Privacy Policy
Last updated: 15 July 2026 · Effective: 15 July 2026
The short version: BYP is local-first. Your portfolio and any broker API keys stay on your device. Optional cloud sync is end-to-end encrypted — our servers store only ciphertext they cannot read. We keep your name and email for your account. We never sell your data.
1. Who we are
This policy describes how BuildYourPocket ("BYP", "we", "us") handles personal information in connection with the BYP — Build Your Pocket applications, websites, and services (the "Service"). For privacy questions or to exercise your rights, contact privacy@buildyourpocket.com.
2. Our local-first principle
BYP is designed so that the most sensitive information never leaves your control:
- On your device: your portfolio and positions, trade journal, watchlists, notes, and any broker or exchange API keys are stored locally on the device you use.
- End-to-end encrypted sync (optional): if you enable cross-device sync, your data is encrypted on your device before it is uploaded. We store only ciphertext and do not hold the keys needed to decrypt it. This means we cannot read your synced portfolio, journal, or API keys.
- Broker keys: BYP does not transmit your broker/exchange API keys to our servers in a form we can read, and does not use them to place real-money trades on your behalf.
3. Information we do process
a. Account information
To create and operate your account we store your name and email address, and basic authentication data. This lets you sign in and lets us link your subscription and encrypted sync.
b. Subscription and payment information
Paid subscriptions are processed by Stripe. Stripe handles your card details directly; we do not store full card numbers. We receive limited billing metadata (such as plan, status, and the last four digits of a card) needed to manage your subscription. See Stripe's privacy policy for how they process payment data.
c. Technical and usage data
We may process limited technical data (such as app version, device/OS type, crash diagnostics, and coarse, aggregated usage events) to keep the Service secure and reliable. [Describe your analytics/crash tooling and whether it is opt-in.] We do not use this to build advertising profiles.
d. Support communications
If you contact us, we keep your messages and contact details to respond and improve support.
4. Encrypted sync ciphertext
When sync is enabled, we store encrypted blobs and the minimal metadata needed to route and version them (for example, timestamps and record identifiers). We cannot decrypt the contents. If you lose your encryption passphrase or recovery key, we cannot recover the data for you.
5. How we use information
- To provide, maintain, and secure the Service and your account.
- To process subscriptions and prevent fraud and abuse.
- To provide customer support and respond to your requests.
- To improve reliability and performance using aggregated, non-identifying diagnostics.
- To comply with legal obligations and enforce our Terms.
Legal bases (where the GDPR applies) include performance of a contract, our legitimate interests in operating and securing the Service, consent (where required, e.g. certain analytics), and compliance with legal obligations.
6. We do not sell your data
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not trade your portfolio data for money or ad targeting.
7. Sharing with service providers
We share limited information with vendors who process it on our behalf under contract, such as:
- Stripe — payment processing.
- Cloud hosting / storage — to store encrypted sync blobs and run the Service (currently Hostinger).
- Market-data providers — to deliver quotes and analytics (they receive requests, not your identity, where feasible).
- Plaid (Elite, optional) — if you use account aggregation, Plaid connects to your financial institutions under its own privacy terms and your explicit authorization.
8. Data retention
We keep account data while your account is active and for a reasonable period afterward as needed for legal, tax, and security purposes, then delete or anonymize it. Encrypted sync blobs are retained while sync is enabled and deleted on account deletion.
9. Your rights (GDPR / CCPA and others)
Depending on where you live, you may have the right to access, correct, delete, or export your personal information; to object to or restrict certain processing; to withdraw consent; and to not receive discriminatory treatment for exercising these rights. California residents have rights under the CCPA/CPRA, including the right to know, delete, and opt out of "sales"/"sharing" (note: we do not sell or share for advertising). To exercise any right, email privacy@buildyourpocket.com; we may need to verify your identity. You can also delete your account from within the app, which removes your encrypted sync data.
10. International transfers
We may process information in countries other than yours. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
11. Security
We use technical and organizational measures including encryption in transit, end-to-end encryption for sync, access controls, and least-privilege practices. No system is perfectly secure; you are responsible for protecting your device, credentials, and recovery keys.
12. Children
The Service is not directed to children under 18 and we do not knowingly collect their data. If you believe a child provided us information, contact us and we will delete it.
13. Cookies
Our marketing website uses only the cookies/local storage strictly necessary to function and remember your preferences. We do not use third-party advertising or analytics trackers.
14. Changes to this policy
We may update this policy; material changes will be posted here with a new date and, where required, additional notice.
15. Contact
BuildYourPocket
Email: privacy@buildyourpocket.com
