Privacy Policy
Last updated 20 August 2026 · Effective 20 August 2026
The short version. You can use StonkWatcher without an account, and if you do, your watchlist never leaves your phone — there is no record of you on our side to delete, because none was ever created.
If you sign in, we store your email, your watchlist and your alert settings, because a server cannot send you an alert about a company it does not know you follow. We never sell data, we show no advertising, and we do not ask for your advertising identifier. Usage analytics are off unless you switch them on.
1. Who is responsible for your data
StonkWatcher is published by Dominykas Linkus, an individual trader operating as SecurityTavern, based in Vilnius, Lithuania. For the purposes of the EU General Data Protection Regulation (GDPR), that is the data controller for the personal data described here.
Contact for any privacy question or request: info@securitytavern.com.
We are not required to appoint a Data Protection Officer, and have not appointed one. Requests go to the address above and are answered by a person.
2. Using the app without an account
The free tier requires no account and no sign-in. If you use the app this way:
- Your watchlist is stored only in the app's local database on your device.
- No account, profile or identifier is created for you on our servers.
- Uninstalling the app removes that data. There is nothing for us to delete, because we never received it.
The app downloads insider-filing data as static files from Cloudflare R2. As with any request to any web server, Cloudflare's access logs record an IP address and browser-style user agent. These requests do not identify you and do not reveal which companies you follow: the app downloads the general feed and filters it on your device.
3. What we collect if you sign in
Signing in with Google is optional. It exists so that your watchlist follows you between devices and so that alerts can be delivered to you. If you sign in, we process:
| Data | Why | Legal basis |
|---|---|---|
| Email address and a user ID | To identify your account across devices | Performance of a contract |
| Your watchlist and alert rules | The server has to know what to watch in order to alert you | Performance of a contract |
| Push notification token for your device | The address a notification is delivered to | Performance of a contract |
| Record of alerts sent to you | To show your alert history and to avoid sending the same alert twice | Performance of a contract |
| Subscription status and Google Play order identifiers | To give you the tier you paid for, and for accounting | Contract, and legal obligation for records |
We do not receive your Google password, and we never see your card or other payment details — payment is handled entirely by Google Play.
4. Crash reports
The app uses Firebase Crashlytics to report crashes. A crash report contains a stack trace, your device model, Android version, app version and the time of the crash. It does not contain your email address, your user ID or your watchlist.
This is on by default, on the basis of our legitimate interest in the app working — a crash on a device we do not own is otherwise invisible and unfixable. You can turn it off at any time in Settings → Privacy → Send crash reports, and the change takes effect immediately rather than at the next launch.
5. Usage analytics
The app can report anonymous usage statistics through Firebase Analytics — which screens are opened and which features are used. This tells us what to improve.
This is off unless you turn it on. We ask once, on first launch, with the box unticked, and analytics collection stays disabled until you tick it. You can change your mind either way in Settings → Privacy → Share anonymous usage data. The legal basis is your consent, and you may withdraw it at any time without giving a reason and without affecting anything else in the app.
We do not use your advertising identifier. The app removes the Android
AD_ID permission entirely, refuses ad personalisation signals,
shows no advertising and takes part in no advertising network.
Analytics never includes your watchlist. What you follow is not sent to an analytics service.
6. These web pages
This website is plain HTML. It sets no cookies, runs no JavaScript, loads no fonts or scripts from third parties, and has no analytics of any kind. Firebase Hosting, which serves these pages, keeps standard web server request logs.
7. Who else processes your data
We use a small number of service providers, each acting on our instructions:
| Provider | What it handles | Where |
|---|---|---|
| Supabase | Account, watchlist, alert rules, device tokens | European Union (Ireland) |
| Google Firebase | Push delivery, crash reports, analytics if enabled, anti-abuse checks | Google infrastructure, including the United States |
| Google Play | Payments and subscription status | |
| Cloudflare R2 | Serving public filing data files | Global edge network |
Your account data is held in the EU. Transfers to Google outside the EEA rely on the European Commission's Standard Contractual Clauses, which form part of Google's terms with us.
We do not sell personal data, and we do not share it with anyone for their own marketing.
8. How long we keep it
- Account, watchlist and alert rules — until you delete your account, plus a short period for backups to cycle out.
- Alert history — rolling, and removed with the account.
- Push tokens — deleted when you sign out, or automatically once Google reports the token is no longer valid, for example after you uninstall.
- Crash reports — retained by Firebase Crashlytics for up to 90 days.
- Analytics — retained for up to 14 months, and only exists at all if you opted in.
- Purchase records — kept for as long as tax and accounting law requires, which in Lithuania is up to 10 years. These are kept even after account deletion, because we are obliged to keep them.
9. Your rights
Under the GDPR you have the right to: get a copy of your data; correct it; have it deleted; restrict or object to how we use it; receive it in a portable format; and withdraw consent you previously gave. Exercising any of these costs nothing, and we will not treat you differently for it.
Write to info@securitytavern.com or use the deletion page. We answer within 30 days. We may ask you to confirm the request from the email address on the account, so that we do not act on someone else's instructions about your data.
If you are unhappy with how we handle it, you can complain to your national data protection authority. In Lithuania that is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt.
10. Children
StonkWatcher is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, write to us and we will delete it.
11. Security
All traffic between the app and our servers is encrypted in transit. Access to the production database is limited to the operator of the service. Firebase App Check is used to reject requests that do not come from a genuine copy of the app.
No system is perfectly secure. If a breach affects your rights, we will notify the supervisory authority and, where required, you.
12. Changes
If this policy changes we will update the date at the top, and if the change is significant we will tell you in the app before it takes effect.
13. Contact
Dominykas Linkus, trading as SecurityTavern
Vilnius, Lithuania
info@securitytavern.com