Human control is part of the security model.

AppPilot is designed to keep review access, AI assistance, and public publishing as separate, visible decisions.

Approval before publishing

Draft generation never equals public submission. A person chooses Publish reply.

Scoped source access

The connection flow explains what AppPilot needs before authorization.

Uncertain cases stay visible

Sensitive or low-confidence items can move to Needs human.

Operational traceability

Published replies, edits, and queue outcomes remain reviewable.

GOOGLE PLAY CONNECTION

Explain access before asking for it.

The connection screen distinguishes reading reviews from publishing approved replies, and it shows the selected app before sync begins.

Requested accessGOOGLE PLAY
Read app reviewsImport review text, rating, language, version, and device context.
Publish approved repliesSubmit only the reply you explicitly approve in AppPilot.
Sync review statusKeep queue and published history consistent with Google Play.
Security details must match the implementation.

This page is a product design target. Data retention, encryption, subprocessors, compliance claims, and incident procedures must be verified before publication.