Privacy Policy
Effective date: 28 August 2026 · Applies from the moment of publication at ota.aistastudio.ru
1. Operator and scope
1.1. The personal data operator is Общество с ограниченной ответственностью «СТУДИЯ АИСТА», OGRN 1267800056260, TIN (INN) 7814865711, KPP 781401001, address: 197706, г. Санкт-Петербург, вн.тер.г. город Сестрорецк, ул. Всеволода Боброва, д. 30, литера А, помещ. 1-Н, офис 13, hereinafter the "Operator", "we".
1.2. This Policy is drafted in accordance with Russian Federal Law No. 152-FZ "On Personal Data" of 27.07.2006 and defines how personal data is processed and protected in the operation of Otapush — an OTA update server for React Native/Expo mobile applications — including the website, the developer portal and the update API at https://ota.aistastudio.ru.
1.3. The contact address for personal data matters is privacy@aistastudio.ru.
2. Data subjects
We process the data of the following categories of data subjects:
- Developer clients — individuals who register an account in the Otapush portal;
- End users of our clients' apps — users of our clients' mobile applications whose devices contact the server for updates. With respect to their data we act not as the operator but on the client's instructions (section 5);
- Website visitors — with respect to cookies, browser storage and web analytics (section 7).
3. What data is processed
| Category | Contents |
|---|---|
| Developer account data | Email address, name, password hash (bcrypt; the password is never stored in plain text), subscription plan, registration date. |
| Portal data | Applications (name, slug, runtime version, code-signing certificates), distribution channels, published updates (JavaScript bundles and assets, publish messages, commit identifiers), API keys. For each API key only its SHA-256 hash and a prefix of the first 12 characters are stored: the key itself is shown once at creation and cannot be recovered. |
| End-user device data | The device identifier deviceId, the application identifier, the calendar month of contact (YYYY-MM), the platform (iOS/Android), the channel, the time of last contact; check, download and install events with the update identifier and timestamp. See section 5 for details. |
| Payment data | Payment amount, date and status, order and payment identifiers of the payment provider, payment method (bank card or invoice), payer type (individual or legal entity). We do not receive or store full bank card data — it is processed by the payment provider (section 6). |
| Server technical logs | Request date and time, HTTP method, request path, response status code, processing duration; on errors — the error message. IP addresses and User-Agent strings are not written to the log. |
| Cookies and browser storage | The portal session token, the selected interface language, the recorded cookie choice — section 7. |
3.1. The Operator does not intentionally collect special categories of personal data (concerning health, criminal records, religious or political beliefs) or biometric personal data.
4. Purposes and legal grounds
| Purpose | Legal ground |
|---|---|
| Registration, identification and provision of access to the portal | Performance of a contract to which the data subject is a party (clause 5, part 1, art. 6 of 152-FZ) |
| Checking for and delivering OTA updates to devices | Performance of a contract (clause 5, part 1, art. 6 of 152-FZ) |
| MAU counting and billing, update statistics for the client | Performance of a contract (clause 5, part 1, art. 6 of 152-FZ); with respect to end-user data — processing on the client operator's instructions (part 3, art. 6 of 152-FZ) |
| Payments, issuance of fiscal receipts, accounting and tax records | Compliance with obligations imposed by law (clause 2, part 1, art. 6 of 152-FZ); Federal Laws 54-FZ and 402-FZ, the Tax Code of the Russian Federation |
| Security, failure diagnostics, abuse prevention | Legitimate interests of the Operator, provided the data subject's rights are not infringed (clause 7, part 1, art. 6 of 152-FZ) |
| Support and responses to inquiries | Performance of a contract; the data subject's consent |
| Website analytics (Yandex Metrika) | The data subject's consent (clause 1, part 1, art. 6 of 152-FZ) — section 7 |
4.1. Processing includes: collection, recording, systematization, accumulation, storage, clarification, retrieval, use, transfer (provision, access), depersonalization, blocking, deletion and destruction. Processing is automated.
4.2. The Operator does not make decisions producing legal consequences for the data subject based solely on automated processing (art. 16 of 152-FZ).
5. End-user data of our clients' apps
5.1. Who the operator is here. Our clients' apps contact the Otapush server for updates, and in doing so we process information about their end users' devices. The purposes and scope of this processing are determined by the developer client — the client is the personal data operator for its end users, and Otapush processes that data on the client's instructions (part 3, art. 6 of 152-FZ). We are physically unable to obtain an end user's consent: we do not know who they are and have no way to contact them.
5.2. What deviceId is. The device identifier is set by the client's app itself and is sent with every update check — the technical details are described in the protocol documentation. We do not generate this identifier, do not verify it and do not link it to a user's identity: to us it is an opaque string chosen by the client. Clients should use a stable technical identifier (for example, getAndroidId() / getIosIdForVendorAsync() from expo-application) and must not put direct personal data — email addresses, names, phone numbers — into deviceId.
5.3. What we store about devices. A record of the form "application + deviceId + calendar month (YYYY-MM) + platform + channel + time of last contact" — needed to count MAU (monthly active users), the unit the service is billed by — and check (update check), download and install (update launch) events with the update identifier and timestamp. These records form the statistics the client sees in the portal.
5.4. Allocation of responsibilities. The lawfulness of the processing (the user's consent or another legal ground), informing users and answering their requests are the client's responsibility; confidentiality, security and processing strictly within the scope of the instructions are the Operator's responsibility (art. 19 of 152-FZ).
5.5. As of this revision, no separate data processing agreement between the Operator and the client has been published; the allocation of roles described in this section applies de facto. Until such an agreement is published, requests from data subjects whose data is processed on a client's instructions will be forwarded to that client as the operator, and the requester will be informed accordingly, unless doing so would violate the rights of others.
