Privacy Policy
Vestipy · Last updated 20 August 2026
This policy explains what data the Vestipy mobile application and its backend service collect, why, and what you can do about it. It applies to the Android application com.prashantkmr389.vestipy and the API at api.vestipy.com.
Who we are
Vestipy is operated by the developer of the app. For any privacy question, data access request, or account deletion request, contact support@vestipy.com.
What we collect
| Data | Why | Source |
|---|---|---|
| Email address | To create and identify your account, and to sign you in | You, via Google Sign-In or email sign-in |
| Display name and profile photo URL | Shown on your profile and next to content you publish | Your Google account, or entered by you |
| Account identifier | Links your account to your data on our server | Generated by Firebase Authentication |
| App activity — signals you publish or view, experts you follow, notification preferences | To provide the core features of the app | Your use of the app |
| Chart images you upload | Attached to trade signals you publish | You, from your device photo library |
| Push notification token | To deliver notifications you have enabled | Firebase Cloud Messaging on your device |
| Crash and error diagnostics | To find and fix defects | Automatically, when the app encounters an error |
Photo library access. The app requests photo access only when you choose to attach a chart image to a signal. We receive only the image you select. We do not browse or upload your library.
What we do not collect
- No advertising ID. The app does not request the
AD_IDpermission and cannot access your advertising identifier. - No advertising or third-party ad networks.
- No location data.
- No contacts, microphone, or camera access.
- No payment or financial account details. The app does not process payments or connect to your broker or bank.
- We do not sell your personal data, and we do not share it for advertising or marketing.
Crash diagnostics
We use Sentry to collect crash and error reports. It is configured not to attach personal identifiers: usernames, email addresses, and IP addresses are disabled, request bodies are not transmitted, and authentication headers are stripped before any report is sent. Reports contain technical information such as the error, the device model, and the app version.
Service providers
We share data only with providers who process it on our behalf, under their own privacy terms:
| Provider | Purpose |
|---|---|
| Google Firebase (Authentication, Cloud Messaging, Firestore) | Sign-in, push notifications, profile storage |
| Google Cloud Platform | Hosting of the backend and database, in the Mumbai (asia-south1) region |
| Sentry | Crash and error diagnostics |
Market data shown in the app is obtained from a market data provider. No personal data is sent to that provider.
Where your data is stored
Application data is stored in Google Cloud Platform in the Mumbai (asia-south1) region. Firebase Authentication and related Google services may process data in other regions in accordance with Google's terms. Backups are encrypted and retained for up to 90 days.
Security
All traffic between the app and our servers is encrypted with TLS. Access to your account requires a valid authentication token, checked on every request. Database credentials and service keys are held in a managed secrets service and are not stored in the application. Our database is not reachable from the public internet.
How long we keep data
Account and profile data is retained while your account is active. Published trade signals are retained as an immutable historical record for the integrity of expert performance statistics, and are dissociated from your identity when your account is deleted. Crash diagnostics are retained for up to 90 days. Encrypted backups are retained for up to 90 days, after which deleted data is removed from them by expiry.
Deleting your account and data
You can request deletion of your Vestipy account and its associated personal data at any time.
Send a request from your registered email address to support@vestipy.com with the subject "Vestipy account deletion request". We verify the request comes from the address registered to the account, then delete it.
What is deleted: your account record, email address, display name, profile photo URL, notification preferences, push notification tokens, follow relationships, in-app notifications, and the image files of any charts you uploaded.
What is retained: trade signals you published, in anonymised form. They form part of the historical performance record other users rely on, and are stored so that they cannot be altered after publication. After deletion the author record carries no name, email, photo, or link to your account.
Where a chart image was attached to a published signal, the stored image file is erased but an empty reference remains inside that immutable record, so the signal continues to display without the image. Chart images never attached to a published signal are deleted outright.
Requests are actioned within 30 days. Data may persist in encrypted backups for up to 90 days before expiring.
Your rights
You may request access to the personal data we hold about you, ask us to correct it, or ask us to delete it, using the contact address above. You may disable push notifications at any time from your device settings or in the app.
Children
Vestipy is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes will be communicated in the app.
Related
Risk Disclosure · Terms & Conditions · SCORES · SMART ODR