Skip to content
TradeAcademy by Aithera
PrivacyTermsRiskSecurityAccount deletionSupport

Template — not a live operator publication. Bracketed fields (legal entity, VAT/UID, emails, official domain) are not production values. Do not paste this URL into App Store Connect or Play Console until those fields are replaced and this notice is gone.

Privacy Policy

Last updated
24 August 2026
Version
2026.08.24
Brand / product
Aithera / TradeAcademy
Controller / Operator
[LEGAL ENTITY NAME REQUIRED], trading as Aithera (“Aithera”, “we”, “us”, “our”), operator of the TradeAcademy mobile application
Registered address
Höglerstrasse 55, 8600 Dübendorf, Switzerland
VAT/UID
[VAT/UID REQUIRED]
Privacy contact
[PRIVACY EMAIL REQUIRED]
Support contact
[SUPPORT EMAIL REQUIRED]
Website
[OFFICIAL DOMAIN REQUIRED]

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use TradeAcademy. It is designed to meet transparency and rights requirements under:

  • the Swiss Federal Act on Data Protection (nFADP / revDSG);
  • the EU/EEA GDPR and UK UK GDPR where applicable;
  • U.S. state privacy laws including the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and similar state laws; and
  • related cybersecurity and breach-notification expectations.

This document is a compliance-oriented template for the shipped product behaviour. Bracketed fields are not production values. Have qualified counsel in Switzerland, the EU/EEA, and relevant U.S. states review and adapt it (including the registered legal entity name, VAT/UID, and official contact mailboxes) before production launch.


1. Who we are and scope

TradeAcademy is a decision-first trading research and coaching application. It is not a broker-dealer, bank, investment adviser, portfolio manager, or execution venue. Scores such as Research Value Score (RVS) and Decision Quality Score (DQS) describe research priority and process quality; they do not predict price direction.

This Policy applies to:

  • the iOS and Android apps (including demo/guest mode);
  • related cloud services we operate when configured (Firebase Auth, Firestore, Storage, Cloud Functions); and
  • public legal/support pages once they are hosted on [OFFICIAL DOMAIN REQUIRED].

It does not govern third-party stores (Apple, Google), payment processors, or market-data vendors’ own processing beyond what we disclose below.


1A. Store rating, contractual eligibility, and privacy eligibility

These are different rules. TradeAcademy does not tell anyone that a 4+ store rating authorises trading, brokerage, or investment advice.

LayerWhat it means
Store content ratingApple App Store 4+ and Google Play Everyone describe content suitability for the store questionnaire. They are not a licence to trade and not an invitation for children to open cloud accounts.
Contractual eligibilityCreating an account or purchasing a subscription requires being at least 18, or the age of majority where you live. Guest/demo exploration of local educational features does not require being 18.
Privacy / children’s eligibilityCloud account features (registration, cloud sync, online journals, online portfolios, paid subscriptions) are not offered to young children. We do not knowingly collect personal data from young children through cloud accounts. The app is not directed toward young children.

2. Categories of personal data

Depending on how you use the app, we may process:

CategoryExamplesTypical source
Account & identityEmail, display name, Firebase UID, auth provider identifiers, email verification statusYou; Google/Apple Sign-In
Security / MFAMulti-factor authentication factors (e.g. TOTP enrolment metadata), recent authentication timestampsYou; Firebase Auth
Device & pushDevice type/OS, Expo/FCM push tokens, app version/releaseDevice; OS
PreferencesTheme, haptics, notification settings, crash-reporting consent and version/timestamp, product-analytics consentYou
Product content you createWatchlists, alerts, journal entries, decision records, holdings you enter, onboarding answersYou
SubscriptionEntitlement status, product IDs, expiry/paid-through dates, RevenueCat app user ID (= Firebase UID)Apple/Google via RevenueCat webhook (server-side)
Diagnostics (optional)Crash/error events, route names, release/build metadata, limited device/OS context — redacted of common credentials and personal fieldsApp, only if you enable Crash Reporting
SupportMessages you send to supportYou
Technical logsServer timestamps, security/auth events, webhook delivery metadata needed to operate the serviceSystems

We do not intentionally collect:

  • government ID numbers, biometric templates (beyond optional OS biometric unlock you enable on-device), precise continuous GPS tracking, health data, or children’s data;
  • advertising identifiers for cross-app tracking;
  • behavioural advertising profiles or cross-app tracking;
  • payment card numbers (billing is handled by Apple/Google).

Optional product analytics (allowlisted screen/feature aggregates only) is off by default and requires explicit consent. Analytics never intentionally collects:

  • journal text;
  • AI chat content or prompts/completions;
  • portfolio monetary values or private trading theses;
  • passwords, authentication tokens, or API keys;
  • sensitive financial credentials.

