Privacy Policy
Last Updated: August 2026
1. Introduction
Welcome to Price Alert ("we", "our", or "the App"). We respect your privacy and are
committed to protecting your personal data. This Privacy Policy explains how we collect, use, and
safeguard your information within our mobile application and website.
Age Requirement: You must be at least 18 years of age to use our Service. We do not
knowingly collect data from individuals under 18.
2. Data Collection & Architecture
Our App is built on a Zero-Knowledge and Local-First architecture. This means we
avoid collecting sensitive financial data whenever possible.
2.1 Local Storage (Device Only)
The following data is stored exclusively on your device (SQLite/Secure Storage) and is never
accessible by us:
- Watchlists & Alerts: The specific assets and price thresholds you monitor.
- Wallet Addresses: Public blockchain addresses you track (read-only). We never
request or store private keys or seed phrases, and the App can never move your funds. The
addresses themselves are stored on your device; they are transmitted to our backend only to
read the blockchain on your behalf — see section 2.2.
- Biometric Data: PIN or Biometric templates used for App Lock remain within your
device's secure enclave.
- Tax & Transaction History: Trade records, LIFO cost basis, and tax calculations are stored exclusively on your device and never transmitted to our servers.
- CEX API Keys: If you connect a centralized exchange, your API keys are stored
in your device's Secure Storage and are never persisted on our servers. For
Binance, Bybit (EU/US), KuCoin and Bitpanda, requests are signed directly on your device and
your credentials never leave your phone. For the remaining exchanges, requests are relayed
through our backend in memory only, for the duration of the request: we do not
log or store your keys, balances or transactions.
2.2 Data Shared with Our Infrastructure
To provide core features, limited data is transmitted via secure HTTPS to our backend
(Supabase/Vercel):
- Anonymous Identifiers: A unique UUID to manage your subscription status,
Supporter badges, and advanced alert synchronization.
- Notification Channels: Your Telegram User ID (if configured) and/or email
address (if configured) to deliver push notifications and alerts.
- Subscription Status: Information required to verify your subscription or
"Supporter" badge.
- Public Wallet Addresses: The addresses you track are sent to our backend to
query balances and transaction history from public blockchain data providers, and to register
real-time activity notifications. We do not link them to your identity: they travel with your
anonymous identifier only.
2.3 AI Assistant Data Processing
When you interact with the AI Market Assistant:
- Your prompts are transmitted to Groq Cloud for processing (using LLaMA 3.3
70B).
- Queries are anonymized; we do not send your email or identity to the AI provider.
- Conversations are not used to train our models and are not permanently archived on our servers.
- When using the assistant from the home screen, the list of assets you monitor (symbols and current public market prices) is included as context to improve response relevance. No personal financial data (cost basis, PnL, transaction history) is transmitted.
3. Google Drive & API Data
We offer an optional feature to backup your locally stored data to your personal Google Drive.
- App Data Folder: We use the
drive.appdata scope. This creates a
hidden file (wallets_backup.json) accessible only by Price Alert.
- Restricted Access: We cannot see or modify any other files in your personal
Drive.
Our use of information received from Google APIs adheres to the Google
API Services User Data Policy.
4. Third-Party Data Processors
We utilize trusted third parties to provide specific components of the Service:
- Groq Inc. (USA): AI inference processing.
- Supabase Inc. (USA): Core cloud infrastructure and database.
- Telegram FZ-LLC (UAE): Alert delivery system.
- Stripe & PayPal: Payment and donation processing. We do not store financial
credentials (CC numbers).
- Google LLC/Ireland: Firebase for anonymous crash reports and Google Drive
hosting.
- Vercel Inc. (USA): Website hosting and serverless API.
- Railway Corp. (USA): Backend infrastructure and runners.
- Resend Inc. (USA): Transactional email delivery (alerts and notifications).
- RevenueCat Inc. (USA): Subscription management and entitlement verification.
- Notion Labs Inc. (USA): Internal documentation management.
- GitHub Inc. (USA): Source code hosting and version control.
5. Cookies
Our website uses only strictly necessary technical cookies required for the
functioning of payment systems (PayPal/Stripe) and font loading (Google Fonts). We do not use
profiling, analytics, or marketing cookies. No cookie consent banner is required as only essential
cookies are utilized.
6. Data Security
We implement industry-standard security measures, including TLS encryption for all data in transit. Since your financial alerts are stored locally, you are responsible for maintaining the
security of your device and enabling the App Lock feature.
7. Your Rights (GDPR)
Under GDPR, you have the right to access, rectify, or erase your data. Since most data is local, you
can delete it by clearing the App's storage or uninstalling it. For data stored on our servers
(associated with your UUID), contact us at: [email protected].
Informativa sulla Privacy
Ultimo aggiornamento: Agosto 2026
1. Introduzione
Benvenuto in Price Alert. Rispettiamo la tua privacy e ci impegniamo a proteggere i
tuoi dati personali. Questa informativa spiega come raccogliamo e trattiamo le informazioni tramite
l'app e il sito web.
Requisito di Età: Devi avere almeno 18 anni per utilizzare il nostro Servizio. Non
raccogliamo consapevolmente dati da minori di 18 anni.
