Privacy Policy
Pre-launch draft · Reviewed September 18, 2026
This draft describes data flows implemented in the Coin Copilot website and app. It distinguishes current processing from planned subscriptions. Cloud settings, retention periods, operator details, and legal bases still require confirmation before this becomes a complete published privacy notice.
Website visits and contacting us
This website presents app information and links for contacting us by email or phone. Visiting it sends normal connection information, such as IP address, browser details, and requested pages, to the hosting service. No website analytics script, tracking-cookie integration, or account form is included in the current source. Hosting-level logging or analytics must still be checked. Clicking an email link opens your email application; if you send a message, your email address and message are used to respond. Requesting early access does not create a subscription.
App accounts and saved activity
Supabase provides app authentication, database, and file storage. The app processes sign-in information, account identifiers, username, selected fiat currency, time zone, and preferences. Apple or Google sign-in can provide authentication information and, when supplied by the provider, email or name. Saved records include watchlists, portfolios, virtual balances, positions, price alerts, push tokens, notification delivery state, and AI prompts and responses. These support account access, simulation, saved activity, and notifications.
Profile photos and local storage
If you choose a profile photo, the app resizes and uploads it to Supabase Storage. The app uses a public URL for that photo, so anyone with the URL may be able to view it. Do not upload a photo you need to keep private. Authentication sessions, preferences, profile information, and watchlist identifiers are also cached on your device. Device caches and stored sessions have separate lifecycles from server records.
AI Insights and OpenAI
When you request AI Insights, your question and snapshots of your simulated portfolios are sent to OpenAI. Snapshots include portfolio identifiers and titles, currencies, virtual cash, holdings, purchase prices, quantities, current market prices, and performance measures. Avoid entering sensitive information in prompts or portfolio names. Questions and generated responses are saved in Supabase. The six-hour AI cache expiry controls reuse of a response, not deletion of the saved record. Provider-side retention and processing terms must be confirmed before this notice is finalized.
Market information and remote images
Coinranking supplies market information and receives requests containing coin identifiers, search queries, and reference currencies. Requests made directly from your device, including requests for remote coin images, expose normal network information such as IP address to the receiving service. Portfolio snapshots sent for AI analysis also include market data retrieved from Coinranking.
Notifications and background services
When notifications are enabled, Expo and Firebase push tokens are stored with your account. Trigger.dev runs background tasks that process alert and portfolio data, notification delivery state, and saved time zone information. Expo and platform notification services deliver the messages. Device permissions and per-portfolio preferences affect delivery. Notifications can display portfolio or price-alert information on your lock screen; you can control notification permissions and previews through your device settings.
Analytics, diagnostics, and updates
The mobile app includes Firebase Analytics and Crashlytics, which may process usage events, app-instance or device identifiers, and crash diagnostics depending on native build configuration. Expo provides app update and notification services. Backend services may maintain operational logs. Exact collection settings, purposes and legal bases, retention, provider agreements, hosting locations, and international transfer safeguards require verification before launch. The current app does not provide an analytics-consent settings screen.
Subscriptions and feedback
RevenueCat is planned for future subscriptions but is not integrated in the current app. This notice will need to describe purchase-related data processing before subscriptions become available. The current in-app feedback form validates email, subject, and message locally but does not send them. The account-deletion endpoint receives a required deletion reason but does not explicitly save it to a database table in the current implementation.
Retention and deletion
Account-linked app records remain stored while the account exists unless removed through an available deletion action. Settings > Delete account removes the authentication account, profile photo, and linked database records, including portfolios, watchlists, alerts, and saved AI insights. Provider logs, backups, caches, and previously delivered messages may persist separately. Their retention periods, deletion schedules, and any legal exceptions have not yet been confirmed; this draft does not promise immediate erasure from every provider or device. Contact-message retention also needs a defined schedule before the notice is finalized.
Choices and privacy rights
You can choose whether to upload a photo or request AI Insights, change device notification permissions, and delete your account in Settings. Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, restrict or object to processing, withdraw consent where used, and complain to a supervisory authority. Contact us using the details below to raise a request. The operator's identity, applicable legal bases, rights-request procedures, and eligibility or minimum-age policy must be confirmed before final publication.
Privacy contact
For privacy questions or requests, email coincopilot@gmail.com or call +33 7 60 10 38 23. Do not send passwords or wallet recovery phrases. The current in-app feedback form does not deliver privacy requests.