Skip to content
AppScoutView on the App Store

AppScout for indie developers and small teams

How AppScout protects your App Store Connect private key

AppScout uses your App Store Connect private key on your iPhone to request reports directly from Apple. The private key and your App Store Connect reports are not uploaded to AppScout’s developer.

Importing a key keeps it on your device

When you import a .p8 file, AppScout stores the private key in the iOS Keychain, configured for that device. It does not send the private key to an AppScout server or ask for your Apple Account password. You still need to create or obtain a Team API key and connect it during setup.

The original file stays where you downloaded or saved it. If you placed that file in cloud storage or shared it yourself, those copies are separate from AppScout’s Keychain storage. Importing the file does not delete them.

Your iPhone requests reports directly from Apple

  1. AppScout uses the private key locally to create a signed, short-lived authentication token.
  2. The app sends that token to Apple’s App Store Connect API to request your app information and reports.
  3. Your iPhone processes the reports and saves metrics for the dashboard, charts, and widgets.

Apple receives the authentication token and the details needed for the request, such as your Vendor Number, report date, and app identifiers. The private key itself is not included in those requests. Your App Store Connect reports do not pass through an AppScout backend.

What AppScout saves locally

AppScout stores setup details, preferences, app lists, icons, report-derived metrics, breakdowns, and exchange rates on your device. Widgets read metric snapshots shared locally by the app. Previously loaded metrics can be viewed offline; new reports need a network connection.

A local Connection Log keeps recent request results and troubleshooting details. Private key contents are not intentionally stored in this log. Some local app data may be included in device backups according to your Apple settings. AppScout does not sync your App Store Connect reports between devices through an AppScout service.

Network access has a specific purpose

  • Apple: app information, daily reports, and app icons.
  • Exchange-rate providers: historical currency rates. These requests do not include your App Store Connect API key details, Vendor Number, app names, or app IDs.
  • Support: if you choose to email the developer, your email service handles the message and attachments you send.

AppScout does not require an analytics SDK in your apps. Keep private keys out of support messages and screenshots. This page explains the App Store Connect metrics connection; see the Privacy Policy for the full privacy terms.

You control the connection

Use Remove Team Key in AppScout’s Settings to remove the stored private key and clear the associated app lists, app preferences, icons, and cached metrics. Issuer ID and Vendor Number remain to prefill a future setup, and recent Connection Log entries may remain.

You can separately revoke the key in App Store Connect to stop future access with it. Removing it from AppScout does not revoke the key at Apple or remove copies of the original downloaded file.

Ready to connect? Follow the guide to checking your app downloads on iPhone. For privacy questions, email andrew.dsgnr@gmail.com.

By Andrew Tanchuk, the developer of AppScout.