2. Architettura dei Dati
La nostra App si basa su una architettura Zero-Knowledge e Local-First. La maggior
parte dei dati sensibili non lascia mai il tuo dispositivo.
2.1 Archiviazione Locale (Solo Dispositivo)
I seguenti dati sono memorizzati esclusivamente sul tuo smartphone e non sono accessibili da noi:
- Watchlist e Alert: I prezzi e i parametri che monitori.
- Indirizzi Wallet: Solo indirizzi pubblici di blockchain (modalità sola
lettura). Non chiediamo né memorizziamo mai chiavi private o seed phrase, e l'App non può in
alcun caso muovere i tuoi fondi. Gli indirizzi sono salvati sul tuo dispositivo; vengono
trasmessi al nostro backend solo per leggere la blockchain al posto tuo — vedi la sezione
2.2.
- Dati Biometrici: L'accesso tramite impronta o volto viene gestito dal sistema
operativo e non viene mai trasmesso all'App.
- Storico Fiscale e Transazioni: Le registrazioni dei trade, il costo fiscale LIFO e i calcoli delle imposte sono memorizzati esclusivamente sul tuo dispositivo e non vengono mai trasmessi ai nostri server.
- Chiavi API CEX: Se colleghi un exchange centralizzato, le chiavi API sono
salvate nel Secure Storage del dispositivo e non vengono mai conservate sui nostri
server. Per Binance, Bybit (EU/US), KuCoin e Bitpanda le richieste sono firmate
direttamente sul dispositivo e le credenziali non lasciano mai il telefono. Per gli altri
exchange le richieste transitano dal nostro backend solo in memoria, per il
tempo della richiesta: non registriamo né salviamo chiavi, saldi o transazioni.
2.2 Dati Condivisi con la nostra Infrastruttura
Per il funzionamento delle notifiche e del profilo, alcuni dati limitati sono trasmessi via HTTPS:
- Identificativi Anonimi: Un UUID per gestire lo stato dell'abbonamento, i badge
e la sincronizzazione degli alert avanzati.
- Canali di Notifica: Il tuo ID Utente Telegram (se impostato) e/o il tuo
indirizzo email (se impostato) per l'invio di notifiche e alert.
- Stato Abbonamento: Informazioni necessarie per validare il tuo abbonamento o
badge Supporter.
- Indirizzi Wallet Pubblici: Gli indirizzi che monitori vengono inviati al
nostro backend per interrogare saldi e storico transazioni presso i fornitori di dati pubblici
blockchain e per registrare le notifiche di attività in tempo reale. Non li colleghiamo alla
tua identità: viaggiano solo con l'identificativo anonimo.
2.3 Elaborazione Dati per l'Assistente AI
Quando interagisci con l'Assistente di Mercato AI:
- I tuoi prompt sono trasmessi a Groq Cloud (modello LLaMA 3.3 70B).
- Le richieste sono anonime; non inviamo la tua email o identità al fornitore AI.
- Le conversazioni non sono usate per il training dei modelli e non vengono archiviate permanentemente sui nostri server.
- Quando usi l'assistente dalla schermata principale, la lista degli asset che monitori (simboli e prezzi di mercato pubblici) viene inclusa come contesto per migliorare la pertinenza delle risposte. Nessun dato finanziario personale (prezzo medio di carico, PnL, storico transazioni) viene trasmesso.
3. Google Drive e API
Offriamo una funzione opzionale di backup su Google Drive.
- Cartella App: Utilizziamo lo scope
drive.appdata per creare un
file di backup nascosto (wallets_backup.json).
- Accesso Limitato: L'App non può vedere né modificare altri file nel tuo Drive
personale.
4. Responsabili del Trattamento (Terze Parti)
I tuoi dati possono essere trattati dai seguenti partner tecnici:
- Groq Inc. (USA): Elaborazione dell'intelligenza artificiale.
- Supabase Inc. (USA): Infrastruttura database e cloud.
- Telegram FZ-LLC (UAE): Sistema di invio notifiche.
- Stripe & PayPal: Elaborazione dei pagamenti. Non memorizziamo dati bancari o
carte di credito.
- Google LLC/Irlanda: Firebase per crash report anonimi e hosting Google Drive.
- Vercel Inc. (USA): Hosting sito web e API serverless.
- Railway Corp. (USA): Infrastruttura backend e runner.
- Resend Inc. (USA): Invio email transazionali (alert e notifiche).
- RevenueCat Inc. (USA): Gestione abbonamenti e verifica dei permessi.
- Notion Labs Inc. (USA): Gestione documentazione interna.
- GitHub Inc. (USA): Hosting del codice sorgente e controllo versioni.
5. Cookie
Il nostro sito web utilizza esclusivamente cookie tecnici strettamente necessari per
il funzionamento dei sistemi di pagamento (PayPal/Stripe) e il caricamento dei font (Google Fonts).
Non utilizziamo cookie di profilazione, analytics o marketing.
6. Diritti dell'Interessato (GDPR)
Hai il diritto di accedere, rettificare o cancellare i tuoi dati. Poiché la maggior parte dei dati è
locale, puoi eliminarli semplicemente cancellando i dati dell'app o disinstallandola. Per i dati sui
server, scrivi a: [email protected].