Scope and current status
ASO Signals is in pre-release development. The public asosignals.dev site provides product information, localized legal pages, optional privacy controls, and a waitlist. The separate app.asosignals.dev application is a restricted private-development dashboard, not a generally available customer service.
Owner/legal review required: Confirm the legal operator’s exact name, address, privacy contact, effective date, and any authoritative-language rule before final publication.
Public waitlist information
When you join the waitlist, ASO Signals trims leading and trailing whitespace from your email address and converts letters to lowercase. It stores exactly that normalized email address and a server-generated creation timestamp in Firebase Cloud Firestore.
A private server function derives a deterministic record identifier with a backend-only key. Direct browser access to Firestore is denied. A duplicate submission receives the same response as a new submission and does not replace the original timestamp.
The waitlist record does not contain your name, company, app information, IP address, user agent, analytics identifier, consent choice, campaign data, marketing attributes, or a marketing profile. Application logs do not include the submitted email address.
How waitlist information is used
The normalized email is used to administer the waitlist, avoid duplicate records, and provide launch or access updates you requested. A hidden anti-abuse field and non-persistent request limits help protect the form.
ASO Signals does not currently use waitlist information to create advertising audiences, behavioral profiles, or cross-product marketing profiles.
Optional analytics and privacy settings
Optional aggregate usage analytics is disabled by default. The site asks before allowing it, stores the choice only in this browser, and provides a Privacy settings control in every public footer so the choice can be reopened or withdrawn.
No verified ASO Signals analytics destination is currently configured, so the present site does not load an analytics client or send analytics events even after a visitor selects Allow analytics. A future analytics integration must remain disabled until explicit consent and must stop after withdrawal.
The analytics choice is never attached to the waitlist request or Firestore waitlist record. Necessary site functions, legal pages, waitlist access, and language and theme controls remain available after a visitor declines.
Firebase and Google processing
The browser submits a waitlist request to the same-origin ASO Signals site backend. That backend invokes a private Firebase Cloud Function, which creates the Firestore record. Google and Firebase provide App Hosting, Authentication, Cloud Functions, and Firestore under their applicable terms and privacy practices.
Infrastructure providers may process network, request, security, and diagnostic metadata needed to deliver and protect their services. That provider processing is not added to the ASO Signals waitlist record.
Owner/legal review required: Confirm any required processor, international-transfer, regional-storage, and legally compelled disclosure language with qualified counsel.
Authentication on the app subdomain
The public waitlist site does not initialize Firebase Authentication or create a sign-in session. Only app.asosignals.dev initializes the Firebase Authentication browser SDK.
Current private-development access uses Google sign-in and is restricted by the server to verified Google identities on the exact emonster.com domain. Firebase Authentication and Google process the identity and authentication data needed for that flow, and ASO Signals uses the resulting token to create a revocation-checked HTTP-only session.
The current Firestore foundation contains no general customer-account or product-data collection.
Browser storage and cookies
ASO Signals stores language and explicit Light or Dark appearance choices in browser local storage. Returning appearance to System removes the explicit theme override. The language choice is also stored in a first-party cookie so the server can preserve the selected public locale.
The optional analytics choice is stored in a separate ASO Signals-only browser-storage key. On app.asosignals.dev, Firebase Authentication uses browser-local persistence, and the server uses an HTTP-only session cookie to protect private routes.
Retention, deletion, security, and rights
A duplicate waitlist submission does not change the original creation timestamp. Current source does not implement an automated retention schedule or self-service waitlist removal flow.
ASO Signals uses private persistence, deny-all browser Firestore rules, backend-only identifiers, dedicated service identities, and restricted server authorization. No method of transmission or storage can be promised to be completely secure.
Owner/legal review required: Approve the retention period, removal-request process, identity verification, legal basis, applicable privacy rights, incident language, and working request contact before presenting them as commitments.
Children, contact, and changes
This policy may be updated as the product or its data boundary changes. Material data-boundary changes must be reflected here before the associated functionality becomes generally available.
Owner/legal review required: Confirm the intended age boundary, children’s-privacy language, operator identity, postal address where required, and working privacy/support contact.