Vestipy · Last updated 29 July 2026
This policy explains what data the Vestipy mobile application and its backend service collect, why, and what you can do about it. It applies to the Android application com.prashantkmr389.vestipy and the API at api.vestipy.com.
Vestipy is operated by the developer of the app. For any privacy question, data access request, or account deletion request, contact pallukumar303@gmail.com.
| Data | Why | Source |
|---|---|---|
| Email address | To create and identify your account, and to sign you in | You, via Google Sign-In or email sign-in |
| Display name and profile photo URL | Shown on your profile and next to content you publish | Your Google account, or entered by you |
| Account identifier | Links your account to your data on our server | Generated by Firebase Authentication |
| App activity — signals you publish or view, experts you follow, notification preferences | To provide the core features of the app | Your use of the app |
| Chart images you upload | Attached to trade signals you publish | You, from your device photo library |
| Push notification token | To deliver notifications you have enabled | Firebase Cloud Messaging on your device |
| Crash and error diagnostics | To find and fix defects | Automatically, when the app encounters an error |
Photo library access. The app requests photo access only when you choose to attach a chart image to a signal. We receive only the image you select. We do not browse or upload your library.
AD_ID permission and cannot access your advertising identifier.We use Sentry to collect crash and error reports. It is configured not to attach personal identifiers: usernames, email addresses, and IP addresses are disabled, request bodies are not transmitted, and authentication headers are stripped before any report is sent. Reports contain technical information such as the error, the device model, and the app version.
We share data only with providers who process it on our behalf, under their own privacy terms:
| Provider | Purpose |
|---|---|
| Google Firebase (Authentication, Cloud Messaging, Firestore) | Sign-in, push notifications, profile storage |
| Google Cloud Platform | Hosting of the backend and database, in the Mumbai (asia-south1) region |
| Sentry | Crash and error diagnostics |
Market data shown in the app is obtained from a market data provider. No personal data is sent to that provider.
Application data is stored in Google Cloud Platform in the Mumbai (asia-south1) region. Firebase Authentication and related Google services may process data in other regions in accordance with Google's terms. Backups are encrypted and retained for up to 90 days.
All traffic between the app and our servers is encrypted with TLS. Access to your account requires a valid authentication token, checked on every request. Database credentials and service keys are held in a managed secrets service and are not stored in the application. Our database is not reachable from the public internet.
Account and profile data is retained while your account is active. Published trade signals are retained as an immutable historical record for the integrity of expert performance statistics, and are dissociated from your identity when your account is deleted. Crash diagnostics are retained for up to 90 days. Encrypted backups are retained for up to 90 days, after which deleted data is removed from them by expiry.
You can request deletion of your Vestipy account and its associated personal data at any time.
Send a request from your registered email address to pallukumar303@gmail.com with the subject "Vestipy account deletion request". We verify the request comes from the address registered to the account, then delete it.
What is deleted: your account record, email address, display name, profile photo URL, notification preferences, push notification tokens, follow relationships, in-app notifications, and the image files of any charts you uploaded.
What is retained: trade signals you published, in anonymised form. They form part of the historical performance record other users rely on, and are stored so that they cannot be altered after publication. After deletion the author record carries no name, email, photo, or link to your account.
Where a chart image was attached to a published signal, the stored image file is erased but an empty reference remains inside that immutable record, so the signal continues to display without the image. Chart images never attached to a published signal are deleted outright.
Requests are actioned within 30 days. Data may persist in encrypted backups for up to 90 days before expiring.
You may request access to the personal data we hold about you, ask us to correct it, or ask us to delete it, using the contact address above. You may disable push notifications at any time from your device settings or in the app.
Vestipy is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
If we change this policy we will update the date at the top of this page. Material changes will be communicated in the app.