Legal
Privacy Policy
Last updated September 14, 2026
This policy explains what the iTrading Buddy app for iPhone, iPad, Mac and Apple Watch (the "App") collects, where that data goes, how long it is kept and how to delete it. The App is published by JV Mobile Development ("we", "us"). It describes the current version of the App. Some items apply only to newer versions: usage counts start with version 1.3.8, and the time zone is sent starting with version 1.3.9.
1. Overview
- No accounts. The App has no sign-up, login or password. Its own screens never ask for your name, email address, phone number or Apple ID. Briefing pages from our website that open inside the App include an optional email sign-up, which is covered by our company Privacy Policy.
- No ads, and we do not sell your data. The App shows no ads. We do not sell your data or share it with data brokers.
- No tracking permission. The App does not ask for permission to track you and does not read your device's advertising identifier (IDFA).
- Some data does leave your device. Price alerts, notifications, subscriptions and AI analysis run through our server, and our server uses service providers. Sections 3 to 8 list what is sent and why.
- Not linked to who you are, but not anonymous. Our server recognizes your device by identifiers the App creates or gets from Apple: a random install ID, a push notification token, an identifier for your iCloud account that is specific to this App, and App Store transaction IDs. None of these is linked to your name, email address or Apple ID. They do let us connect requests from the same device over time.
The App does not access your location, contacts, photos, camera, microphone or Face ID. The only permission it asks for is notifications, and it asks when you first set up an alert, not at launch.
2. Data Stored on Your Device and in iCloud
What you enter in the App is stored on your device:
- Watchlists, including any share counts and purchase prices you enter
- Portfolio positions, with price, share count, date and notes
- Trade journal entries, with prices, quantities, notes and tags
- Price alerts and their conditions
- Theses you write, with your conviction and the latest AI review
- Recent searches and cached company profiles
- Settings, such as appearance, chart and notification preferences, your AI model preference and your investor profile (time horizon and investing style)
When iCloud is available, the App syncs these items to your private iCloud database using Apple's CloudKit, and syncs most settings through iCloud key-value storage. That data is stored in your iCloud account, and we cannot read it. The App has no switch of its own to turn iCloud sync off; you control it in iOS Settings. A few settings stay on the device only, including the Morning Briefing notification setting and Read Aloud preferences.
The App also keeps caches on the device, such as recent research results, the latest Morning Brief and company names. Read Aloud uses Apple's on-device speech voices, and no audio leaves your device.
Apple Watch and widgets. Your iPhone sends the Apple Watch app a snapshot of your portfolio totals and your first watchlist, including share counts and purchase prices, over Apple's WatchConnectivity. The snapshot is saved in the App's shared storage on the iPhone and on the watch. The watch app does not contact our server itself. Home Screen widgets request prices directly from our server for the stock or watchlist you choose, and the App saves the watchlist names and symbols they display in its shared storage on the device.
Install ID. The App creates a random install ID and stores it in the iOS Keychain on your device. It is not synced to iCloud Keychain. iOS normally keeps Keychain items when an app is deleted, so if you delete and reinstall the App on the same device, it reuses the same install ID. The install ID can also move to a new device if you restore from an encrypted backup or transfer data directly from your old device. Delete My Data (Section 14) removes it.
Exports and sharing. When you export a watchlist or portfolio as a CSV file, or share something from the App, it goes through the iOS share sheet to wherever you choose. It does not pass through our server.
3. What the App Sends to Our Server
The App talks to our own server, which runs on Fly.io in the United States (New Jersey). The server fetches market data, runs AI analysis, checks your alerts and sends notifications. The App sends it the following.
With every request
- Your install ID and the App's iCloud account identifier
- Your IP address and a standard user agent with the App's build number and your operating system version, as with any internet request
For each install ID, the server records the days the App was used, the first and latest build number, and whether it runs on iOS or macOS. The server does not store your IP address or the full user agent in its database. It holds IP addresses briefly in memory to limit abuse, such as how many new installs or AI requests can come from one address in a short time. When an address goes over the AI request limit, that address is written to the server log.
