Privacy Policy

Last updated: July 31, 2026

We take data protection seriously and process personal data in accordance with the GDPR.

1. Data Controller

Wotaso GmbH
Bostonring 5
71686 Remseck am Neckar
Germany
Email: [email protected]

Represented by the Managing Director: Lucas Damian Orzan
Registered office: Remseck am Neckar
Commercial Register: HRB 801744
Register Court: District Court of Stuttgart
VAT ID: DE457485481

2. What Data We Collect

Account Data

  • Name (if provided)
  • Email address
  • Account ID

Service Data

  • App metadata you enter or generate
  • Locale settings
  • Keyword data
  • Usage actions in the dashboard

Technical Data

  • IP address (temporarily in server logs)
  • Device/browser information

Error Monitoring

We use Sentry to detect and fix errors. This may include technical data and error context.

Hosted AI Data

When you choose a hosted AI feature, LocalizeASO sends the minimum content needed to OpenAI through our server-side proxy. This can include App Store metadata, locale and keyword context, your instructions, and validation feedback. App Store Connect private keys are not sent to OpenAI.

We store the generated proposal and an access-controlled, append-only audit record containing the actual provider and model, time, prompt/policy/workflow versions, and cryptographic input/output hashes. Human edits and approval are recorded separately. The audit record does not store a second copy of the raw prompt solely for provenance.

3. Payment Data

Payments are handled by our payment provider. We do not store full payment details.

4. How We Use Data

We process data to:

  • Provide and operate the Service
  • Authenticate users
  • Store metadata drafts
  • Generate and review AI-assisted metadata when you request it
  • Communicate with users
  • Improve stability and performance
  • Ensure security

Legal basis: contract performance (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f)).

Hosted AI processing is necessary to perform the feature you request (Art. 6(1)(b) GDPR). Security, abuse prevention, and compliance audit records rely on our legitimate interest (Art. 6(1)(f) GDPR), balanced against data minimization and access controls.

5. Analytics

We use AnalyticsCLI to understand how visitors use our website, how users move through onboarding and checkout, and how product features are used. We may collect anonymous, non-persistent analytics without storing a user identifier. With consent in the browser banner, we also remember analytics state across visits.

Data processed:

  • Page views
  • Referrer URL
  • Device type (generalized)
  • Country (derived from anonymized IP)
  • UTM parameters (if provided)

We do not:

  • Use third-party tracking cookies
  • Track users across websites
  • Create behavioral advertising profiles
  • Store full IP addresses

Legal basis for persistent optional website analytics: Art. 6(1)(a) GDPR (consent). Anonymous aggregate analytics may rely on Art. 6(1)(f) GDPR (legitimate interest). Essential auth, checkout, and fraud-prevention processing may also rely on contract performance or legitimate interest where applicable.

6. Product Analytics (Authenticated Users)

Within our authenticated dashboard and plugin, we use AnalyticsCLI custom events and custom properties to understand feature usage and improve product quality.

Data processed:

  • Feature usage events
  • Generalized technical metadata (browser/device category)
  • Initial acquisition properties (UTM/referrer/path, if available)

We do not process:

  • Email addresses
  • Names
  • Content created within the product
  • Uploaded files or design data

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in product improvement and system security).

Users can opt out of product analytics at any time in account settings.

7. Hosting & Subprocessors

Provider Purpose Location
PostgreSQL / Better Auth Database & authentication Germany
Hetzner Backend hosting Germany
AnalyticsCLI Web + product analytics EU
GlitchTip (self-hosted) Error monitoring EU
OpenAI Ireland Ltd. Hosted AI metadata generation and localization EEA and other locations used by its approved subprocessors

8. Data Retention

We retain account data as long as your account exists. You may request deletion at any time.

Analytics data is automatically deleted after 12 months unless a shorter period is required by law.

AI proposals, human review records, and AI-origin export manifests are retained while your account exists so you can audit what was generated and approved. They are deleted through our controlled account-deletion process unless legal retention duties apply. Under the current API project settings, OpenAI retains Responses API application state for at least 30 days by default and may retain abuse-monitoring data for up to 30 days. A shorter, Modified Abuse Monitoring, or Zero Data Retention setting would apply only if it is separately approved and activated for our project.

9. Security

We use encryption, access controls, and secure infrastructure to protect data.

10. Your Rights (GDPR)

You have the right to:

  • Access your data
  • Correct data
  • Delete data
  • Restrict processing
  • Data portability
  • Lodge a complaint with a supervisory authority

11. Data Transfers

Our analytics stack is self-hosted in the EU. Hosted AI data may be processed outside the EEA by OpenAI or its approved subprocessors. OpenAI's Data Processing Addendum applies; where required, transfers are protected by the EU Standard Contractual Clauses and supplementary safeguards. No data is shared with third-party advertising providers.

12. Opt-Out

Authenticated users can disable product analytics in account settings. Website visitors can block analytics through browser settings.

13. Changes

We may update this policy.

14. Contact

Email: [email protected]