Legal
Privacy Policy
What we hold about you, why we hold it, who else sees it, how long it stays, and how to get it out or have it deleted.
Last updated: August 26, 2026
Who we are
Charted Apps ranks App Store apps by verified customer growth, at chartedapps.com. It is operated from Germany by Sorin-Ionut Curescu, who decides what happens to the data described here and is therefore its controller. The postal address is on the imprint, published once rather than repeated on every page that mentions us. We are too small to be required to appoint a Data Protection Officer, and have not appointed one.
Every request under this policy goes through the contact form, and is answered by email.
How the product works
Anyone can paste an App Store link and the listing joins the board, read from Apple's public lookup. The owner claims it by signing in with GitHub and connecting a read-only RevenueCat key whose project contains that listing's bundle id. From then on we pull that project's growth charts every six hours and publish what the owner chooses to publish. There is no password and no advertising cookie. Site usage may be measured with Google Analytics after you accept the cookie banner, described below.
What we collect
- Your GitHub account. Signing in gives us your handle, your account email address and your avatar, through GitHub's OAuth. The handle is public on a listing you have claimed, because naming the owner is what makes a claim mean anything. Sign-in is handled by better-auth; we never see or store a GitHub password.
- Your RevenueCat key, if you claim. One v2 secret key with two read scopes, encrypted with AES-256-GCM before it touches the database, under a secret that does not live in the database. The API never returns it to anybody, including you. What it can read is set out on the Security page.
- The growth figures we pull with it. New customers, MRR, revenue, active subscriptions, trials and churn for the connected project, snapshotted over time. These describe an app, not a person: we never receive your customers' identities, receipts, email addresses or device identifiers, because the key's scopes cannot read them.
- What you write here. Growth notes you pin to your own record, your portfolio bio and social links, and any report, message or takedown you send us.
- Sponsorship records. If you buy an ad window, we hold the order, the window, and your Stripe customer and session ids. Payment card details go to Stripe and never reach us.
- Counters. One number per event kind, subject and UTC day: board views, profile views, store clicks, ad impressions and ad clicks. No IP addresses, no user agents, no user ids, no raw event log. There is nothing in these rows to identify anyone by.
- Google Analytics. Only after you accept the cookie banner. Google then receives page URLs, approximate location derived from IP, device and browser details, and a client id stored in its own cookies. We use it to understand traffic and which pages people open, not to sell ads against you. Google's processing is governed by their terms and their data processing agreement with us. Rejecting the banner, or later withdrawing consent from Cookies in the footer, keeps analytics storage denied and no Analytics cookies are set.
- Rate-limit counters. A count per IP address per UTC day, used to stop one address flooding the site, purged when the day closes. Nothing is stored beside it: no page, no account, no history.
- Diagnostics. Server error reports, so a broken page gets fixed.
We do not collect passwords, advertising identifiers, or precise location. We do not receive anything from the App Store beyond what Apple publishes on a public listing page. Google Analytics is the one Google surface on this site; it is not a lookup of your App Store account.
Cookies
Three kinds. After you sign in, a session cookie keeps you signed in for thirty days. It is HTTP-only, and marked Secure on any https deployment. Separately, if you accept the cookie banner, Google Analytics sets its own first-party cookies (names that start with _ga) so return visits can be counted as the same browser. Your Accept or Reject choice is kept in your own browser's local storage so we do not ask again every visit; the same storage holds your theme preference. There is no advertising cookie and no marketing pixel. You can change the Analytics choice at any time from Cookies in the footer, which brings the banner back.
Why we are allowed to hold it
- Contract. Signing you in, holding your claim, pulling your project's charts, publishing the record you asked us to publish, and delivering an ad window you bought.
- Consent. Google Analytics, only after you accept the cookie banner. You can withdraw that consent at any time from Cookies in the footer.
- Legitimate interest. Keeping the site up and honest: rate limits, moderation, error reports, aggregate counters, and the public listing of an App Store app that has not been claimed yet.
- Legal obligation. Tax and invoicing records behind a sponsorship, which the law requires us to keep.
