ChartRooster
Last updated: 2026-08-05Language: EN · DE

Privacy Policy

Last updated: 5 August 2026

ChartRooster shows market charts and notifies you when chart alarms trigger. This policy explains which personal data the ChartRooster app (Android and iOS) and its backend at `api.chartrooster.com` process, why, and what rights you have.

1. Who is responsible

Controller within the meaning of the GDPR:

Tom Robert Am Schürenbusch 9a, 58638 Iserlohn, Deutschland Email: [email protected]

2. What we collect and why

password, collected when you register. The password is stored only as a hash, never in plain text. We use this data to create and secure your account, to send the account-confirmation email and password-reset emails. Providing it is required to open an account.

session. On your device they are kept in encrypted storage (Android Keystore / iOS Keychain).

Cloud Messaging (FCM) registration token of your device plus the platform (Android/iOS) is stored on our server so we can deliver alarm notifications. It is removed when you disable push notifications in the app, log out, or delete your account.

(instrument, timeframe, market, indicator parameters) and your triggered- alarm history. This is the core service.

Google Play purchase token, product ID, plan ID and an obfuscated account ID (a SHA-256 hash of your user ID); on iOS the App Store (StoreKit) transaction ID and product ID. We use these to verify your purchase with Google/Apple and to manage your entitlement. Payment itself is handled entirely by Google Play or the Apple App Store — we never see your payment details (card numbers, bank data).

you accepted, in which version and language, and when — kept as legal proof.

counters arise technically on our servers. We use them for security, abuse prevention and operating the service.

from Binance's public market-data API. Your IP address thereby reaches Binance; no account or personal data is sent with these requests.

(language, theme, quiet hours, displayed time zone), a short local log of recently triggered alarms (kept at most 24 hours / 100 entries), and — in encrypted storage — your email address for login convenience.

The app contains no advertising and no analytics or tracking SDKs, and we do not sell personal data.

3. Legal bases

as part of the service, subscription handling.

notification permission and can revoke it or switch notifications off in the app at any time.

prevention, service integrity (server logs, rate limiting).

records.

4. Who we share data with

We share personal data only with the processors and recipients needed to run the service:

of push notifications) and Google Play (subscription purchase and server-side purchase verification).

StoreKit subscription purchase and verification (iOS version).

backend.

account-confirmation and password-reset emails.

API (see section 2); Binance receives your IP address, nothing more.

No data is shared for advertising purposes. No automated decision-making including profiling (Art. 22 GDPR) takes place.

5. International transfers

Google, Apple, Railway, Cloudflare and Resend are US companies; data may be processed in the United States. These transfers rely on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR). The direct market-data connection to Binance transmits only your IP address and request metadata.

6. How long we keep data

push tokens already go when you log out or disable notifications.

no longer needed for security and operations.

(statutory commercial and tax retention, § 257 HGB / § 147 AO — depending on the record up to ten years) and consent records (proof of your acceptance of the legal documents, until the statutory limitation periods expire). Everything else is erased.

7. Deleting your account and data

You can delete your account in the app: Settings → Subscription & Account → *Delete account*. Deletion is immediate: profile and credentials, sessions, push tokens, alarm subscriptions and alarm history are erased; your email address becomes free for re-registration. What remains is only what section 6 lists. If you have an active subscription, cancel it first in Google Play / the App Store — the app guides you there; account deletion alone does not stop the subscription billing.

Alternatively, email us at [email protected] from your registered address and we will delete the account for you.

8. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Where processing relies on consent, you may withdraw it at any time with effect for the future (Art. 7(3)) — e.g. by disabling push notifications. You may lodge a complaint with a data-protection supervisory authority (Art. 77). Contact for all requests: [email protected].

9. Security

All transmissions are TLS-encrypted. Passwords are stored only as hashes. Session tokens are kept in your device's encrypted storage. Access to production systems is restricted. Neither the app nor this page embeds third-party trackers.

10. Children

ChartRooster deals with trading and market data and is directed at adults. It is not directed at children, and we do not knowingly collect data from children.

11. Changes to this policy

We update the date at the top when this policy changes and announce material changes in the app.

12. Contact

Tom Robert Am Schürenbusch 9a, 58638 Iserlohn, Deutschland Email: [email protected]

← Back to ChartRooster