Legal
Privacy Policy
This policy explains how Chart-echo collects, uses, stores, and protects personal data when you use the website, the iOS or Android mobile app, and related services.
Data We Collect
Account data: email address, username, password hash, profile details you choose to provide, authentication events, and account settings.
Product data: saved charts, saved fractals, collections, shared views, feedback, search settings, and chart workspace preferences.
Subscription data: subscription status, plan, billing period, and billing-provider identifiers. On the web, payments are processed by Stripe; mobile subscriptions are processed by Google Play or Apple. Full card details are handled by the payment provider and are not stored by Chart-echo.
Mobile app data: when you enable pattern alerts, we store a device push notification token (provided by Expo and the platform notification service) so we can deliver alerts to your device. You can turn this off in your device notification settings.
Mobile analytics data: Google Analytics for Firebase assigns a pseudonymous app-instance identifier and measures first opens, app lifecycle events, feature interactions, and purchase events. It may derive coarse location from a masked IP address. We do not attach your Chart Echo account identifier to Firebase Analytics events.
Technical data: server logs, device/browser details, approximate location derived from IP address, security events, and diagnostics needed to keep the service reliable.
Local storage data: authentication tokens, stored user information, and preferences are kept on your device - in your browser on the web, and in the operating system’s secure storage and local app storage in the mobile apps - so the app can keep you signed in and remember your settings.
How We Use Data
To provide accounts, authentication, subscriptions, saved workspaces, chart sharing, feedback, support, security, fraud prevention, and service maintenance.
To process payments and manage subscriptions through Stripe (web), Google Play (Android), or Apple (iOS).
To deliver pattern alerts and account notices as push notifications to your device when you enable them.
To measure mobile app installs and understand how pseudonymous users interact with core features and subscriptions.
To improve reliability, troubleshoot bugs, protect the service, and understand whether core product features are working.
To send service messages such as password reset emails, account notices, subscription notices, and important product or legal updates.
Legal Bases
Contract: to provide the account, subscription, saved chart, and charting services you request.
Legitimate interests: to secure the service, prevent abuse, maintain reliability, respond to feedback, and improve core product functionality.
Legal obligation: to keep records required for tax, accounting, dispute, or regulatory reasons.
Consent: for optional marketing, advertising, analytics where required, or non-essential storage.
Sharing And Processors
Data may be processed by hosting, database, email, payment, error-monitoring, and support providers needed to operate the service.
Stripe processes payments and may independently set cookies or collect payment data on Stripe-hosted checkout and billing pages.
Google Play and Apple process mobile subscription purchases under their terms. Expo and the platform notification services process device push tokens to deliver notifications you have enabled.
Google Analytics for Firebase processes pseudonymous mobile app analytics and conversion-measurement data. On iOS, install attribution uses Apple SKAdNetwork and Google modelled measurement without requesting the IDFA, and events default to ineligible for personalised advertising.
With your consent, advertising and analytics partners (Google and Meta) receive limited information through their tags or pixels to measure advertising performance and conversions. These load only after you accept marketing cookies and can be turned off via "Cookie settings".
Public shared chart links may be visible to anyone with the link and may generate preview metadata for social platforms.
Retention And Deletion
Account and workspace data is kept while your account is active or as needed to provide the service.
You can delete your account from account settings. Some records may be retained where required for legal, tax, security, backup, or dispute-resolution purposes.
Password reset tokens and session records are time-limited or invalidated when no longer needed.
Your Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data.
You may also have rights to opt out of sale, sharing, or targeted advertising. Chart-echo uses advertising and analytics tools (Google Ads and the Meta Pixel) that are loaded only after you consent through our cookie banner; you can withdraw consent at any time via "Cookie settings" in the footer.
Use the in-product feedback or support channel to make a privacy request. You may also complain to your local data protection authority.
Security
Chart-echo uses authentication, hashed passwords, access controls, and operational safeguards to protect data.
No online service is perfectly secure. Keep your password private and use a unique password for this account.
Children
Chart-echo is not intended for children. Do not use the service if you are under the age required to create an online account in your country.