Privacy Policy
Last updated: May 18, 2026
This policy explains what data Juice Machine ("we", "us") collects when you use the service at juicemachine.net, why we collect it, how we keep it safe, and the rights you have over it.
Who we are
Juice Machine is a small SaaS that receives webhooks from Apple's App Store Connect and forwards them to channels of your choice (Slack, generic HTTP destinations, etc.). It's operated by Simon Maddox.
For any privacy-related questions, please email support@juicemachine.net.
What we collect, and why
Account data
- Email address, password (hashed via bcrypt), and display name — required to sign you in and address you in emails.
- Team name(s) you create, and the role you hold in each — required to scope what you can access.
App configuration
- App name, bundle ID, and (optionally) App Store Connect API credentials (Issuer ID, Key ID, and the contents of a
.p8private key file) — used to enrich incoming webhooks with app-name, version, and build details from Apple's API on your behalf. - The
.p8private key is encrypted at rest using ActiveRecord Encryption. It is decrypted in memory only when we need to call the App Store Connect API on your behalf, and is never written to logs.
Webhook events
- Payloads Apple sends to your Juice Machine webhook URL — stored so you can audit, replay, and inspect what was received. These payloads may contain bundle IDs, version numbers, build numbers, transaction IDs, subscription state, and TestFlight feedback text. They do not contain Apple customer payment details or personally identifiable information beyond what Apple itself sends.
- Delivery records — for each webhook, which destination(s) it was forwarded to, the HTTP response status, and any error message. Useful for debugging and for surfacing failures in your dashboard.
Notification destination data
Each notification destination you configure has its own requirements; we store only what's necessary to deliver to that destination on your behalf.
- Slack — if you connect a Slack workspace via "Add to Slack", we receive and store a bot token granted by Slack, the workspace's name and ID, and the IDs of channels you choose to forward to. The bot token is encrypted at rest. We do not read messages from your workspace; the scopes we request (
chat:write,chat:write.public,channels:read,groups:read) are read-only with respect to channel metadata and write-only with respect to messages. - Microsoft Teams — we store the incoming-webhook URL you provide so we can POST to it.
- Discord — we store the webhook URL you provide so we can POST to it.
- Email — we store the email address you nominate. Messages are sent via our transactional email provider (Postmark, listed below).
- PagerDuty — we store the Events API v2 routing key you provide so we can trigger incidents on your behalf.
- Telegram — we store the bot token and chat ID you provide so we can call Telegram's
sendMessageAPI on your behalf. - Generic webhook — we store the URL you provide and POST event payloads to it. We do not modify or inspect the payload beyond what's required to format it for delivery.
Once a notification has been delivered to a destination, that destination's own privacy and retention policies apply. Juice Machine has no further control over the data once it leaves our servers.
Customer user-lookup (optional, per-app)
You can optionally configure a per-app URL ("user lookup URL")
that Juice Machine calls during enrichment of any event that
carries an appAccountToken. The token is appended
as ?app_account_token=…, and if you've configured
an auth header, that header is sent with the request. The
response is validated against a strict schema (name, primary
URL, up to eight name/value fields, up to four links) and
stored on the webhook event so the data lands in your
notifications.
This URL points at your own infrastructure, not a third party. Juice Machine is not a sub-processor of whatever data you choose to return — the customer fields, links, and any user identifiers in the response are entirely under your control. The auth header value (if configured) is encrypted at rest in the same way as your App Store Connect private key.
Billing data
- If you subscribe to a paid plan, payment is handled by Stripe. We do not receive or store your card number, CVV, or expiry. We do store a customer identifier from Stripe so we can look up your subscription state, plus the plan you signed up under.
Server-side logs
- Routine access logs include IP addresses, request paths, and timestamps. These are kept for operational and abuse-mitigation purposes and rotate out within ~30 days.
- Sensitive fields (passwords, tokens, secrets, private keys, certificates) are filtered out of request logs before they're written.
Sub-processors
We use the following third-party services to run Juice Machine. Each processes a defined slice of your data under their own privacy terms, which we encourage you to review:
- Hetzner Cloud (Germany, EU) — server hosting and database storage. Your data is stored in the EU.
- Cloudflare — DNS, CDN, and WAF. Requests transit through Cloudflare's edge network before reaching our origin.
- Stripe — billing and subscription management.
- Postmark — transactional email. Used for our own service emails (account confirmation, password reset, team invitations) and, if you've configured an email destination, to deliver webhook notifications to recipients you nominate.
- Sentry — error tracking. Stack traces and request metadata for failed requests are sent to Sentry; we have configured it not to include user PII by default.
- Apple — the source of webhooks the service forwards.
Notification destinations you choose
The notification destinations you configure (Slack, Microsoft Teams, Discord, PagerDuty, Telegram, email addresses, generic webhook URLs) are recipients, not sub-processors — you're directing Juice Machine to send data on your behalf to systems you've chosen. Each of those services has its own privacy and retention policies that apply once a message reaches them. Juice Machine has no further control over the data once it leaves our servers, and we recommend reviewing the privacy terms of any destination you connect.
Security
- All traffic between you and Juice Machine is encrypted in transit (TLS 1.2+).
- Sensitive credential columns (App Store Connect
.p8keys; Slack bot tokens) are encrypted at rest in the database. Losing the encryption keys would make these columns permanently unreadable; they are stored separately from the database. - Database backups are taken daily and retained for 30 days in Hetzner Object Storage (EU).
- Inbound webhooks are size-limited, rate-limited per source IP, and authenticated before processing (JWS signature verification for App Store Server Notifications V2; a unique, secret webhook URL per app for App Store Connect webhooks).
How long we keep data
- Account and team data: for as long as your account exists.
- Webhook events and delivery records: indefinitely, so you can audit history. Contact us if you want events older than a given date purged.
- Server-side request logs: ~30 days.
- Encrypted backups: 30-day rolling retention.
- If you delete your account, your team's data is removed within 30 days, except where we are legally obliged to retain certain records (e.g. billing records for tax purposes).
Your rights
If you are in the UK or EU, you have rights under the UK GDPR / EU GDPR including the right to access, correct, delete, restrict, and port your personal data, and to lodge a complaint with a supervisory authority. Email support@juicemachine.net and we'll respond within 30 days.
Cookies
We use a single first-party session cookie to keep you signed in. We do not use third-party advertising or tracking cookies.
Children
Juice Machine is a B2B developer tool and is not directed at children under 16. We do not knowingly collect data from children.
Changes to this policy
If we make material changes, we'll update the "Last updated" date at the top and, where appropriate, email account holders. Continued use of the service after a change indicates acceptance of the revised policy.