Privacy Policy — Tkr
Tkr ("we", "us") provides real-time market prices, charts, alerts, widgets and Live Activities for forex, equities, crypto, indices, commodities and futures. This policy describes what we collect, how we use it, and your rights.
1. What We Collect
- Account information: email address from Sign in with Apple (used as your account identifier). Apple may provide a relay (hide-my-email) address — we store whichever address the provider returns. No password is stored; authentication is via Apple token verification and a JWT we issue.
- Instruments & preferences you create: tickers you follow, watchlists, chart drawing state, alert definitions (instrument, condition, threshold), and app preferences (theme, currency display). Stored per-account to enable sync and push delivery.
- Push & widget state: APNs device tokens and alert delivery records, plus widget / Live Activity registration state, so we can deliver price alerts and update your Home Screen and Dynamic Island.
- Usage counters: per-user and per-IP request counts for rate limiting (e.g., auth and price endpoints). No browsing history, no ad identifiers.
- Diagnostics (server-side logs only): HTTP method, path, status, timing, and IP for rate limiting, abuse prevention, and debugging. No third-party analytics SDKs, no ads, no cross-app tracking.
2. How We Use Your Data
- Authenticate you (Apple token verification, JWT issuance) and keep you signed in.
- Store and sync your instruments, alerts, and preferences across your devices.
- Deliver real-time price quotes (WebSocket + REST fallback) for your saved instruments, and fire push notifications when your alert conditions are met.
- Update widgets and Live Activities (via APNs and WidgetKit timeline) so prices are glanceable without opening the app.
- Enforce rate limits and protect endpoints from abuse (per-IP and per-user limits on
/api/authand price/data endpoints). - Operate, secure, and debug the service.
3. Where Data Lives
- On device: your auth token is stored in the iOS Keychain. Preferences, cached prices, and chart state live in app storage and sync to the server. Tokens for Live Activities are managed by the system.
- On server: JSON files (
users.jsonfor accounts,price_cache.json/metals_spot.jsonfor quotes,push_registry.jsonfor alert routing) on a US-based Ubuntu VPS. All traffic is HTTPS (TLS). Price history is served from cache; we do not store your brokerage credentials or place trades. - Backups: nightly compressed backups of
data/are retained off-VM (retention 30 days). Restores are tested on deploy.
4. Third Parties & Sub-processors
- Apple — Sign in with Apple authentication and APNs push / Live Activity delivery.
- Deriv — real-time forex / metals / indices WebSocket price feed (
frxXAUUSD,frxXAGUSD, etc.). - Yahoo Finance — REST price data for indices, futures and commodities (fallback and non-WS instruments).
- CoinGecko — cryptocurrency price data.
- No analytics SDKs, no ad networks, no Facebook/Google ads tracking, no data brokers. We do not sell your data. We do not place trades on your behalf.
5. Data Retention & Deletion
- We retain your account, instruments, and alert definitions until you delete them.
- Self-service deletion: Settings → Account → Delete Account permanently removes your user row, push registrations, and alert state. This is irreversible.
- You may also request deletion via tesla@fin-sh.xyz — we respond within 30 days.
- Backups age out after 30 days; deleted accounts will not be restored from backup except for disaster recovery, and any restored backup containing a deleted account is purged on next rotation.
- Cached price data (
price_cache.json) is ephemeral and not tied to a single user; it is refreshed continuously and not retained as personal data.
6. Your Rights
Depending on your jurisdiction (including GDPR / CCPA where applicable) you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us at tesla@fin-sh.xyz to exercise these rights. We may need to verify your identity via your sign-in provider.
7. Children
Tkr is not directed to children under 13. We do not knowingly collect data from children.
8. Security
- HTTPS everywhere; JWTs signed with
JWT_SECRETand validated on every authenticated route. - Per-IP rate limiting on auth endpoints and brute-force throttling.
- Server firewall, SSH key-only auth, automatic security patches (
unattended-upgrades), and PM2-managed process supervision. - Price cache is decoupled from boot via disk persistence — the app serves last-known quotes instantly and refreshes via live WebSocket streams.
9. App Privacy Nutrition Label (Apple)
This policy backs the App Store Connect "App Privacy" disclosure. "Collected" means transmitted off device, even if never used for Tracking (linking with third-party data for ads / brokers). Not tracked ≠ not disclosed. The narrow "Optional Disclosure" exception (infrequent, not primary functionality, fully optional, transparent form with your name shown, you choose each time, not for ads/marketing/brokers) does not apply — our data is primary functionality and collected ongoing after sign-in. Summary disclosed in ASC:
- Contact Info — Email Address (from Apple sign-in) and Name when provided — Purpose: App Functionality. Linked: Yes. Tracking: No.
- User Content — Other User Content — saved instruments, watchlists, alert definitions, chart drawings — Purpose: App Functionality. Linked: Yes. Tracking: No.
- Identifiers — User ID (JWT) and Device ID / Push Token (APNs) — Purpose: App Functionality (auth, alert/Live Activity delivery). Linked: Yes. Tracking: No.
- Usage Data — Product Interaction / Other Usage Data (per-user & per-IP request counts, HTTP diagnostics) — Purpose: App Functionality + Fraud Prevention. Linked: Yes. Tracking: No.
- Diagnostics — Crash Data + Performance Data (Sentry Release-only if enabled, production, sample 0.1) — Purpose: Analytics. Linked: Yes. Tracking: No.
- Photos or Videos — Not collected. Tkr has no photo picker. Do not tick.
- We do not collect precise/coarse location, contacts, browsing/search history, health, financial payment info, or advertising IDs. No Third-Party Ads, no data brokers, no cross-app Tracking.
10. Financial Disclaimer
11. How Prices Work (reference)
Detail for the quotes shown in the app; in-app views give a shorter summary.
Live Streams
Forex, metals and a subset of indices stream live via Deriv WebSocket (frx*). Spots for XAU/USD and XAG/USD are sourced only from Deriv spot (not futures) and cached as metals_spot.json so the app can show the last real spot with a freshness dot when the feed is temporarily down.
REST Fallback
Instruments without a live WS feed (most equities, crypto, futures like GC=F, SI=F, CL=F, NG=F, ES=F, YM=F, NQ=F) are refreshed via Yahoo Finance REST on a 15-minute cadence and via on-demand /api/prices calls. The disk cache (price_cache.json) serves last-known quotes instantly at boot.
Freshness
The app shows a colored dot per instrument based on age of the last tick (green = fresh, amber/red = stale). Stale does not mean the instrument is closed; it means the feed has not ticked within the expected window.
12. Changes to This Policy
We will update this page when the policy changes and bump the "Last updated" date above. Continued use after changes constitutes acceptance. Material changes will be noted in the app release notes.
13. Contact
Email: tesla@fin-sh.xyz · Websites: tkr.fin-sh.xyz · fin-sh.xyz