Listings nobody has claimed
A listing on the board before its owner claims it carries only what Apple already publishes about it: name, subtitle, icon, category, seller, price and rating count, plus the link back to the App Store. It never carries a growth figure, a rank or a number of any kind, because we have no verified data about it and we do not show unverified numbers next to verified ones.
The seller name Apple publishes is sometimes a person rather than a company. If that is you and you would rather not be listed here at all, say so through the contact form and we will remove the listing. You do not have to claim an app to have it taken down, and we do not ask you to prove ownership twice.
What you control once you have claimed
- Per metric, how much shows. Every published figure is exact, a band ("$1k to 5k MRR"), or withheld entirely. Trials and churn are withheld by default.
- Whether your name is on it. An anonymous listing keeps its verified numbers and its rank, and loses its name, icon, subtitle, seller and store link from every page, card and feed.
- Whether it reports at all. Pausing deletes the stored key and stops the polling; hiding takes the listing off the board, out of search and out of the sitemap.
- Whether you have a portfolio page. The page at /u/your-handle can be hidden with one switch.
Rank, pace and milestones are always computed from the exact values we hold, never from what is printed. That is the trade the board is built on: we can be the validator without making you publish a number you are not ready to publish.
Who else sees it
We never sell personal data and we never share it for advertising. It reaches exactly these places:
- GitHub, which authenticates you. We receive a profile from them; they receive nothing about your use of this site.
- RevenueCat, which we call with your key to read your project's charts.
- Apple, whose public iTunes lookup and RSS feeds we read for listing data. Reading them tells Apple nothing about who was looking.
- Stripe, which takes sponsorship payments, calculates tax, and emails your receipt.
- Resend, which delivers the mail we send, and Sentry, which receives error reports.
- Google, which receives the Analytics events described above when you have accepted the cookie banner and then load a page.
- Our host. The site runs on one server we rent, with the database on the same machine.
- Anyone we are legally required to tell, and nobody else.
Some of these providers are outside the EU. Where they are, the transfer runs on the European Commission's standard contractual clauses.
What is public on purpose
A board is a public thing, so it is worth being exact about which parts of it are. On a claimed listing: the app's identity, the owner's GitHub handle, the figures the owner chose to publish, the rank, the milestones, the notes they pinned, and the portfolio page that collects them. Share cards and the rank badge render the same facts as images so they can travel.
Not public, ever: your key, your email address, your Stripe details, your owner dashboard, and any figure you set to private.
How long we keep it
- Your account, claim and record: while the account exists.
- Snapshots, milestones and notes: kept as history. Hiding a listing is not deleting it, because a milestone link somebody already shared must not turn into a dead end.
- Your RevenueCat key: until you rotate it, pause reporting, or ask us to delete it.
- Aggregate counters: 400 days, then swept.
- Rate-limit counters: until the UTC day closes.
- Sponsorship orders and invoices: as long as tax law requires, which is longer than the rest of this list and is the one thing a deletion request cannot reach.
Your rights
Under the GDPR and comparable laws you can ask us to show you what we hold, correct it, delete it, restrict or stop our use of it, hand it to you in a portable format, or object to processing we base on legitimate interest. Ask through the contact form. We answer within a month, and usually far sooner.
Deleting your account removes your account, your claim, your key, your notes and your portfolio. Tell us in the same message whether the app's listing should stay on the board as an unclaimed App Store listing or come off entirely, and we will do that.
If you are unhappy with how we handled it you can complain to a data protection authority: the one where you live, the one where you work, or the one where the thing you are complaining about happened. Any of them can take it, and you do not have to come to us first. The European Data Protection Board keeps the list of national authorities.
Security
Traffic is encrypted in transit. Keys are encrypted at rest under a secret held in the server environment rather than the database, so a stolen copy of the database yields ciphertext. A stolen server yields the key, which is exactly why the key we ask for is read-only and cannot change anything in your RevenueCat project. The whole threat model, including what we would do and tell you if it happened, is on the Security page.
Children
This is a tool for people who ship software commercially. It is not directed at children, and we do not knowingly hold data about anyone under 16. If we learn that we do, we delete it.
Changes
When the product changes what it holds, this page changes with it and the date at the top moves. A change that materially affects owners is also emailed to them, on the same address their account carries.
Questions, or a request about your own data: Contact.