Taplistic Legal

Taplistic LLC

Privacy Policy

How Taplistic LLC collects, uses, shares and protects information when you use our iPhone apps — including Cryptosignal, Stocks Alerter, Stockvisor, Extrinsic and Options Alerter — and the taplistic.com website.

Effective date September 15, 2026 Last updated September 15, 2026 Reviewed September 2026

The short version

We collect as little as we can. We do not sell your personal information, and we do not share it with advertisers or data brokers for their own marketing.

We never ask for and never store your brokerage or exchange login credentials, account numbers, bank details, Social Security number, or payment card numbers. Our apps do not connect to your trading accounts. Purchases are handled entirely by Apple, and we never see your card.

You can delete your account and the data attached to it from inside the app at any time. Section 12 explains how.

Who we are and what this covers

Taplistic LLC, a Delaware limited liability company (“Taplistic,” “we,” “us”), publishes finance research apps for iPhone. This Privacy Policy explains what we do with information relating to you when you use any app we publish — including Cryptosignal, Stocks Alerter, Stockvisor, Extrinsic and Options Alerter, and any app we release later under the Taplistic brand (each an “App”) — or visit taplistic.com (together, the “Services”).

For users in the European Economic Area and the United Kingdom, Taplistic LLC is the data controller for the processing described here.

This policy does not apply to Apple, to your broker or exchange, or to any other third party whose service you reach from our Services. Their handling of your information is governed by their own policies. Your use of the Services is also governed by our Terms of Service.

Information we collect

We collect only what an App needs to work. What we actually collect depends on which App you use and which features you turn on. The categories below use the same labels as the App Privacy section of each App's App Store product page, so you can compare the two directly.

CategoryWhat it includesWhy we have it
Contact info Email address, and a display name if you choose to set one. Only if you create an account. To create and secure your account, sync your settings across devices, and send service messages you ask for.
User content Watchlists, tickers you follow, alert rules, saved screens, notes, and any feedback or support message you send us. To deliver the feature you set up and to answer support requests.
Identifiers A randomly generated account or device identifier, and the Apple push token if you enable notifications. To link your settings to your account and to deliver alerts to your device.
Purchases Subscription status, plan, renewal state and transaction receipt identifiers, received from Apple. To unlock paid features and validate that a subscription is active. We never receive your payment card or billing address.
Usage data Which screens and features you open, taps, session length, and aggregated interaction counts. To understand which features are used, fix confusing flows, and prioritise development.
Diagnostics Crash logs, error traces, performance timings, app version, device model and OS version. To find and fix bugs and keep the App stable.
Approximate location Country or region inferred from your IP address. Not precise location. To apply regional legal requirements, prevent fraud and abuse, and comply with sanctions law.

Some Apps work fully without an account. Where that is the case, we do not require you to give us an email address to use the core features.

If you sign in using Sign in with Apple, Facebook or Google, we receive only what that service releases to us with your permission — typically a name, an email address (which may be a private relay address) and a platform user identifier. We do not receive your password, and we do not post anything to your social accounts.

What we never collect

To be unambiguous, our Apps are research and information tools. They do not connect to your money. We do not ask for, receive, or store:

  • Brokerage, exchange or bank login credentials, API keys, or account numbers
  • Payment card numbers, CVVs, or billing addresses — Apple processes all purchases and does not pass this to us
  • Your portfolio holdings, balances, order history or trade confirmations from any broker
  • Social Security numbers, tax identification numbers, or government ID documents
  • Precise GPS location, contacts, photos, microphone or camera data
  • Health, biometric, genetic, or fingerprint data
  • Information about your race, ethnicity, religion, political opinions, union membership, sexual orientation, or immigration status
  • Private wallet keys, seed phrases, or recovery phrases for any digital asset wallet

No Taplistic employee will ever ask you for a password, seed phrase, API key or brokerage credential. If someone claiming to be from Taplistic asks, it is a scam — do not respond, and report it to us.

How we use information

We use the information described above to:

  • provide, operate, maintain and improve the Apps and their features;
  • create and secure your account and authenticate you;
  • generate and deliver the alerts, signals, screens and research output you have asked for;
  • verify your subscription status and unlock paid features;
  • respond to your support requests, feedback and legal requests;
  • diagnose crashes, monitor performance and debug problems;
  • measure feature usage in aggregate so we know what to build next;
  • detect, investigate and prevent fraud, abuse, credential sharing, scraping, and security incidents;
  • comply with legal obligations, including sanctions and export control screening; and
  • establish, exercise or defend legal claims.

We may create aggregated or de-identified data that cannot reasonably be used to identify you, and we may use and retain that data for any lawful business purpose, including improving our models and publishing statistics. We do not attempt to re-identify it.

We do not use your personal information to make automated decisions that produce legal or similarly significant effects about you. The signals and scores our Apps generate are about markets and instruments, not about you.

