The short version
Kaptal holds two things about you: a very small account record, and the portfolio you typed in.
The account record is an identifier from Google or Apple, your email address, a display name, your plan, and the dates the record was created and changed. That is all of it. There is no password, because Kaptal has none. There are no broker logins, because Kaptal never connects to a broker. There is no analytics or advertising SDK in the app, no advertising identifier, no location tracking and no third-party tracker on this website.
The portfolio is whatever you enter — accounts, holdings, transactions, notes and settings — and it exists so the app can sync between your devices. We do not sell it, mine it or share it with the market-data providers.
If you only use the demo, no account is created and nothing about you is stored beyond ordinary server logs.
Who is responsible for your data
The controller of the personal data described here is TBD — controller legal entity name, registered address and company number; this must match the entity named in the Terms.
Contact for anything in this policy, including a request to see or delete your data: TBD — data-protection contact address, and a postal address.
TBD — whether a Data Protection Officer must be appointed under GDPR Art. 37 (likely not, but confirm) and, if the controller is established outside the EU/UK, the Art. 27 EU representative and the UK representative, each with an address
What this policy covers
The Kaptal apps for iOS, macOS and Android, the Kaptal sync and market-data service behind them, and the website at wealthbeing.app. It does not cover Google, Apple, your broker, or any other site we link to; those have their own policies.
What we collect, and where it comes from
| What | Examples | Where it comes from |
|---|---|---|
| Account record | An opaque identifier for you at your identity provider, your email address, whether that address was verified, a display name, your plan (free or paid), created and updated timestamps | Google or Apple at sign-in, then your own edits in the app |
| Sign-in sessions | Hashed refresh tokens with their expiry and revocation time | Created by us when you sign in |
| Your portfolio | Account groups, accounts, instruments you hold, transactions (date, quantity, price, fee, currency, exchange rate, notes), holdings snapshots | You, in the app |
| Your settings | Base currency, time zone, language, theme, the countries and exchanges you chose during setup | You, in the app |
| Instrument searches | The text you type into symbol search | You, in the app |
| Technical request data | IP address, request time, path, response status and duration in server access logs; counters used for rate limiting | Automatically, on every request |
| Purchases | That a subscription exists and what plan it is | TBD — the billing channel; if it is the App Store or Google Play we receive a transaction identifier and no card details, but this row must state exactly what the chosen processor passes back |
Your portfolio data is stored under your user identifier and is only ever returned to a request carrying your own signed-in session.
What we deliberately do not collect
- No password. Sign-in is Google today and Apple later. We have no password field, store no password hash, and cannot reset a password.
- No broker or bank credentials, and no account connection. Kaptal never logs into a broker. Everything in your portfolio is there because you or an import you ran put it there.
- No card or bank details. If you subscribe, the payment is handled by the store or processor named above; card numbers never reach us.
- No analytics, attribution or advertising SDK in the apps, and no analytics or advertising script on wealthbeing.app. TBD — confirm this is still true at launch. It is true of the current code; adding crash reporting or product analytics later means this section, the legal bases and the processor list all have to change first.
- No location, contacts, photos, health or biometric data, and no advertising identifier.
- No special-category data. Please do not put any in a transaction note.
Cookies and what is stored on your device
This website sets no cookies and runs no third-party scripts. It stores one value in your browser’s local storage, kaptal-theme, which remembers whether you chose light or dark. It never leaves your browser and is not used to identify you.
The apps store your session tokens and a local copy of your portfolio on the device, so the app works while a request is in flight and starts instantly. TBD — confirm where tokens are held on each platform (iOS/macOS Keychain, Android EncryptedSharedPreferences or Keystore) and state it plainly here
Why we process it, and on what legal basis
For anyone in the EU, the EEA, the UK or Switzerland, the legal bases under the GDPR are these.
| Purpose | Legal basis |
|---|---|
| Creating your account and signing you in | Performance of a contract — Art. 6(1)(b) |
| Storing your portfolio and syncing it between your devices | Performance of a contract — Art. 6(1)(b) |
| Valuing your holdings and running the calculations you asked for | Performance of a contract — Art. 6(1)(b) |
| Taking payment and managing a subscription | Performance of a contract — Art. 6(1)(b) |
| Keeping accounting and tax records of a sale | Legal obligation — Art. 6(1)(c) |
| Keeping the service up: server logs, rate limiting, abuse and fraud prevention, debugging | Legitimate interests — Art. 6(1)(f): running a service that stays available and is not abused. Logs identify requests, not people, and are kept briefly |
| Answering your support message | Performance of a contract, or legitimate interests where you are not a customer — Art. 6(1)(b) / (f) |
| Sending you a message about the service itself (an outage, a change to these documents) | Performance of a contract — Art. 6(1)(b) |
| Sending you marketing email | Consent — Art. 6(1)(a). TBD — whether any marketing email is sent at all; if none is, delete this row rather than leaving an unused basis in the policy |
You can object to processing based on legitimate interests — see Your rights.
What we send to other companies, and what we do not
Market-data providers never receive your identity or your portfolio. Kaptal buys prices, exchange rates, dividends and splits into a shared warehouse keyed by instrument, not by user. When a price is needed, the request names the instrument; it does not name you, and no provider is told who holds what.
