Bull Trading Journal
Package: com.bullatschool.tradingjournal
Version covered: 1.0 and later unless we publish a replacement
Effective date: 25 September 2026
This Privacy Policy explains what information Bull Trading Journal (“the App”, “we”, “us”) handles when you use the Android app distributed on Google Play and the Solana mobile app store.
1. Who we are
- Publisher: Bull at School
- Email: bull@bullatschool.com
- App: Bull Trading Journal (
com.bullatschool.tradingjournal)
If we appoint an EU/UK representative, we will list them here.
2. Short version
- Your journal (tickets, playbook, notes, grades, mood, screenshots, account settings) is stored on your device.
- We do not create a user account and we do not run cloud sync in v1.0.
- The App may call the public internet to fetch FX reference rates (currently Frankfurter / ECB).
- We do not sell personal data.
- We do not use advertising SDKs or cross-app tracking in v1.0.
- Screenshots stay on-device unless you export or share them.
3. Information the App stores on your device
You may enter or generate:
| Category | Examples | Stored where |
|---|---|---|
| Journal content | Instrument, side, market, timestamps, P&L, R-multiple, grade, mood, “followed the plan”, notes | Local app storage |
| Playbook | Setup names and rules | Local app storage |
| Account settings | Desk name, starting balance, max daily loss, max consecutive losses, display currency, language | Local app storage |
| Media | Chart screenshots you attach | Local app storage (not uploaded by us) |
| Backups you create | JSON backup of tickets and setups; CSV of the book | Where you save or share the file |
This data can include personal data if you put your name, account numbers, or other identifiers in notes or file names. Treat notes as confidential.
Android allowBackup is enabled in the current build. Depending on your device settings, the OS may include App data in a system backup you control (for example Google Backup). That backup is handled by Google or the device vendor under their policies, not by a Bull Trading Journal server.
4. Information we do not collect on our servers
In normal v1.0 use we do not receive:
- your tickets or screenshots
- your name or email (the App does not have sign-in)
- precise location
- contacts, calendar, or microphone
- seed phrases, private keys, or wallet addresses (the App is not a wallet)
We do not integrate Firebase Analytics, Crashlytics, Google Ads, Meta Ads, or similar third-party analytics/ads SDKs in the v1.0 APK we reviewed.
5. Network requests
The App declares:
android.permission.INTERNETandroid.permission.ACCESS_NETWORK_STATE
Foreign-exchange rates. To convert a ticket’s P&L into your desk currency, the App may request rates from:
https://api.frankfurter.dev/v2/providers/ecb/rate/
Frankfurter is a third-party service that exposes ECB reference rates. That operator may see standard technical data such as IP address, time, and the currency pair requested. Their terms and privacy notice apply to that request. You can avoid that call by not using conversion features or by using the App offline (conversion will then be unavailable or stale).
System intents. If you tap Share CSV, Export backup, or open a link, Android may send the file or URL to another app you choose (Drive, email, Files, a browser). Those apps are independent controllers.
Stores. Google Play and the Solana mobile app store collect installer, device, and payment data under their policies when you download or pay. We do not control that collection.
6. File sharing (FileProvider)
The App uses Android FileProvider (com.bullatschool.tradingjournal.fileprovider) so you can export JSON or share CSV. Only the file you choose to share is exposed to the receiving app, for as long as that share lasts.
7. Permissions we do not require in v1.0
The current APK does not request camera, photos/media, contacts, precise location, or notifications as standalone dangerous permissions. If a future version needs them (for example a dedicated photo picker), we will update this policy and the store Data safety form before release.
8. Why we process data (GDPR legal bases)
| Processing | Purpose | Legal basis (EU/UK) |
|---|---|---|
| Local journal storage | Provide the journal you asked for | Contract (Art. 6(1)(b)) and/or your control of data that never leaves the device |
| FX API request | Convert currencies you selected | Contract / legitimate interest in performing a feature you invoked |
| Store listing and support email | Answer a message you send us | Contract or legitimate interest; consent where required |
| Legal compliance | Tax, accounting, abuse reports | Legal obligation (Art. 6(1)(c)) |
We do not use your journal for profiling or automated decisions that produce legal effects.
9. Retention
- On-device data stays until you delete a ticket, clear App storage, or uninstall.
- Exported JSON/CSV files last as long as you (or the app you shared them with) keep them.
- If you email us, we keep the correspondence only as long as needed to handle the request and required record-keeping (typically up to 24 months unless law requires longer).
10. Children
The App is not directed at children under 18. We do not knowingly collect children’s data on our servers. If you believe a minor provided personal data to us by email, contact us and we will delete it.
11. International transfers
Journal data does not leave your device through our servers. An FX request may be processed by Frankfurter’s infrastructure, which may be outside your country. Store platforms transfer data under their own rules.
12. Your rights
Depending on your country you may have rights to access, correct, delete, restrict, port, or object to processing, and to withdraw consent.
Because most journal data never reaches us, the practical way to exercise deletion is: delete tickets in the App, clear App storage, and uninstall. For emails you sent us, use the contact below.
EU/EEA users may complain to their local supervisory authority. California residents may have CPRA rights; we do not sell or “share” personal information for cross-context advertising.
13. Security
We use on-device storage and standard Android sandboxing. No method is perfectly secure. Protect your phone with a lock screen. Encrypted device storage and a private backup location reduce risk. Anyone with the phone or a JSON/CSV export can read your journal.
14. Third parties
| Party | Role |
|---|---|
| Google Play | Distribution, payments, possible OS backup |
| Solana Mobile / Solana dApp Store | Alternative distribution on compatible devices |
Frankfurter (api.frankfurter.dev) | Optional ECB FX rates |
| Apps you share files with | Receive exports you initiate |
We are not responsible for third-party privacy practices.
15. Google Play Data safety summary (for your store form)
Use this as a starting checklist when you fill Play Console:
- Data collected by you / your servers: none in v1.0 (unless a user emails you).
- Data collected by the app on-device: financial info the user types (trade P&L, balances) — collected? No for “collected by developer”; stored locally.
- Data shared with other companies: FX API technical data only if conversion runs. Mark as not sold, not used for ads.
- Security practices: data encrypted in transit (HTTPS to Frankfurter).
- Users can request deletion: yes, by deleting local data / uninstalling.
- Account creation: no.
Confirm the form against Play’s current definitions. “Collected” usually means transmitted off the device.
16. Solana app store notes
The App does not connect to Solana RPC, does not request wallet signatures, and does not custody tokens. If the Solana store asks whether you collect wallet addresses or on-chain identifiers: no for v1.0.
17. Changes
We will post an updated policy and change the effective date when we add accounts, cloud sync, analytics, ads, or new permissions. Material changes will be noted in the store listing or an in-app notice.
18. Contact
Privacy questions: bull@bullatschool.com
Publisher: Bull at School
Last updated: 25 September 2026