Privacy Policy
What SigniBull collects, why, who can see it, and how to get rid of it. Written from the actual database and application code rather than from a template.
The short version
- We collect what you give us to run an account, and what you create in the app. We do not buy data about you, and we do not sell data about you.
- There is no advertising and no tracking anywhere — no advertising identifier, no ad pixels, no third-party trackers, no cookies that follow you, and no Google Analytics, on the website or in the apps. What we do measure is how many people opened which page, and how fast the page was for them, using two Vercel features. They put nothing on your device — no cookie, nothing stored — and they are loaded from our own address rather than from an advertising domain. They record the page, where you came from, your device, operating system and browser, and your approximate location: Vercel places this to the city, not just the country. To tell one visitor from another they use a code worked out from the request itself, which is thrown away after 24 hours, so today's visit can never be joined to tomorrow's. Nothing you do inside the app — the screen you are on, the symbol you look at, the profile you open — reaches them at all, because that part of the address never leaves your browser.
- Your data is stored in the European Union (Ireland).
- Private messages are readable by you and the person you sent them to. Not by administrators.
- You can delete your account from inside the app, and it takes your data with it.
- No real money and no real securities are involved anywhere in SigniBull. Every position is a record.
1. What we collect
What you give us
- To open an account: an email address, a password, your first and last name, a handle and a display name. The password is never stored — the authentication service keeps a one-way hash of it, and we cannot read it or recover it.
- Your profile, if you fill it in: a short bio, a profile picture and a banner image, where you are, since when you have been trading, and links. All of it is optional. The two pictures are served from a public address, so anyone who has the link can load them, signed in or not; the rest is visible to signed-in members.
- What you answer when you join: which of three reasons brought you here, how experienced you are, and whether you want email tips. Used to choose what the app shows you first, and nothing else.
- What you record: the companies you hold or watch, how many shares, at what price and on what date, and any orders you place. This is the substance of the product.
- What you write: posts, replies, direct messages, price alerts, support messages and feedback.
- Who you block, and what you report. Blocking records that you blocked that account and when. Reporting records what you reported, the reason you chose, anything you wrote in the box, and a copy of the content as it was at that moment — kept deliberately, because acting on a report usually means the content is deleted, and a record that erases itself then is not a record.
- What you choose: which screens you want, light or dark, which chart indicators you like, the dashboards you build, and the drawings you make on a chart.
- If you ask for alerts to reach you outside the app: the email address or phone number you type for that. Nothing is sent to it unless you switch it on, and you can clear it at any time.
- When you invite somebody: for a friend invitation we keep a one-way hash of their address and its domain — not the address itself — so the same person is never invited twice and one account cannot send hundreds. For a channel invitation we keep the address until the invitation is accepted, withdrawn or expires, because the invitation is what carries it.
What the system records by itself
- An activity log of what the app did — an event name, an area, a duration and, where the event belongs to a member, that member's identifier. It does not store IP addresses.
- The date you last signed in, so we can tell an active account from a dormant one.
- A count of how much market data you requested per day, so one account cannot exhaust an allowance everybody shares. It is a number, not a history of what you looked at.
- Which company you picked from the search box, what you typed to find it, and when. This is the one record that says what you were interested in, so it is worth being precise: it is written only when you choose a result, not as you type; no member can read it, not even you; administrators can, to see which companies members are looking for; and it is deleted with your account.
What the website keeps in your browser
The website uses the browser's local storage and no cookies. It holds your sign-in, your preferences, cached market data, and a copy of your own trades, drawings and dashboards so a page opens filled in rather than empty. None of it is readable by another website. Clearing it signs you out and deletes nothing from your account.
What the apps keep on your own device
The iOS and Android apps store two things locally, and neither leaves the device:
- Your session, in the operating system's own secure storage — the iOS Keychain and the Android Keystore. Signing out removes it and also tells our server to end the session.
- A copy of what the app last showed you — your holdings and watchlists, the last prices, and the last news it fetched — in the app's private cache, so the app opens with something on screen instead of a blank one. It is cleared when you sign out, and it is removed with the app.
What we do not collect
No advertising identifier. We never ask your device where it is. No contacts, camera, microphone or files — a picture you choose for your profile is the one exception, and only the picture leaves the device. No device fingerprinting. No cross-app or cross-site tracking of any kind — so the apps never ask for tracking permission, because there is nothing to ask about.
2. Why we process it
To run the account you asked for and to provide the features you use — the portfolio, the charts, the leaderboard, the community, the alerts. Where the law requires a basis for processing (the GDPR and UK GDPR), ours is the performance of our agreement with you for everything in section 1, and our legitimate interest in keeping the service working and secure for the activity log and the request counters.
We do not use your data to make automated decisions that have a legal or similarly significant effect on you.
3. Who can see what
- Only you, by default: your holdings, your watchlists, your orders, your alerts and your email address.
- You choose whether your portfolio and your profile are public. If you make them public, other members see your positions and your results. That choice is yours and is reversible.
- Everyone signed in can see what you post in a public channel, your handle, your display name, what you put on your profile, and the name and description of a dashboard you choose to share.
- Anyone with the link can load your profile picture and banner, because they are served from a public address. Choose them with that in mind.
- Only you and the recipient can read a direct message. Administrators cannot.
- Only you can see who you have blocked. Not the people on that list, and not anyone else — a block that could be discovered would announce itself, which is the thing a block must not do.
- Only administrators can read reports. They are anonymous: the reported member is never told who reported them, and no member — including the one who filed it — can read a report back through the app, because being able to would be the beginning of a way to work out who filed it.
