Privacy policy
What the beta stores
RateMyApp stores the name and email you enter, a salted password hash, session records, your app listings, testing assignments, private feedback, optional screenshot evidence, credit transactions, purchase references and issue reports. Payment card details are processed by Stripe and are not stored in our database. Basic request identifiers are hashed for temporary abuse prevention. Never upload credentials, payment information or sensitive personal records.
Who can see your work
Community star ratings and optional rating comments are visible to signed-in members. App names, store links, testing briefs and developer display names are visible to signed-in community members. In the workspace, test reports and screenshots are visible to the participating tester and app owner. Authorized operators may access records to maintain the service and investigate reports. Testing circles expose member app listings to their members. Account emails are not shown in the discovery feed. Referrers can see their invited members’ display names, signup and verification status, and referral credit bonuses. Email addresses, payment amounts and card details are not shared with referrers. Referral relationships and hashed email identifiers are stored to prevent duplicate rewards.
Infrastructure and cookies
The service is designed to run on Cloudflare Workers and D1. Cloudflare Email Sending delivers verification and recovery email, and sends internal registration alerts to our authorized operator inbox. These alerts include the account name, email, signup time and verification status. When automatic report approval is enabled, Cloudflare Workers AI processes the submitted screenshot, report and app brief to screen their relevance. Remove private information before uploading. AI can be wrong; uncertain or unavailable screening leaves the report for owner review. It does not establish image authenticity or actual app use. An essential session cookie keeps you signed in. The optional demo saves sample activity in your browser and can be reset from Profile. Visiting a referral link saves its code in browser storage for up to 30 days to attribute a new signup; it is cleared when signup completes. You can remove the invitation on the signup form. Signup links can include a recognized source and campaign label, which we store with the account. Recognized link labels can follow your navigation between our pages in the URL; this uses no browser storage or tracking cookie. We measure registrations, email verification and app listings by source label or ASO resource entry link. Resource labels identify the guide or tool used to enter signup; they do not establish a visitor’s original traffic source. We discard other campaign values and do not store your referring page. Optional X advertising measurement is off unless you accept it in Ad privacy choices. If accepted, X receives visit and completed registration events through RateMyApp’s dedicated pixel and may use advertising cookies and device or network information to measure and attribute our ads. We hide the page location before initializing the pixel and do not pass account email, phone number, app briefs or payment details in these events. This is separate from our aggregate first-party counts. You can reject or withdraw optional measurement through Ad privacy choices; withdrawing reloads the page to stop the loaded pixel. Your preference is stored for up to six months. Do Not Track and Global Privacy Control requests disable this measurement. Browser or provider blocking may prevent events from arriving; advertising attribution is not proof of a unique person or a paid purchase. We count signup form views and submissions by UTC day and recognized link label, without saving form contents or visitor identifiers in those counts. Repeated visits are not unique visitors. Demo visits and browsers requesting Do Not Track are excluded. These activity totals are separate from completed registrations. App icons may be loaded from Apple or Google’s asset servers.
Retention and requests
Sessions expire after seven days and rate-limit records expire after fifteen minutes. Account and testing records persist until removed by the operator. During the beta, send an access, correction or deletion request to reach@ratemyapp.io or through Profile → Report an issue. Email verification and password recovery use emailed, time-limited links when email delivery is connected. Automated account deletion is not available yet. Do not use this beta for sensitive testing material.