Privacy Policy

Vestipy · Last updated 29 July 2026

This policy explains what data the Vestipy mobile application and its backend service collect, why, and what you can do about it. It applies to the Android application com.prashantkmr389.vestipy and the API at api.vestipy.com.

Vestipy is an advisory and information platform. It publishes trade signals authored by other users for informational purposes. It does not execute trades, place broker orders, or manage funds on your behalf. Nothing in the app is a personal recommendation, and trading carries risk of loss.

Who we are

Vestipy is operated by the developer of the app. For any privacy question, data access request, or account deletion request, contact pallukumar303@gmail.com.

What we collect

DataWhySource
Email address To create and identify your account, and to sign you in You, via Google Sign-In or email sign-in
Display name and profile photo URL Shown on your profile and next to content you publish Your Google account, or entered by you
Account identifier Links your account to your data on our server Generated by Firebase Authentication
App activity — signals you publish or view, experts you follow, notification preferences To provide the core features of the app Your use of the app
Chart images you upload Attached to trade signals you publish You, from your device photo library
Push notification token To deliver notifications you have enabled Firebase Cloud Messaging on your device
Crash and error diagnostics To find and fix defects Automatically, when the app encounters an error

Photo library access. The app requests photo access only when you choose to attach a chart image to a signal. We receive only the image you select. We do not browse or upload your library.

What we do not collect

Crash diagnostics

We use Sentry to collect crash and error reports. It is configured not to attach personal identifiers: usernames, email addresses, and IP addresses are disabled, request bodies are not transmitted, and authentication headers are stripped before any report is sent. Reports contain technical information such as the error, the device model, and the app version.

Service providers

We share data only with providers who process it on our behalf, under their own privacy terms:

ProviderPurpose
Google Firebase (Authentication, Cloud Messaging, Firestore)Sign-in, push notifications, profile storage
Google Cloud PlatformHosting of the backend and database, in the Mumbai (asia-south1) region
SentryCrash and error diagnostics

Market data shown in the app is obtained from a market data provider. No personal data is sent to that provider.

Where your data is stored

Application data is stored in Google Cloud Platform in the Mumbai (asia-south1) region. Firebase Authentication and related Google services may process data in other regions in accordance with Google's terms. Backups are encrypted and retained for up to 90 days.

Security

All traffic between the app and our servers is encrypted with TLS. Access to your account requires a valid authentication token, checked on every request. Database credentials and service keys are held in a managed secrets service and are not stored in the application. Our database is not reachable from the public internet.

How long we keep data

Account and profile data is retained while your account is active. Published trade signals are retained as an immutable historical record for the integrity of expert performance statistics, and are dissociated from your identity when your account is deleted. Crash diagnostics are retained for up to 90 days. Encrypted backups are retained for up to 90 days, after which deleted data is removed from them by expiry.

Deleting your account and data

You can request deletion of your Vestipy account and its associated personal data at any time.

Send a request from your registered email address to pallukumar303@gmail.com with the subject "Vestipy account deletion request". We verify the request comes from the address registered to the account, then delete it.

What is deleted: your account record, email address, display name, profile photo URL, notification preferences, push notification tokens, follow relationships, in-app notifications, and the image files of any charts you uploaded.

What is retained: trade signals you published, in anonymised form. They form part of the historical performance record other users rely on, and are stored so that they cannot be altered after publication. After deletion the author record carries no name, email, photo, or link to your account.

Where a chart image was attached to a published signal, the stored image file is erased but an empty reference remains inside that immutable record, so the signal continues to display without the image. Chart images never attached to a published signal are deleted outright.

Requests are actioned within 30 days. Data may persist in encrypted backups for up to 90 days before expiring.

Your rights

You may request access to the personal data we hold about you, ask us to correct it, or ask us to delete it, using the contact address above. You may disable push notifications at any time from your device settings or in the app.

Children

Vestipy is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of this page. Material changes will be communicated in the app.

Contact

pallukumar303@gmail.com