Keyword Intelligence and your personal data
emonster, inc. acts as the data controller for information it uses to operate the Keyword Intelligence website, waitlist, account access, private workspaces, and communications. The current product is a prelaunch website and internal workspace foundation.
emonster, inc. acts as the data controller for the information it uses to operate Keyword Intelligenceâs website, waitlist, account access, and communications. Connected workspaces also contain information supplied by their authorized owners and members, including report recipient details and data obtained through Apple connections.
The GDPR rights described here apply when the GDPR covers the processing concerned, including where services are offered to people in the EU. The authenticated portal is currently restricted to verified Google accounts on the exact emonster.com domain; the public waitlist is available separately.
The information we use and why
- Launch waitlist: your email address, language, signup time, and records of the form notice, Terms acceptance, and optional consent choices. We use these to maintain your request, acknowledge your signup, notify you about launch, manage communication preferences, and understand demand. A valid email address and acceptance of the Terms are required to join; product news and optional analytics are separate choices.
- Optional waitlist analytics: with your consent, we retain coarse browser and operating-system categories and major versions, device category, the landing page, limited campaign fields, and the referring websiteâs origin. These help us understand how people discover Keyword Intelligence and use the waitlist. We do not retain a full referring URL or raw user-agent string in the signup record.
- Account and authentication information, including Firebase user identifiers, verified Google email addresses, sign-in provider and session information, and enrolled authentication factors.
- Private workspace information you provide: a workspace name, App Store app identifiers and display names, selected storefronts, tracked keywords, notification preferences, and account-deletion requests.
- Keyword queries and storefronts submitted for analysis. The current analysis endpoint returns an unavailable state and does not store a market observation or generate a measured score.
- Email information: waitlist addresses, consent records, provider message identifiers, delivery events, and bounce or complaint status. Internal signup notifications include the submitted email, signup time, language, consent records, and available country and continent.
- Technical and support information, including operational security and request logs, diagnostics, and information you send in support or privacy requests.
Consent and communication choices
We ask for your consent separately for Keyword Intelligence product news and offers and for the optional waitlist analytics described above. Both are optional. Accepting the Terms to join the waitlist does not opt you into either choice.
You can withdraw consent at any time without affecting processing that was lawful before withdrawal. If you opt into product news, your signup acknowledgement includes a marketing unsubscribe link. You can also contact privacy@emonster.com. Marketing unsubscribe changes the product-news preference; contact us if you also want to leave the launch waitlist.
Use Privacy settings at the end of the footer to allow or decline optional analytics. The choice is saved in that browser and controls the optional context included in future waitlist submissions from it. Changing the browser choice does not itself delete information already submitted; contact us to exercise your rights over that information.
Service providers and recipients
Google and Firebase provide hosting, authentication, backend processing, database storage, secret storage, and reCAPTCHA Enterprise abuse assessment. Resend sends waitlist acknowledgements and internal signup notifications and returns delivery events. IPinfo receives the waitlist request IP address to infer an approximate country and continent; Keyword Intelligence stores that limited location result when available.
Resend receives the addresses and message content needed for those emails. emonster personnel handling waitlist, support, and privacy operations can receive information needed for those tasks.
We do not sell personal information. We may disclose information to the providers needed to operate the Service, when required by law, to protect the Service or the rights and safety of users and others, in connection with a business transaction, or with your consent. Keyword Intelligence does not use workspace information for behavioral advertising.
Private workspaces and market observations
Keyword Intelligence is being developed to use public App Store market observations and separately labeled modeled scores. The current portal does not collect App Store Connect credentials or private Apple analytics. It does not yet collect market observations or compute keyword scores.
Your tracking lists, app contexts, preferences, and account requests are private workspace records. They do not enter a shared public market-data corpus. The PRD requires public observations and private customer analytics to remain separate as further capabilities are implemented.
