Security and store access
Connecting a store gives AppDrift access to private app information and the actions allowed by your key. Choose that access when you need it, and keep control of it in your store console.
Start without store keys
You can create screenshots, prepare listing copy, and track public keyword rankings without connecting App Store Connect or Google Play. Saving and exporting screenshots requires an account; template and plan limits still apply.
A connection is needed for private store data and supported store actions. AppDrift asks for an App Store Connect API key or a Google service account key. It does not need your Apple ID or Google account password.
Verify your email before connecting
Confirm your AppDrift email before adding or replacing store credentials, or adding and testing your own AI provider keys. Open the verification email, sign in to the matching account if needed, and select Confirm my email. Links expire after one hour and can only be used once. Request another from Email verification if it expires.
Google and GitHub sign-in can confirm the email when the provider supplies verified ownership. An existing password account may first need email verification or password recovery before provider sign-in can use it.
Email verification confirms control of an inbox. It is not multi-factor authentication or proof of app ownership. AppDrift does not currently provide a separate passkey or authenticator-app setting. Enable multi-factor authentication on your email, Apple, and Google accounts.
Existing store connections continue to work. Screenshot work and public keyword tracking remain available while your email is unverified.
Choose the permissions you need
| Connection | Access to consider | How to stop access |
|---|---|---|
| App Store Connect | AppDrift uses a team API key with an issuer ID. Choose a role that supports your intended tasks; App Manager supports listing management. Team keys can access all apps in the Apple team within their assigned role. | Revoke the dedicated key in App Store Connect → Users and Access → Integrations. |
| Google Play | Use a dedicated service account. Invite its email in Play Console and grant access to the intended apps and required tasks. Google Cloud Owner and Service Account Key Admin are not required permissions for the service account to use the Play API. | Remove its Play Console access and delete its JSON key in Google Cloud IAM → Service Accounts → Keys. |
Use a dedicated key for AppDrift so revoking it does not interrupt another integration. Read the Apple setup guide or Google setup guide, and check current permissions in Apple’s API documentation and Google’s API documentation.
How credentials are handled
Uploads use HTTPS. Newly uploaded or replaced store key files are encrypted by AppDrift with AES-256-GCM before they enter private S3 storage. Credential identifiers in the database are also encrypted. The server assigns the storage location and checks the workspace and app before attaching a file.
Older uploaded files use the storage protections present when they were uploaded; they are not automatically rewritten by a new upload. Replacing a key uses the current upload protection. AppDrift’s servers must decrypt credentials to authenticate with Apple or Google, so this is not end-to-end encryption.
Store key files are excluded from public file previews. Credential forms and authentication pages are excluded from AppDrift’s analytics and session recording. Store credentials are used for store authentication, not as input to AI generation. Listing text and images submitted for AI features have separate processing described in the privacy policy.
AppDrift can access the private data and supported write operations allowed by a connected key. Review the destination, app, version, and fields before sending a store update. Saving a local draft and sending a change to a store are separate actions.
Revoke or replace access
- Revoke in the store or cloud console. This is the authoritative way to make a key unusable. Removing an app from AppDrift does not revoke a key at Apple or Google.
- Replace it if you still need the connection. Create a dedicated replacement, verify your email, and upload it in your app’s Settings → Store connection. Check the connection status afterward.
- Request removal of stored data when needed. Contact AppDrift about retained account or credential data. Replacing a key is not a claim that every historical copy or backup has been erased.
If you suspect a key was exposed, revoke it first. Do not paste private keys or service account JSON into email, chat, issue reports, or screenshots.
Account recovery and security questions
A password reset link expires after one hour and works once. Completing a reset changes the password and signs out earlier AppDrift sessions. Open password recovery if you cannot sign in.
For access questions or a suspected security issue, use Contact AppDrift. Include the affected page, approximate time, and a description with secrets removed. This guide describes product behavior; it does not assert an independent security certification or audit.