Skip to content
SubmitCheck
ProductPricingWaitlist
Legal
Privacy PolicyTerms of ServiceGDPR Compliance
Language
🇺🇸English🇫🇷Français🇩🇪Deutsch🇮🇹Italiano🇯🇵日本語🇰🇷한국어🇧🇷Português🇪🇸Español
ProductPricingWaitlist
Legal
Privacy PolicyTerms of ServiceGDPR Compliance
🇺🇸English🇫🇷Français🇩🇪Deutsch🇮🇹Italiano🇯🇵日本語🇰🇷한국어🇧🇷Português🇪🇸Español

SubmitCheck service information

Privacy Policy

How SubmitCheck handles website and waitlist information, and how local inspection is separated from the optional hosted service.

Last updated September 18, 2026
Privacy PolicyTerms of ServiceGDPR Compliance
01

Scope and operator

SubmitCheck is operated by emonster inc., the US company. This policy covers the public website, launch waitlist, protected web portal, and related communications. emonster inc. is the controller for personal information used to operate its website, waitlist, accounts, and support. Contact [email protected] about your personal data.

The installed macOS app and CLI inspect files locally without networking. The installed app has its own bundled privacy notice. Using a local scan does not register you for the waitlist, connect an Apple account, or upload a report.

02

What stays local

The macOS app and CLI inspect user-selected iOS or iPadOS .ipa or .xcarchive files without networking and produce an inspectable, sanitized JSON manifest. The manifest contains build evidence for a separate hosted report; a local scan does not collect App Store Connect information. Raw app packages, source code, assets, dSYMs, executable bytes, and private keys are not uploaded by these tools. Temporary extraction files are removed when a scan finishes, is canceled, or fails; you control the original files and saved exports.

App Store Connect key storage, updated September 18, 2026: only the protected web portal offers App Store Connect access. When you connect, it sends your selected .p8 API key to the authenticated server for encrypted, workspace-isolated Google Secret Manager storage. The server signs short-lived scoped tokens and makes allowlisted GET-only Apple calls. Stored keys and Apple tokens are not returned to the browser, placed in reports, or logged. SubmitCheck does not request Apple Account passwords or reviewer credentials.

03

Public waitlist

We collect the email address you provide, normalize it, and record your language, original signup time, notice identifiers, Terms acceptance, and optional marketing and analytics choices. With analytics consent, the signup can also include coarse browser, operating-system and device categories, the first-party landing path, limited campaign fields, and the referring website’s origin.

The server separately processes your request IP for abuse controls and sends it to IPinfo for an approximate country and continent lookup. The signup stores the limited location result when available, and can include trusted hosting-provided coarse geography. This lookup is separate from optional analytics. Raw IP addresses, raw user-agent strings, full referrers, reCAPTCHA tokens or scores, completion-timing signals, and honeypot values are not stored with the signup. Hosting and security providers may keep operational request and diagnostic logs.

We use waitlist information to record your request, send a signup acknowledgement and the requested launch notification, manage your choices, understand demand, and protect the form from abuse. Product news and offers require the separate optional marketing choice. Signup information and choice records are also included in an internal notification to the SubmitCheck team. Resend returns delivery and failure events.

04

Accounts, hosted evidence, and data sources

If you use the protected portal, Firebase Authentication supplies Google sign-in identity, including your user identifier, email, and verification status. The service uses account and workspace membership, access, cycle, and usage records to authorize hosted operations.

You choose and confirm the sanitized JSON before submitting it. Hosted records can include bundle identifiers, versions, build and signing facts, entitlement and privacy-manifest summaries, minimized App Store Connect configuration, findings, and source citations. Apple supplies the authorized app and submission facts obtained through the portal. These records are used to compare evidence, generate reports, explain missing information, and maintain release history. Sanitized evidence is minimized; it is not necessarily anonymous.

You supply waitlist, support, and uploaded evidence directly. Google supplies sign-in identity; Apple supplies authorized submission facts; IPinfo supplies approximate geography; email and infrastructure providers supply operational events. Support correspondence includes the information you choose to send. Avoid including raw builds, private keys, reviewer credentials, or unnecessary personal information.

05

Browser storage and optional analytics

The public website uses Google Analytics through Firebase only after Allow analytics is selected. It measures public-page usage and technical events using browser identifiers and cookies. Authenticated routes and unsubscribe pages are excluded from optional analytics. Declining does not restrict access to the site or the waitlist.

Privacy settings in the public footer lets you change the choice stored in this browser. It controls future analytics collection and the optional context included with future waitlist submissions from that browser. Changing it does not erase earlier analytics or signup data. Public language and appearance choices are stored separately in the browser. Profile preferences, including language, appearance, timezone and table page size, are saved with your account and cached in the browser. The protected portal also uses authentication persistence.

reCAPTCHA Enterprise assesses form abuse using a short-lived token. When it runs, it uses the _GRECAPTCHA cookie for risk analysis. Request IP handling and the country/continent lookup described above are separate from the optional analytics setting.

