Skip to content
Refund Sensor

Security & privacy

Official store APIs only, credentials encrypted with AES-256-GCM, and no personal customer data ever stored.

Official channels only

Refund Sensor works exclusively through Apple and Google's own official APIs. Responding to a consumption request or a chargeback review is a normal, sanctioned developer action, so using Refund Sensor does not put your store account at risk. Nothing ever touches your app binary or your customers' devices.

Verified events

Every inbound notification is checked for authenticity before it is acted on. Apple's notifications are cryptographically signed and verified against Apple's own certificates, and Google's deliveries are validated the same way, so a forged or tampered event is rejected rather than processed.

Credential encryption

The store credentials you provide, your Apple API key and your Google service-account key, are encrypted at rest with AES-256-GCM under a rotatable key, and are transmitted only over encrypted connections. They are verified once when you connect, and are never displayed again or exposed in logs after you save them.

What data we store

Refund Sensor logs the refund request and the response it sends, things like transaction IDs, product IDs, and subscription details, plus the outcome the store returns. It does not collect, request, or store your customers' personal information, and it does not need any usage analytics from your app.

No pop-up is required. Apple already permits sharing consumption data, and most developers add a short line to their privacy policy or terms. Because Refund Sensor never handles personal data, there is nothing extra for your customers to accept.

On this page