Privacy Policy
Last updated: September 3, 2026
Overview
Wagyu ("the App") is a portfolio tracking application for iOS and Android. We are committed to protecting your privacy. This policy explains what data the App handles, how it is processed, and your rights.
The short version: your credentials stay on your device. Banking PINs and exchange API keys are never uploaded. Your portfolio data is synced to our cloud backend only to enable cross-device sync and automatic background refresh — and is never sold, shared, or used for advertising.
Credentials That Never Leave Your Device
The following sensitive data is stored exclusively in your device's secure keychain and is never transmitted to any server operated by us:
- Banking credentials (login and PIN) used for FinTS connections
- Read-only API keys for connected exchanges (e.g. Kraken, Coinbase)
We have no technical means to access this data.
Banking Connections (FinTS)
When you connect to a bank via FinTS, the connection is established directly between your device and your bank's server. No banking data passes through any intermediary server. Your banking credentials are stored in your device's keychain and are never transmitted to us.
Exchange Connections
When you connect an exchange account (e.g. Kraken or Coinbase), you provide a read-only API key that cannot trade or move funds. Balance requests are made directly from your device to the exchange. The API key is stored in your device's keychain and is never transmitted to us. Only the resulting balances become part of your synced portfolio data (see below).
Account, Cross-Device Sync and Background Refresh
The App uses Firebase Authentication to create an account. Your account is identified by your email address or third-party sign-in provider (Google, Apple). We store only the minimum data required for authentication — no personal profile is built from this data.
To enable cross-device sync and automatic background updates, the following data is stored in Google Firebase (Firestore), associated with your account:
- Your portfolio holdings (asset names, quantities, purchase prices)
- Public wallet and staking addresses you add
- App settings (display currency, connected wallet list)
- A push notification token for your device
Data is transmitted and stored encrypted (TLS in transit, encryption at rest by Google). Access is restricted to your authenticated account. Our backend periodically refreshes the balances of your public wallet and staking addresses so your portfolio stays up to date; for this purpose those addresses are sent to public blockchain data providers (see "Market Data"). Deleting holdings, wallets, or your account in the App removes the corresponding data from our backend.
Market Data
The App (and, for wallet balances, our backend) fetches publicly available market and blockchain data from third-party providers such as CoinGecko, Yahoo Finance, Blockscout, publicnode.com, mempool.space, Everstake and OpenFIGI. These requests may include:
- Asset identifiers (ticker symbols, coin IDs, ISINs)
- Public wallet or staking addresses (for balance lookups)
- The requesting IP address (as part of standard network requests)
These requests never include your name, email address, banking data, or API keys. Public blockchain addresses are, by nature, public information.
Analytics and Crash Reporting
The App uses Firebase Analytics, a service provided by Google LLC, to collect anonymous usage data such as screen views and app engagement metrics. This data helps us understand how the App is used and improve the experience. Firebase Analytics may collect:
- Screen views and navigation patterns
- App open/close events and session duration
- Device type, operating system version, and app version
- Country/region (derived from IP address, which is not stored)
This data is aggregated and does not include your portfolio holdings, financial data, or personal information. Firebase Analytics is subject to Google's Privacy Policy.
The App may also use the operating system's built-in crash reporting frameworks. On iOS you can opt out under Privacy & Security > Analytics & Improvements; on Android under Google settings > Usage & diagnostics.
Data We Do Not Collect
- We never receive your banking credentials or exchange API keys
- We do not use advertising or ad-tracking SDKs
- We do not sell, share, or transfer your data to third parties for their own purposes
Your Rights (GDPR)
If you are located in the EU/EEA, you have the right to access, rectify, delete, and export your personal data, and to object to or restrict its processing (Art. 15–21 GDPR). You can delete your portfolio data and account directly in the App; for any other request, contact us at the address below. You also have the right to lodge a complaint with a data protection supervisory authority.
Data controller: Stefan Pledl (see Imprint). Processing is based on Art. 6(1)(b) GDPR (providing the service you request) and Art. 6(1)(f) GDPR (app analytics and service improvement). Data is hosted on Google Firebase (region: Europe, where configured); Google LLC processes data under standard contractual clauses.
Children's Privacy
The App is not directed at children under 13. We do not knowingly collect any personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated date. Continued use of the App after changes constitutes acceptance of the revised policy.
Contact
If you have questions about this Privacy Policy, contact us at hello@wagyu.app.