Privacy Policy
Short version: MRRKit is built so that your revenue stays yours. Your API keys are stored only in the iOS Keychain of your device, your revenue numbers are downloaded directly from your payment providers to your device, and they are never sent to our servers. We do not track you, show ads, or sell anything about you. We only keep a few anonymous usage statistics (never revenue figures or keys) to improve the app.
1. Who we are
MRRKit is published by Louis Valli (smartcom.digital), who is the data controller for the processing described below. Contact: support@smartcom.digital.
2. Data we process
| Data | Why | Where it lives |
|---|---|---|
| Account: email address, first name / nickname, user identifier, sign-in method (Apple, Google or email) | Create your account and sync your projects between your devices | Google Firebase Authentication |
| Project settings: project names, website, tagline, colours, emoji, goal, list of connected source types (no keys) | Restore and sync your dashboard | Google Cloud Firestore, in a space only your account can access |
| Anonymous usage statistics: number of projects, connected provider types, category, currency, website domain, sign-in method, locale (see section 4) | Understand how the app is used and improve the service | Google Cloud Firestore, readable only by the publisher |
| API keys (Stripe, RevenueCat, Lemon Squeezy, Paddle, App Store Connect, Google Play) | Read your revenue, read-only | Only on your device, in the iOS Keychain. Never uploaded. |
| Revenue metrics (MRR, revenue, subscribers, downloads…) | Display charts, widgets and Apple Watch complications | Only on your devices (iPhone/iPad App Group and your paired Apple Watch) |
| Purchases | Unlock MRRKit Pro | Handled entirely by Apple. We never receive your payment information. |
You can use MRRKit without an account: in that case your project settings stay on your device, and only the anonymous usage statistics described in section 4 are recorded, through an anonymous Firebase session.
3. Requests made from your device
- To your payment providers' official APIs (Stripe, RevenueCat, Lemon Squeezy, Paddle, Apple App Store Connect, Google Cloud Storage for Google Play reports), using the keys you provided.
- To frankfurter.dev to fetch public European Central Bank exchange rates (no personal data is sent).
- When you add a website, to that website to read its public title, description and logo, and to Google's public favicon service (only the domain name is sent). The optional text analysis runs on device with Apple Intelligence.
4. Anonymous usage statistics
To understand how MRRKit is used and to improve the service, the app stores a small set of anonymous usage statistics in Google Cloud Firestore. They are linked only to a random technical identifier, never to your name or email address:
- Per account: sign-in method (Apple, Google, email or guest), locale (language and region setting), country, app version and platform.
- Per project: connected provider types (e.g. “Stripe”, “RevenueCat”), category, display currency, whether a website is set and its domain name (e.g. example.com), whether MRRKit Pro is active, and creation date. Counting these entries gives us the number of projects.
Never collected: revenue figures or any metric, API keys, project names, email address or payment information. These statistics can only be read by the publisher, are never shared or sold, and are deleted together with your account.
5. What we don't do
- No advertising, no tracking across apps or websites, no data brokers.
- No third-party analytics or advertising SDK. Firebase Analytics is disabled.
- We never sell or rent personal data.
6. Processors
Google Ireland Ltd / Google LLC (Firebase Authentication, Cloud Firestore, Firebase Hosting) acts as our processor, under the Google Cloud Data Processing Addendum and the EU Standard Contractual Clauses. Apple Inc. processes purchases under its own policy.
7. Legal bases (GDPR)
Performance of the contract (providing the app and your account, art. 6(1)(b)) and our legitimate interest in securing and improving the service, including the anonymous usage statistics (art. 6(1)(f)). You can object to the statistics at any time by writing to us.
8. Retention & deletion
Account data, synced project settings and the related usage statistics are kept until you delete your account. You can delete your account at any time:
- In the app: Settings → Delete account (immediate).
- On the web: mrrkit.app/delete-account.
- By email: support@smartcom.digital (processed within 30 days).
Deleting the app removes local data, including API keys stored in the Keychain via the in-app "Erase local data" option or by deleting each project.
9. Your rights
You can access, rectify, export or delete your data, object to or restrict its processing, by writing to support@smartcom.digital. You may also lodge a complaint with your supervisory authority (in Belgium: the Data Protection Authority, autoriteprotectiondonnees.be).
10. Security
Keys are stored with iOS Keychain protection. All network traffic uses HTTPS. Firestore security rules ensure only your authenticated account can read or write your projects, and only the publisher can read the usage statistics. You can additionally lock the app with Face ID.
11. Children
MRRKit is intended for professionals and is not directed to children under 16.
12. Changes
We will update this page when the app evolves and change the date above. Significant changes will be announced in the app.