Privacy Policy
Wall Street: Stock Market & Shares — last updated: September 4, 2026
Account and data deletion
Data controller and intended audience
- The controller of the personal data described below is Nicolas Stordeur, sole trader (French micro-enterprise) trading as “Wall Street Apps”, 6 allée des Ormes, 10300 Sainte-Savine, France, publisher of the app “Wall Street: Stock Market & Shares” (legal notice).
- For any question about your data or to exercise your rights, contact contact@wallstreetapps.fr (or, failing that, stordeur.nicolas10@gmail.com).
- No Data Protection Officer is appointed: the processing does not involve large-scale monitoring or sensitive data. The controller remains reachable at the address above.
- The app is intended for adults and is not directed to persons under 18. It does not knowingly collect data from a minor; if you believe a minor has provided us data, contact us for its deletion.
Data we collect
- If you sign in with Google, we receive your name and email address to identify and synchronize your account.
- We store data you create, including portfolios, watchlists, alerts, widget preferences, wealth tracking, cash flows and recent searches.
- Without Google sign-in, portfolios, watchlists and alerts remain only on the device and are not synchronized to Firebase.
- Viewed assets may be counted to produce an aggregated ranking of the 10 most viewed stocks over the last 48 hours. It does not publish your identity or portfolio content. Per-stock counters are purged after four days.
- Anonymous daily counters may measure use of the five main sections, Premium features and total session duration. They contain no UID, email, installation ID, viewed symbol, search or portfolio data.
- To understand usage by broad area, these counters may include only the country code configured on the device (for example FR or US). This is neither precise geolocation nor an IP address, and it is kept only as an aggregate total.
- An estimate of users currently online uses a random token created only in memory at each app launch. The server stores only a temporary fingerprint with no UID, email, viewed page or financial data. It expires ten minutes after the last signal and is used only to produce an aggregate administrator total.
- To prevent AI quotas from being reset by signing out or changing accounts, a stable technical device identifier is converted into a cryptographic fingerprint before a daily counter is stored. The raw identifier is not retained on our servers, the fingerprint is not used for advertising or navigation tracking, and expired device counters are deleted after three days.
- Market, news, dividend, chart, classification and offline-pack data may be cached on your device or backend to display saved information quickly and reduce repeated provider calls.
- Premium payments are handled by Google Play. We receive subscription status but never your card number or banking details.
- We do not collect precise location, contacts, photos or personal files from your device.
Why we collect this data
- To provide portfolios, watchlists, alerts, performance calculations, widgets, wealth history and synchronization across your devices.
- To display relevant stock and portfolio news, improve data availability and avoid unnecessary repeated API calls.
- To enforce Basic and Premium limits, verify purchases or Premium codes, prevent abuse, secure backend access and improve app reliability.
Legal basis for each processing activity
- Performance of the contract (providing the service and subscription): account management, portfolios, watchlists, alerts, cross-device synchronization, the performance and wealth history you generate, and verification of Basic / Premium entitlements and Premium codes.
- Your consent: personalized advertising through Google (collected via the Google UMP message) and sending your holdings to the Google Gemini AI service when you request an analysis. You can withdraw these consents at any time.
- Our legitimate interest: app security and abuse prevention (App Check, device fingerprint for AI quotas), strictly aggregated audience measurement, caching of shared financial data, and the aggregated ranking of the most viewed stocks.
- Compliance with legal obligations: keeping payment-related records and responding to rights requests.
How your data is stored and secured
- Account data is stored using Google Firebase services (Google Cloud), encrypted in transit (HTTPS/TLS) and at rest by Google.
- Strict access rules ensure that only your account can read or modify your own data — no one else, including another user, can access it.
- Writes (portfolio, watchlist, alerts) are also validated server-side before any save.
- Keys to our financial-data providers are never present in the app: they stay on our servers.
- Histories, prices, annual fundamentals (notably the last five fiscal years where available), dividends, index compositions and news cached on the backend are shared financial data, unrelated to your identity or portfolio content. Local caches remain on your device until replaced, deleted or the app is uninstalled.
- Public revenue breakdowns by broad geographic area are archived without personal data, with their date and documentary reference, and shared between users like other fundamental data.
- Firebase App Check and authentication help limit unauthorized backend access, but no system can guarantee absolute security. Language-specific news and content caches are separated so French translated content is not reused as English content.
International transfers outside the European Economic Area
- Some providers process data from the United States, in particular Google (Firebase, Firebase Authentication, Google Cloud, Google Cloud Translation, Google Gemini, Google AdMob) and Twelve Data.
