Bond Tracker

Privacy policy

Local tracking does not require an account. Cloud storage and subscriptions involve the services described below. Cloud encryption is optional and has specific recovery limits.

Last updated:

On this page
  1. 1. Who is responsible
  2. 2. Data on your device
  3. 3. Accounts and cloud portfolios
  4. 4. Optional encryption and recovery
  5. 5. PRO and RevenueCat
  6. 6. Other services and the website
  7. 7. Purposes and legal grounds
  8. 8. Retention and deletion
  9. 9. Your choices and rights
  10. 10. Security, children, and changes

1. Who is responsible

Bond Tracker is operated by Artem Oleksandrovych Lymanskyi, a sole proprietor registered in Ukraine. This policy covers the Bond Tracker app and this website. For privacy questions or requests, contact .

2. Data on your device

The app stores portfolio names, currencies, goals, bond definitions, prices, purchases, sales, fees, cash operations, coupon and redemption payments, and calculation inputs in a local database. It also stores settings, cached market data, sync metadata, and local recovery copies.

We do not receive your local portfolio contents merely because you use the app, create a cloud account, or buy PRO. Uploading requires explicitly linking a portfolio to your account. Automatic sync is initially off and applies to portfolios already linked.

Signing out or losing PRO does not erase local portfolios. Removing the app or clearing its storage may remove local records. Operating-system backup and secure-storage behavior depends on your device and settings.

3. Accounts and cloud portfolios

Supabase provides account authentication and cloud database services. When you create or use an account, it processes your email address, password authentication, account identifier, session credentials, and technical connection information such as IP address and request logs. Passwords are handled by Supabase Auth; the app operator does not receive your password through a support request.

When you link and synchronize a portfolio, Supabase receives its current snapshot: portfolio settings and goals, financial records, relevant custom bond definitions and schedules, transaction exchange rates, portfolio identifiers, revisions, timestamps, and deletion markers. The backend also stores subscription-access status and cloud encryption settings. Unused custom catalogue bonds and device display preferences are not included in portfolio sync.

These records support sign-in, recovery, cross-device synchronization, conflict checking, access verification, and deletion. Authorized administrators can access readable cloud records when optional encryption is off. Account access rules separate users’ cloud data; this is not the same as encryption that prevents administrator access.

4. Optional encryption and recovery

Cloud encryption is off by default. If enabled, the app encrypts portfolio contents on the device before upload using AES-256-GCM. Names, financial records, goals, and included bond information are inside the encrypted payload. Account and portfolio identifiers, revisions, timestamps, key identifiers, deletion markers, and subscription and authentication information remain readable.

Plaintext portfolio-encryption keys and recovery codes are not sent to Supabase or RevenueCat. The cloud holds an encrypted key wrapper. Unlocked devices retain a data key in native secure storage. This feature does not encrypt the local portfolio database, local recovery copies, or authentication/session storage.

If you lose both your recovery code and every unlocked device, support and a password reset cannot recover the encrypted cloud contents. A recovery QR image contains the recovery code, not a portfolio backup. Anyone with that code and the corresponding encrypted data can decrypt it.

Turning encryption off converts current cloud portfolios to readable data. Enabling encryption cannot retroactively encrypt earlier exports, logs, or provider backups. Changing a recovery code does not change the code needed for an older encrypted backup file or revoke keys already held by another device.

5. PRO and RevenueCat

Google Play, or another supported app store where the app is available, handles purchase payment details. Bond Tracker uses RevenueCat to validate purchases and determine PRO access. RevenueCat receives your app account identifier, purchase history, product and transaction identifiers or purchase tokens, renewal and expiration status, and technical SDK information needed to provide its service.

The app uses the Supabase account identifier to associate PRO with your account. It does not send portfolio contents, encryption keys, or recovery codes to RevenueCat, and does not set your email or name as RevenueCat customer attributes. We do not receive full payment-card details from the store. RevenueCat purchase reporting may include subscription analytics; the app does not use advertising attribution integrations.