For market data and research
- The ticker symbols you view, hold, watch or track, so the server can return prices, charts, fundamentals, news and filings
- The text you type into symbol search
- A copy of the ticker symbols on your watchlists (not share counts or prices), stored with your push token
For other features
- AI features: portfolio, thesis and investor-profile details, only for the features that use them (Section 4)
- Alerts and notifications: your push token, alert settings, Morning Briefing setting, time zone and Live Activity details (Section 6)
- Purchases: App Store transaction IDs (Section 7)
- Diagnostics: crash diagnostics and usage counts (Section 8)
AI credits. The server counts the AI credits you use each month. For free use, the count is kept under your iCloud account identifier, install ID or push token, so reinstalling the App does not reset the free allowance. For subscribers, it is kept under the subscription's App Store transaction ID.
4. AI Analysis (Anthropic)
AI features are powered by Anthropic's Claude. The App sends the request to our server, and our server sends the prompt to Anthropic. Our server does not send Anthropic your install ID, push token, iCloud account identifier or IP address. What Anthropic receives depends on the feature:
- Portfolio Brief (when you tap it): each holding's symbol, its share of your portfolio's total cost basis and your average purchase price, plus current quotes
- Morning Brief: up to 25 symbols from your portfolio and watchlists, the weight of each holding, and news, filings and prices for those symbols. For Pro subscribers it loads automatically once a day when you open the Today tab.
- Market Digest (when you tap it): your holdings' share counts, prices, daily change and profit or loss
- Thesis check: the thesis text you wrote, your conviction, when you saved it and the price at that time, plus current market data
- Personalized research (Pro): your investor profile's time horizon and style
- Natural-language screener: the screening request you type
- Stock research, such as AI Insights, comparisons, dossiers, deep dives, technical and analyst views, and news summaries: ticker symbols and public market data only. Deep dives use Anthropic's web search tool, with searches written from the ticker and public research, not from your data.
Our server caches AI results so repeat requests are fast. Portfolio Brief and Morning Brief results are stored with your push token and expire after 12 hours. Thesis check results expire after 4 hours. For Portfolio Brief, Morning Brief and thesis checks, the cache holds the AI's response, which can describe your holdings or thesis, but not the details you sent. Stock research results are cached by ticker, not by user, and can be shared across users. Natural-language screener requests are cached for 7 days, together with the text you typed, and symbol search results for 24 hours under the search text. Those two caches are stored by the words you typed, not with any identifier, and are shared across users who type the same thing. Expired cache entries are deleted from the server within about 6 hours after they expire. Anthropic handles the data it receives under its own terms and Privacy Policy.
5. Market Data and News Providers
Our server gets market data and news from the providers below. The requests come from our server, so these providers do not receive your install ID, push token, iCloud account identifier or IP address. They receive ticker symbols, company names and search queries.
- Twelve Data: quotes, price history, company profiles, fundamentals, earnings and a live price stream. It also receives the text you type into symbol search.
- Brave Search: news and web search, with queries built from tickers and company names
- Google News (RSS): news headlines, including headlines for each symbol in a Morning Brief
- SEC EDGAR: company filings, 8-K events and insider transactions
- FRED (Federal Reserve Bank of St. Louis): macroeconomic data and the economic calendar. It receives no data derived from you, not even tickers.
- GDELT: global news signals for research dossiers, by ticker and company name
- StockTwits and Reddit: public sentiment for research dossiers, by ticker
When you open a news article or an SEC filing from the App, the publisher's website loads directly. That site receives your IP address like any web visit and has its own privacy practices.
Provider privacy policies: Twelve Data, Brave Search API, Google and SEC.
6. Push Notifications, Alerts and Live Activities
Price alerts are checked on our server, not on your device. To make that work, the App sends:
- Your push token, the address Apple Push Notification service (APNs) gives the App on your device, each time the App launches
- Your alerts: symbol, company name, alert type, conditions and thresholds, and whether each alert is on, triggered or snoozed
- Your Morning Briefing setting and your device's time zone, so the briefing notification arrives at 8 a.m. your time on trading days (no later than 9:30 a.m. Eastern). The setting is on by default. The time zone is sent whether it is on or off.
- Live Activities: when you track stocks on the Lock Screen, the Live Activity's push token and its symbols (up to three)
The server watches live prices, and when an alert's conditions are met it sends the notification through APNs. Alert notifications show the symbol and the price or condition. Morning Briefing notifications show the title and summary of our public daily briefing. The App also schedules some notifications locally on your device.
7. Subscriptions and Payments
Pro subscriptions and AI credit packs are sold through Apple's App Store. Apple handles payment. We never receive your card details, name, email address or Apple ID.
