Privacy Policy
Last updated: September 10, 2026
MarketTrace ("we", "our") operates the MarketTrace web app and the MarketTrace iOS and Android apps (together, the "Service"). This page explains what data we collect, why, and how it's handled.
What the Service does
MarketTrace tracks public posts from public figures' accounts on X, Truth Social, and Bluesky that you choose to add to your watchlist, and pairs each post with a snapshot of market prices around the time it was posted. We do not access your accounts on those platforms, and you do not log in to them through MarketTrace — we only read publicly available posts.
Information we collect
- Account information — email address, display name, a securely hashed password, timezone, and an optional avatar URL.
- Watchlist data — the public accounts and stock/ crypto tickers you choose to track. This describes your interests within the app, not personal information about you.
- Two-factor authentication — if you enable 2FA, a TOTP secret used to verify your authenticator app. We never see or store the codes it generates.
- Push notification tokens — a device token issued by Apple (APNs) or Google (FCM) when you enable notifications, plus the device name and app version, so we can deliver alerts and clean up tokens that stop working.
- Billing identifiers — depending on how you subscribe: a Stripe customer/subscription ID, an Apple transaction ID, a Google Play purchase token, or a crypto checkout reference. We never see or store your card number — that's handled entirely by Stripe, Apple, or Google.
- Security and session logs — sign-in sessions, device labels, and audit events (e.g. login, password change) with an IP address and timestamp, kept to protect your account and investigate abuse.
- Product usage events (web) — on the web app only, we record a small set of product-interaction events (for example, viewing the landing page, starting or completing signup, opening a market reaction, viewing an upgrade prompt, or starting checkout). See "Product analytics" below for details and retention.
How we use it
- To authenticate you and keep your session secure
- To show you the feed and market data for your watchlist
- To deliver push notifications you've opted into
- To process and verify subscription payments
- To detect and respond to abuse or unauthorized access
We do not sell your data, and we do not use it for advertising.
Product analytics
The web app records a small, first-party set of product-interaction events — such as viewing the landing page, starting or completing signup, opening a market reaction, viewing an upgrade prompt, or starting checkout — so we can see which parts of MarketTrace are working and where visitors drop off. This is separate from, and does not replace, the account-level signup and billing records described above.
- Before you sign in, events are tied to a random identifier stored in your browser's local storage, not to your name, email, or IP address. Once you sign up, that browser's earlier events are linked to your new account; events after that point are tied to your account directly.
- We record which acquisition source or campaign referred you (from the page's URL, if present), which page/action triggered an upgrade prompt or checkout, and your plan at the time — never post content, email addresses, URLs you visited, or your ticker/watchlist selections.
- We use no third-party analytics SDK, advertising identifier, fingerprinting technique, or cross-site/cross-app tracking. These events never leave MarketTrace's own servers.
- Events that never get linked to an account are deleted after 180 days. Events linked to your account are deleted when your account is deleted, same as the rest of your account data.
- This collection currently applies to the web app only. If we add equivalent measurement to the iOS or Android apps, we'll update this policy and the apps' store privacy disclosures first.
Who we share it with
Only the processors needed to run the Service:
- Stripe — card payment processing
- Apple — App Store payment processing and push notification delivery (APNs)
- Google — Play Store payment processing and push notification delivery (Firebase Cloud Messaging)
- BTCPay Server — optional cryptocurrency payment processing, self-hosted, no third-party custodian involved
- Cloudflare — network transport (TLS termination / tunnel) for our server; they do not have access to your account data
We do not share data with anyone else, and never for marketing purposes.
Data retention and deletion
We keep your account data for as long as your account is active. To request deletion of your account and associated data, email us at the address below. We'll delete your data within 30 days, except where we're required to keep billing records for tax or legal purposes.
Security
Passwords are salted and hashed, never stored in plain text. Sessions use bearer tokens stored in the iOS Keychain or Android's EncryptedSharedPreferences (Keystore-backed) — never in plain preferences. All traffic to the Service is encrypted with TLS.
Children's privacy
The Service is not directed at children under 13, and we do not knowingly collect data from them.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page.
Contact
Questions or deletion requests: [email protected]