- The leaderboard ranks verified performance. Only members who have made their portfolio public appear on it.
4. Who we share it with
We do not sell data and we do not share it for anyone else's marketing. The companies below process data on our behalf so that the service can work at all:
- Supabase — the database and the authentication service. Your data lives here, in the European Union (Ireland).
- Vercel — hosting for the website and the small server functions the apps talk to, and the two measurement features described above. Both are served from our own address, so neither is a third-party request from your browser, and neither stores anything on your device.
- Market data providers — we ask them for prices, company information, earnings dates and news. They receive a stock symbol. They do not receive your identity, your holdings, or how much of anything you own.
- Expo — delivers app updates to the iOS and Android apps.
- An email provider — sends account emails such as confirmation and password reset, and receives the address it is sending to.
- Google (Gemini) — when you ask for an AI summary. See the next section.
5. The AI summaries, precisely
Where the app offers a written summary of a chart or of the market, the text is generated by a language model. What we send it is deliberately narrow: stock symbols and percentages. It never receives your name, your email, your share counts, or any amount of money. We do not use your data to train anybody's model.
6. Where your data is
The database is in Ireland. Some of the processors above operate globally, so data may be handled outside the European Economic Area. Where that happens we rely on the transfer mechanisms those providers offer, including the European Commission's Standard Contractual Clauses.
7. How long we keep it
- Your account and what you created: until you delete it.
- The activity log: 72 hours, then it is erased automatically.
- Your search picks: while your account exists. They are not rotated, because their use is seeing how interest moves over months.
- Reports: kept after they are dealt with, so a pattern of behaviour across months is still visible. A moderation record that expired would mean somebody could repeat the same thing indefinitely by spacing it out.
- Blocks: until you undo them, or until either account is deleted.
- The trade log: for as long as your account exists. It is append-only on purpose — a record that can be edited is not a record — and it goes when the account goes.
- Backups: a rolling window, after which deleted data ages out of them too.
8. How we protect it
- Everything travels over HTTPS. The apps refuse to send anything over an unencrypted connection.
- The database enforces, row by row, that you can only read and write your own data. That is not a rule in the app — it is a rule in the database, so an app that asked for somebody else's row would be refused by the server.
- Passwords are hashed by the authentication service and are never visible to us.
- Your verified positions are written only by our server, never by the app or the browser — which is what makes the word "verified" mean something.
9. Your rights
Depending on where you live, you have the right to see the data we hold about you, to correct it, to delete it, to receive a copy of it, to object to some processing, and to complain to a supervisory authority.
Deleting your account does most of this immediately and without asking anyone. It is in Settings, in the apps and on the website, and it removes your profile, your holdings, your watchlists, your orders, your alerts and your private messages.
One thing is kept, without your name on it. What you wrote in a shared space — a post in a channel, a reply under one, a reply on the feed — stays where it is, and your name comes off it. Not replaced with "deleted", not moved to some placeholder account: the author is detached, so nothing on it points back at you. We do it this way because deleting a reply out of a conversation other people are still having takes their conversation away too, and you cannot make that choice for them. Anything that is a record of you rather than a conversation with you — a like, a reaction, a poll vote, whether you had read something — goes with the rest.
For anything else, write to privacy@signibull.com and we will reply within 21 days, and acknowledge within five business days.
10. Children
SigniBull is not intended for children. You must be at least 18 to hold an account. We do not knowingly collect data from children; if you believe a child has an account, write to us and we will remove it.
11. If something goes wrong
If a breach affects your data and is likely to put you at risk, we will tell you and the relevant authority, and we will say what happened rather than what we would prefer to have happened.
12. Changes to this policy
If we change what we collect or what we do with it, we will update this page and change the date at the top. Material changes will also be announced in the app.
7 September 2026, later the same day. Deleting your account now leaves what you wrote in shared channels in place with your name taken off it, instead of deleting it out of conversations other people are still in. Nothing else about deletion changed, and section 9 says exactly what stays and what goes. The section saying who is responsible for your data also moved from the top of the page to the end (section 13), so the page opens with what is collected and why, and it now names the controller — a person, with an address — as the law requires. The other sections moved up one number.
7 September 2026. This page was checked line by line against the database again, and it was under-saying what we hold. Added: your first and last name and the optional profile fields, the fact that profile pictures are served publicly, the answers you give when you join, the record of which companies you pick from the search box, what an invitation stores, the contact details for alerts, and what the website keeps in your browser. The activity log's retention is now stated as the 72 hours it actually is. Nothing new is being collected — the page now says all of what already was.
2 September 2026. Reporting and blocking were added, so this page now says what each of them records, who can see it, and how long it is kept. Nothing else about what we collect changed.
13. Who is responsible for your data
The controller — the person answerable for everything on this page — is Guy Rubinger, operating as SigniBull, from Israel, of Maccabi 8, Ra'anana, Israel.
A person and not a company, because there is no registered company yet: "SigniBull" is a trading name, and a trading name cannot be responsible for anything. The law asks for the identity of whoever is, and the identity of a service run by one person is that person. When a company is registered, this section changes and section 12 records it.
For anything in this policy write to privacy@signibull.com. Everything else about the service, the Terms included, goes to admin@signibull.com — the two are split so that a request about your data lands in a mailbox that is watched for exactly that.
Contact us
For anything on this page — a question, a request to see or correct or delete what we hold, a complaint, or a concern about how your data has been handled — write to privacy@signibull.com.
That address reaches a person, not a queue. We acknowledge within five business days and answer within 21 days — the shortest period any law that applies to us allows, and the one we hold ourselves to for everybody, wherever you live.