GoNetZ← Back to site

Privacy Policy

Last updated 30 July 2026

This policy explains what data the GoNetZ platform collects, why, and what your rights are. It covers gonetz.io and the GoNetZ web application.

It does not cover the separate consumer apps published by the same operator (Decision Wheel and Daily Quote), which have their own policy at gonetz.io/privacy.

1. Who is responsible

The controller of your data under the GDPR is:
David Scuturici, Bahnstrasse 81, 2624 Neusiedl am Steinfeld, Austria
Email: info@gonetz.io

2. What GoNetZ collects

Account data

  • Your email address.
  • A cryptographic hash of your password. Your password itself is never stored and cannot be recovered by us.
  • A session token stored in a cookie, so you stay signed in.

Data from the accounts you connect

GoNetZ only reads accounts you explicitly connect. Depending on which you link, this includes:

  • App Store Connect and Google Play — app metadata, store listing content, keyword rankings, and download and rating figures for your own apps.
  • Google Ads, Meta Ads and Apple Ads — campaign, ad group, and keyword structure, along with spend, impressions, installs, and cost-per-install metrics.
  • Public App Store data about competing apps, used to compare your listing against apps ranking above you. This is public information, not data from anyone's account.

GoNetZ does not collect or process the personal data of your apps' end users. It works with aggregate performance figures, not individual-level or device-level data.

Access credentials

Tokens and credentials for the platforms you connect are stored encrypted at rest. They are used solely to fetch your data on your behalf and to carry out actions you have approved. They are never shared with anyone.

3. Why GoNetZ processes it, and on what legal basis

  • To provide the service — analysing your listings and campaigns and producing recommendations. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • To operate and secure the platform — authentication, error diagnosis, abuse prevention. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
  • To contact you about your account — service notices and, if you have asked for them, product updates. Legal basis: contract, or your consent for marketing.

4. Automated processing and AI

Recommendations are produced by an automated analysis engine that compares your listings, keywords, and campaign metrics against defined thresholds and against publicly visible competing apps.

As of the date above, that analysis runs on our own infrastructure and no customer data is sent to a third-party AI or machine-learning provider. We are actively developing AI-assisted analysis. If that comes to involve sending your data to an external AI provider, we will name the provider in this policy and notify account holders by email before the change takes effect. You will not be opted in silently, and no customer data will be used to train third-party models.

No recommendation is applied automatically: each one waits for your approval, and any automation rule runs only within limits you define and can change or delete at any time.

5. Who else sees your data

GoNetZ does not sell your data and does not share it for advertising. It is processed by:

  • Hetzner Online GmbH (Germany, EU) — hosting and storage of the application and its database.
  • Sendinblue/Brevo (France, EU) — outbound transactional email.
  • The platform providers you yourself connect (Apple, Google, Meta), when GoNetZ calls their APIs on your behalf.

All processing infrastructure is located within the European Union.

6. Google user data — Limited Use

GoNetZ’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data obtained through the Google Ads API and Google Play Developer API is:

  • used only to provide and improve the features you can see in GoNetZ — the campaign and keyword views, the recommendations, and the automation rules you configure;
  • never transferred to anyone except as needed to provide those features, or where the law requires it;
  • never used for advertising of any kind, and never sold;
  • never read by a human, except with your explicit permission (for example if you ask for help with a specific problem), where it is necessary for security or to comply with the law, or in aggregated and anonymised form for internal operations;
  • never used to develop, improve, or train generalised AI or machine-learning models. This does not prevent GoNetZ from using AI to analyse your own data in order to produce your own recommendations, which is a user-facing feature and is covered by section 4.

7. How long it is kept

  • Account and connected-platform data: for as long as your account exists.
  • After account deletion: erased within 30 days, except where a legal retention obligation (such as Austrian accounting law for invoices) requires otherwise.
  • Access credentials: deleted immediately when you disconnect a platform.

8. Revoking access

You can disconnect any platform from GoNetZ at any time, which deletes the stored credentials for it. You can also revoke GoNetZ's access from the provider's own settings — for example in your Apple Ads, Google Ads, or Meta account. Revoking on either side stops further data collection.

9. Cookies

GoNetZ sets one strictly necessary cookie, gonetz_session, which keeps you signed in. There are no advertising, analytics, or tracking cookies, and therefore no cookie consent banner.

10. Your rights

Under the GDPR you have the right to:

  • Access the data held about you, and receive a copy in a portable format.
  • Have inaccurate data corrected.
  • Have your data erased.
  • Restrict or object to processing based on legitimate interests.
  • Withdraw consent at any time, where processing is based on consent.

To exercise any of these, email info@gonetz.io. You also have the right to complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna).

11. Security

Traffic is encrypted in transit with TLS. Platform credentials are encrypted at rest. Passwords are stored only as hashes. Access to production systems is restricted to the operator.

12. Changes

If this policy changes materially, the date above is updated and account holders are notified by email before the change takes effect.

© 2026 GoNetZ · David ScuturiciPrivacyTermsinfo@gonetz.io