To confirm what you bought, the App sends your purchases' App Store transaction IDs to our server, which checks them with Apple's App Store Server API. Apple also notifies our server about changes such as renewals and refunds. The server stores the transaction details Apple returns, such as the product, purchase and expiration dates, trial status, App Store country, and price and currency, together with your push token. When a subscription is first confirmed, our server also sends Meta a subscription event (Section 8). For how Apple handles payment data, see Apple's Privacy Policy.
8. Crash Reporting, Analytics and Ad Measurement
App Store and TestFlight builds include the tools below. Development builds do not. The App has no setting to turn them off.
Crash and error reports (Sentry)
The App uses Sentry to report crashes and errors. A report includes the error and stack trace, the App version, device model, OS version, locale, time zone, memory state, a random identifier Sentry creates for the installation, and a trail of recent events. Sentry also receives session data, used to measure how often the App crashes, and performance timings for a random 10% of operations. The App's Sentry settings tell Sentry not to infer your IP address from the reports it receives.
The trail of recent events can include the addresses of requests the App made to our server. Those addresses can contain ticker symbols, symbol search text and your push token. When our server returns an error, the report can also include that request's headers, which carry your install ID and iCloud account identifier.
Our server also uses Sentry. If an error happens while the server handles one of your requests, the report can include details of that request: your IP address, your install ID and iCloud account identifier, your push token, App Store transaction IDs when a purchase check fails, and the request's contents, which for some features include holdings, thesis text or a screener request.
Crash diagnostics from Apple (MetricKit)
iOS gives the App diagnostic reports about earlier crashes through Apple's MetricKit, and the App uploads them to our server. A report contains stack traces and device details such as model, OS version, region format and App version. The server does not store your install ID, push token or IP address with it.
Usage counts
The App counts how often certain things happen and sends the counts to our server in batches: screens viewed, actions taken, feature milestones, kinds of errors and sessions started. Every event name comes from a fixed list, and each carries only a count. The counts never include ticker symbols, search text, prices or anything else you enter. The server stores daily counts per install ID, and also counts which AI features each install ID requested. We do not share these counts with anyone.
Google Analytics for Firebase (iPhone and iPad)
The iPhone and iPad App includes Google Analytics for Firebase so we can measure installs from our Google Ads campaigns. It sends Google the events the SDK records automatically (first open, session start and app update), an app-instance identifier created by Firebase, and the device and app details the SDK attaches to those events. As with any internet request, Google also receives your IP address, which Google Analytics can use to estimate an approximate location, such as country or city, for our reports. The App records no events of its own and sends no user ID. Automatic screen reporting, ad personalization signals and ad network registration are turned off, and the version of the SDK in the App cannot read the advertising identifier. The Mac App does not include it. See Privacy and Security in Firebase and Google's Privacy Policy.
Meta (sent from our server)
The App does not include any Meta or Facebook SDK. To measure our Meta ad campaigns, our server sends two kinds of events to Meta's App Events API:
- An app activation event the first time the server sees a new iPhone or iPad install, with the App's build number, the major iOS version and the App's bundle ID
- A start-trial or subscribe event the first time a real (not test) App Store subscription is confirmed, with the product ID
Each event carries an identifier made by one-way hashing your install ID or push token. The same install always produces the same value, so Meta can group events without receiving the ID itself. The advertising identifier is sent as all zeros, and both of Meta's tracking flags are set to off. Meta does not receive your install ID, push token, IP address, device model or locale. See Meta's Privacy Policy.
Apple install attribution
The App reports a conversion value to Apple's SKAdNetwork and AdAttributionKit: one value when the App is opened and another when you subscribe. Apple designed these frameworks to report ad results to ad networks without identifying you or your device. The App sends nothing to ad networks itself.
Pages from our website inside the App
The Today tab loads the daily briefing list, card images and videos directly from our website, which is hosted on Cloudflare. These requests carry your IP address and a standard user agent, but no App identifiers. When you open a full briefing, the page from this website opens inside the App, and the Google tag described in Section 9 runs there as it would in a browser. Outside the EEA, the UK and Switzerland, that tag can set advertising cookies in the App's built-in browser.
9. This Website
This website is separate from the App, and it does use one third-party measurement tool. When you visit these pages, Google's tag (gtag.js) loads and records whether you clicked through to the App Store. This tells us which ads and which pages actually send people to the App Store, so we do not waste a small advertising budget on ones that do not.
What this measures is the click on this website — nothing more. Apple does not tell us, and we have no way to determine, whether you went on to install the App, or who you are. We do not upload email addresses or any other personal identifiers to Google, and the site has no login, no account, and no contact form that feeds this tag.
