Storestand logoStorestand

Privacy Policy

Last updated: July 12, 2026

This policy describes how Storestand ("we", "us") collects, uses and protects information when you use our website-building service for iOS apps (the "Service").

Information we collect

  • Account data. Your name, email address and a hashed password when you register. We never store passwords in plain text.
  • Session data. For security, active sessions record an IP address and browser user agent.
  • Content you create. The sites, sections, images, legal documents, app-ads.txt and llms.txt content you build with the editor, and settings such as custom domains and social links.
  • Imported App Store data. When you import an app, we fetch its public listing (name, icon, screenshots, description, rating) from Apple's public APIs and store it with your site.
  • Support communication. Emails you send us.

Your Apple App Store Connect key never reaches us

If you connect App Store Connect, your .p8 private key is read and used only inside your browser. It is sealed into a non-exportable browser key, is never uploaded to or stored on our servers, and optionally persists only on your own device. Our servers see a short-lived request token (valid ≤15 minutes) that is forwarded to Apple and never stored. Your Issuer ID and Key ID are kept in your browser's local storage, not in our database.

Cookies and local storage

We use a single essential, httpOnly session cookie to keep you signed in. Your theme preference and App Store Connect identifiers live in your browser's local storage. We do not use advertising or third-party analytics cookies.

How we use information

  • To provide, secure and improve the Service.
  • To publish the sites you choose to publish.
  • To enforce rate limits and prevent abuse.
  • To respond to support requests.

We do not sell your personal data.

Service providers

We run on cloud infrastructure providers (hosting, database, content delivery) that process data on our behalf under their own security commitments. When you use App Store features, requests are made to Apple under Apple's terms.

Published sites and their visitors

Sites you publish are delivered by our infrastructure, which keeps standard server logs. The privacy practices of an individual published site (including its own privacy policy) are the responsibility of the account that created it.

When a published site collects visitor data through platform features — waitlist signups or contact-form messages — we store that data (email address, and for contact forms the message itself) as a processor on behalf of the site owner, who is the data controller. We use it for nothing else, never sell it, and delete it when the owner deletes it, the site, or their account. Visitors can request erasure via the site's contact page or from us directly.

Data retention and deletion

Your data is kept while your account exists. Deleting a site permanently removes its sections and legal documents. To delete your account and all associated data, contact us at hello@storestand.app.

Your rights

Depending on where you live (including under the GDPR), you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. Email us and we will act on verified requests.

Security

All traffic is served over HTTPS, passwords are hashed, and the Service is designed so that your most sensitive secret — your Apple signing key — never leaves your device.

Children

The Service is not directed to children under 16.

Changes

We will post any changes to this policy on this page and update the date above. Material changes will be communicated to registered users.

Contact

Privacy questions or requests: hello@storestand.app