Scope and local use
Byst is a tool for App Store developers. Local use stores your Apple credentials in device-only Keychain and reports in a local cache. Byst does not ask for your Apple Account password. Apple receives requests made directly by the app.
Optional cloud processing
If enabled, Byst processes account/workspace identifiers, device identifiers and public keys, consent records, subscription verification data, report data and encrypted report-key copies. These support authentication, membership, synchronization and authorized background fetching. Admin .p8 and your recovery private key are not uploaded.
Notifications and transactions
Enabling notifications sends an APNs token, language, environment and notification choices. Separately authorized transaction connections process product and transaction identifiers, amounts, currency, dates and purchase/refund status. Normalized transaction data is encrypted at rest; the authorized service can read it. Raw signed Apple transaction payloads are not stored in the application database.
Service providers
Apple provides App Store Connect, purchases, APNs and optional private iCloud storage. Cloudflare hosts Byst cloud processing and storage. Exchange-rate services provide reference rates. Providers receive the requests needed for these functions and may process network/security metadata under their own policies; their infrastructure may operate across regions.
Retention and your controls
Cloud history remains until deleted; stopping reports alone does not erase it. Removing a cloud report key removes its two encrypted copies and stops background reports. Deleting a workspace removes its reports, hosted keys, transactions, notification connections and sessions and invalidates its recovery key. Delete iCloud and local copies separately. Imported .p8 originals and exported recovery files remain wherever you saved them.
Website and security
This informational website adds no advertising or analytics trackers. Language preference is stored in your browser; the host may handle access/security logs and access-control cookies. App diagnostics use limited codes and request IDs rather than private-key contents. No system can promise absolute security; see Data security for the service access boundary.
Monthly and yearly Byst Pro subscriptions
Byst Pro offers monthly (byst.monthly) and yearly (byst.yearly) auto-renewable subscriptions. Both use the same privacy practices. Apple processes payment through the App Store; Byst does not receive your full card number, bank details or Apple Account password. Purchasing Pro does not itself authorize uploading your Apple developer keys, reports or customer transactions. Cloud reports, transaction connections and notifications require their own setup and authorization.
Purchase verification and subscription data
Byst creates a random billing identifier (appAccountToken), stores it in the device Keychain and supplies it to Apple with the purchase. StoreKit verifies purchases and restores available entitlements. When linking Pro to a cloud workspace, Byst sends the Apple-signed transaction to its service for verification. The service checks the product, app, purchase environment, expiry and revocation status, and stores the original transaction identifier, billing identifier, expiry, signing timestamp and revocation status, plus the workspace association. Apple server notifications update renewal and refund status. These records support Pro access, restoration and protection against invalid purchase claims; they are separate from your apps’ customer transaction data.
Cancellation, expiry and retained records
Manage or cancel either plan in Apple Settings → your name → Subscriptions. Cancellation stops future renewal; access depends on the entitlement Apple reports, including its expiry and any revocation. Deleting Byst or cloud data does not cancel the subscription. Deleting a cloud workspace removes its subscription association, but independent subscription verification records are retained and are not automatically erased on cancellation or expiry. Apple manages its own purchase and payment records under its privacy policy. Local and iCloud copies are managed separately.
Policy updates and data controls
The date above identifies this version. Changes to data handling will be reflected in this policy. You can manage cloud authorizations and delete workspace data in the app, and manage subscriptions with Apple. These controls apply separately to local data, cloud services and purchases.
