BYST / 02

Privacy policy

How Byst handles information on your device and when you enable optional services.

Updated September 11, 2026

Policy preview: the operator identity and privacy contact must be confirmed before public release.

01

Scope and local use

Byst is a tool for App Store developers. Local use stores your Apple credentials in device-only Keychain and reports in a local cache. Byst does not ask for your Apple Account password. Apple receives requests made directly by the app.

02

Optional cloud processing

If enabled, Byst processes account/workspace identifiers, device identifiers and public keys, consent records, subscription verification data, report data and encrypted report-key copies. These support authentication, membership, synchronization and authorized background fetching. Admin .p8 and your recovery private key are not uploaded.

03

Notifications and transactions

Enabling notifications sends an APNs token, language, environment and notification choices. Separately authorized transaction connections process product and transaction identifiers, amounts, currency, dates and purchase/refund status. Normalized transaction data is encrypted at rest; the authorized service can read it. Raw signed Apple transaction payloads are not stored in the application database.

04

Service providers

Apple provides App Store Connect, purchases, APNs and optional private iCloud storage. Cloudflare hosts Byst cloud processing and storage. Exchange-rate services provide reference rates. Providers receive the requests needed for these functions and may process network/security metadata under their own policies; their infrastructure may operate across regions.

05

Retention and your controls

Cloud history remains until deleted; stopping reports alone does not erase it. Removing a cloud report key removes its two encrypted copies and stops background reports. Deleting a workspace removes its reports, hosted keys, transactions, notification connections and sessions and invalidates its recovery key. Delete iCloud and local copies separately. Imported .p8 originals and exported recovery files remain wherever you saved them.

06

Website and security

This informational website adds no advertising or analytics trackers. Language preference is stored in your browser; the host may handle access/security logs and access-control cookies. App diagnostics use limited codes and request IDs rather than private-key contents. No system can promise absolute security; see Data security for the service access boundary.

07

Policy changes and requests

The update date identifies this version. Material changes should be reflected here before new processing begins. Use the in-app deletion controls to remove service data. Operator identity, privacy contact, operational log retention and applicable request procedures require confirmation before this preview is published publicly.

Back to top ↑