Volt Privacy

How Volt stores, uses, and deletes your data.

Data we store

Volt stores your Supabase account ID, email, optional display name, sign-in provider details, account activity times, terms-acceptance time, and morning-reminder choice. We store the holdings or watchlist entries you confirm: ticker, optional name, optional asset type, and optional quantity. We also store your account ID with minute-level request counts to enforce market limits. Supabase can automatically record account security events, including the action, time, account ID, IP address, device or browser details, and sign-in provider.

Sign in and account security

For email sign-in, your email and password go to Supabase's account service. Supabase stores a protected, one-way version of the password, not the password itself. It creates the account and sign-in records needed to keep you signed in. Your local sign-in credentials are stored in the secure iOS Keychain. For Sign in with Apple, Apple and Supabase process proof of your Apple identity, one-time security codes, which sign-in provider you used, and random security values that prevent reuse. During Apple account deletion, the server briefly receives an Apple access token to revoke the Apple connection. Volt code does not intentionally save that token, but live provider logs could retain request details under their own settings.

Market requests, caches, and logs

Volt sends signed-in market requests to Supabase. A request can include the requested feature, symbol, company search text, or news date range. Finnhub receives the symbol, search text, or date range needed to return the result. Volt does not send Finnhub your email, display name, holdings quantity, screenshot, or Supabase account ID. Finnhub says it may store queries in log files and use them to generate results, evaluate performance, and study usage patterns. Supabase can generate request and diagnostic logs. Depending on live settings, they may include URLs or search details, IP address and approximate location, device or browser details, status, timing, and errors. Opening Volt's public privacy page sends a web request to Vercel. Vercel says it can collect the page viewed, timestamp, browser and device details, IP address, IP-derived city or country, system configuration, response timing, errors, and log data. The exact live log contents and retention are not verified. A cache is a temporary shared copy of limited market result fields. It can contain a symbol or company search text, but no account ID.

Screenshot import

Screenshot pixels and OCR text stay on your device. Volt stores only the ticker, name, and optional quantity you confirm. We do not upload the screenshot itself.

Why we use data

We use account and security data to sign you in, prevent abuse, and process deletion. We use portfolio data to show your holdings and watchlist. We use market requests to return market information and protect availability. We use onboarding choices to record terms acceptance and schedule a local reminder. Request timing, status, and errors help operate and secure the service.

Who processes data

Supabase provides account, database, server, and logging services. Finnhub provides market data and may analyze query usage under its terms. Vercel hosts the public privacy page and processes its page-request and network metadata. Apple processes Sign in with Apple data when you choose that method. Apple Photos, Vision, Keychain, and Notifications process relevant data on your device. Each provider's own terms and privacy practices govern its processing. Volt does not include advertising SDKs or use data for cross-company tracking.

Retention

Account, sign-in, onboarding, holdings, and watchlist records remain while your account is active. A short-lived security challenge used for Apple deletion expires after 10 minutes. User-linked request-count records become eligible for cleanup after 24 hours. Shared caches expire after 60 seconds for quotes, 10 minutes for news, 30 minutes for recommendations, and 24 hours for searches. Expiration stops reuse, but deletion can happen later. Public rating-history records contain no account ID. Retry records for those public updates become eligible for cleanup after 14 days. Provider logs, account security records, sign-in sessions, and backups follow provider and project settings. Vercel's documented runtime-log access depends on plan. Exact static-request log fields and retention for Volt's policy page are not verified. The deployed policy file can remain under Vercel's deployment-retention settings, but it contains the policy text, not user records. Other exact live retention periods are not verified. Finnhub does not state a query-log duration in the terms reviewed.

Delete account

Use Delete account in the signed-in account menu. Email accounts confirm the destructive action. Apple accounts must complete a fresh Apple authorization so Volt can verify the request and revoke Apple authorization before deletion. The server deletes your holdings, watchlist, related profile and preference data stored under your account ID, user-linked request-count records, the short-lived deletion challenge, and your Supabase account. The app then clears its local portfolio and sign-in state. Shared cache copies, public market-history records, provider logs, and backups are not part of the account deletion flow and can remain under the retention terms above. Deleting your account does not cancel a pending local morning notification or change iOS notification permission. Disable Volt notifications in iOS Settings if you want to stop it.

Your choices

Display name, holdings quantity, watchlist entries, and the morning reminder are optional. You can remove portfolio entries, turn off Volt notifications in iOS Settings, sign out, or delete your account. You can also contact privacy support to ask a question or withdraw consent where applicable.

Security and limits

Volt uses signed-in requests to Supabase. Private service credentials and the Finnhub key stay on the server. The Supabase publishable key is public configuration shipped in the app. No online service can guarantee absolute security.

Contact

Use Email privacy support below for privacy questions or consent requests.