Business transfers: in the event of a merger, acquisition, reorganization, asset sale, or similar transaction, your data may be transferred to the relevant successor entity (see Section 23).
- With your consent: we may share data in other ways where you have given explicit consent.
16. Service Providers and Subprocessors
We engage third-party service providers to support the delivery and operation of ASO Copilot. These providers act as our data processors and are permitted to use your personal data only as instructed by us and in accordance with this policy. We take reasonable steps to ensure these providers offer appropriate technical and organizational data protection measures.
Our subprocessors may include providers in the following categories:
- Cloud hosting and infrastructure providers
- Authentication and identity management providers
- Payment processors and billing platforms
- AI and machine learning model providers (including large language model APIs and natural language processing services)
- ASO data and keyword intelligence providers
A named list of our current subprocessors is available on request at [email protected] . We will provide reasonable advance notice of any new subprocessor engagements that materially affect the processing of your personal data.
17. International Data Transfers
ASO Copilot and its service providers may process personal data in countries other than the country in which you reside. When we transfer personal data across borders, we take steps intended to ensure that appropriate protections are in place, which may include standard contractual clauses, adequacy decisions, or other legally recognized transfer mechanisms.
The data controller is established in Poland (European Union). Personal data is primarily processed within the EU/EEA. Where we engage service providers located outside the EU/EEA, we rely on one or more of the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) — European Commission's 2021 SCCs, supplemented where necessary by a Transfer Impact Assessment, for transfers to the United States and other third countries (for example, to AI model providers and cloud infrastructure providers).
- EU-US Data Privacy Framework (DPF) — where a US-based provider is certified under the DPF, we may rely on the adequacy decision adopted by the European Commission on 10 July 2023 as the transfer mechanism instead of or in addition to SCCs.
- UK adequacy decision — transfers to our payment processor Paddle.com Market Limited, a UK entity, are covered by the European Commission's adequacy decision for the United Kingdom.
A current list of our third-country transfers and the applicable transfer mechanism for each is available on request at [email protected] .
18. Data Retention
We retain personal data for as long as necessary to fulfill the purposes described in this policy, unless a longer period is required or permitted by law. The table below sets out our indicative retention periods for key data categories:
| Data category | Retention period |
|---|---|
| Account and identity data | Duration of active account + 12 months for recovery, then deleted or anonymized |
| Billing and transaction records | 5 years from end of the relevant tax year (Polish Ordynacja podatkowa) |
| Server logs and technical data | Up to 90 days on a rolling basis |
| Support communications | 2 years from last contact |
| Customer content and workspace data | Duration of active account + 30 days after account closure |
| AI inputs and outputs | Duration of active account + 30 days after account closure, or shorter if requested |
Upon account deletion, we will delete or anonymize your personal data within the periods above, subject to any longer retention required by legal obligation, fraud prevention, dispute resolution, or financial record-keeping requirements.
19. Data Security
We implement technical and organizational measures designed to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures are calibrated to the nature of the data and the risks involved in its processing.
No method of transmission over the internet or electronic storage is completely secure. While we take reasonable steps to safeguard your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials and for notifying us promptly if you suspect unauthorized access to your account.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals directly, as required by applicable law.
Data Protection Officer (DPO). We have assessed whether the appointment of a Data Protection Officer is required under GDPR Art. 37. Given the nature, scope, and scale of our processing activities — primarily B2B SaaS operations without large-scale systematic monitoring or processing of special category data — we have determined that the appointment of a DPO is not currently mandatory. We will reassess this determination if our processing activities materially change.
20. Your Rights
Depending on your location and applicable law, you may have some or all of the following rights with respect to your personal data:
- Access: the right to request a copy of the personal data we hold about you.
- Correction: the right to request that inaccurate or incomplete data be corrected.
- Deletion: the right to request deletion of your personal data, subject to retention obligations.
- Restriction: the right to request that processing be restricted in certain circumstances.
- Portability: the right to receive a machine-readable copy (in JSON or CSV format, as applicable) of data you have provided, where processing is based on consent or contract. You may also request that we transmit such data directly to another controller where technically feasible.
- Objection (general): the right to object to processing based on legitimate interests, on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Objection to direct marketing (absolute): where we process your data for direct marketing purposes, you have the unconditional right to object at any time. We will cease using your data for direct marketing immediately upon receipt of your objection, without any requirement to justify your request.
- Withdrawal of consent: where processing is based on your consent, the right to withdraw consent at any time without affecting prior processing.
- Automated decision-making (Art. 22 GDPR): where processing consists solely of automated means and produces legal or similarly significant effects concerning you, the right to: (i) request human intervention; (ii) express your point of view; and (iii) contest the decision. As described in Section 13, ASO Copilot's AI outputs are recommendations requiring your active review and do not currently constitute Art. 22(1) automated decisions — but this right applies should that position ever change.
- Complaint (Art. 13(2)(d) GDPR): the right to lodge a complaint with a supervisory authority — in particular, the Polish Data Protection Authority (Urząd Ochrony Danych Osobowych — UODO, ul. Stawki 2, 00-193 Warsaw; uodo.gov.pl ) as the lead supervisory authority for this controller — if you consider that processing of your personal data infringes applicable data protection law. You may also lodge a complaint with the supervisory authority in your country of habitual residence or place of work.
To exercise any of these rights, please contact us at [email protected] . We will respond within one month of receiving your verified request. Where requests are complex or numerous, we may extend this by a further two months; we will inform you of any extension and its reasons within the first month, as required by GDPR Art. 12(3). We may need to verify your identity before processing your request.
21. Marketing Communications
We may send you product updates, feature announcements, and promotional communications by email. For business or professional users who are existing customers, we may do so on the basis of our legitimate interests in marketing our own similar products and services, subject to your right to object at any time. For all other recipients, we will obtain prior consent before sending marketing communications. You may opt out at any time by clicking the unsubscribe link in any such message or by contacting us. Opting out does not affect transactional or service-related messages.
22. Children
ASO Copilot is designed for use by businesses, developers, and professional users. The service is not directed at children under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it promptly. If you believe we have collected data from a child, please contact us at [email protected] .
23. Business Transfers
In the event that ASO Copilot or its assets are acquired by, merged with, or transferred to another entity — whether through a merger, acquisition, asset sale, restructuring, or other corporate transaction — your personal data may be transferred as part of that transaction. Where required by applicable law, we will provide notice of such a transfer and describe any material changes to how your data is handled.
24. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the product, applicable law, or our data practices. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will provide advance notice through the product or by email before the changes take effect. We encourage you to review this policy periodically to stay informed about how we handle your data.
25. How to Contact Us
For any questions or requests relating to this Privacy Policy, including exercising your rights or reporting a concern, please contact us:
Email: [email protected]
We aim to acknowledge all privacy-related inquiries promptly and will respond within the period required by applicable law.
26. Region-Specific Rights
European Economic Area, United Kingdom, and Switzerland
The data controller (Kiryl Sadko) is established in Poland, an EU member state. The processing of personal data of EEA residents is therefore subject to the GDPR directly. The rights described in Section 20 apply in full. As the controller is established in the EU, no Art. 27 GDPR representative is required. If you are located in the UK, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk .
If you are located outside the EEA or UK and believe you have rights under applicable local privacy law, please contact us and we will consider your request in good faith.