Privacy Policy — FinDash
FinDash provides a trading journal and market-intelligence app. This policy describes what we collect, how we use it, and your rights.
1. What We Collect
- Account information: email address from Sign in with Apple or Google Sign-In (used as your account identifier). Apple may provide a relay (hide-my-email) address — we store whichever address the provider returns.
- Journal & trading content you create: trades (instrument, direction, entry/exit, quantity, fees, strategy tags, notes, rating), journal entries (title, content, mood, lessons, bias snapshots, confluence), strategies and strategy-map data, linked exit records, and journal images you optionally pick via the system photo picker. When you tap "Insert image" the system
PhotosPickerlets you choose one photo — we save that image to your device Photo Library (ph://asset) so it survives reinstall and store only the asset reference (image_file_name) in your journal entry. Image bytes are not automatically uploaded to our server; the server only receives the reference string when you save the entry. A server upload endpoint (POST /api/journal/images) exists but is not called by the current app — if you use it in future, image bytes you explicitly upload are stored per-user on the VPS. This is primary functionality, not an infrequent optional form, so it must be disclosed even though it is not used for tracking or advertising. - App preferences & state: selected currencies, time-zone, theme, notification choices, and sync cursors — stored per-account to enable cross-device sync.
- Usage counters: daily AI-chat request counts per user (to enforce free/paid rate limits). No browsing history, no ad identifiers.
- Diagnostics (server-side logs only): HTTP method, path, status, and IP for rate-limiting and abuse prevention. No third-party analytics SDKs, no ads, no cross-app tracking.
2. How We Use Your Data
- Authenticate you (Apple / Google token verification, JWT issuance) and keep you signed in.
- Store, encrypt-in-transit, and sync your journal/trading data across your devices.
- Power the in-app AI assistant — chat messages you send are forwarded to our AI provider (Cloudflare) for inference only; they are not used to train models.
- Enforce daily AI limits and protect endpoints from abuse (per-IP and per-user rate limiting).
- Operate, secure, and debug the service.
3. Where Data Lives
- On device: your auth token is stored in the iOS Keychain. Journal/trade caches live in app storage and sync to the server.
- On server: databases holding your account and your journal/trading content, on a US-based server. All traffic is HTTPS (TLS).
- Backups: nightly encrypted SQLite backups are retained off-VM (retention 30 days). Restores are tested on deploy.
4. Third Parties & Sub-processors
- Apple — Sign in with Apple authentication (
apple-signin-authverification). - Google — Google Sign-In verification when you link a Google account.
- Cloudflare — processes AI chat/coach requests you explicitly send. Messages are transmitted for inference and not retained for training by us; see Cloudflare's policy.
- No analytics SDKs, no ad networks, no Facebook/Google ads tracking, no data brokers. We do not sell your data.
5. Data Retention & Deletion
- We retain your account and journal data until you delete it.
- Self-service deletion: Settings → Delete Account permanently removes your app data. This is irreversible.
- You may also request deletion via tesla@fin-sh.xyz — we respond within 30 days.
- Backups age out after 30 days; deleted accounts will not be restored from backup except for disaster recovery, and any restored backup containing a deleted account is purged on next rotation.
6. Your Rights
Depending on your jurisdiction (including GDPR / CCPA where applicable) you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us at tesla@fin-sh.xyz to exercise these rights. We may need to verify your identity via your sign-in provider.
7. Children
FinDash is not directed to children under 13. We do not knowingly collect data from children.
8. Security
- HTTPS everywhere; sessions are validated on every authenticated route.
- Per-IP rate limiting on auth endpoints and brute-force throttling.
- Server firewall.
9. App Privacy Nutrition Label (Apple)
This policy backs the App Store Connect "App Privacy" disclosure. "Collected" in Apple's sense means data transmitted off your device (so you can be identified by us), even if we never use it for Tracking (linking with third-party data for ads / sharing with data brokers). Not tracked ≠ not disclosed — if data is used for App Functionality, you must still disclose it. The narrow "Optional Disclosure" exception (infrequent, not primary functionality, fully optional, transparent form with your name shown, you choose each time, and not used for ads/marketing/brokers) does not apply here — our data is primary functionality and collected on an ongoing basis after you sign in. Summary of data linked to you and disclosed in ASC:
- Contact Info — Email Address (from Apple / Google sign-in) and Name when Apple provides it — Purpose: App Functionality (account creation / sign-in). Linked: Yes. Tracking: No.
- User Content — Other User Content — journal entries, trades, strategies, strategy-maps, lessons, mood,
image_file_namereference (not image bytes in current app) — Purpose: App Functionality (journal/sync). Linked: Yes. Tracking: No. - User Content — Photos or Videos — Not collected off-device in current app (images live in your Photo Library; server gets only the
ph://reference). Do not tick Photos/Video in ASC unless you enable server upload. If you later upload via/api/journal/images, then tick Photos — Purpose: App Functionality, Linked: Yes, Tracking: No. - Identifiers — User ID (JWT
userId) and Device ID (Sentry crash grouping, APNs push token) — Purpose: App Functionality + Analytics (crash). Linked: Yes. Tracking: No. - Purchases (StoreKit subscription state) — Purpose: App Functionality. Linked: Yes. Tracking: No.
- Usage Data — Product Interaction (AI request counts per user) and Other Usage Data (HTTP method/path/status counts) — Purpose: App Functionality + Fraud Prevention. Linked: Yes. Tracking: No.
- Diagnostics — Crash Data + Performance Data (Sentry Release-only, production, hang/watchdog off, sample 0.1, beforeSend drops
-999/NSURLErrorCancelled) — Purpose: Analytics. Linked: Yes (per install). Tracking: No. - We do not collect precise/coarse location, contacts, browsing history, search history, health, financial payment info, or advertising identifiers. We do not use data for Third-Party Advertising, Marketing, or share with brokers. We do not do cross-app Tracking.
10. Financial Disclaimer
11. How Calculations Work (reference)
Detail for the indicators shown in the app; in-app views give a shorter summary.
Instrument Score (−5 to +5)
Weighted blend of price momentum, interest-rate differentials, calendar events, relative strength and (where available) positioning. Positive = bullish, negative = bearish.
Earnings (EPS) Surprise
- EPS = net income / outstanding shares.
- Surprise = (actual − estimate) / estimate × 100. Positive is a beat (green), negative a miss (red).
- Orbit: dots fill from oldest quarter (outer ring) inward; center dot is the latest surprise.
CARRY (currency crosses)
Each leg shows its central-bank rate. Carry = base rate − quote rate — the payment earned (or paid) holding one leg vs the other.
FLOWS & CREDIT (sector funds)
- FLOWS = accumulation vs distribution via volume (MFI + OBV). Positive = buying pressure.
- CREDIT = high-yield minus investment-grade bond spread — wider = risk-off.
COT Positioning
Currencies, commodities and indices show a COT orrery of institutional positioning. Crosses and sector funds have no CFTC COT data and show a factor signal card instead.
12. Changes to This Policy
We will update this page when the policy changes and bump the effective date below. Continued use after changes constitutes acceptance. Material changes will be noted in the app release notes.
13. Contact
Email: tesla@fin-sh.xyz · Website: fin-sh.xyz