Data Processing Addendum
Last updated: July 26, 2026
This addendum applies when you connect an app to StudioDash. It sets out what Gulden Studio does with the subscription notifications Apple sends about your customers, and what it does not do with them. It forms part of the StudioDash Terms.
Language
This addendum exists in English only, and the English text governs. A translation offered elsewhere on this site is for reading, not for interpretation.
Who Is Who
You are the controller. The subscription events describe your customers, and you decide what happens to them.
Gulden Studio is the processor. We act on your instruction and for no other purpose. Connecting an app instructs us to receive its subscription notifications. Removing it, or deleting your account, instructs us to stop and to erase the routing data listed below.
What We Do With It
One thing: telling you when a subscription starts, converts, cancels, hits a billing problem, expires or is refunded.
Apple sends the notification to our endpoint. We check Apple's signature on it, build your alert, send the alert to your devices, and discard the notification. It is not written to a database, not added up, not combined with anything from another developer, not used to build a profile, and not used to train a model.
The figures on your dashboard are not part of this. Your device reads those from Apple and Google with your own credentials, and they never pass through our servers.
What We Keep
Nothing about your customers. The subscription notification lives only for as long as the request that carries it.
Three things about you, because an alert cannot be delivered without them: an anonymous sign-in identifier, so we know which apps you have claimed; your devices' push tokens and alert preferences, so the alert reaches you; and your app's bundle id, name and App Store id, so the alert can say which app it is about.
We hold this until you remove the app or delete your account. Both are immediate and permanent.
What We Never Receive
Apple gives us no names, no email addresses, no postal addresses and no payment details.
Your App Store Connect key and your Google Analytics credentials never reach us at all. They stay in your device's Keychain.
How It Is Protected
Every notification is verified against Apple's root certificate, pinned to the app the payload itself names. A forged notification for an app the sender does not control fails that check and is rejected.
Claiming an app requires proof from Apple that you control it, and the proof expires after fifteen minutes, so a captured one cannot be replayed later. That proof, not the sign-in, is what keeps one developer away from another's alerts.
All traffic is over HTTPS. Push signing keys are held in Google Secret Manager. Push tokens appear in logs truncated to four characters, and subscriber records are never logged. Every endpoint has a ceiling on how far it can scale, so a flood cannot run up an unbounded bill.
Access is limited to the studio's sole operator. There are no other staff and no contractors. The studio holds no external security certification and does not claim one.
Who Else Is Involved
Google LLC runs the relay and stores the routing data above, on servers in the United States. Apple Inc. is the source of the notifications and delivers the alerts. Those two are our only sub-processors, and we will tell you before that changes so you can object.
Transfers Out of Europe
Gulden Studio operates from Türkiye, and the servers it uses are in the United States. If you are in the European Economic Area or the United Kingdom, that means your data leaves it, and neither country has an adequacy decision covering this.
For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, Module Two, which covers a controller sending data to a processor. Those clauses are incorporated into this addendum in full and unmodified, and the annexes they require are set out below. Where the United Kingdom applies, the ICO's International Data Transfer Addendum applies alongside them, using the same annexes.
We link the clauses rather than reprinting them, so that what applies is the official text and not a copy that could fall out of date: eur-lex.europa.eu/eli/dec_impl/2021/914/oj
Onward to Google: their terms carry the same clauses, and they are certified under the EU-US Data Privacy Framework.
Annex I. Parties and Transfer
Data exporter, and controller: you, the developer who connects an app. Your details are the ones you give when you accept this.
Data importer, and processor: Gulden Studio, a sole trader based in Türkiye rather than a company. Contact: support@studiodash.live. The operator's full legal name and postal address are on the App Store listing for this app, and we will send them on request for your own records.
Data subjects: your own account, for everything kept. Your customers, for the notifications that pass through and are not kept.
Categories of data: an anonymous sign-in identifier, device push tokens with alert preferences, and your app's bundle id, name and App Store id. Passing through and discarded within the request: a subscription's transaction identifier, product, store country, event type, amount and expiry.
Sensitive data: none.
Frequency: continuous, whenever Apple has an event for one of your apps.
Purpose and nature: receipt, signature check, alert, discard. Nothing is aggregated, enriched, combined across developers, profiled or used to train a model.
Retention: each notification for the life of the request. The routing data until you remove the app or delete your account.
Competent supervisory authority: the one for the country you are established in, since you are the exporter.
Annex II. Security Measures
Not retaining subscriber data at all, which is the measure the rest of this list rests on.
Every notification verified against Apple's root certificate, pinned to the app the payload names. A forged notification for an app the sender does not control is rejected.
Claiming an app requires proof from Apple that you control it, and the proof expires after fifteen minutes so a captured one cannot be replayed.
HTTPS on every endpoint. Push signing keys in Google Secret Manager. Push tokens logged truncated to four characters, and subscriber records never logged. A ceiling on every endpoint's scale, so a flood cannot run up an unbounded bill.
Access limited to one person, the studio's sole operator. No other staff and no contractors.
Stated plainly rather than left out: there is no external security certification, and device attestation on the app's own endpoints is being rolled out rather than already enforced.
Annex III. Sub-processors
Google LLC, for running the relay and storing the routing data, in the United States.
Apple Inc., as the source of the notifications and for delivering the alerts, in the United States.
Requests From Your Customers
A request from one of your customers comes to you, not to us, and you can answer it without us: your own device holds the subscription history, read from Apple with your own key.
We cannot look a subscriber up, because we keep no record of one. What we can do on your instruction is erase the routing data listed above, which the app already does when you delete your account.
If Something Goes Wrong
We will tell you within 48 hours of becoming aware of a breach affecting your data, with what we know about how far it reaches and what caused it.
We will make this addendum, the security rules and the ingestion code available if you ask to see them.
Changes
If this addendum changes, the date at the top of this page changes with it. We will tell you before a change that affects what we receive or keep.
Contact
support@studiodash.live