Privacy policy

Most of what ChartPeak knows about you stays on your phone. This page says exactly what that means, what reaches our servers, and which services we use to run the app.

Last updated 19 September 2026

The short version

  • On your phone: your journal, your saved reads and their images, your setup answers, your Academy progress. None of it syncs and we have no copy.
  • On our servers: your account (a name, the email you signed in with, or your Google or Apple identity), a record of whether your subscription is active, a daily scan counter, and any bug report you choose to send.
  • Sent to service providers: the chart image you ask to have read goes to Google’s Gemini API for the analysis. Your purchase goes through RevenueCat, which checks your subscription with Apple or Google. Bug reports reach us through a notification service. The full list is under who we share data with.
  • Never: tracking across apps or sites, advertising identifiers, selling or sharing personal information, analytics SDKs.

Who we are

ChartPeak operates the ChartPeak app and the website at https://chartpeak.app. When this policy says “we”, it means ChartPeak. To reach us about anything on this page, use the Report a bug option in the app’s Profile tab, or the support link on the App Store listing.

What stays on your device

  • Every trade you log, including entries, exits, sizes, fees and notes.
  • Every read you save, and the chart image attached to it.
  • The answers you gave during setup, and your appearance preference.
  • Your Academy progress and quiz results.
  • Your sign-in session, held in the iOS keychain (or the Android equivalent) rather than in the app database.

None of this is transmitted to us. We do not operate a sync service, so we cannot read it, restore it, or hand it to anyone else. Deleting the app deletes all of it.

What we hold on our servers

Your account

You create an account after subscribing, with an email address and password, with Google, or with Apple. Our authentication provider (Supabase, hosted in the United States) stores the identity you signed in with. Alongside it we keep a profile row holding the name you entered and the date the account was completed. We do not store your password; the provider stores a one-way hash of it. If you sign in with Google or Apple, we receive the identity token and the name and email those services release to us, and nothing else from those accounts. Like most sign-in services, our authentication provider also records the IP address and time of each sign-in, for security.

Your subscription

So that chart reads can be limited to subscribers, we keep one record per account saying whether a subscription is active: the plan, the store’s transaction identifier, when it expires, and whether it was a test purchase. It holds no payment details. It is written by our servers from what RevenueCat reports.

Scan counters

Every chart read is counted against your account so the fair use limits below can be enforced. The counter holds a number and an expiry time. It holds no chart, no result and no journal data.

Read results

The analysis service returns a structured result to your phone (the verdict, the levels, the reasoning) and does not keep it. Neither the photograph nor the result is written to our storage. The only copy of a read is the one saved on your device.

Bug reports

If you send a bug report from the app, we receive the app version and build, your device model and operating system version, the screen you were on, your colour scheme, and the error text, plus anything you type into the description. A report does not include your name, your email, your journal, or any chart. It is stored linked to your account, so that reports can be limited per account and so we can tell which reports came from the same person. We use reports only to fix the problem described. Each report is also forwarded to a notification service so that we see it promptly.

What leaves your device, and when

The chart image you ask to have read. When you confirm a crop, that image is sent to our analysis service, which forwards it to Google’s Gemini API. Gemini performs the analysis and returns the structured result you see. This happens only when you choose to run a read.

Nothing else is sent with it: not your journal, not your trades, not your answers, not your name. The request is authenticated with your account so it can be counted, but the image is not labelled with who you are when it reaches Google.

Once the image reaches Google, it is handled under Google’s terms for the Gemini API rather than ours. We do not store it. If a chart contains information you would not want to send to a third party, such as an account balance visible in the screenshot, crop it out or do not send it.

Fair use limits on chart reads

Every chart read costs us a call to a paid AI service, so the number of reads is capped. The limits are set far above what reading charts by hand looks like. They exist to stop automated abuse, not to meter ordinary use, and most people never come near them.

