K Kaptal

Privacy Policy

What we hold about you, why we hold it, and how to get it back or deleted.

Draft — not in force

This document is a working draft. Every passage marked TBD — like this is a fact that has to be supplied or confirmed before it binds anyone. Until they are filled in and the text has been reviewed by a qualified lawyer in each market, nothing here is a representation by Kaptal.

Text last edited In force from not yet — see the note above

The short version

Kaptal holds two things about you: a very small account record, and the portfolio you typed in.

The account record is an identifier from Google or Apple, your email address, a display name, your plan, and the dates the record was created and changed. That is all of it. There is no password, because Kaptal has none. There are no broker logins, because Kaptal never connects to a broker. There is no analytics or advertising SDK in the app, no advertising identifier, no location tracking and no third-party tracker on this website.

The portfolio is whatever you enter — accounts, holdings, transactions, notes and settings — and it exists so the app can sync between your devices. We do not sell it, mine it or share it with the market-data providers.

If you only use the demo, no account is created and nothing about you is stored beyond ordinary server logs.

Who is responsible for your data

The controller of the personal data described here is TBD — controller legal entity name, registered address and company number; this must match the entity named in the Terms.

Contact for anything in this policy, including a request to see or delete your data: TBD — data-protection contact address, and a postal address.

TBD — whether a Data Protection Officer must be appointed under GDPR Art. 37 (likely not, but confirm) and, if the controller is established outside the EU/UK, the Art. 27 EU representative and the UK representative, each with an address

What this policy covers

The Kaptal apps for iOS, macOS and Android, the Kaptal sync and market-data service behind them, and the website at wealthbeing.app. It does not cover Google, Apple, your broker, or any other site we link to; those have their own policies.

What we collect, and where it comes from

WhatExamplesWhere it comes from
Account recordAn opaque identifier for you at your identity provider, your email address, whether that address was verified, a display name, your plan (free or paid), created and updated timestampsGoogle or Apple at sign-in, then your own edits in the app
Sign-in sessionsHashed refresh tokens with their expiry and revocation timeCreated by us when you sign in
Your portfolioAccount groups, accounts, instruments you hold, transactions (date, quantity, price, fee, currency, exchange rate, notes), holdings snapshotsYou, in the app
Your settingsBase currency, time zone, language, theme, the countries and exchanges you chose during setupYou, in the app
Instrument searchesThe text you type into symbol searchYou, in the app
Technical request dataIP address, request time, path, response status and duration in server access logs; counters used for rate limitingAutomatically, on every request
PurchasesThat a subscription exists and what plan it isTBD — the billing channel; if it is the App Store or Google Play we receive a transaction identifier and no card details, but this row must state exactly what the chosen processor passes back

Your portfolio data is stored under your user identifier and is only ever returned to a request carrying your own signed-in session.

What we deliberately do not collect

Cookies and what is stored on your device

This website sets no cookies and runs no third-party scripts. It stores one value in your browser’s local storage, kaptal-theme, which remembers whether you chose light or dark. It never leaves your browser and is not used to identify you.

The apps store your session tokens and a local copy of your portfolio on the device, so the app works while a request is in flight and starts instantly. TBD — confirm where tokens are held on each platform (iOS/macOS Keychain, Android EncryptedSharedPreferences or Keystore) and state it plainly here

For anyone in the EU, the EEA, the UK or Switzerland, the legal bases under the GDPR are these.

PurposeLegal basis
Creating your account and signing you inPerformance of a contract — Art. 6(1)(b)
Storing your portfolio and syncing it between your devicesPerformance of a contract — Art. 6(1)(b)
Valuing your holdings and running the calculations you asked forPerformance of a contract — Art. 6(1)(b)
Taking payment and managing a subscriptionPerformance of a contract — Art. 6(1)(b)
Keeping accounting and tax records of a saleLegal obligation — Art. 6(1)(c)
Keeping the service up: server logs, rate limiting, abuse and fraud prevention, debuggingLegitimate interests — Art. 6(1)(f): running a service that stays available and is not abused. Logs identify requests, not people, and are kept briefly
Answering your support messagePerformance of a contract, or legitimate interests where you are not a customer — Art. 6(1)(b) / (f)
Sending you a message about the service itself (an outage, a change to these documents)Performance of a contract — Art. 6(1)(b)
Sending you marketing emailConsent — Art. 6(1)(a). TBD — whether any marketing email is sent at all; if none is, delete this row rather than leaving an unused basis in the policy

You can object to processing based on legitimate interests — see Your rights.