Legal bases for processing

If you are in the EEA or the UK, we rely on the following legal bases under the GDPR and UK GDPR:

BasisWhere we rely on it
ContractCreating and running your account, delivering the features and alerts you configure, and providing paid functionality.
Legitimate interestsKeeping the Apps secure and stable, preventing fraud and abuse, understanding aggregate feature usage, and defending legal claims — balanced against your rights.
ConsentPush notifications, tracking under App Tracking Transparency, optional analytics where consent is required, and marketing email. You can withdraw consent at any time.
Legal obligationSanctions screening, tax and accounting records, and responding to lawful requests.

Service providers

We use a small number of third-party companies to run the Apps — the ordinary infrastructure any mobile app needs. Each one receives only the data required for the specific job we hire it to do, acts on our instructions under a written contract, and is required to protect that data to a standard at least equivalent to this policy.

No service provider is permitted to use your information for its own marketing, to build its own profile of you, or to sell or share it with anyone else.

FunctionWhat it receives
AppleApp distribution, in-app purchases, push notification delivery and crash reporting. Apple receives purchase and subscription data, push tokens and crash diagnostics under its own privacy policy.
Cloud hosting and storageAccount records, watchlists and alert settings, held on our behalf.
Analytics and crash reportingUsage events, app version, device model and OS version, and crash logs. Not your email address or contact details.
Subscription validationReceipt identifiers and subscription status, used to confirm a plan is active.
Market data providersThe symbols and screens requested. These providers do not receive your identity.

If you sign in through a third-party platform, that platform is also involved to the extent described in Section 2.

If we engage a provider that would receive personal information for a genuinely new purpose, we will update this policy and, where the law requires it, ask for your consent first. You can request the identity of the providers handling your personal information at any time using the contact details in Section 21.

Artificial intelligence and third-party AI

Some features use machine learning and artificial intelligence to produce research summaries, scores and signal commentary. We want to be explicit about what is and is not sent to AI systems.

What we send. Market data, instrument identifiers, and the parameters of the screen or query you ran. This is information about securities and markets.

What we do not send. We do not transmit your name, email address, account identifiers, subscription details or contact information to any third-party AI provider, and we do not allow any AI provider to train its models on data we send.

If we ever need to share personal data with a third-party AI service, we will disclose it here and ask for your explicit permission before doing so.

AI output is probabilistic and can be wrong. Section 9 of our Terms of Service explains the limits of that output and why you must verify it independently.

Tracking, advertising and ATT

We do not track you across other companies' apps and websites, and we do not serve third-party advertising in our Apps.

If we ever introduce a feature that would track you in the sense Apple defines, the App will ask through Apple's App Tracking Transparency prompt first, and we will only track if you tap Allow. You can change your answer at any time in Settings › Privacy & Security › Tracking, and declining never costs you access to any paid feature.

We do not sell or share your personal information for cross-context behavioural advertising as those terms are defined under California and other state privacy laws.

Cookies on our website

taplistic.com uses only what is necessary to serve the site. We do not run advertising cookies or cross-site trackers there.

Where we do use analytics or non-essential cookies, we honour the Global Privacy Control (GPC) and other recognised universal opt-out signals as an opt-out of sale and sharing for residents of states where that is required.

When we share information

We do not sell your personal information, and we have not sold or shared it in the preceding twelve months. We disclose it only in these situations:

  • Service providers. The processors listed in Section 6, acting on our instructions under contract.
  • At your direction. When you connect a third-party account or ask us to share something.
  • Legal requirements. When we reasonably believe disclosure is required by law, subpoena, court order or government request. Where we are permitted to notify you, we will try to do so.
  • Protection of rights. To investigate fraud or abuse, enforce our Terms, or protect the rights, property or safety of Taplistic, our users or the public.
  • Business transfer. In connection with a merger, acquisition, financing, reorganisation or sale of assets, in which case the recipient will be bound by this policy or will give you notice before materially changing how your information is handled.
  • Aggregated or de-identified data, which is not personal information.

How long we keep information

DataRetention
Account and profileWhile your account is active, then deleted or de-identified within 30 days of account deletion.
Watchlists, alerts, settingsDeleted with your account.
Support correspondenceUp to 24 months after the matter closes.
Crash and diagnostic logsTypically 90 days, then deleted.
Aggregated usage statisticsIndefinitely, in de-identified form only.
Purchase and tax recordsAs long as required by tax, accounting and audit law, generally 7 years.

We may retain information longer where we are required to by law, or where it is necessary to resolve a dispute, enforce our agreements, or defend a legal claim. In that case we isolate it and stop using it for any other purpose.

Deleting your account and data

You have three routes, and all of them work:

  • In the app. Open Settings inside the App and choose Delete Account. This starts the deletion immediately — you do not need to email anyone or wait for approval.
  • By email. Write to the address in Section 21 from the email address on your account.
  • Through Meta, if you signed in with Facebook. Go to Settings & Privacy › Settings › Apps and Websites on Facebook, remove the app, and choose to send a data deletion request. We act on those requests the same way.

Deletion removes your account, profile, watchlists, alert configurations and associated identifiers from our production systems, normally at once and in any event within 30 days. Encrypted backups are purged on their ordinary rotation cycle, within 90 days. We keep only what the law requires us to keep, such as purchase records for tax purposes.