6. Other services and the website

  • National Bank of Ukraine (NBU): the app requests public bond catalogue data and exchange rates. Requests can reveal an IP address and requested dates or currencies; they do not upload your portfolio snapshot.
  • Email delivery: the configured email provider processes account confirmation and password-recovery emails. Your own email provider and ours process messages you send to support.
  • Cloudflare: hosts this website and processes connection and security information such as IP address, requested URL, and browser information. These pages do not include advertising trackers, third-party font requests, or website analytics scripts. Hosting security features may process additional technical data.
  • Camera and files: camera access is requested for recovery-code scanning. QR processing occurs on the device. Files are selected or saved through system pickers; the app does not upload your recovery QR image to its cloud.

Service-provider processing can take place outside Ukraine, including in countries where their infrastructure and subprocessors operate. We use providers for the functions described here, subject to their applicable service and data-processing terms. We do not sell your portfolio data or use it to target advertising.

Provider information: Supabase, RevenueCat, Cloudflare, and Google.

7. Purposes and legal grounds

We process account, cloud, and purchase information to provide features you request and administer your subscription. We process limited technical and support information to secure the service, diagnose failures, verify ownership, and answer requests. Where applicable law requires it, processing also relies on consent, legitimate interests in operating a secure service, or legal obligations. Choosing a cloud feature does not authorize unrelated advertising use.

We may disclose information when required by law or to address fraud or security incidents. Any disclosure is limited to what is necessary for that purpose.

8. Retention and deletion

Local data remains under your control until removed from the device. Exported files remain wherever you saved or shared them. Active cloud account records and snapshots are retained while the account exists or until you delete the relevant cloud data. Subscription expiry alone does not delete stored cloud portfolios; you can recover existing cloud copies or request deletion without PRO.

The cloud stores the current portfolio snapshot, not a user-accessible version archive. A deleted linked portfolio may leave a deletion marker until the account’s cloud data or account is deleted, so other devices can detect the deletion. Local recovery copies are stored on the device.

Deleting cloud data removes active cloud portfolios and encryption settings but keeps the sign-in account. Deleting the account also removes the Supabase sign-in account and associated app database rows. Neither action remotely erases local copies, exported files, or store transaction records.

Technical logs and any provider backups follow the retention configured for those services and may remain after active data is removed, until expiration. Support correspondence is kept while resolving a request and for as long as necessary to document its resolution, address disputes, or meet legal obligations. Store transaction records may have separate statutory retention requirements.

RevenueCat customer records are not automatically removed by the app’s Supabase account-deletion action. Contact support to request removal of those associated records. A verified web deletion request includes handling applicable RevenueCat customer data. Store billing and subscription cancellation remain separate.

9. Your choices and rights

You can use local tracking without an account, leave cloud sync disabled, choose whether to link portfolios, stop automatic sync, export backups, and request cloud-data or account deletion. See account deletion for a request route that works without reinstalling the app.

Depending on applicable law, you may request access to, correction, deletion, restriction, or portability of your personal data, object to certain processing, or withdraw consent where processing relies on consent. Contact from your account email when possible. We may verify ownership, but will not ask for your password or encryption recovery code. We aim to respond within 30 days, subject to applicable legal deadlines and permitted extensions. You may also complain to the competent data-protection authority.

The operator cannot provide readable contents of an encrypted portfolio without your key. Encryption does not prevent deleting that portfolio or processing requests concerning readable account metadata.

10. Security, children, and changes

Network connections to account and purchase services use HTTPS. Access controls and native secure storage protect relevant records and keys, but no device, hosting service, or encryption scheme eliminates every risk. Keep your device, account, exported backups, and recovery codes secure.

Bond Tracker is intended for adults managing their own investment records and is not directed to children under 18. Contact support if you believe a child has provided account data.

We may update this policy when features, providers, or legal requirements change. The date above identifies this version. Material changes affecting your use will be communicated through the app or another appropriate channel.