Privacy Policy
Last updated: 5 August 2026
ChartRooster shows market charts and notifies you when chart alarms trigger. This policy explains which personal data the ChartRooster app (Android and iOS) and its backend at `api.chartrooster.com` process, why, and what rights you have.
1. Who is responsible
Controller within the meaning of the GDPR:
Tom Robert Am Schürenbusch 9a, 58638 Iserlohn, Deutschland Email: [email protected]
2. What we collect and why
- Account data — first name, last name, email address, phone number and a
password, collected when you register. The password is stored only as a hash, never in plain text. We use this data to create and secure your account, to send the account-confirmation email and password-reset emails. Providing it is required to open an account.
- Session tokens — after login, opaque access/refresh tokens identify your
session. On your device they are kept in encrypted storage (Android Keystore / iOS Keychain).
- Push notification token — if you enable notifications, the Firebase
Cloud Messaging (FCM) registration token of your device plus the platform (Android/iOS) is stored on our server so we can deliver alarm notifications. It is removed when you disable push notifications in the app, log out, or delete your account.
- Alarm settings and alarm history — the alarms you subscribe to
(instrument, timeframe, market, indicator parameters) and your triggered- alarm history. This is the core service.
- Subscription/purchase data — if you buy a subscription: on Android the
Google Play purchase token, product ID, plan ID and an obfuscated account ID (a SHA-256 hash of your user ID); on iOS the App Store (StoreKit) transaction ID and product ID. We use these to verify your purchase with Google/Apple and to manage your entitlement. Payment itself is handled entirely by Google Play or the Apple App Store — we never see your payment details (card numbers, bank data).
- Consent records — which legal documents (terms of service, risk notice)
you accepted, in which version and language, and when — kept as legal proof.
- Server logs — IP address, request timestamps, user agent and rate-limit
counters arise technically on our servers. We use them for security, abuse prevention and operating the service.
- Market data connection — the app loads price data (candles) directly
from Binance's public market-data API. Your IP address thereby reaches Binance; no account or personal data is sent with these requests.
- Stored only on your device (never transmitted): interface settings
(language, theme, quiet hours, displayed time zone), a short local log of recently triggered alarms (kept at most 24 hours / 100 entries), and — in encrypted storage — your email address for login convenience.
The app contains no advertising and no analytics or tracking SDKs, and we do not sell personal data.
3. Legal bases
- Contract performance (Art. 6(1)(b) GDPR): account, alarms, notifications
as part of the service, subscription handling.
- Consent (Art. 6(1)(a) GDPR): push notifications — you grant the system
notification permission and can revoke it or switch notifications off in the app at any time.
- Legitimate interests (Art. 6(1)(f) GDPR): security, fraud and abuse
prevention, service integrity (server logs, rate limiting).
- Legal obligation (Art. 6(1)(c) GDPR): statutory retention of billing
records.
4. Who we share data with
We share personal data only with the processors and recipients needed to run the service:
- Google LLC / Google Ireland Limited — Firebase Cloud Messaging (delivery
of push notifications) and Google Play (subscription purchase and server-side purchase verification).
- Apple Inc. / Apple Distribution International Ltd. — App Store /
StoreKit subscription purchase and verification (iOS version).
- Railway Corp. (USA) — hosting of our backend (`api.chartrooster.com`).
- Cloudflare, Inc. (USA) — DNS and traffic proxying in front of our
backend.
- Resend, Inc. (USA) — technical delivery of
account-confirmation and password-reset emails.
- Binance — your device connects directly to Binance's public market-data
API (see section 2); Binance receives your IP address, nothing more.
No data is shared for advertising purposes. No automated decision-making including profiling (Art. 22 GDPR) takes place.
5. International transfers
Google, Apple, Railway, Cloudflare and Resend are US companies; data may be processed in the United States. These transfers rely on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR). The direct market-data connection to Binance transmits only your IP address and request metadata.
6. How long we keep data
- Account data, alarms, push tokens: for as long as your account exists;
push tokens already go when you log out or disable notifications.
- Server logs: short-term only; deleted or anonymized as soon as they are
no longer needed for security and operations.
- After account deletion we retain only: billing/subscription records
(statutory commercial and tax retention, § 257 HGB / § 147 AO — depending on the record up to ten years) and consent records (proof of your acceptance of the legal documents, until the statutory limitation periods expire). Everything else is erased.
7. Deleting your account and data
You can delete your account in the app: Settings → Subscription & Account → *Delete account*. Deletion is immediate: profile and credentials, sessions, push tokens, alarm subscriptions and alarm history are erased; your email address becomes free for re-registration. What remains is only what section 6 lists. If you have an active subscription, cancel it first in Google Play / the App Store — the app guides you there; account deletion alone does not stop the subscription billing.
Alternatively, email us at [email protected] from your registered address and we will delete the account for you.
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Where processing relies on consent, you may withdraw it at any time with effect for the future (Art. 7(3)) — e.g. by disabling push notifications. You may lodge a complaint with a data-protection supervisory authority (Art. 77). Contact for all requests: [email protected].
9. Security
All transmissions are TLS-encrypted. Passwords are stored only as hashes. Session tokens are kept in your device's encrypted storage. Access to production systems is restricted. Neither the app nor this page embeds third-party trackers.
10. Children
ChartRooster deals with trading and market data and is directed at adults. It is not directed at children, and we do not knowingly collect data from children.
11. Changes to this policy
We update the date at the top when this policy changes and announce material changes in the app.
12. Contact
Tom Robert Am Schürenbusch 9a, 58638 Iserlohn, Deutschland Email: [email protected]