Boring, deliberate, and checkable.
You are about to connect an advertising account that spends real money, and point an app at the report that says what you earn. Here is exactly what that gives us, what it does not, and where each piece of data physically sits. Everything below describes the product as it ships today.
Amazon · Access
How we reach your ads
Advertising data moves over Amazon’s official Advertising API. You authorize SelfPub Go on Amazon’s own OAuth screen, with the campaign-management scope and nothing else. You never type an Amazon password into our app, and you can revoke our access from your Amazon account at any time — without asking us, and without uninstalling anything.
- No scraping. We do not log into Amazon’s advertising console on your behalf and we do not read it with a browser extension. If the API cannot do something, the app says so instead of working around it.
- Identified on every call. Requests to Amazon carry a versioned
User-Agentthat identifies the app, its version, and the account making the call, so Amazon can attribute every action to a named tool rather than to anonymous traffic. - No Selling Partner API, no KDP login. We hold no credential to your KDP account. Royalties get in through the report you export yourself.
Royalties
The part that never leaves
KDP’s terms restrict handing your royalty reports to third parties. That single constraint is why SelfPub Go is a desktop app and not a website.
- Parsed and stored locally. Royalty reports are read on your machine and written to a local database in your user profile. They are not uploaded to us, and there is no server-side copy to leak, subpoena, or lose.
- Encrypted at rest with the OS. That local store is encrypted through your operating system’s own secret service — Keychain on macOS, DPAPI on Windows — so the file is readable only under your account on your machine.
- Moving machines is your call. If you want your royalty history on a second computer, you export a password-encrypted bundle and import it there. Nothing travels through us.
Server side
What our servers do hold
Advertising data has to pass through our servers, because that is the only way Amazon’s API works. Being specific about it matters more than sounding minimal:
- Stored: your books and their ASINs, campaign structure, keywords, negatives and search terms, and the advertising metrics Amazon reports for them.
- Not stored: your KDP royalty reports and your Amazon password.
- Tenant isolation in the database, not just the code. Account rows are separated by Postgres row-level security: the policy is enforced by the database itself, and a query that arrives without an account context returns nothing rather than everything.
- Amazon tokens are encrypted at the application layer before they touch the database, with a key held in the server environment rather than in the repository or the client.
Writes
Nothing changes without you
Every operation that reaches Amazon — a bid, a budget, a paused campaign, a negative keyword, a new campaign — is started by you in the app and shown to you first, with the old value beside the new one.
- Automation proposes, it does not execute. The rules engine and the AI bid co-pilot produce suggestions with the data behind them. Applying is a button you press.
- New campaigns start paused. A campaign created in the app does not spend until you enable it.
- Changes are journalled. Bid, budget, state and negative-keyword changes are recorded with the old value, the new value, and who made them, so an unexpected number has a history you can read.
- Your data does not train models. We do not use your advertising or royalty data to train AI models, ours or anyone else’s.
Reporting
If you find a problem
Send security findings to security@selfpubgo.com. We answer within one business day, we will tell you plainly what we found and what we changed, and we will credit you if you want the credit. There is no paid bug bounty.
SelfPub Go is a small team in early access. We would rather publish a short list of controls that are true today than a long list that reads well. If a control you need is missing, ask — the honest answer is more useful to both of us than a page that implies otherwise.
Questions about how your data is handled?