Security

Your account stays yours.

ASA Agent needs enough access to manage the campaigns you authorize, but it does not need your Apple password. Access is scoped, credentials are encrypted, and you can revoke it at any time.

How access works

No Apple password

ASA Agent never asks for or stores your Apple Account password or two-factor authentication code.

Scoped API access

Apple Ads access uses API credentials or Apple authorization. Access can be limited to the campaign group the agent manages.

Encrypted credentials

Private API keys and authorization tokens are encrypted at rest with AES-256-GCM and sent over encrypted HTTPS connections.

You stay in control

You can pause the agent from the dashboard and revoke its Apple Ads access from Apple at any time.

What we access

Apple Ads
Campaign structure and performance data, plus permission to create and update campaigns, bids, keywords, negatives, and budgets in the authorized account or campaign group.
App Store Connect
Optional reporting access for downloads and proceeds. This lets the agent evaluate performance; it does not provide access to your Apple Account password.
Revenue providers
Optional RevenueCat, Adapty, AppsFlyer, or ASA Agent SDK events used to attribute trials and purchases to managed campaigns.

Revoking access

You can pause all managed campaigns from ASA Agent, remove the API user or authorization in Apple Ads, and delete connected integrations from the ASA Agent settings. Account deletion requests are handled under our Privacy Policy.

Report a security issue

Send details directly to rail@getasaagent.com. Reports are reviewed by the founder.