06

Service providers and recipients

Google and Firebase provide hosting, authentication, backend functions, database and object storage, secret storage, analytics, and reCAPTCHA Enterprise. Resend sends waitlist acknowledgements and internal signup notifications and supplies delivery events. IPinfo receives the request IP for its location lookup. Apple provides the authorized App Store Connect service. Authorized personnel use the information needed to operate and support SubmitCheck.

Hosted billing is available only when configured and enabled. That flow uses Stripe-hosted checkout for payment details; SubmitCheck stores the necessary Stripe identifiers and entitlement state rather than card numbers. Optional hosted AI review is configuration-gated and uses a minimized findings envelope when enabled. It does not receive the raw build or Apple private key, and its output cannot change deterministic findings. These optional operations are separate from a public waitlist signup.

Information may also need to be disclosed in response to applicable legal requirements or to address misuse and protect rights.

07

Retention and deletion

Waitlist records receive a 24-month expiry from original creation. A duplicate signup does not extend that expiry. Rotating abuse records expire within 24 hours. Aggregate demand records receive a 36-month expiry from the end of their period, with small groups suppressed. Expiry-driven database deletion is asynchronous.

Temporary sanitized inputs used only for immediate analysis are removed after processing; abandoned uploads expire within 24 hours. Hosted reports expire after 365 days. Scan and submission-cycle deletion controls concern hosted data, not your original files. Disconnecting a saved Apple connection stops its use by your workspace; stored secret versions are disabled with retry if the storage service is temporarily unavailable.

Marketing unsubscribe changes your marketing choice; it does not delete the signup or withdraw the separate launch request. Clearing browser storage does not remove the saved server-side Apple connection. Revoke the original API key in App Store Connect to invalidate it at Apple. Contact [email protected] to leave the launch list or request access, correction, or deletion of information held by SubmitCheck.

08

Account deletion

After an account-deletion request is confirmed, normal product access, synchronization, background processing, reports, delivery, and analytics stop immediately. Remaining data stays frozen during a 30-day grace period, subject to existing shorter retention. Signing in only displays deletion management; it does not cancel deletion. You may explicitly reactivate before the deadline or choose Delete Permanently Now.

Permanent deletion removes this SubmitCheck account’s credentials, source and derived data, reports, stored files, preferences, configuration, and authentication identity from live systems. Other emonster products and data held independently by Apple are outside this scope. Operational logs and Resend email content and delivery logs have a 30-day retention period. Google Cloud’s mandatory administrative and system audit logs use its required 400-day retention; these restricted security records are separate from ordinary product use and are not copies of uploaded evidence, reports, or integration keys. Other narrow legal retention is limited to required records, kept separately with restricted access and an expiry or review date.

Encrypted residual backups may remain for up to 30 days after permanent deletion, isolated from ordinary use. Deletion controls are reapplied before any restored system resumes service. Copies you downloaded or that independent services hold cannot be removed by SubmitCheck.

Resend sends the request confirmation and one final warning targeted for 24 hours before the deadline. A plain-text internal notice records the request and verified context for our existing administrator. No completion email is sent. Open and click tracking remains enabled for these lifecycle emails; opens and clicks do not prove delivery, authentication, or consent.

09

Security and international processing

SubmitCheck uses access restrictions, server-side validation, and minimized evidence to protect hosted information. Waitlist records use keyed identifiers and deny direct browser database access. Local tools operate without network access. No security measure eliminates every risk.

emonster inc. and its providers may process information outside your country, including in the United States. A service region does not establish the location of all authentication, logging, email, analytics, or backup processing. Contact us for information about the safeguards applicable to your data.

10

Your choices and rights

Where the GDPR applies, you may request access and correction and, where its conditions are met, erasure, restriction, portability, or objection. You may withdraw consent for processing based on consent without affecting the lawfulness of earlier processing, and object to direct marketing. Terms acceptance and Apple account authorization are separate from GDPR consent.

Our GDPR Compliance page explains these rights, relevant limits, requests, and complaints. You can contact [email protected] using the address associated with your request. We may need proportionate information to verify identity; do not send a password, private key, or app binary.

[email protected]
SubmitCheck

Submission readiness with inspectable evidence and an explicit local-first boundary.

emonster

Product

ProductPricingWaitlist

Resources

Security

Legal

Privacy PolicyTerms of ServiceGDPR Compliance

DevTools

AppReportApp Ads InsightsASO SignalsKeyword Intelligence

Company

emonster Studioemonster Dev

Copyright © 1997–2026 emonster inc. All rights reserved.