Last updated July 22, 2026
Nalya (“Nalya”, “we”, “us”) is a console operated by Nalya LLC that helps app developers manage reviews, releases, store listings, monetization, and growth analytics for their own apps on the app-store platforms they connect (currently Google Play, with more platforms to come). This policy explains what information we collect, why we collect it, who we share it with, and the choices and rights you have. We collect only what the product needs to work for you, we don't sell personal information, and we don't use your data for advertising.
Nalya is currently in early access (beta). The product is evolving, and this policy will be updated as features ship - see “Changes to this policy” below.
This policy covers three groups of people, and our role differs for each:
Customers (you). The developers and teams who create a Nalya account. For your account information, we act as the data controller - we decide how and why it's processed.
Your apps' users and reviewers. When Nalya syncs your app-store reviews, purchase records, or SDK events, it processes information about people who use your apps - for example a reviewer's public display name and review text, or a buyer's country and an opaque purchase identifier. For that data we act as a processor (service provider) on your instructions; you remain the controller and are responsible for having a lawful basis and an appropriate privacy notice for your own users. See “Data from your app's users” below.
Visitors. People who browse our marketing pages without signing in. We don't load product analytics or set analytics cookies until you accept them in our cookie banner; if you decline, or before you choose, we collect essentially nothing about you. See “Cookies and analytics” below.
Account. When you sign in with Google, we receive your name, email address, and profile picture to create and secure your account. We request only basic profile and email scopes - never access to your Gmail, Drive, or other Google content.
Connections you set up. To do its job, Nalya stores the credentials and configuration you provide: app-store platform credentials (for example a Google Play service-account key), and optionally a PostHog API key or a GitHub repository connection. You create and scope each credential yourself in the third-party service, and you can revoke or disconnect any of them at any time. Treat these as sensitive: they grant Nalya (and anyone who obtains them) the access you configured.
API and ingest keys. If you create an MCP key (to control Nalya from an AI assistant or other client) or an app ingest key (used by the Nalya SDK), we generate and store those keys for your account. MCP keys can read your data and perform the same actions you can perform in the console, so keep them secret and revoke any key you no longer use.
App context and content. Anything you type into the console - app descriptions and context notes, edits to drafts, approval decisions, notification preferences - is stored so the service can act on it.
Support. If you email us, we keep the correspondence so we can help you and improve the service.
Using the access you grant, Nalya reads and stores data about your apps so it can show it back to you and act on it:
Reviews and ratings - the public app-store reviews of your apps, including the reviewer's display name, star rating, review text, language, app version, and device model, plus the replies you draft and post.
Releases and listings - your release tracks, rollout status, version information, tester lists, and store-listing copy.
Monetization data - where you enable it, purchase and subscription records from the connected app store: product identifiers, order identifiers, purchase tokens, the buyer's country or region, estimated amounts and currency, and subscription lifecycle events (renewals, cancellations, refunds). These records identify buyers only by opaque identifiers that the platform or your app supplies - Nalya does not receive buyers' names, emails, or payment card details.
Quality and analytics data - crash, ANR, and vitals statistics from the connected platform's reporting APIs (such as the Play reporting APIs), and, if you connect your own PostHog project, the in-app product events we look up there to attribute and explain purchases in your revenue views.
We use this data solely to provide the features you enable, on your behalf. We do not use it to build profiles of your users, for advertising, or for any purpose unrelated to operating Nalya for you.
If you add the Nalya SDK to your app, your app sends events to Nalya through your app's ingest key. Today the SDK reports purchase events only: the product identifier, purchase type, and the purchase token, which our servers verify with the app store. The SDK does not collect names, email addresses, advertising identifiers, precise location, or device fingerprints. Future SDK versions may support additional event types (such as feature-usage analytics or experiment exposures); if you adopt those features, the events your app chooses to send will be processed under the same terms - as your processor, only to provide the service to you.
