Uprate uses your store access to import data and to run the store actions you ask for. Each feature, such as reviews, listings and analytics, has its own access check.
What access to grant
For App Store Connect, an Admin Team key covers everything and a Customer Support key covers reviews and replies. A Team key reaches every app in your Apple account. An Individual key follows its user's role and app access. See App Store Connect.
For Google Play, invite the service account that Uprate shows you and give it Admin (all permissions) only on the apps you want to connect. It does not need account-level Admin. Sales reports need account-level financial access, and Google's report files cover every app in the developer account. See Google Play.
How keys are stored
Uprate stores private keys encrypted and does not show them again after you save them. It never asks for your Apple ID or Google password.
What happens without asking
Connecting a store starts data imports and nothing else. Submissions and listing changes wait for your approval before Uprate sends them to a store.
Automatic review replies are the exception. When you turn them on, Uprate posts replies to matching reviews after the delay you set, without asking each time. See Reviews and replies.
Team access
Owners and Members can use store connections, including sending changes to the stores. The Analytics role sees analytics and the Reviewer role works with reviews. Only the team owner can edit or remove saved store keys.
Cut off access
Revoke the key in App Store Connect, or remove the service account from your apps in Play Console. That stops Uprate at the source.
Removing a key in Uprate alone may not be enough. Apps that already use a saved Apple key for pricing, or an uploaded Google account, keep an encrypted copy and keep syncing. Removing a Google account that Uprate created disconnects every app that uses it.