Market quotes and news are market data, not personal data about you, though requests may be associated with your session/account for rate limiting and service delivery.


3. Purposes and legal bases

PurposeLegal basis (GDPR Art. 6 / Swiss equivalent)
Create and authenticate accounts; provide core app featuresContract (Art. 6(1)(b)); Swiss overriding private interest / contract
Process Premium entitlements and prevent fraud/abuseContract; legitimate interests (security, billing integrity)
Sync your content to Firestore when signed in and verifiedContract
Send price-alert / transactional notifications you enableContract; consent where required for push on the OS
Optional crash diagnostics to SentryConsent (Art. 6(1)(a)); off by default
Optional first-party product analytics (allowlisted aggregates)Consent (Art. 6(1)(a)); off by default
Security, abuse prevention, MFA, deletion throttlingLegitimate interests (Art. 6(1)(f)); legal obligation where applicable
Comply with law, respond to lawful requests, enforce TermsLegal obligation (Art. 6(1)(c)); legitimate interests
Improve reliability using consented, aggregated, non-identifying product signalsConsent when analytics enabled; otherwise not collected

You may withdraw consent for crash reporting or product analytics at any time in Settings → Privacy without affecting other processing that does not rely on that consent.


4. How we use and store data

  • Client storage: Preferences and demo/local content may be stored on-device (e.g. AsyncStorage / SecureStore as applicable).
  • Cloud: Authenticated, email-verified users may sync data to Google Firebase (Auth, Firestore, Storage) under security rules that restrict access to the account owner (and server-only paths for subscriptions). Firebase Storage is used for user-scoped files under users/{uid}/ when the signed-in user stores files there.
  • Guest / demo mode: Designed to stay local; it does not create a verified cloud identity for personal cloud writes under our hardened rules.
  • Encryption in transit: TLS for network traffic to our providers.
  • Encryption at rest: Provider-managed encryption for Firebase/Google Cloud and Sentry as offered by those vendors.
  • Access control: Least-privilege rules, verified-email write gates, MFA options, and recent-authentication requirements for account deletion.

We apply data minimisation and purpose limitation: we process what is needed for the purposes above and do not sell personal information.


4A. AI processing

TradeAcademy’s in-app “Ask” / analysis features are decision-coaching aids. They describe process and evidence. They are not buy/sell signals and not price predictions.

For this release:

  • On-device / local rules-and-template analysis runs in the app. Prompts and answers stay on the device unless you later enable an approved cloud path.
  • Production third-party cloud AI is disabled in the shipped client (CLOUD_AI_ENABLED = false). We do not currently send journal text, chat transcripts, or portfolio values to a third-party generative-AI provider.
  • If cloud AI is enabled in a future release, this Policy will be updated, a new legal-acceptance version may be required, and any processor will be named here before that feature is marketed.

AI usage counters (how many analyses you used) may be stored locally and, when you are signed in, as quota metadata on the server. Those counters are not the text of your questions or answers.

Optional crash reports and product analytics do not include AI conversation content.


5. Sharing and processors (recipients)

We share personal data only with:

  1. Infrastructure processors acting on our instructions, including:
    • Google Firebase / Google Cloud — authentication, database, storage, functions;
    • RevenueCat — subscription entitlement sync (server webhook; no client secret keys);
    • Sentry — optional crash diagnostics after consent;
    • Expo / Apple / Google — app distribution, push delivery infrastructure as configured;
  2. Market-data / news providers (e.g. Finnhub, Alpha Vantage, CoinGecko, NewsAPI or successors) — typically receive technical requests (symbols, IP as seen by their edge) necessary to return quotes/news; their policies apply to their processing;
  3. Professional advisers or authorities when legally required;
  4. A successor in a merger or asset transfer, subject to continued protection consistent with this Policy.

We do not currently share personal data with a third-party generative-AI cloud provider because that path is disabled.

We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are used under CCPA/CPRA. We do not use your journal or decision content for advertising.


6. International transfers

Servers and processors may be located in the United States, EU/EEA, Switzerland, or other countries. Where GDPR/UK GDPR or Swiss nFADP require safeguards for transfers abroad, we rely on:

  • adequacy decisions where available; and/or
  • Standard Contractual Clauses (or Swiss-recognised equivalents) and vendor DPAs; and/or
  • other lawful transfer tools.

You may request information about transfer safeguards via [PRIVACY EMAIL REQUIRED].