6. Who data is shared with
| Recipient | What is shared and why |
|---|---|
| TBank JSC (Russia) — payment provider (internet acquiring) | Payment amount and description, order identifier, email address for the fiscal receipt (54-FZ). Purpose — accepting payment and issuing the receipt. Bank card data is entered on the payment provider's page and never reaches us. |
| Yandex LLC (Russia) — the Yandex Metrika counter | Website visit information — only after explicit consent via "Accept all" (section 7). Before consent the counter is not loaded and no data is transferred. |
| Government authorities | Upon a reasoned request, in the cases and to the extent provided by the legislation of the Russian Federation. |
6.1. Personal data is not sold and is not shared with advertising networks or data brokers.
6.2. All recipients listed above are located in the Russian Federation.
7. Cookies and analytics
7.1. Identifiers in cookies and browser storage, together with the IP address, may allow a user to be indirectly identified, so we treat them as personal data (art. 3 of 152-FZ, art. 10.1 of 149-FZ).
7.2. Necessary storage — processed without separate consent because the service cannot work without it (legal ground — performance of a contract, clause 5, part 1, art. 6 of 152-FZ):
ota_token(localStorage) — the portal session token (JWT, valid for 30 days);otapush-lang(localStorage) — the selected interface language;otapush_cookie_consent(localStorage) — the record of your choice in the cookie banner (clause 7.4).
7.3. Optional storage — Yandex Metrika web analytics. The counter loads only after you click "Accept all" in the banner. Until then the counter script is not loaded and no data is transferred; silence or closing the banner does not count as consent. The counter is enabled with the click map (clickmap), outbound link tracking (trackLinks) and accurate bounce tracking (accurateTrackBounce); the session replay (Webvisor) is deliberately disabled.
7.4. The choice is stored in localStorage under the key otapush_cookie_consent as {"choice":"all"|"necessary","version":1,"decidedAt":"<ISO timestamp>"}. The record has no expiry; consent is re-asked of all users by incrementing the consent text version number.
7.5. Choosing "Necessary only" leaves the service fully functional. You can change or withdraw your choice at any time via the "Cookie settings" link in the site footer — it opens the same banner showing your current choice — or by clearing the site data in your browser, or by writing to privacy@aistastudio.ru. When consent previously given is withdrawn, the page reloads: an already loaded counter cannot otherwise be switched off from within the page.
8. Retention periods
| Data | Period |
|---|---|
| Account data and portal content (apps, channels, updates, API keys) | For the lifetime of the account; deletion — upon request (section 10) |
| Payment data | The periods mandated by accounting and tax legislation (at least 5 years — part 1, art. 29 of 402-FZ) |
| Device records and update events | Organized by calendar month; automatic rotation is not configured as of this revision, and a fixed period will be stated here once it is implemented |
| Server technical logs | Automatic rotation is not configured; a period will be stated here once it is implemented |
| The cookie consent record | On the user's device, without expiry — until the choice is changed or the site data is cleared |
8.1. Data is destroyed or depersonalized once the processing purposes are achieved, when consent is withdrawn (if there is no other legal ground for processing), or when the periods above expire.
9. Data protection
9.1. The Operator takes legal, organizational and technical measures under art. 18.1 and 19 of 152-FZ, including:
- passwords are stored only as irreversible hashes (bcrypt, cost 10);
- API keys are stored as a SHA-256 hash plus a short prefix;
- portal sessions use signed JWT tokens (HS256) valid for 30 days;
- the private code-signing keys for updates never leave the server;
- external connections are encrypted (TLS, terminated at the reverse proxy);
- each client's data is isolated: requests to apps, keys and statistics are served only to their owner.
10. Data subject rights and how to exercise them
10.1. You have the right to: obtain information about the processing of your data (art. 14 of 152-FZ); demand its clarification, blocking or destruction if it is incomplete, outdated, inaccurate or unlawfully obtained; withdraw your consent to processing (part 2, art. 9 of 152-FZ); object to processing; appeal the Operator's actions to Roskomnadzor or in court (art. 17 of 152-FZ).
10.2. Rights are exercised by sending a request to privacy@aistastudio.ru from the email address linked to your account; the request must contain information allowing us to identify you and the substance of your demand. As of this revision the portal has no self-service tools for exporting or deleting data — requests are handled manually. A response is provided within 10 working days, extendable by no more than 5 working days with notice of the reasons.
10.3. If you are an end user of one of our clients' apps, the operator of your data is the developer of that app: direct your request to them. A request that reaches us will be forwarded to the client, and you will be informed accordingly, unless doing so would violate the rights of others (clause 5.5).
10.4. Supervisory authority: the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor), rkn.gov.ru.
11. Changes to this Policy
11.1. The Operator may amend this Policy. A new revision is published on this page with its effective date; in case of material changes we additionally notify users through the portal interface or by email.
11.2. Previous revisions are provided upon request to privacy@aistastudio.ru.
12. Operator details
- Operator: Общество с ограниченной ответственностью «СТУДИЯ АИСТА» (ООО «СТУДИЯ АИСТА»)
- OGRN: 1267800056260
- TIN (INN): 7814865711, KPP: 781401001
- Registered address: 197706, г. Санкт-Петербург, вн.тер.г. город Сестрорецк, ул. Всеволода Боброва, д. 30, литера А, помещ. 1-Н, офис 13
- Service website: https://ota.aistastudio.ru
- Contact address for personal data matters: privacy@aistastudio.ru
- Roskomnadzor processing notification (art. 22 of 152-FZ): уведомление готовится к подаче
- Tax regime: НДС не облагается в связи с применением упрощённой системы налогообложения (п. 2 ст. 346.11 НК РФ)