LimitReadsWindow
Per account, across all your devices60Each day
Short burst, per account6Each minute
  • The daily count resets at midnight UTC, not twenty-four hours after your first scan. Depending on your timezone, that may land in your afternoon.
  • A read counts once it reaches our server, even if the result that comes back is not useful to you. The cost is incurred when the request is made.
  • The cap cannot be bought past. There is no higher tier, and reaching it does not affect the rest of the app.
  • There is also a service-wide ceiling that protects us from a runaway bill. It is set well above what our current number of users could reach, and if it is ever hit the app says so plainly rather than failing silently.

When you reach a limit, the app tells you which one and when it resets. We may adjust these numbers as the service grows; this page is updated when they change.

Permissions the app asks for

  • Camera: only to photograph a chart. No video is recorded and no audio is captured.
  • Photo library: only to let you pick a chart screenshot. ChartPeak reads the image you select and nothing else in your library.
  • Notifications: optional, and local to the device. The few reminders the app sends are scheduled on your phone rather than pushed from a server, and you can turn them off in your device settings at any time.

Tracking, analytics and advertising

ChartPeak does not track you across apps or websites, does not use advertising identifiers, and does not sell or share personal information. There are no third-party advertising or analytics SDKs in the app. The website sets no tracking cookies; see the cookie policy.

Payments

Subscriptions are sold through Apple’s App Store (and Google Play, when the Android version is listed). The store handles payment and holds your payment details. We never see your card number.

We use RevenueCat to manage subscriptions. When you buy on the paywall, before you have an account, the app identifies you to RevenueCat with a random identifier. Once you create an account, that purchase is linked to your account identifier. RevenueCat receives your purchase and renewal history from the store and basic technical details from the app (such as the app version, device model, operating system, country and IP address), and tells us whether your subscription is active. It does not receive your journal, your reads or your charts. RevenueCat processes this data on our behalf under its own privacy policy.

Who we share data with

These service providers process data for us, only to run the app:

  • Google (Gemini API): receives the chart image, for analysis. Depending on the Gemini service tier, Google’s terms may allow it to use submitted content to improve its products.
  • Supabase: hosts our authentication, database and the analysis function, in the United States.
  • RevenueCat: manages subscriptions, as described under Payments.
  • A notification service: receives the content of each bug report you send, so that it reaches us.
  • Apple and Google: as sign-in providers if you choose them, and as the stores that process your subscription.

We do not share data with anyone else, and we do not sell it. We would disclose data if the law required us to, and we would tell you if we were allowed to.

How long we keep it

  • Your account and profile: until you delete the account.
  • Scan counters: they expire on their own within a day of being set.
  • Subscription record: until you delete the account. RevenueCat’s record is deleted when you delete the account; Apple and Google keep their own purchase records under their terms.
  • Sign-in records kept by our authentication provider: for a limited period set by that provider, for security.
  • Bug reports: deleted automatically twelve months after you send them, or straight away when you delete your account.
  • The chart image: not stored by us. Google’s retention is under its terms.

Your rights and choices

You can see and change your name in the app’s Profile tab. You can delete your account from the same tab, which removes it, your subscription record and your bug reports from our servers, asks RevenueCat to delete its record of you, and clears the local database; the account deletion page walks through it. If you are in the EU, the UK, California or anywhere else with a privacy law that gives you rights of access, correction, portability or erasure, you can exercise them by deleting the account yourself or by writing to us, and we respond within the time the law sets. We do not discriminate against anyone for exercising a privacy right.

Because we hold so little, a data access request usually returns your name, your sign-in email, the dates on the account, your subscription record and any bug reports you sent. Everything else is already on your phone.

International transfers

Our servers, and the services listed above, are in the United States. If you use ChartPeak from elsewhere, your account data, subscription data and the chart images you send are processed there, under the safeguards our providers offer for international transfers.

Children

ChartPeak is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from anyone under 18; if you believe we have, write to us and we delete it.

Changes to this policy

If this policy changes in a way that affects what leaves your device or what we keep, the app says so rather than relying on you re-reading this page. The date at the top is the date of the current version.

Get ChartPeak

Snap a chart with your phone and get the whole read back in about 12 seconds: trend, levels, risk and the reasoning behind it. When there is no trade in the chart, ChartPeak says so.

Coming tothe App StoreComing toGoogle Play