ReviewBell is a Mac app for managing App Store and Google Play reviews and, if you enable it, customer messages sent to a ReviewBell-hosted support address. This policy describes the data each feature handles.
1. Store credentials and review data
- For App Store Connect, ReviewBell uses the App Store Connect API key (.p8) that you provide. For Google Play, ReviewBell asks you to sign in with Google and approve the Google permissions shown on the consent screen.
- App Store credentials and Google OAuth access and refresh tokens are stored only on your Mac, in the macOS Keychain. They are never transmitted to ReviewBell's servers.
- ReviewBell calls Apple's and Google's official APIs directly from your Mac. Google Play access is used to list apps, read reviews and reports, submit replies you approve, and read the order or subscription information needed for enabled sales features.
- If you provide a Google Play historical-report bucket, ReviewBell uses read-only Google Cloud Storage access only to import that bucket's Play Console reports. It does not create, change, or delete Cloud Storage objects.
- Every Google Play connection requires live sales setup. ReviewBell uses Google Cloud Pub/Sub only for the topic or subscription you configure for real-time developer notifications.
- Reviews, drafts, translations, triage tags, and settings are cached in an on-device database. You can remove this local data by removing the connection or deleting the app's data.
- When you request an AI feature for a review or support email, the relevant bounded review or support-message text and necessary tone or template settings are sent over HTTPS to a ReviewBell Cloudflare Worker and then to OpenAI to produce that result. Sender and recipient addresses and attachment content are excluded from this AI payload.
- ReviewBell does not use review or support-message content to train an AI model.
Google OAuth scopes and exact uses
ReviewBell requests the following scopes when you connect Google Play. These are the narrowest scopes Google provides for the production features described below; ReviewBell does not request the broader cloud-platform scope.
openidandemail: authenticate the Google sign-in session, read the selected account's primary email address, and show which Google account is connected.https://www.googleapis.com/auth/androidpublisher: read Google Play reviews, submit only the review replies you approve or explicitly configure for eligible automation, and read the order, subscription, and voided-purchase information used by the enabled sales features. Google does not provide narrower method-specific scopes for these Android Publisher operations.https://www.googleapis.com/auth/playdeveloperreporting: discover the package names and display names of apps the signed-in developer can access. Google exposes one scope for the Play Developer Reporting API.https://www.googleapis.com/auth/devstorage.read_only: list and download Play Console review, install, and financial report files only from the historical-report bucket URI you provide. This read-only scope cannot create, change, or delete Cloud Storage objects.https://www.googleapis.com/auth/pubsub: create or reuse the fixedreviewbell-rtdntopic and pull subscription in the Google Cloud project you select, add the publisher and subscriber IAM bindings needed for Google Play real-time developer notifications, and pull, acknowledge, or extend the acknowledgement deadline for those notifications. Google does not offer a narrower Pub/Sub scope for these operations.https://www.googleapis.com/auth/service.management: enable only the Cloud Pub/Sub API in the Google Cloud project you select so the in-app real-time notification setup can complete. ReviewBell does not use this scope to enable, disable, or configure other Google services, and requests it instead of the broadercloud-platformscope.
Google API data storage, transfer, retention, and deletion
- The raw Google data ReviewBell can access consists of the selected account email; accessible app package and display names; review identifiers, ratings, text, author display names, language or country, app version, device details, and developer replies; the report files and metrics in the bucket you select; purchase, subscription, order, and voided-purchase status needed for enabled sales features; and the Pub/Sub resources and real-time notification payloads created for the apps you select.
- Google OAuth tokens stay in the macOS Keychain. Imported Google data, derived dashboard totals, drafts, translations, classifications, and settings are stored in the app's on-device database. ReviewBell does not upload OAuth tokens, the selected Google account email, report-bucket contents, purchase data, or Pub/Sub payloads to ReviewBell servers.
- When an enabled AI review feature runs, ReviewBell may send a bounded payload containing the review identifier, rating, title or body, territory or language, optional app name, and your selected tone, template, or recent published-reply samples to a ReviewBell Cloudflare Worker and OpenAI solely to return the visible classification, translation, summary, theme, or reply draft. Reviewer display names, Google account emails, OAuth tokens, report files, purchase data, Pub/Sub payloads, and device details are excluded from this AI payload.
- Removing a Google Play connection clears its credential and associated local connection data. You can also revoke ReviewBell from your Google Account and remove on-device data by deleting the app's data or uninstalling the app.
- Google Cloud resources remain in your Google Cloud project under your control. Because removing the connection does not delete those cloud resources, you must delete the
reviewbell-rtdntopic, subscription, or IAM bindings in Google Cloud if you no longer want to retain them.
2. Hosted support-email account
Creating or managing an address at hello-support.com requires Sign in with Apple. We request only the Apple identity needed to authenticate you; the app does not request your Apple name or email scopes for this feature.
- We store a keyed, non-reversible representation of your Apple user identifier, account and session identifiers, subscription entitlement, project and source assignments, and security/audit events.
- If Apple provides an authorization code, we exchange it for an encrypted Apple refresh token so we can revoke the Sign in with Apple credential when you delete the account. We never receive your Apple password.
- Access and refresh tokens are stored in your Mac's Keychain. Server-side token values are stored as keyed digests, not plaintext.
3. First-party product analytics
When you are signed in to hosted support email, ReviewBell records limited interactions needed to understand whether the feature works and which parts are useful. These records are linked to your ReviewBell account and user identifier.
- Examples include viewing the support-email card or inbox, choosing the all/reviews/email filter, opening setup or a thread, copying an address, starting and completing address creation or assignment, starting and sending a reply, changing an address state, requesting an upgrade, and exporting data.