What we send to other companies, and what we do not

Market-data providers never receive your identity or your portfolio. Kaptal buys prices, exchange rates, dividends and splits into a shared warehouse keyed by instrument, not by user. When a price is needed, the request names the instrument; it does not name you, and no provider is told who holds what.

The one exception worth stating plainly: symbol search. When you search for an instrument the text you typed may be passed to a market-data provider to find matches. It is sent without your identity attached, but it is text you typed, so please do not type anything personal into symbol search.

Other companies that process data for us, as processors under our instructions:

WhoWhat forWhere
TBD — application hosting provider and the regions usedRunning the API and workersTBD — region
TBD — managed PostgreSQL providerThe database holding your account and portfolioTBD — region
TBD — managed Redis providerRate-limit counters and short-lived session stateTBD — region
TBD — market-data provider(s), currently Twelve Data, with the exact legal entityPrices, FX, dividends, splits, instrument reference data and symbol searchTBD — region
TBD — billing channel / payment processorSelling and renewing subscriptionsTBD — region

Google and Apple are not our processors when they sign you in — they act as independent controllers of your identity-provider account, under their own policies. What they pass to us is listed in the table above.

TBD — a signed data processing agreement (GDPR Art. 28) must be in place with every processor in this table before launch, and this list must be kept current. Decide whether it lives on this page or on a separate sub-processor page that is versioned and linked from here.

We disclose data outside this list only where the law requires it, or to establish or defend a legal claim. If Kaptal is ever sold or merged, your data may transfer with it, and you will be told before it does.

Sending data outside the EEA and the UK

TBD — the full transfer story: which processors are outside the EEA/UK, which transfer mechanism applies to each (adequacy decision, EU Standard Contractual Clauses, UK Addendum, the Swiss addendum), and where a copy of the safeguards can be requested. This depends entirely on the hosting regions chosen and cannot be drafted before they are.

How long we keep things

DataKept for
Account record and portfolioUntil you delete your account, then TBD — deletion grace period, if any, and the deadline for completing deletion
Refresh tokensUntil they expire or are revoked, then TBD — purge interval for expired tokens
Server access logsTBD — log retention, e.g. 30 days
Rate-limit countersMinutes — they expire on their own
BackupsTBD — backup retention window, and the wording that deleted data disappears from backups within that window rather than immediately
Records of a saleTBD — the statutory accounting retention period in the controller’s jurisdiction, typically 6–10 years

Market data in the warehouse is not personal data: it describes instruments, not people, and it is kept and refreshed independently of any account.

Your rights

If the GDPR or the UK GDPR applies to you, you have the right to:

To exercise any of these, write to TBD — data-protection contact address. We answer within one month, and will say so if we need longer, as the GDPR allows. We may need to confirm it is really you asking.

TBD — Apple and Google both require account deletion to be initiable from inside the app, not only by email. There is no delete-account endpoint in the backend today, and no in-app path. This has to be built before the apps can be submitted; until it exists, this section cannot promise it.

TBD — if users in the United States, California or other US states are accepted at launch, a state-privacy section (CCPA/CPRA notice at collection, “do not sell or share”, sensitive-data disclosure) has to be added and reviewed. Do not paste a generic one — the accurate answer here is that no data is sold or shared for advertising, which is worth saying precisely.

Automated decisions

We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you. Kaptal calculates on the figures you enter; the calculations are the product, not a judgement about you.

Children

Kaptal is not intended for children. You must be at least TBD — minimum age, matching the Terms and the app-store age ratings to use it. If we learn that a younger child has an account, we delete it.

How we protect it

No service can promise perfect security, and we do not.

Changes to this policy

If we change this policy in a way that matters, we will tell you in the app or by email before it takes effect, and the date at the top of the page will change. Adding any new processor, any analytics, or any new purpose counts as a change that matters.

The language of this policy

This policy is published in English, and the English text is the version we maintain. TBD — GDPR Art. 12 requires this information in clear and plain language for the people it is addressed to. Confirm which markets need a reviewed local-language version before launch (Poland, the Netherlands, Germany, Switzerland at minimum) and which language governs if versions differ.

How to reach us

TBD — data-protection contact email and postal address; must match the entity named as controller above

The other document