Privacy Policy
BlueGuardian:TrendScope
This policy explains how this application handles information and how to contact us about privacy.
Information we process
BlueGuardian:TrendScope stores the virtual portfolio, manually entered asset prices and candlestick data, trading scenarios, risk limits, and preferences on your iPhone. The app is a simulation and does not connect to an exchange or handle real trades. If you enable synchronization, the app encrypts portfolio and scenario snapshots before sending them to our server over the network. It creates a random installation secret in the iOS Keychain; the server receives that secret to authorize requests, stores only its SHA-256 hash, and stores the encrypted snapshots. We do not ask for an account, name, or email address. Railway, our hosting provider, receives network requests and may process technical information such as IP addresses, request times, and service logs.
How we use information
The app uses local information to calculate simulated balances, profit and loss, scenario comparisons, and risk warnings. If synchronization is used, the server stores the latest portfolio and scenario snapshots so the same installation can retrieve them while its secret remains available. The installation secret restricts access to those snapshots and authorizes deletion. Hosting infrastructure processes technical request information to deliver and operate the service. We do not use the app for advertising, analytics, account creation, or email delivery.
Service providers and sharing
Railway hosts the API and its attached persistent storage and may process the network and infrastructure information needed to operate them. We do not send portfolio or scenario data to advertising networks, analytics providers, or exchanges. Exporting a scenario to PDF creates a local file; if you choose a destination in the iOS Share Sheet, that destination handles the file under its own practices. We do not operate an outbound email or support form in the app.
Data retention
Local portfolio data, scenarios, candlestick data, risk settings, and preferences remain on your device until you remove them in the app or remove the app, subject to iOS storage behavior. The server keeps an active installation record and its latest encrypted snapshots until an authenticated deletion request removes that installation or the service is retired. This application does not create a separate backup of personal sync records. Railway may retain infrastructure logs or storage copies under its own operational practices; we do not claim a fixed retention period for them, and deletion of active records may not immediately remove residual infrastructure copies.
Deleting your information
You can clear local portfolio and scenario data in the app. When synchronization has been used and the installation secret is available, the app clears local data immediately and sends an authenticated deletion request that removes its server snapshots and revokes that installation secret. If the service is unavailable, the app retains a pending deletion state and retries when it next starts; server data may remain until that request succeeds. Removing the app may remove local data but does not necessarily send a server deletion request; use the in-app deletion control first if you want the active server record removed. If the secret is lost, there is no account identifier with which to identify or recover that record. For privacy questions or assistance, contact Dunmore2002@icloud.com. Residual infrastructure copies may remain under the hosting provider's normal processes.
Permissions and your choices
The portfolio, charts, scenarios, and risk calculations work without notification permission and can work offline. The app may request notification permission if you choose local risk or drawdown alerts; you can change this permission in iOS Settings. Network access is used for optional synchronization and the public privacy page. PDF export uses the standard iOS Share Sheet only when you choose to share a file. The app does not request location or contacts access for its core functions.
Your privacy rights
You can view and change local portfolio entries, scenarios, risk limits, and preferences in the app. You can clear local data and request deletion of the active server installation record while its secret is available. For questions about access, correction, deletion, or this policy, contact Dunmore2002@icloud.com. Because there is no account or identity record, we cannot restore synchronized data or identify a server installation after its secret is lost.
Security
The deployed API uses HTTPS. Each installation has a random secret held in the iOS Keychain and sent only in the authorization header for private requests. The app encrypts snapshots before upload. The server stores a SHA-256 hash of the secret to check authorization, and encrypts the received snapshots again before writing them to persistent SQLite storage using a key derived from that installation secret. Deleting the installation removes its active encrypted snapshots and hash. These measures reduce risk but cannot guarantee absolute security; avoid entering information that is unnecessary for a virtual trading simulation.
Children’s privacy
BlueGuardian:TrendScope is intended for adults practicing virtual portfolio and risk analysis and is not directed to children. It does not ask for a child's name, account, or documents. If you believe information about a child has been sent to the service, contact Dunmore2002@icloud.com so we can discuss the available deletion options.
Changes to this policy
We may update this policy if the app, synchronization service, or hosting practices change. The current version and effective date will be published on this page. Review the policy when an app update changes how your information is handled; privacy questions can be sent to Dunmore2002@icloud.com.