The one exception worth stating plainly: symbol search. When you search for an instrument the text you typed may be passed to a market-data provider to find matches. It is sent without your identity attached, but it is text you typed, so please do not type anything personal into symbol search.
Other companies that process data for us, as processors under our instructions:
| Who | What for | Where |
|---|---|---|
| TBD — application hosting provider and the regions used | Running the API and workers | TBD — region |
| TBD — managed PostgreSQL provider | The database holding your account and portfolio | TBD — region |
| TBD — managed Redis provider | Rate-limit counters and short-lived session state | TBD — region |
| TBD — market-data provider(s), currently Twelve Data, with the exact legal entity | Prices, FX, dividends, splits, instrument reference data and symbol search | TBD — region |
| TBD — billing channel / payment processor | Selling and renewing subscriptions | TBD — region |
Google and Apple are not our processors when they sign you in — they act as independent controllers of your identity-provider account, under their own policies. What they pass to us is listed in the table above.
TBD — a signed data processing agreement (GDPR Art. 28) must be in place with every processor in this table before launch, and this list must be kept current. Decide whether it lives on this page or on a separate sub-processor page that is versioned and linked from here.
We disclose data outside this list only where the law requires it, or to establish or defend a legal claim. If Kaptal is ever sold or merged, your data may transfer with it, and you will be told before it does.
Sending data outside the EEA and the UK
TBD — the full transfer story: which processors are outside the EEA/UK, which transfer mechanism applies to each (adequacy decision, EU Standard Contractual Clauses, UK Addendum, the Swiss addendum), and where a copy of the safeguards can be requested. This depends entirely on the hosting regions chosen and cannot be drafted before they are.
How long we keep things
| Data | Kept for |
|---|---|
| Account record and portfolio | Until you delete your account, then TBD — deletion grace period, if any, and the deadline for completing deletion |
| Refresh tokens | Until they expire or are revoked, then TBD — purge interval for expired tokens |
| Server access logs | TBD — log retention, e.g. 30 days |
| Rate-limit counters | Minutes — they expire on their own |
| Backups | TBD — backup retention window, and the wording that deleted data disappears from backups within that window rather than immediately |
| Records of a sale | TBD — the statutory accounting retention period in the controller’s jurisdiction, typically 6–10 years |
Market data in the warehouse is not personal data: it describes instruments, not people, and it is kept and refreshed independently of any account.
Your rights
If the GDPR or the UK GDPR applies to you, you have the right to:
- know what we hold and get a copy of it;
- correct anything inaccurate;
- delete it — the right to erasure;
- restrict or object to processing we base on legitimate interests;
- take it with you — receive the data you gave us in a machine-readable form, or have it sent to another service where that is technically feasible;
- withdraw consent at any time where processing rests on consent, without affecting what was done before;
- complain to a supervisory authority. You may complain to the authority where you live or work. TBD — the lead supervisory authority for the controller, with its name and website
To exercise any of these, write to TBD — data-protection contact address. We answer within one month, and will say so if we need longer, as the GDPR allows. We may need to confirm it is really you asking.
TBD — Apple and Google both require account deletion to be initiable from inside the app, not only by email. There is no delete-account endpoint in the backend today, and no in-app path. This has to be built before the apps can be submitted; until it exists, this section cannot promise it.
TBD — if users in the United States, California or other US states are accepted at launch, a state-privacy section (CCPA/CPRA notice at collection, “do not sell or share”, sensitive-data disclosure) has to be added and reviewed. Do not paste a generic one — the accurate answer here is that no data is sold or shared for advertising, which is worth saying precisely.
Automated decisions
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you. Kaptal calculates on the figures you enter; the calculations are the product, not a judgement about you.
Children
Kaptal is not intended for children. You must be at least TBD — minimum age, matching the Terms and the app-store age ratings to use it. If we learn that a younger child has an account, we delete it.
How we protect it
- All traffic runs over TLS.
- There is no password to steal: authentication is delegated to Google and Apple, and only a hash of each refresh token is stored, never the token.
- Every query for portfolio data is scoped to the signed-in user’s identifier; there is no shared table a request can read across.
- Market-data provider keys live on the server only and are never shipped in an app.
- Access to production data is limited to those who need it. TBD — describe the access controls actually in place (who has database access, MFA, audit logging), and the breach-notification process required by GDPR Art. 33/34: who assesses, and the 72-hour clock
No service can promise perfect security, and we do not.
Changes to this policy
If we change this policy in a way that matters, we will tell you in the app or by email before it takes effect, and the date at the top of the page will change. Adding any new processor, any analytics, or any new purpose counts as a change that matters.
The language of this policy
This policy is published in English, and the English text is the version we maintain. TBD — GDPR Art. 12 requires this information in clear and plain language for the people it is addressed to. Confirm which markets need a reviewed local-language version before launch (Poland, the Netherlands, Germany, Switzerland at minimum) and which language governs if versions differ.
How to reach us
TBD — data-protection contact email and postal address; must match the entity named as controller above