Privacy Policy
Last updated: July 31, 2026
We take data protection seriously and process personal data in accordance with the GDPR.
1. Data Controller
Wotaso GmbH
Bostonring 5
71686 Remseck am Neckar
Germany
Email: [email protected]
Represented by the Managing Director: Lucas Damian Orzan
Registered office: Remseck am Neckar
Commercial Register: HRB 801744
Register Court: District Court of Stuttgart
VAT ID: DE457485481
2. What Data We Collect
Account Data
- Name (if provided)
- Email address
- Account ID
Service Data
- App metadata you enter or generate
- Locale settings
- Keyword data
- Usage actions in the dashboard
Technical Data
- IP address (temporarily in server logs)
- Device/browser information
Error Monitoring
We use Sentry to detect and fix errors. This may include technical data and error context.
Hosted AI Data
When you choose a hosted AI feature, LocalizeASO sends the minimum content needed to OpenAI through our server-side proxy. This can include App Store metadata, locale and keyword context, your instructions, and validation feedback. App Store Connect private keys are not sent to OpenAI.
We store the generated proposal and an access-controlled, append-only audit record containing the actual provider and model, time, prompt/policy/workflow versions, and cryptographic input/output hashes. Human edits and approval are recorded separately. The audit record does not store a second copy of the raw prompt solely for provenance.
3. Payment Data
Payments are handled by our payment provider. We do not store full payment details.
4. How We Use Data
We process data to:
- Provide and operate the Service
- Authenticate users
- Store metadata drafts
- Generate and review AI-assisted metadata when you request it
- Communicate with users
- Improve stability and performance
- Ensure security
Legal basis: contract performance (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f)).
Hosted AI processing is necessary to perform the feature you request (Art. 6(1)(b) GDPR). Security, abuse prevention, and compliance audit records rely on our legitimate interest (Art. 6(1)(f) GDPR), balanced against data minimization and access controls.
5. Analytics
We use AnalyticsCLI to understand how visitors use our website, how users move through onboarding and checkout, and how product features are used. We may collect anonymous, non-persistent analytics without storing a user identifier. With consent in the browser banner, we also remember analytics state across visits.
Data processed:
- Page views
- Referrer URL
- Device type (generalized)
- Country (derived from anonymized IP)
- UTM parameters (if provided)
We do not:
- Use third-party tracking cookies
- Track users across websites
- Create behavioral advertising profiles
- Store full IP addresses
Legal basis for persistent optional website analytics: Art. 6(1)(a) GDPR (consent). Anonymous aggregate analytics may rely on Art. 6(1)(f) GDPR (legitimate interest). Essential auth, checkout, and fraud-prevention processing may also rely on contract performance or legitimate interest where applicable.
6. Product Analytics (Authenticated Users)
Within our authenticated dashboard and plugin, we use AnalyticsCLI custom events and custom properties to understand feature usage and improve product quality.
Data processed:
- Feature usage events
- Generalized technical metadata (browser/device category)
- Initial acquisition properties (UTM/referrer/path, if available)
We do not process:
- Email addresses
- Names
- Content created within the product
- Uploaded files or design data
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in product improvement and system security).
Users can opt out of product analytics at any time in account settings.
7. Hosting & Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| PostgreSQL / Better Auth | Database & authentication | Germany |
| Hetzner | Backend hosting | Germany |
| AnalyticsCLI | Web + product analytics | EU |
| GlitchTip (self-hosted) | Error monitoring | EU |
| OpenAI Ireland Ltd. | Hosted AI metadata generation and localization | EEA and other locations used by its approved subprocessors |
8. Data Retention
We retain account data as long as your account exists. You may request deletion at any time.
Analytics data is automatically deleted after 12 months unless a shorter period is required by law.
AI proposals, human review records, and AI-origin export manifests are retained while your account exists so you can audit what was generated and approved. They are deleted through our controlled account-deletion process unless legal retention duties apply. Under the current API project settings, OpenAI retains Responses API application state for at least 30 days by default and may retain abuse-monitoring data for up to 30 days. A shorter, Modified Abuse Monitoring, or Zero Data Retention setting would apply only if it is separately approved and activated for our project.
9. Security
We use encryption, access controls, and secure infrastructure to protect data.
10. Your Rights (GDPR)
You have the right to:
- Access your data
- Correct data
- Delete data
- Restrict processing
- Data portability
- Lodge a complaint with a supervisory authority
11. Data Transfers
Our analytics stack is self-hosted in the EU. Hosted AI data may be processed outside the EEA by OpenAI or its approved subprocessors. OpenAI's Data Processing Addendum applies; where required, transfers are protected by the EU Standard Contractual Clauses and supplementary safeguards. No data is shared with third-party advertising providers.
12. Opt-Out
Authenticated users can disable product analytics in account settings. Website visitors can block analytics through browser settings.
13. Changes
We may update this policy.
14. Contact
Email: [email protected]
LocalizeASO