The Google tag sets cookies in your browser for this purpose. In the EEA, the UK and Switzerland it does not set them unless you accept the consent banner. Any ad or tracker blocker, or your browser's cookie settings, will block it — the site works normally either way. For more detail, see Google's Privacy Policy and How Google uses information from sites that use its services. The optional briefing email sign-up and the contact form are covered by our company Privacy Policy.
10. YouTube API Services
JV Mobile Development operates an internal automation ("iTrading Buddy Automation") that publishes our own daily market-briefing video to our own YouTube channel using YouTube API Services. If you interact with our YouTube channel, the YouTube Terms of Service and the Google Privacy Policy also apply.
This automation is not a consumer-facing product. It does not access, collect, store, or share any YouTube user data belonging to viewers or to anyone other than our own channel account: it uploads our own videos to our own channel and reads nothing else. No YouTube API data is stored on our servers, displayed to users, or shared with any third party.
The only Google account connected to this automation is our own. That authorization can be reviewed or revoked at any time in Google security settings at myaccount.google.com/permissions.
11. Service Providers
These companies process data for the App. We share with them only the data they need to provide their service, and we choose providers whose terms and privacy commitments protect that data at least as well as this policy does. We do not sell data to any of them.
- Fly.io hosts our server, its database and its logs in the United States. Privacy policy
- Apple provides iCloud sync, push notifications, App Store purchases, crash diagnostics and install attribution. Privacy policy
- Anthropic provides AI analysis (Section 4). Privacy policy
- Sentry receives crash and error reports from the App and our server (Section 8). Privacy policy
- Google provides Google Analytics for Firebase (Section 8), the Google tag on this website (Section 9) and Google News headlines (Section 5). Privacy policy
- Meta receives ad measurement events from our server (Section 8). Privacy policy
- Cloudflare hosts this website and the briefing list, images and videos the App loads. Privacy policy
- Market data and news providers are listed in Section 5. They receive ticker symbols, company names and search queries, not your identifiers or IP address.
12. Children's Privacy
iTrading Buddy is not directed at children under the age of 13. We do not knowingly collect information from children, and the App does not ask for anyone's age. If you believe a child has used the App, use Delete My Data (Section 14) or contact us and we will help remove what we can find.
13. Data Security
- The App connects to our server over HTTPS, and our server connects to its service providers over encrypted connections.
- The install ID is stored in the iOS Keychain.
- Data on your device is protected by iOS, including its file encryption when your device has a passcode. Data synced to iCloud is stored in your private iCloud database, which we cannot access.
- There are no accounts, so there are no passwords to steal. It also means our server identifies your device by the identifiers in Section 1, not by a login.
No method of sending or storing data is completely secure, and we cannot guarantee absolute security.
14. Data Retention and Deletion
How long data is kept
- Push token, alerts, watchlist symbols, Morning Briefing setting, time zone, and subscription and credit purchase records: no fixed retention period while you keep using the App. They are removed if Apple reports that your push token is no longer valid, or by a cleanup that normally deletes devices that have not contacted our server for about 30 days. The cleanup is not guaranteed to run on an exact schedule, and it does not remove AI credit counts or usage counts.
- Deleted alerts: removed from our server when the App next syncs your alerts, which happens right away when you delete one, or the next time the App connects if you are offline.
- Live Activity registrations: until the App unregisters the Live Activity or Apple reports that it has expired.
- AI credit counts and usage counts: no automatic expiry. Credit counts are kept on purpose so that reinstalling the App does not reset the free allowance.
- Credits already used, after Delete My Data: no automatic expiry. We keep only how many free, trial or monthly AI credits were already used, stored under one-way hashes of your push token, install ID, iCloud account identifier and subscription transaction ID, so deleting your data cannot be used to claim free credits again. The hashes cannot be turned back into those identifiers, and nothing else about you is kept with them.
- Cached AI results tied to your push token: expire after 4 to 12 hours, and are deleted within about 6 hours after that.
- Screener requests and symbol searches: the text of a natural-language screener request is cached with its result for up to 7 days, and symbol search results for 24 hours. They are stored by the words you typed, not with any identifier.
- Records of which Morning Briefing notifications were sent to your push token: about 14 days. They are removed during a later daily briefing send.
- Daily request counts per server endpoint, with no identifiers: 120 days.
