Security

Last updated September 30, 2026

You trust Starquill with keys to your developer accounts. Here's how we protect them.

Least privilege

  • App Store: we ask for an API key with the Customer Support role, which can read reviews and answer them, and nothing else: no builds, no pricing, no finance.
  • Google Play: the service account only needs “View app information” and “Reply to reviews”.
  • You can revoke a key anytime in App Store Connect or Google Cloud, and remove it from Starquill in one click.

Encryption

  • Store keys and Slack webhook URLs are encrypted with AES-256-GCM before they reach the database, with a key kept outside the database.
  • Keys are never sent back to the browser after you save them.
  • All traffic uses HTTPS. Passwords are stored as salted hashes.

Isolation

Every request is checked against your workspace on the server, so one account can never read or change another's data.

Replies need you

Nothing is posted to the stores automatically. AI drafts replies; a person presses Send.

Reporting a problem

If you find a security issue, email [email protected]. We'll respond quickly and credit you if you'd like.