Legal
Privacy Policy
Last updated: 1 July 2026 · RealCPA
1. Controller
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
Marco Pollmann
Schwalenbergstr. 7
33428 Marienfeld
Germany
Email: info.twoclouds@gmail.com
RealCPA (https://realcpa.tech) is a software service for mobile app developers to analyse paid user acquisition performance.
2. Scope
This policy applies to visitors of our website, registered account holders, and data submitted through the self-report attribution ingest API that our customers integrate into their mobile apps.
If you use RealCPA as a customer, you remain the controller for end-user data collected in your app. We process that data on your instructions as a processor (Art. 28 GDPR).
3. Data we collect
Account and profile data: email address, authentication credentials (or Google sign-in via OAuth), subscription plan, trial and billing status.
Payment data: subscriptions are handled by Stripe. We store Stripe customer and subscription identifiers, not full card numbers.
Integration credentials: when you connect RevenueCat, TikTok Ads, or AppsFlyer, we store API tokens and related account identifiers encrypted at rest (AES-256-GCM).
Business and analytics data: campaign names and IDs, ad spend, revenue, conversion metrics, geo breakdowns, and aggregated subscriber statistics synced from your connected accounts.
Self-report attribution data: when your app sends responses to our ingest API, we store an app user identifier (typically your RevenueCat user ID), the selected answer, and an optional timestamp. We do not intentionally collect IP addresses or device identifiers through this endpoint.
AI feature inputs: if you use in-app chat or AI recommendations, your messages and aggregated dashboard context are sent to our AI provider to generate responses. Chat history is kept in your browser session and is not stored permanently in our database.
4. Purposes and legal bases
We process personal data to provide and operate the service, manage accounts and subscriptions, sync connected integrations, display dashboards, and generate AI-assisted insights (Art. 6(1)(b) GDPR, performance of a contract).
We process data necessary to secure the platform, prevent abuse, and comply with legal obligations (Art. 6(1)(c) and (f) GDPR).
Where Google OAuth is used, authentication is based on your consent to sign in with Google (Art. 6(1)(a) GDPR).
5. Processors and third-party services
We use the following categories of service providers. We do not use marketing analytics, advertising trackers, or similar profiling tools on our website or in the product.
- Supabase (database, authentication, hosting of application data in the EU)
- Stripe (subscription billing and payment processing)
- Hosting provider (delivery of the web application)
- DeepSeek (AI chat and campaign recommendations, only when you use those features)
When you connect third-party accounts, data is also exchanged with those providers under your configuration: RevenueCat, TikTok for Business, and AppsFlyer. Those providers process data under their own terms and privacy policies.
Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses where applicable.
6. Cookies and local storage
We do not use cookies for advertising or analytics.
Strictly necessary cookies: Supabase authentication cookies to keep you signed in.
Local storage: we store UI preferences locally in your browser (for example selected app, dashboard widget visibility, theme, and chat panel state). These are functional settings only and are not used for tracking.
7. Retention
We retain account and integration data for as long as your account is active. After account deletion, we delete or anonymise personal data within a reasonable period unless longer retention is required by law.
Synced metrics and self-report responses are retained to provide the service. You may request deletion by contacting us.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw consent at any time where processing is based on consent.
You also have the right to lodge a complaint with a supervisory authority. In Germany, you may contact the data protection authority responsible for your place of residence or our registered location.
To exercise your rights, email info.twoclouds@gmail.com.
9. Security
Integration credentials are encrypted at rest. Database access is protected by row-level security so each customer can only access their own data. API keys you provide are requested with read-only scope where supported.
10. Children
RealCPA is a B2B service for app developers and is not directed at children under 16.
11. Changes
We may update this policy when our service or legal requirements change. The current version is always published on this page.