- MetricKit crash diagnostics: no automatic expiry. They are stored without an identifier, so we cannot find or delete one person's reports.
- Server logs: kept by Fly.io under its own retention settings. We do not copy them to any other log service. Logs can include the first characters of a push token, App Store transaction IDs with the product and subscription status, the symbols of alerts and Live Activities, an IP address that exceeded the AI request limit, and the text of a symbol search that failed.
- Storage snapshots: our hosting provider can keep copies of the server's storage, so deleted records may remain in those copies for a time.
- Sentry, Google, Meta and Anthropic keep the data they receive under their own policies.
Delete My Data
In the App, go to Settings > Data & Privacy > Delete My Data. You need an internet connection. The App first asks our server to delete the records tied to your push token, install ID and iCloud account identifier. The server removes AI credit counts first, then your device record and the records stored with it, then usage counts. If any step fails, the App is told the deletion failed and shows an error, and nothing is deleted from your device, so you can try again. The server deletes:
- Your device record, alerts, watchlist symbols, subscription records and credit purchase records
- Live Activity registrations and your notification preferences, including your time zone
- AI credit counts kept under your push token, install ID, iCloud account identifier or subscription transaction ID, except a record of how many credits were already used (see below)
- Usage counts and daily activity for your install ID
If that request fails, the App shows an error and deletes nothing. If it succeeds, the App deletes its database on your device (watchlists, portfolio, journal, alerts, theses and recent searches), removes the install ID from the Keychain, forgets its push token and returns to onboarding. If the App has no push token saved, it skips the server request and deletes only the data on your device.
Delete My Data does not currently remove:
- MetricKit crash diagnostics, which are stored without an identifier
- Cached AI results (they expire within 12 hours and are deleted within about 6 hours after that), screener and symbol search caches (up to 7 days, not stored with an identifier) and Morning Briefing delivery records (about 14 days)
- A record of how many free, trial or monthly AI credits were already used, kept under one-way hashes of your identifiers so free credits cannot be claimed again by deleting your data
- Data already sent to Sentry, Google, Meta or Anthropic, server logs and storage snapshots
- Your investor profile and settings, which stay on the device and in iCloud, along with some on-device caches and the Apple Watch snapshot
We have not confirmed that Delete My Data removes copies already synced to your iCloud account. To remove them, delete the App's data from iCloud in Settings > [your name] > iCloud, under account storage. Your subscription also keeps running until you cancel it with Apple.
If you only delete the App
Deleting the App sends nothing to our server, so server records stay as described above. The install ID usually stays in your device's Keychain and is reused if you reinstall. Data in your iCloud account stays there and comes back if you reinstall while signed in to the same iCloud account. To delete server data, use Delete My Data before you delete the App.
Requests by email
You can also ask us to access or delete your data, including anything Delete My Data leaves behind, by emailing hello@jvmobiledevelopment.com. Because there are no accounts, we can only find records you help us identify. If you subscribed or bought credits, include the Order ID from Apple's receipt email so we can look up the transaction. We cannot see data stored only on your device or in your iCloud account.
15. Your Choices
- Notifications. You can allow or turn off notifications for iTrading Buddy in iOS Settings. You can turn off the Morning Briefing notification in the App under Settings > Notifications.
- Alert notifications from our server. Quiet Hours, Mute on Weekends, the Price Alerts switch and the other notification switches in the App apply to notifications scheduled on your device. They do not currently stop alert notifications sent from our server. To stop an alert, turn it off or delete it in the App, or turn off notifications for the App in iOS Settings.
- AI features. Portfolio, thesis and profile details go to Anthropic only when you use the features in Section 4. The Morning Brief is the exception: for Pro subscribers it loads automatically once a day when you open the Today tab.
- Investor profile. You can change it in the App under Settings > How I Invest.
- iCloud. You can turn iCloud on or off for the App in iOS Settings. The App has no separate switch.
- Crash reporting and analytics. The App has no setting to turn off Sentry, MetricKit uploads, usage counts or Google Analytics for Firebase.
- Deleting your data. Use Delete My Data, or email us (Section 14).
- Subscriptions. Manage or cancel them in your Apple Account settings.
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, or to object to how it is used. To make a request, email us.
16. Changes to This Privacy Policy
We may update this Privacy Policy as the App changes. When we do, we will update the "Last updated" date at the top of this page, and for material changes we may also let you know in the App.
17. Contact Us
If you have any questions or concerns about this Privacy Policy or your data, please contact us at: