SubmitCheck service information
GDPR Compliance
How SubmitCheck handles personal data and the choices and rights available where the General Data Protection Regulation (GDPR) applies. This page supplements our Privacy Policy; it is not a certification.
Este documento está disponível em inglês.
SubmitCheck and your personal data
SubmitCheck is operated by emonster inc., the US company. It is the controller for personal information it uses to operate its website, waitlist, accounts, and support. The local macOS app and CLI inspect files without networking; hosted processing happens separately through the protected web portal. Contact [email protected] about your data.
The information we use and why
The waitlist uses your email, language, notice and choice records to manage your signup, acknowledgement, launch notification, and optional marketing. Coarse technical and acquisition context is included only with optional analytics consent. The server separately uses the request IP for abuse protection and an IPinfo country/continent lookup, retaining the limited result with the signup. Demand totals use minimized groups.
Google sign-in supplies identity for protected access. Hosted reports use confirmed sanitized build evidence and authorized Apple submission facts to explain detectable issues. Support uses information you send. Minimization does not make every identifier or report anonymous. These are the purposes of processing; accepting Terms is not blanket consent for them.
Consent and communication choices
Optional marketing starts only when you choose it; its unsubscribe link stops product news and offers. The launch request is separate. Contact [email protected] to leave that list. Optional Google Analytics and optional signup context are controlled by Privacy settings. Declining either optional choice does not prevent a waitlist signup.
For processing based on consent, withdrawal does not affect earlier lawful processing. Browser Privacy settings affects future collection from that browser and does not erase earlier server data. Terms acceptance, permission to access an Apple account, and email-address verification are distinct actions; none establishes GDPR consent for every purpose or another person.
Service providers and recipients
Google/Firebase supplies hosting, identity, databases, storage, server functions, secrets, reCAPTCHA Enterprise, and optional analytics. Resend receives the address and message content needed for waitlist and internal notification emails and returns delivery events. IPinfo receives the raw request IP to estimate country and continent. Apple supplies authorized submission facts. Authorized staff use information needed to operate and support SubmitCheck.
Configured hosted billing uses Stripe; optional configured AI review uses a minimized findings envelope. These are separate from the public signup. See the Privacy Policy for the data boundary and purpose of each service.
Local files and authorized Apple evidence
Raw builds, source, assets, dSYMs, and private keys stay outside hosted report intake. The macOS app and CLI do not connect to App Store Connect. App Store Connect key storage, updated September 18, 2026: the protected web portal sends a selected .p8 API key to the authenticated backend for encrypted, workspace-isolated Google Secret Manager storage. The server signs short-lived tokens and performs allowlisted GET-only Apple calls; keys and tokens are not returned to the browser.
A user can explicitly submit sanitized evidence for a hosted report. That evidence can include app identifiers, build and signing facts, privacy summaries, and authorized submission configuration.
Browser storage and automated processing
The site stores public language, appearance, and analytics choices in the browser. Profile language, appearance, timezone and table page size are saved with your account and cached in the browser. Public Google Analytics runs only after opt-in; protected routes and unsubscribe pages exclude it. reCAPTCHA Enterprise uses the _GRECAPTCHA risk-analysis cookie when it runs. Security processing is separate from optional analytics.
Submission checks produce findings and identify missing evidence for a developer’s review. They do not decide Apple approval. If a decision about you falls within the GDPR’s rules for solely automated decisions with legal or similarly significant effects, the applicable protections and exceptions must be considered.
Retention and deletion
A confirmed account-deletion request immediately freezes normal access and processing for 30 days. Sign-in alone does not reactivate it. Explicit reactivation is available before the deadline; permanent deletion can be requested sooner. The Privacy Policy describes the two user notices, internal request notice, legal exceptions and backup expiry within 30 days after permanent deletion.
Waitlist expiry is set 24 months from original creation, without an extension on duplicate signup; abuse records expire within 24 hours. Aggregate records expire 36 months after period end, with small groups suppressed. Database expiry deletion is asynchronous.
Temporary sanitized inputs are removed after processing, abandoned uploads expire within 24 hours, and reports expire after 365 days. The portal includes scan, cycle, and account deletion controls. Delivery, support, security, financial, and backup records may require separate handling. Marketing unsubscribe, clearing browser storage, and disconnecting Apple do not erase all associated data. Contact us about the records that concern you.
Security and international processing
Local inspection, explicit upload, server authorization, schema validation, and restricted storage help limit exposure. No system provides absolute security. Providers may process data in the United States and other countries outside your own. The GDPR’s transfer rules apply where relevant; a provider’s public terms or a selected region alone does not establish the safeguards for every processing activity. Contact us for information about applicable safeguards.
Your rights under the GDPR
Where applicable, you can request access to personal data and correction of inaccurate data. Erasure and restriction are available when the GDPR’s conditions are met. Portability applies to qualifying data you provided when processing is automated and based on consent or contract.
You may object to processing based on legitimate interests or a public task on grounds relating to your situation. You may object to direct marketing at any time. Consent can be withdrawn for processing based on it. These rights have conditions and exceptions; deleting one item does not necessarily require deletion of every associated record.
Make a privacy request
Email [email protected] with your request and enough information to identify the relevant account or signup. Do not send passwords, keys, or app binaries. Where reasonable doubt exists, proportionate identity checks may be needed.
The GDPR requires a response without undue delay and normally within one month of receipt. An extension of up to two further months may be permitted for complexity or volume, with notice and reasons within the first month. If a request is refused, the reasons and available remedies must be explained. Requests are generally free, subject to the GDPR’s limited exceptions.
Complaints and further information
You may complain to a supervisory authority, particularly in the EU country of your habitual residence, place of work, or the alleged infringement, and seek a judicial remedy. The official sources below explain the applicable requirements.