- These transfers rely on GDPR safeguards: Google LLC is certified under the EU–US Data Privacy Framework and, failing that, the European Commission’s Standard Contractual Clauses apply.
- DeepL (Germany), the European Central Bank and Frankfurter.dev process data within the European Economic Area. GDELT, CoinGecko and the US Treasury receive no personal data.
- Each provider also applies its own privacy policy to the technical request data it receives.
Third-party services
- Twelve Data provides market prices, security search, histories, fundamentals according to coverage and a server-side WebSocket feed for a limited set of securities. It receives only the requested ticker and exchange, never your identity, email address or portfolio contents.
- SEC EDGAR may provide US-company financial information and receives only a ticker or CIK. AMF / info-financiere.gouv.fr may provide French issuer documents and receives only an ISIN, company name or ticker. Neither service receives your identity, email address or portfolio.
- GDELT and official public company feeds provide financial news. Requests contain only relevant company names or symbols. Yahoo Finance may be used solely as a public fallback source for certain index-price histories; no personal data is sent.
- Google Cloud Translation and DeepL may translate public news text into French. They receive only the public text to translate, never your identity. News is not translated when the app is displayed in English. Public company-profile text may be sent to an automatic translation service; the original and French text are stored as shared financial data.
- CoinGecko may provide cryptocurrency ranking, prices and historical fallback data. The European Central Bank, US Treasury and Frankfurter.dev may provide public rates. No personal data is sent to these sources.
- Google Gemini (Premium AI features): receives the glossary term viewed or, only at your request, the selected portfolio holdings and already-stored statistics of an index composition. This data is used solely to produce the requested report; no open conversation with the model is offered. Portfolio reports and their chart data are then stored locally on your device until you delete them.
- Google AdMob (ad-supported versions, including during the three-day Premium discovery period with ads, but never with an active paid Premium subscription): may receive standard technical identifiers from your device to serve ads. Before any ad request, Google UMP collects or updates your choices where required by law. Refusing does not block the app and may result in non-personalized, limited or technical-only ads where law and recorded choices allow. Choices can be changed under Settings > Privacy where that option is required. No portfolio or account data is sent to it.
- Google Sign-In / Firebase Authentication: manages your sign-in under Google’s privacy policy.
- The Android sharing system receives only the PDF files or CSV backups you explicitly choose to export. Their processing then depends on the recipient app you select.
Retention periods and arrangements
- Active account data is retained while your account exists or until deleted from the app, and as needed to provide synchronization, purchase verification, legal compliance and fraud prevention.
- After Premium ends, additional portfolios and watchlists remain locked for 15 days and are deleted at the end of that period unless Premium is reactivated. The main portfolio and main watchlist are excluded. Assets above the Basic five-asset limit in those two main containers remain saved without an automatic deletion deadline.
- Identity-free financial data may be retained long-term to provide histories, offline operation and last closing prices without unnecessary provider calls.
- Per-stock view counters used for the Top 10 are kept for at most four days; only the current aggregated ranking is shared in the app.
- Verified ETF and ETP descriptions, replicated indices and ISINs may be archived without a predefined limit as a shared reference, unrelated to your account.
- Locally stored AI portfolio reports and quiz results remain available until deleted by the user, cleared with app data or uninstalled.
- Monthly wealth-history snapshots are kept while your account exists.
- Aggregated anonymous usage counters are retained for no more than 31 days.
- Strictly anonymous Firebase accounts with no Premium record may be deleted automatically after 30 days without activity. Google accounts and every account with a Premium record are always excluded from this automatic purge.
Your rights
- Depending on applicable law, you may request access, correction, export, restriction or deletion of personal data associated with your account.
- You can modify or delete individual items directly in the app, or use the web partial-deletion procedure.
- You can request full account deletion from Settings > Delete my account or the web deletion page: access is disabled immediately and the Firebase account and associated active data are permanently deleted after a 30-day grace period. Signing in again during that period cancels the request.
- Deleting the app account does not cancel a Google Play subscription. It must be canceled separately in Google Play to prevent renewal.
- For any other request, contact us at the address below. You may also lodge a complaint with the CNIL (www.cnil.fr) or your country’s data-protection authority.
- United States residents: depending on your state law, you may request to know, correct or delete personal data about you, and we will not treat you differently for exercising those rights. We do not sell your personal data. Serving personalized ads through Google may be considered “sharing” for cross-context behavioral advertising: you can opt out (“Do Not Sell or Share My Personal Information”) from Settings > Privacy, without this blocking the app.
Contact