Browser storage and automated processing
Browser storage remembers your language, appearance, and optional analytics choice. Firebase Authentication uses browser storage for sign-in state. You can sign out or clear local site data; clearing browser data does not delete records already held by Keyword Intelligence.
The current website does not activate Google Analytics or advertising trackers. Optional waitlist analytics records the limited submission context described above. reCAPTCHA and hosting services separately process technical information for their operation and abuse protection. When reCAPTCHA runs, it uses a cookie called _GRECAPTCHA for risk analysis.
Keyword Intelligence automatically validates requests, checks access, limits suspected abuse, manages workspace records, and handles email delivery events. These activities serve the functions described above. The GDPRâs separate protection for decisions made solely by automated processing concerns decisions with legal or similarly significant effects; it does not apply to every automatically processed record.
Retention and deletion
You can remove saved apps and tracked keywords and submit an account-deletion request for review after recent authentication. Submitting a request does not itself delete all records. Contact us about access, export, or deletion.
- Waitlist signup records: scheduled to expire 24 months after the original creation time. Duplicate signups do not restart that retention period.
- Waitlist abuse records: scheduled to expire within 24 hours. Identifier-free aggregate waitlist records have a 36-month expiry measured from the end of their reporting period; groups below 10 signups are suppressed. Database time-to-live deletion is asynchronous, so physical deletion may follow the recorded expiry time.
- Other records: the Privacy Policy describes retention by purpose, including providing and protecting the service, handling requests and disputes, and keeping necessary business or legally required records. Account, workspace, email, support, security, and backup records may require separate handling. Contact us about the records that concern you.
Security and international processing
Keyword Intelligence uses protected server operations, server-checked workspace access, restricted credential storage, verified recipient addresses, and signed email delivery events to protect the information it handles. Access and delivery checks help prevent one workspaceâs information from reaching an unauthorized person.
As described in the Privacy Policy, information may be processed in the United States, Japan, Monaco, and other locations where emonster or its providers operate. Location alone does not identify the legal arrangement for a transfer. For information about the recipients and any applicable transfer safeguards relevant to your data, contact privacy@emonster.com.
Your rights under the GDPR
Your rights depend on the processing concerned and the GDPRâs conditions and exceptions.
- Information and access: find out whether your personal data is processed, obtain a copy, and understand its use, sources, and recipients.
- Correction: request correction of inaccurate data or completion of incomplete data.
- Erasure: request deletion where the legal grounds apply. Obligations to retain information or the establishment, exercise, or defence of legal claims may limit deletion.
- Restriction: request limits on processing in qualifying circumstances, including while disputed accuracy is checked.
- Portability: receive qualifying data you provided in a structured, commonly used, machine-readable format when processing is automated and based on consent or a contract; ask for direct transfer where technically feasible.
- Objection: object on grounds relating to your situation where processing relies on legitimate interests or a public task, subject to the applicable conditions. Objection to direct marketing stops that marketing.
- Automated decisions: protections apply to solely automated decisions with legal or similarly significant effects, subject to exceptions and safeguards, including human intervention where required.
Make a privacy request
Email privacy@emonster.com with the address or workspace concerned and the right you want to exercise. Please do not send passwords, private keys, or authentication codes. If there are reasonable doubts about identity, we may request proportionate information to verify it; access to workspace information also requires appropriate authority.
Under the GDPR, requests must be handled without undue delay and normally within one month of receipt. Complexity or the number of requests may justify up to two additional months, with the reason and extension communicated within the first month. Requests are generally free; a reasonable fee or refusal is permitted only under the applicable exceptions, such as manifestly unfounded or excessive requests.
If a request is refused, the GDPR requires the reasons and information about complaint and judicial-remedy rights. Where required, corrections, erasure, or restrictions must also be communicated to recipients of the affected data.
Concerns and complaints
You can contact us with a privacy concern. Where the GDPR applies, you may also complain directly to a competent data protection authority, particularly where you habitually live, work, or believe an infringement occurred. You do not have to contact us first.