Privacy policy
Last updated: 2 May 2026
Who we are
TradeCompass is operated by Burin Choomnuan as a sole trader, based in Sydney, New South Wales, Australia. The app is currently in private TestFlight beta. There is no incorporated entity at this stage — privacy obligations under this policy fall to me personally. Plan to incorporate before any commercial public launch.
You can reach me at support@b12n.app for any privacy-related question or request.
Beta status — important context
This is a closed TestFlight beta with a small trusted-circle audience. The
backend (b12n-fin-svc) currently runs as a single-tenant deployment —
there is no users table; every authenticated client shares one
namespace, sees the same portfolios, and has read/write access to the
same data. If you need stronger isolation, the public commercial release
(planned for v3) is the appropriate version — this beta is for trusted-
circle use only.
This policy describes how the beta version handles your data. The v3 public release will get its own updated policy.
What we collect
When you use TradeCompass, the following data is sent to the backend and persisted:
- Portfolios — name, optional description, created/updated timestamps.
- Holdings within portfolios — ticker symbol, share count, average cost basis, optional notes.
- Static educational content — read-only, not personalised; tracking what you've read is not stored anywhere.
That's the complete list of personal data. Because the backend has no
users table, there is no email, no name, no IP address logged against
"your" account — there is no account.
What we don't collect
For transparency, here's a list of common categories we explicitly do NOT collect:
- No third-party analytics. No Firebase Analytics, no Sentry, no
Crashlytics, no Mixpanel, no Segment, no Amplitude, no PostHog, no
Google Analytics. The mobile app's
pubspec.yamlcontains zero analytics dependencies. - No advertising IDs. No IDFA, no IDFV, no ad-tracking SDKs.
- No location data. The app does not request the location permission.
- No camera, microphone, contacts, photos, or calendar access. The
iOS
Info.plistcontains noNS*UsageDescriptionkeys for any of these categories. - No push notification tokens. The app does not register for remote notifications.
- No marketing emails. We never send unsolicited mail. The only emails you'll get from us are direct replies if you contact us.
- No cookies or tracking pixels on this website. The
tradecompass.b12n.appsite is static HTML with no scripts.
Where data is stored
The backend runs on a single DigitalOcean droplet in their NY1 datacenter
(US East Coast — IP 164.90.130.103 at the time of writing) and stores
data in a SQLite file on the host. Data is encrypted in transit (TLS
1.2+) but is not encrypted at rest. This is acceptable for a closed
beta but is one reason the multi-tenant v3 will move to a properly
managed AWS deployment with encryption-at-rest defaults.
Third parties
The app and backend interact with the following third parties:
- Apple — TestFlight distributes the app and (if external testers are used) runs a lightweight beta review on the build. Apple sees the app binary and the metadata you provide in App Store Connect. Apple's privacy policy applies to that data: https://www.apple.com/legal/privacy/.
- Yahoo Finance — we fetch OHLCV market data via their public endpoints (no API key, no user data sent). Their terms apply to the data we receive: https://policies.yahoo.com/us/en/yahoo/terms/.
- sec.gov / EDGAR — we fetch SEC filings via the EDGAR public API. No user data is sent. EDGAR's privacy notice: https://www.sec.gov/privacy.
- DigitalOcean — hosts the backend droplet. Their privacy policy: https://www.digitalocean.com/legal/privacy-policy.
- No payment processors — TestFlight is free; we don't process payments.
Retention
Data is retained until you request deletion or until the v3 multi-tenant migration retires the current backend (estimated several months out at the time of writing; the policy will be updated then). Because the backend is single-tenant, "your" data is shared with all testers — see the section on rights below.
Your rights
If you are based in the European Union, United Kingdom, California, or Australia (or anywhere else with applicable data-protection law), you have rights of access, correction, deletion, objection, and where applicable portability with respect to your personal data.
Email support@b12n.app with your request.
A practical note about the single-tenant architecture: because there is
no users table, "delete my data" doesn't have a clean per-user
boundary. We'll coordinate with you on what specifically to delete (a
specific portfolio you created? all portfolios? everything?) and
schedule the work — typically same-week — with notice to other testers
if it affects shared content.
Children
TradeCompass is rated 17+ on the App Store. Financial topics target adults; the app is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided data to us, contact us and we will delete it promptly.
Changes to this policy
For material changes (new third parties, new data categories, jurisdiction changes, etc.) we'll communicate via TestFlight release notes when you get the next build. Minor wording / formatting updates may be made silently. The "Last updated" date at the top reflects the most recent change.
Governing law
This policy is governed by the laws of New South Wales, Australia. Disputes that cannot be resolved by direct communication are subject to the jurisdiction of NSW courts.
Contact
For any question, comment, or rights request: support@b12n.app.