Deleting your account does not cancel a subscription bought through Apple. Apple controls billing. Cancel in Settings › your name › Subscriptions on your device, or your subscription will keep renewing.

Your privacy rights

Depending on where you live, you may have some or all of the following rights. We extend the core rights — access, correction and deletion — to every user, wherever you are.

  • Access a copy of the personal information we hold about you, and know what we collect and why.
  • Correct information that is inaccurate.
  • Delete your information (see Section 12).
  • Portability — receive your data in a portable, machine-readable format.
  • Opt out of sale, sharing for targeted advertising, or profiling with significant effects. We do none of these, so there is nothing to opt out of, but the right stands.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Object to or restrict processing based on legitimate interests (EEA/UK).
  • Non-discrimination — we will never degrade your service, raise your price or deny you a feature for exercising a privacy right.

How to exercise them. Email us at the address in Section 21 and say what you want. We will verify that the request really comes from you, usually by confirming control of the email address on the account, and respond within 45 days (extendable once by a further 45 days where permitted) or within one month under the GDPR. An authorised agent may act for you with written proof of authority. There is no charge unless a request is manifestly unfounded or excessive.

If we say no. You may appeal by replying with the word “Appeal” and your reasons. We will respond in writing within 45 days. If you remain unhappy, you can complain to your state attorney general, or — in the EEA or UK — to your local supervisory authority or the UK Information Commissioner's Office.

Some rights apply only where a particular law covers us and covers you. Nothing in this section is an admission that any specific statute applies to Taplistic.

Notice to California residents

Under the California Consumer Privacy Act as amended by the CPRA, and to the extent it applies to us, we disclose the following about the preceding twelve months.

Categories collected: identifiers (email, random user ID, device and push identifiers); commercial information (subscription status and transaction identifiers); internet or electronic network activity (feature usage, diagnostics); geolocation data (approximate, country-level only); and your own content (watchlists, alerts, support messages). Sources, purposes and recipients are described in Sections 2, 4, 6 and 10.

Sensitive personal information: we do not collect it, and we do not use or disclose any personal information for purposes that would require offering a “Limit the Use of My Sensitive Personal Information” link.

Sale and sharing: we have not sold personal information and have not shared it for cross-context behavioural advertising. We do not knowingly sell or share the personal information of anyone under 16.

California residents also have the rights listed in Section 13, exercisable the same way. Under the “Shine the Light” law you may request information about disclosures to third parties for their direct marketing purposes — we make none.

International data transfers

We operate from the United States, and our service providers may process information in the United States and other countries. Data protection law in those countries may differ from the law where you live.

Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional safeguards where appropriate. You can ask us for details of the safeguards that apply to your data using the contact details in Section 21.

Security

We use administrative, technical and physical safeguards appropriate to the sensitivity of the data we hold: encryption in transit (TLS) and at rest, access limited to people who need it, hardened cloud infrastructure, and regular dependency and configuration review. Because we deliberately do not hold credentials, account numbers or payment details, the value of our data to an attacker is low by design.

You are responsible for the security of your own device, your Apple Account and any password you use with us. Enable a passcode and two-factor authentication.

No system is perfectly secure. We cannot and do not guarantee that unauthorised access will never occur, and to the extent permitted by law we do not accept liability for any security incident that occurs despite reasonable safeguards. If a breach affects your personal information, we will notify you and the relevant regulators as and when applicable law requires.

Children's privacy

The Services are financial research tools for adults. They are not directed to children, and you must be 18 or older to use them. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect any personal information from a child under 13 as defined by COPPA.

If you believe a child has given us information, contact us and we will delete it promptly.

We are not a financial institution

Taplistic is a software publisher. We are not a bank, broker-dealer, registered investment adviser, exchange, money transmitter or other financial institution, we do not execute trades or hold customer funds or assets, and we do not provide personalised financial advice.

As a result we do not collect “nonpublic personal information” within the meaning of the Gramm-Leach-Bliley Act, and this policy is not a GLBA privacy notice. Section 8 of our Terms of Service sets this out in full.

Third-party links and market data

The Services display data from third-party providers and may link to brokers, exchanges, news sites and other destinations. Once you leave our Apps or website, this policy stops applying and the destination's own policy takes over. We do not control those parties and are not responsible for their privacy practices. Read their policies before giving them information.

Changes to this policy

We may update this policy as our Apps and the law change. When we do, we revise the “Last updated” date above. For material changes — for example, a new category of data, a new recipient, or a genuinely new purpose — we will give prominent notice in the App, by email, or on this page before the change takes effect, and we will obtain your consent where the law requires it.

Continuing to use the Services after a change takes effect means you accept the updated policy. If you do not accept it, delete your account and stop using the Services.

How to contact us

For any privacy question, or to exercise a right described in Section 13, contact:

Publisher Taplistic LLC
Entity A Delaware limited liability company
Privacy tos at taplistic.com
Website www.taplistic.com

Please put “Privacy Request” in the subject line so we can route it quickly. We do not require you to create an account in order to make a privacy request.