Your responsibilities. Because this is your users' data, you are responsible for disclosing your use of the SDK in your own privacy policy and in each platform's required data disclosures (such as Google Play's Data safety form or Apple's App Privacy details), and for having a lawful basis to send us these events. If one of your users asks you to delete their data, contact us at support@nalya.io and we will delete the corresponding records we hold for you. Where we act as your processor, a Data Processing Addendum (DPA) is available to business customers on request at support@nalya.io.
We use the information described above to: operate the console and show you your reviews, releases, and metrics; draft review replies, release notes, and listing copy; generate suggestions (for example experiments or monetization changes); carry out the actions you approve or have enabled for automation (such as posting a reply or promoting a release); send you the notifications and digests you've opted into; secure the service, prevent abuse, and debug problems; and comply with legal obligations.
Capabilities start in a supervised mode where you approve each action; automation is opt-in per capability, and every action - manual or automated - is recorded in your activity log.
To draft replies, release notes, and listing copy and to generate suggestions, relevant content is sent to our AI provider, Anthropic, to produce an output. Depending on the feature, that content can include: the text of a review and the reviewer's public display name; your existing store listing and ASO signals; the context you wrote about your app; your product catalog and list prices (for monetization suggestions); and anonymized in-app event data (for example a buyer's sequence of screens and actions, used to summarize a journey). This content is used only to produce output for you; under our agreement with Anthropic it is not used to train their models. We do not send your stored credentials, your account password-equivalents, or your buyers' identities or individual verified-purchase transaction records (order ids, amounts, tokens) to AI providers.
AI-generated drafts are suggestions. You review and approve them before they're published, unless you have explicitly enabled automation for that capability.
No solely-automated decisions. Nalya does not make decisions that produce legal or similarly significant effects about you or your apps' users by solely automated means. Capabilities are supervised by default; any automation you turn on acts on your instructions, is limited to the actions you enabled, is recorded in your activity log, and can be paused or disabled at any time.
We rely on a small set of providers to run Nalya, each processing data only to provide their service to us:
Supabase - database and authentication. Vercel - application hosting. Google - sign-in and, if you connect a Play account, the Play Developer and reporting APIs you authorize. Anthropic - AI drafting, as described above. PostHog - our own product analytics (see “Cookies and analytics”), which processes usage events and, once you consent, may include your account email and id. Resend - transactional email (for example a notification when you delete an app).
Two of these you connect under your own accounts and their own terms: if you connect your own PostHog project, we use it to look up buyers' in-app activity to attribute and explain purchases in your revenue views. If you connect a GitHub repository, we currently store only the repository name you enter - Nalya does not yet access GitHub, read your code, or write to it. We do not use a payment processor because Nalya does not currently charge for the service. We will update this list if our providers change; material changes are announced as described under “Changes to this policy.”
We share personal information only: with the service providers above; with the third-party platforms you connect, on your instruction (for example, posting your approved reply to the app store); if required by law, legal process, or to protect the rights, safety, or security of Nalya, our users, or the public; and in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to apply to your data and we will notify you of any change in ownership. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Nalya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request only the Google sign-in scopes and the Play Developer API access needed for the features you enable, use that data solely to provide and improve those features for you, do not transfer it to others except as necessary to provide the service, to comply with the law, or with your consent, and never use it for advertising or sell it. Human access to this data is limited to what is necessary for security, compliance, or support you request.
Functional cookies (always on, strictly necessary). An authentication session cookie so you stay signed in, small preference cookies (such as your last-opened app and your Real/Test view), and a cookie that simply records your analytics choice below. Your theme preference is stored locally in your browser, not sent to us.
Product analytics (only if you accept). To understand how Nalya is used and improve it, we run our own first-party PostHog analytics. When enabled it records page views, clicks and interactions, error events, and an anonymous or (once you sign in) identified usage profile including your account email and id, and it may capture session replays of your use of the console. This is off by default on every page, including our marketing pages: it loads and sets its cookies only after you accept in our cookie banner, and you can decline at any time. We do not use advertising cookies, sell your data, or engage in cross-context behavioral advertising. Because analytics stay off until you opt in, a “Do Not Track” signal changes nothing - we already collect nothing until you accept.
