Privacy Policy
This policy explains what information the CandleScan app ("the app", "we") collects, how it is used, and the choices you have. We keep it in plain language on purpose.
What we collect
- Account data. Your email address (when you sign in), a user identifier, and your onboarding answers (experience level, markets of interest, goals).
- Content you create. Chart photos you submit for analysis, the analyses generated for you, your personal chart notes and favorites, your chat conversations with the in-app assistant, references to reports selected for questions or comparisons, your followed instruments, and your app settings (such as language).
- Purchase state. Your app user identifier, email address, and subscription status are shared with our subscription-management provider RevenueCat so purchases can be associated with your account, subscription access can be restored, and we can provide subscription support. We never see your payment details — Apple handles all billing.
- Attribution data. Permitted device and app identifiers, install and session data, campaign attribution, tracking-permission status, and subscription lifecycle and revenue events processed by RevenueCat and AppsFlyer.
- Product interactions. Limited app-usage events, such as onboarding steps, report views, favorite or follow changes, and notification choices, processed through AppsFlyer. These events may include language, feature, plan or usage-count categories. We do not include chart images, report text, chat questions or personal notes in these product events.
- Notification preferences. If you enable analysis-ready notifications, we store your device push token, its account association, language and enabled status in our backend. We also keep delivery-ticket records to check provider errors and remove invalid device registrations. A daily reminder time and schedule are stored locally on your device.
How your data is used
- Chart photos you submit are sent to our AI providers (via OpenRouter) solely to generate your analysis, and are stored in your private storage area so the app can display your past analyses to you.
- News and fundamentals research is performed with live web search grounding; the sources used are shown to you in the app.
- Account and content data is stored in our backend (Supabase) to sync your analyses, chats, chart notes, favorites, followed instruments and settings across sessions.
- When you ask about a selected chart or compare reports in chat, the relevant saved analysis and research are supplied to our AI providers through OpenRouter to explain that context.
- Your email address may be used for sign-in codes, account or security notices, support replies, and other essential service communications.
- Attribution and subscription event data is used to measure campaign performance and optimize advertising for subscription outcomes rather than app installs alone.
- Product interactions help us understand which features are useful and where people encounter difficulties, so we can improve onboarding and the app.
- For optional analysis-ready notifications, Expo's push service and Apple's notification delivery service receive the device push token, a generic completion message, and a report identifier used to open the correct report. Notification messages do not contain your chart image, analysis text, notes or chat content.
Email choices
We send promotional emails only if you separately opt in. Every promotional email includes a way to unsubscribe, and opting out of promotional email does not prevent essential account or service messages.
Tracking choices
On iOS, your App Tracking Transparency choice controls whether the advertising identifier is available. Attribution may still use other identifiers permitted by Apple and aggregated campaign information. You can change the app's tracking permission in iOS Settings.
Notification choices
Analysis-ready notifications and daily reminders are optional. The app asks for notification permission when you enable one of these features. You can turn either option off in the app's Settings, and change device notification permission in iOS Settings. A daily reminder is scheduled locally at the time you choose; it does not generate new research automatically or send your reminder time to our backend for delivery.
What we don't do
- We do not sell your personal data.
- We do not show third-party ads.
- We do not access your camera roll beyond the photos you explicitly choose to analyze.
Service providers
We rely on a small set of processors to run the app: Supabase (database, storage, and authentication), OpenRouter and its underlying AI model providers (chart image analysis and text generation), Google Search grounding (news research), Apple (payments and notification delivery), RevenueCat (subscription management), AppsFlyer (install, campaign, subscription attribution and product interactions), and Expo (optional push notification delivery). Each receives only the data needed for its function. Some providers may process data outside your country of residence with appropriate safeguards.
Data retention and deletion
Your data is retained while your account is active. You can permanently delete your app account and associated backend data (analyses, photos, chats, chart notes, favorites, followed instruments and notification registrations) at any time under Settings → Delete account. The app also attempts to remove RevenueCat's copy of your email address. RevenueCat and AppsFlyer may retain account identifiers, device and attribution data, and purchase or subscription records under their retention policies and for billing, fraud prevention, analytics, tax, or legal obligations. Contact us to request deletion from these providers where applicable. Local reminder schedules and device notification permission are managed through the notification controls described above.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these rights, contact us. You can also request account deletion in the app.
Children
The app is not directed at children and is intended for users aged 18 or older, in line with its financial-education subject matter.
Changes
If this policy changes materially, we will update this page and the effective date above. Continued use of the app after changes take effect constitutes acceptance.
Contact
Privacy questions or requests: support@azdigitalinc.com or via the support page.