7. Retention

We retain personal data only as long as needed for the purposes above:

  • Account data: for the life of the account, then deleted or anonymised after account deletion completes (subject to short backup/log retention);
  • Decision/journal/watchlist content: until you delete it or delete the account;
  • Subscription entitlement records: while needed to provide Premium access and resolve billing disputes, then deleted or minimised;
  • RevenueCat webhook event references tied to your UID: removed as part of account deletion where implemented;
  • User-scoped security/ops event documents tied to your UID: removed as part of account deletion where implemented;
  • Aggregated product-analytics counters: not stored as your journal or chat text; they are not a substitute for deleting your account content;
  • Crash diagnostics: according to Sentry retention settings for consented data; stopped when consent is withdrawn (future events not sent);
  • Security logs: typically short periods unless needed for investigations or legal holds;
  • Legal holds: longer retention when required to establish, exercise, or defend legal claims.

8. Your rights

8.1 Switzerland (nFADP)

Subject to statutory exceptions, you may request access, rectification, erasure, restriction, objection to processing based on overriding interests, and data portability where applicable. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).

8.2 EU/EEA & UK (GDPR / UK GDPR)

You have rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. You may withdraw consent at any time. You may complain to your local supervisory authority (and to the ICO in the UK).

We do not use solely automated decision-making that produces legal or similarly significant effects about you within the meaning of GDPR Art. 22. In-app scores are research/coaching aids you control; they are not credit, employment, or similarly significant automated decisions.

8.3 United States (including California CCPA/CPRA)

Depending on your state, you may have rights to know/access, delete, correct, and opt out of sale/sharing. We do not sell or share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA beyond what is necessary to provide the service.

How to exercise rights: use in-app controls (Privacy & Security, Delete Account, Manage Subscription) or email [PRIVACY EMAIL REQUIRED]. We will verify requests as required by law and will not discriminate against you for exercising privacy rights.


9. Children’s privacy and audience

TradeAcademy is intended for a general audience. Anyone may download the app and explore educational Guest/demo features that remain local on the device.

Cloud account features — including registration, cloud sync, online journals, online portfolios, and paid subscriptions — are available only to users who meet the minimum eligibility requirements: at least 18 years old, or the age of majority in their jurisdiction. We do not knowingly collect personal data from young children through cloud accounts. The application is not directed toward young children. If you believe a minor has created an account or provided personal data, contact [PRIVACY EMAIL REQUIRED] and we will delete it.

A 4+ / Everyone store rating does not change this. It does not mean a minor may legally trade, receive investment advice, or open a TradeAcademy cloud account.


10. Cookies and similar technologies

The native apps do not use web advertising cookies. If you visit [OFFICIAL DOMAIN REQUIRED] in a browser, any cookies or local storage will be described on that site. Push tokens and local preference stores are used as described above.


11. Security and cybersecurity

We implement technical and organisational measures appropriate to the risk, including:

  • TLS in transit; provider encryption at rest;
  • authentication, optional MFA, verified-email write rules, and deletion re-authentication windows;
  • least-privilege Firestore/Storage rules and server-owned subscription records;
  • redaction of common secrets/PII and user-content fields in optional crash reports;
  • debug console logging restricted to development builds;
  • dependency and CI hygiene practices for the codebase.

No method of transmission or storage is perfectly secure. If a breach is likely to result in a high risk to your rights, we will notify you and/or competent authorities as required under Swiss nFADP, GDPR (including the 72-hour supervisory notification rule where applicable), and applicable U.S. state breach laws.

Report suspected security issues to [SECURITY EMAIL REQUIRED] (or [SUPPORT EMAIL REQUIRED] if that address is not yet active).


12. Account deletion

You may delete your account in Settings. Deletion is intended to remove:

  • Firebase Authentication account;
  • your Firestore user document tree and settings;
  • server subscription-access record and related webhook event references we store;
  • files under your Storage path users/{uid}/;
  • user-scoped security/ops event documents we stored for your UID;
  • local app user data (device theme preference may be preserved).

Shared educational content (Academy lessons, public catalogs) is not deleted; it is not your personal account data.

Deleting the TradeAcademy account does not cancel Apple App Store or Google Play billing. Manage or cancel the store subscription first via Settings → Manage Subscription. Store purchase records remain with Apple/Google under their policies.

More detail: in-app Settings → Account deletion information, and the hosted Account Deletion notice once [OFFICIAL DOMAIN REQUIRED] is live.


13. Changes

We may update this Policy. Material changes will be indicated by updating the “Last updated” date and, where required, seeking fresh consent (e.g. for crash reporting). Continued use after the effective date constitutes acceptance where permitted by law; where consent is required, we will ask again.


14. Contact

Privacy
[PRIVACY EMAIL REQUIRED]
Support
[SUPPORT EMAIL REQUIRED]
Registered address
Höglerstrasse 55, 8600 Dübendorf, Switzerland
Website
[OFFICIAL DOMAIN REQUIRED]

Please include your registered email / account identifier so we can verify your request.

TradeAcademy by Aithera is a trading education and simulated-practice app.

Not a broker. Not an execution venue. Not buy/sell signals. Simulated P/L does not grade a decision. Decision Quality Score is process quality, not a price prediction.