Privacy Policy

Last updated August 20, 2026

This policy explains what the Chart Algo AI iOS app and the chartalgoai.com website (together, the “Service”) collect, why, who it is shared with and how long it is kept. The Service is operated by [Company legal name] (“Chart Algo AI”, “we”, “us”).

The short version. There are no accounts — we never ask for your name, email or password. Your analyses, photos and watchlists live on your phone. A chart photo you analyse is sent to our server, forwarded to an AI provider, and kept in private cloud storage for up to 30 days for debugging and quality checks, then deleted. We use a random device identifier for rate limiting and to keep track of your subscription. We do not sell your personal data.

1. What we collect

We keep this deliberately small. In total:

We do not collect your name, email address, postal address, phone number, payment card details, contacts, precise location or health data. We never see your card number: Apple handles all payment.

2. Chart photos and the analysis pipeline

When you analyse a chart, this is exactly what happens:

  1. The cropped image is saved on your device so the app can show it in your history and watchlists.
  2. A copy is uploaded to our server at chartalgoai.com over HTTPS, together with the ticker and any company name or timeframe you entered, and your device identifier.
  3. Our server forwards the image to an AI vision model via OpenRouter, which routes it to the model provider that performs the analysis. Providers process the image to generate the result and, under OpenRouter's terms as we use them, do not use it to train their models.
  4. The structured result comes back to the app and is saved on your device.
  5. We write an audit record of the call (timestamp, ticker, model, status, HTTP code, duration, device identifier, IP address) and store the image bytes in private Cloudflare R2 object storage.

The R2 copy exists so that when an analysis fails or returns something odd we can look at the picture that caused it. The bucket is private — there is no public URL, and access requires a short-lived signed link generated by an authenticated administrator. Audit records and the stored images are deleted automatically after 30 days.

Only upload charts. Please don't photograph anything containing personal information, and note that if a chart screenshot happens to include your account balance or broker details, that goes up with it.

3. The device identifier

On first launch the app generates a random UUID and stores it on the device. It is not your Apple ID, not your device's advertising identifier (IDFA) and not derived from any hardware serial. We use it to:

Deleting and reinstalling the app produces a new identifier, which is why your on-device history does not survive a reinstall. Your subscription does — tap Restore Purchases.

4. Subscriptions

Subscriptions are sold through Apple's In-App Purchase system and managed with RevenueCat, which acts as our processor for entitlement state. RevenueCat receives the anonymous device identifier as the app user ID, plus the purchase receipt information Apple provides (product, purchase and expiry dates, renewal and cancellation events, store country). Apple processes your payment and we never receive your payment details. See RevenueCat's privacy policy and Apple's privacy policy.

5. Server logs and IP addresses

Our servers record standard request logs: IP address, user agent, path, response status, timing and a request identifier. We use them to keep the Service running, to debug errors, and to detect and block abuse (rate limiting and scanner blocking operate on IP address). We also use an error-monitoring service to capture exception reports, which may include an IP address and request metadata.

6. Advertising and tracking

We plan to advertise the app on platforms such as Apple Search Ads, Meta and Google, and to measure which campaigns bring in users.

This website uses no analytics scripts, no advertising pixels and no third-party cookies. The only cookie it sets is a session cookie on the administrator sign-in page, which is strictly necessary and never reaches ordinary visitors.

7. Data stored on your device

Your analysis history, watchlists, cropped chart images and app preferences are stored locally on your iPhone and are not backed up to our servers. They are included in your iCloud or iTunes device backup if you have that enabled, under Apple's control, not ours. Deleting the app deletes this data.

8. Who we share data with

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose data only to the service providers that make the Service work, each acting on our instructions:

We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, safety and property of our users or ourselves. If the business is ever sold or merged, data may transfer as part of that transaction; we will say so here first.

9. How long we keep things

If you are in the EEA or UK, we process personal data on these bases:

11. Your rights and how to delete your data

Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to complain to your data protection authority. California residents have rights of access, deletion, correction and to opt out of sale or sharing — we do not sell or share personal information as those terms are defined by the CCPA/CPRA. We will not discriminate against you for exercising any of these rights.

To delete data:

Because the Service has no accounts, the device identifier is the only way we can locate your records — we cannot action a deletion request without it, and we may ask for information to verify the request.

12. Security

All traffic between the app and our servers uses HTTPS. AI provider keys are held server-side and never shipped in the app. The R2 bucket is private, with no public access; administrative access to the call audit requires authentication and is limited to the operators of the Service. No system is perfectly secure, and we cannot guarantee absolute security.

13. Children

The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with data, email support@chartalgoai.com and we will delete it.

14. International transfers

Our providers operate globally, so your data may be processed in countries other than yours, including the United States. Where required we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, for those transfers.

15. Changes to this policy

We may update this policy as the Service evolves. The “Last updated” date above shows when it last changed; material changes will be highlighted in the app or on this page.

16. Contact

Questions, requests or complaints: email support@chartalgoai.com. We aim to respond within 30 days.