Privacy Policy
StockSpy
This Privacy Policy explains how StockSpy (“we”, “us”, “our”) collects, uses, and shares information when you use the StockSpy mobile application on iOS and Android (the “App”).
1. Summary
- You can browse much of the App without an account.
- Sign-in uses your phone number (Firebase Authentication).
- When signed in we store account data such as follows, watchlists, “My tickers”, alert preferences, and push tokens so your choices sync across devices.
- Free users may see ads (Google AdMob).
- Paid StockSpy Pro is handled by Apple / Google and RevenueCat; we do not receive your full payment card details.
- Disclosure content in the App comes from public government sources, not from private brokerage accounts.
- You can delete your account and associated cloud profile from Settings.
2. Information we collect
2.1 Information you provide
- Phone number and related authentication data when you sign in (verification codes are processed by our authentication provider).
- Account preferences you choose in the App, including:
- people and entities you follow;
- ticker watchlist items;
- “My tickers” symbols and optional notes;
- smart alert rules (e.g. large trades, buys, sells, watched tickers, clusters);
- push notification preference (on/off).
- Content of support messages if you contact us by email.
2.2 Information collected automatically
- Device and app data typical of mobile apps (device type, OS version, app version, language, time zone, crash/diagnostic logs where available).
- Push notification token (FCM) when you enable remote push, so we can deliver alerts while the App is closed.
- Approximate usage signals needed to operate subscriptions and ads (for example, whether Pro is active, ad request events).
- Advertising identifiers and related signals used by our ad partner on free-tier experiences (subject to your device ad / tracking settings and platform rules).
2.3 Information from stores and subscription partners
- When you purchase or restore StockSpy Pro, Apple App Store, Google Play, and/or RevenueCat process the transaction and may share with us a non-sensitive subscription status (e.g. active entitlement, product identifier, original transaction references). We do not store full payment card numbers.
2.4 Public content (not personal data about you)
The App displays publicly available financial disclosure information (for example U.S. House and Senate periodic transaction reports, OGE executive disclosures, and SEC EDGAR 13F holdings) and related market context (such as ticker symbols and publicly available price charts where shown). That content concerns public filers and markets; it is not collected from your private brokerage accounts.
3. How we use information
- Provide, maintain, and improve the App (authentication, sync, feed, insights, compare, alerts).
- Deliver in-app and remote push notifications you enable, filtered by your rules when applicable.
- Process and validate subscriptions (Free vs Pro features, restore across devices on the same account where supported).
- Show advertising to free users and measure ad performance.
- Secure the service, prevent abuse, debug crashes, and comply with law.
- Communicate about the App when you contact us or where required (e.g. material policy changes).
We do not sell your personal information.
4. Legal bases (EEA/UK users)
Where GDPR / UK GDPR applies, we rely on:
- Contract — to provide the App and account features you request;
- Legitimate interests — to secure, maintain, and improve the service, and to understand aggregate usage in a privacy-respecting way;
- Consent — where required for notifications, certain advertising/tracking, or optional features (you can withdraw consent in device settings or by disabling the feature);
- Legal obligation — when we must retain or disclose information to comply with law.
5. How we share information
We share personal information only as needed with service providers who process it on our instructions, or as required by law:
- Google Firebase (Google LLC) — Authentication, Cloud Firestore, Cloud Messaging / related infrastructure.
- Google AdMob — advertising for free-tier users.
- Apple and Google Play — app distribution, in-app purchases, and platform services.
- RevenueCat — subscription status and receipt validation.
- Hosting / cloud infrastructure used to run backend jobs that power remote alerts (e.g. scheduled checks of public filings).
- Authorities if required by law, legal process, or to protect rights, safety, and security.
These providers may process data in the United States or other countries. Where required, we rely on appropriate safeguards (such as standard contractual clauses implemented by those providers).
6. Data retention
- Account profile (follows, lists, rules, tokens, etc.) is kept while your account is active.
- If you delete your account in the App, we delete your cloud user profile and associated personal data we control, subject to short technical backup windows and any data we must retain by law.
- Local data on your device (caches, local preferences) may remain until you uninstall the App or clear app storage.
- Store subscriptions are managed by Apple or Google; deleting the App account does not automatically cancel a paid subscription—you must cancel in the store settings if desired.
- Public disclosure datasets and caches are not “your” personal data and may be retained or refreshed independently.
7. Your choices and rights
- Account — sign out anytime; delete account from Settings (removes cloud profile and personal lists we store).
- Push notifications — disable in the App and/or system settings.
- Ads / tracking — use iOS App Tracking Transparency / system privacy settings and Android ad preferences where available.
- Access, correction, deletion, portability, objection — contact us at the email above. You may also have the right to lodge a complaint with your local supervisory authority (EEA/UK).
8. Children’s privacy
The App is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
9. Security
We use industry-standard measures appropriate to a consumer mobile app (including encrypted transport (HTTPS/TLS) and access controls on cloud data). No method of transmission or storage is 100% secure.
10. Third-party links and content
The App may open external links (for example Privacy Policy / Terms pages, or official filing pages). Third-party sites and services are governed by their own policies. Public disclosure data may be incomplete, delayed, or incorrect; see our Terms of Use.
11. California and similar U.S. state notices
We do not sell personal information as “sell” is commonly defined. We may “share” limited data for cross-context advertising via ad partners when ads are shown; you can control tracking where the OS provides controls. To request access or deletion, email us with “California Privacy Request” (or your state) in the subject line.
12. International users
If you use the App from outside the country where our infrastructure is hosted, your information may be transferred to and processed in other countries that may have different data-protection laws than your own.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version at this URL and change the “Last updated” date. Material changes may also be highlighted in the App where appropriate. Continued use after the effective date means you accept the updated policy.
14. Contact
Guribye design
Email: post@guribye.no
Last updated: 11 August 2026
Related: Terms of Use