We keep your data while your account is active and as needed to provide the service. Specifically: deleting an app from the console takes effect immediately and removes its stored connection credentials and the app's associated data (reviews, purchases, suggestions, activity); revoking an MCP or ingest key disables it immediately. To delete your entire account, contact us at support@nalya.ioand we will complete the deletion within 30 days. Support and contact correspondence is kept for up to 24 months, and records we are required to retain by law (such as those needed for tax, accounting, or dispute purposes) are kept only as long as required and then deleted. Residual copies in encrypted backups are purged within 30 days on our providers' standard backup-rotation schedules; if you accepted analytics, product-analytics events are retained no longer than needed for the purposes above and are removed when you delete your account.
Deleting your data from Nalya does not revoke the access you granted at the source. You should also remove Nalya's Google Play service-account grant and disconnect any other services (such as your own PostHog) from those providers directly; after an app deletion we email you a checklist of exactly what to revoke.
We take reasonable technical and organizational measures to protect your information: data is encrypted in transit (TLS) and encrypted at rest by our infrastructure providers; every account's data is isolated by row-level access controls scoped to that account; credentials you store are accessible only to the systems that need them to act on your instructions; and administrative access is limited. No method of transmission or storage is completely secure, so we cannot guarantee absolute security - if we learn of a breach affecting your personal data, we will notify you without undue delay and as required by law. Please also do your part: protect your Google account with strong authentication and treat your Nalya keys as secrets.
Nalya and its service providers (including Supabase, Vercel, Google, Anthropic, PostHog, and Resend) may process and store data in the United States and other countries, which may have data-protection laws different from those where you live. Where personal data is transferred internationally, we rely on the safeguards our providers offer, such as standard contractual clauses and equivalent mechanisms, and we require providers to protect data consistently with this policy.
Everyone. You can access, correct, export, or delete your personal data at any time by emailing support@nalya.io. You control which permissions Nalya has and can revoke them at the source (for example in Google Play or PostHog) or by disconnecting the integration in the console. You can opt out of non-essential emails and notifications in your settings. We will never discriminate against you for exercising a privacy right.
European Economic Area, United Kingdom, and Switzerland. We process your data on these legal bases: performance of our contract with you (operating the service you signed up for), our legitimate interests (securing and improving the service, preventing abuse), your consent where we ask for it, and legal obligations. You have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent at any time, and the right to lodge a complaint with your local supervisory authority.
California and other US states. You have the right to know what personal information we collect, use, and disclose (this policy), to access, correct, and delete it, and to opt out of sale or sharing - which does not apply to us, because we do not sell or share personal information as those terms are defined in the CCPA/CPRA. We do not use or disclose sensitive personal information for purposes requiring a right to limit. You may exercise these rights, including through an authorized agent, by emailing support@nalya.io; we will verify requests using your account email.
If you are a user of one of our customers' apps (for example, you left a review or made a purchase in an app that uses Nalya), the developer of that app is the controller of your data. Please direct requests to them; if you contact us directly, we will forward your request to the relevant developer and assist them in honoring it.
Nalya is a professional tool for app developers and is not directed to children. We don't knowingly collect personal information from anyone under 16, and you may not create an account if you are under 16 (or under the age of digital consent where you live). If you believe a child has provided us information, contact us at support@nalya.io and we will delete it.
We may update this policy as the product evolves. We'll revise the “last updated” date above and, for material changes, give you reasonable advance notice in the console or by email before the change takes effect. If you continue to use Nalya after a change takes effect, the updated policy applies; if you don't agree with a change, you can delete your account.
Nalya LLC, a Delaware limited liability company, is responsible for the processing described in this policy. Questions, concerns, or requests about this policy or your data? Email us at support@nalya.io and we will respond as soon as we can, and within any timeline required by applicable law. You can also reach us by mail at Nalya LLC · 611 South DuPont Highway, Suite 102, Dover, DE 19901, USA.