- Each event may include its time, result, screen and mode, source-provider category (App Store, Google Play, or web), subscription tier, app version and build, and opaque ReviewBell account and user identifiers.
- Product-analytics events do not contain the hosted email address or alias, project name, store app identifier, website URL, sender or recipient, subject, message body, reply text, attachment name, Apple token, or arbitrary custom properties.
- We use these records for product functionality, adoption and funnel measurement, reliability, support, capacity planning, and abuse prevention—not advertising, data sale, or cross-app profiling.
4. Support messages we store
When someone sends mail to your hosted address, ReviewBell processes and stores data needed to show the conversation and send your approved reply:
- sender, recipient, and reply-to addresses; subject; text body; message and threading headers; timestamps; delivery status; message size; and the project/mailbox receiving the message;
- your outbound reply text and delivery or bounce status; and
- limited operational records used for de-duplication, abuse prevention, suppression, retention, and incident investigation.
Message bodies are stored in a private Cloudflare R2 bucket. Account and message metadata are stored in Cloudflare D1. Contact addresses and subjects use additional application-level encryption where described by the service design; Cloudflare also provides encryption at rest. Data is encrypted in transit.
Image attachments: ReviewBell stores inbound PNG, JPEG, GIF, and WebP images in the same private Cloudflare R2 storage used for message bodies and makes them available only through an authenticated account-scoped request. Original attachment filenames are not stored. Unsupported, mismatched, or over-budget attachments—including video, SVG, documents, archives, and executables—are discarded and shown as omitted. Images are retained for up to 30 days on Free, 90 days on a paid plan, or 7 days when received in a locked mailbox. A message that exceeds the published per-message safety limits may be rejected.
5. Access rules and retention
- Readable message bodies are scheduled for deletion 90 days after receipt on Free and 365 days after receipt on a paid plan.
- After a paid plan ends, one selected hosted address remains available on Free. New content received by other retained addresses is locked and scheduled for deletion after 30 days. Re-subscribing before deletion restores retained locked content.
- Requesting mailbox deletion stops new mail immediately. The mailbox enters a 7-day recovery period, after which its messages and body objects are deleted and the alias is permanently tombstoned to prevent reassignment to another customer.
- Expired content is removed from R2 and its identifying message metadata is cleared. Minimal deletion receipts and alias tombstones are retained to prevent account or address reuse abuse.
- Raw first-party product events are deleted after 90 days. Daily event counts associated with opaque account and user identifiers are deleted after 760 days. Deleting the hosted-email account deletes both forms of analytics through the same account-deletion process.
- On-device data remains until you remove it or uninstall the app.
6. Your controls
- You can pause, reactivate, unassign, or request deletion of a hosted address from the app.
- You can download an NDJSON copy of currently accessible hosted-email account and message data, including first-party product-event records and daily counts, from Settings. Locked paid-feature content remains redacted. Binary image bytes are not embedded in this self-service NDJSON file; use the in-app authenticated viewer while retained, or contact us for a statutory access request.
- You can delete the hosted-email account in Settings after a fresh Sign in with Apple confirmation. ReviewBell immediately revokes active sessions, requests deletion of Cloudflare data, and attempts to revoke the stored Apple credential.
- For a statutory access, correction, or deletion request—including retained data not shown by the self-service export—contact privacy@hello-support.com. We may need to verify account ownership.
- You can revoke store access by removing the connection in ReviewBell, revoking App Store Connect access, or revoking ReviewBell from your Google Account's third-party connections page.
7. Subscriptions and payments
Subscriptions are sold through Apple's App Store using StoreKit. Apple handles payment details. ReviewBell receives and verifies signed subscription status, transaction identifiers represented as keyed digests, product tier, expiration, refund, revoke, billing-retry, and grace-period events so access can be applied across devices.
8. Service providers and disclosures
We use Apple and Google for store access, Google Cloud Storage for read-only historical Play reports, Google Cloud Pub/Sub for required real-time Play notifications, Apple for authentication and subscriptions, Cloudflare for application processing, email routing and sending, databases, object storage, queues, rate limiting, logs, and site hosting, and OpenAI only for AI actions you request. These providers process data under their own terms and as needed to perform those functions.
We may disclose information when legally required, to protect users or the service, or in connection with a business transfer subject to appropriate safeguards. We do not sell or rent support-message content or use it for cross-context behavioral advertising.
9. Website measurement
The ReviewBell website uses Reddit Pixel and LinkedIn Insight Tag to measure site visits and Mac App Store link clicks. Those providers may process cookies, IP address, browser/device data, URL, referrer, and advertising identifiers. We do not intentionally send store credentials, review content, support messages, names, email addresses, or phone numbers to these tags; advanced or enhanced matching is not configured.
See the Reddit Privacy Policy and LinkedIn Privacy Policy.
10. Security and appropriate use
We use access controls, tenant-scoped database relationships, encryption, rate limits, suppression rules, and retention jobs. No internet service is risk-free. Hosted support email is intended for ordinary product-support communications, not health records, financial-account data, government identifiers, legal secrets, or other regulated or highly sensitive information.
11. International processing and children
Service providers may process data in countries other than yours. ReviewBell is a developer tool, is not directed to children under 13, and should not be used to intentionally collect children's data through a hosted address.
12. Changes and contact
We will update the date above when this policy changes and will provide additional notice when appropriate. Privacy questions or requests can be sent to privacy@hello-support.com. Abuse reports can be sent to abuse@hello-support.com.