Privacy Policy

Bull Trading Journal
Package: com.bullatschool.tradingjournal
Version covered: 1.0 and later unless we publish a replacement

Effective date: 25 September 2026

This Privacy Policy explains what information Bull Trading Journal (“the App”, “we”, “us”) handles when you use the Android app distributed on Google Play and the Solana mobile app store.


1. Who we are

  • Publisher: Bull at School
  • Email: bull@bullatschool.com
  • App: Bull Trading Journal (com.bullatschool.tradingjournal)

If we appoint an EU/UK representative, we will list them here.

2. Short version

  • Your journal (tickets, playbook, notes, grades, mood, screenshots, account settings) is stored on your device.
  • We do not create a user account and we do not run cloud sync in v1.0.
  • The App may call the public internet to fetch FX reference rates (currently Frankfurter / ECB).
  • We do not sell personal data.
  • We do not use advertising SDKs or cross-app tracking in v1.0.
  • Screenshots stay on-device unless you export or share them.

3. Information the App stores on your device

You may enter or generate:

CategoryExamplesStored where
Journal contentInstrument, side, market, timestamps, P&L, R-multiple, grade, mood, “followed the plan”, notesLocal app storage
PlaybookSetup names and rulesLocal app storage
Account settingsDesk name, starting balance, max daily loss, max consecutive losses, display currency, languageLocal app storage
MediaChart screenshots you attachLocal app storage (not uploaded by us)
Backups you createJSON backup of tickets and setups; CSV of the bookWhere you save or share the file

This data can include personal data if you put your name, account numbers, or other identifiers in notes or file names. Treat notes as confidential.

Android allowBackup is enabled in the current build. Depending on your device settings, the OS may include App data in a system backup you control (for example Google Backup). That backup is handled by Google or the device vendor under their policies, not by a Bull Trading Journal server.

4. Information we do not collect on our servers

In normal v1.0 use we do not receive:

  • your tickets or screenshots
  • your name or email (the App does not have sign-in)
  • precise location
  • contacts, calendar, or microphone
  • seed phrases, private keys, or wallet addresses (the App is not a wallet)

We do not integrate Firebase Analytics, Crashlytics, Google Ads, Meta Ads, or similar third-party analytics/ads SDKs in the v1.0 APK we reviewed.

5. Network requests

The App declares:

  • android.permission.INTERNET
  • android.permission.ACCESS_NETWORK_STATE

Foreign-exchange rates. To convert a ticket’s P&L into your desk currency, the App may request rates from:

  • https://api.frankfurter.dev/v2/providers/ecb/rate/

Frankfurter is a third-party service that exposes ECB reference rates. That operator may see standard technical data such as IP address, time, and the currency pair requested. Their terms and privacy notice apply to that request. You can avoid that call by not using conversion features or by using the App offline (conversion will then be unavailable or stale).

System intents. If you tap Share CSV, Export backup, or open a link, Android may send the file or URL to another app you choose (Drive, email, Files, a browser). Those apps are independent controllers.

Stores. Google Play and the Solana mobile app store collect installer, device, and payment data under their policies when you download or pay. We do not control that collection.

6. File sharing (FileProvider)

The App uses Android FileProvider (com.bullatschool.tradingjournal.fileprovider) so you can export JSON or share CSV. Only the file you choose to share is exposed to the receiving app, for as long as that share lasts.

7. Permissions we do not require in v1.0

The current APK does not request camera, photos/media, contacts, precise location, or notifications as standalone dangerous permissions. If a future version needs them (for example a dedicated photo picker), we will update this policy and the store Data safety form before release.

8. Why we process data (GDPR legal bases)

ProcessingPurposeLegal basis (EU/UK)
Local journal storageProvide the journal you asked forContract (Art. 6(1)(b)) and/or your control of data that never leaves the device
FX API requestConvert currencies you selectedContract / legitimate interest in performing a feature you invoked
Store listing and support emailAnswer a message you send usContract or legitimate interest; consent where required
Legal complianceTax, accounting, abuse reportsLegal obligation (Art. 6(1)(c))

We do not use your journal for profiling or automated decisions that produce legal effects.

9. Retention

  • On-device data stays until you delete a ticket, clear App storage, or uninstall.
  • Exported JSON/CSV files last as long as you (or the app you shared them with) keep them.
  • If you email us, we keep the correspondence only as long as needed to handle the request and required record-keeping (typically up to 24 months unless law requires longer).

10. Children

The App is not directed at children under 18. We do not knowingly collect children’s data on our servers. If you believe a minor provided personal data to us by email, contact us and we will delete it.

11. International transfers

Journal data does not leave your device through our servers. An FX request may be processed by Frankfurter’s infrastructure, which may be outside your country. Store platforms transfer data under their own rules.

12. Your rights

Depending on your country you may have rights to access, correct, delete, restrict, port, or object to processing, and to withdraw consent.

Because most journal data never reaches us, the practical way to exercise deletion is: delete tickets in the App, clear App storage, and uninstall. For emails you sent us, use the contact below.

EU/EEA users may complain to their local supervisory authority. California residents may have CPRA rights; we do not sell or “share” personal information for cross-context advertising.

13. Security

We use on-device storage and standard Android sandboxing. No method is perfectly secure. Protect your phone with a lock screen. Encrypted device storage and a private backup location reduce risk. Anyone with the phone or a JSON/CSV export can read your journal.

14. Third parties

PartyRole
Google PlayDistribution, payments, possible OS backup
Solana Mobile / Solana dApp StoreAlternative distribution on compatible devices
Frankfurter (api.frankfurter.dev)Optional ECB FX rates
Apps you share files withReceive exports you initiate

We are not responsible for third-party privacy practices.

15. Google Play Data safety summary (for your store form)

Use this as a starting checklist when you fill Play Console:

  • Data collected by you / your servers: none in v1.0 (unless a user emails you).
  • Data collected by the app on-device: financial info the user types (trade P&L, balances) — collected? No for “collected by developer”; stored locally.
  • Data shared with other companies: FX API technical data only if conversion runs. Mark as not sold, not used for ads.
  • Security practices: data encrypted in transit (HTTPS to Frankfurter).
  • Users can request deletion: yes, by deleting local data / uninstalling.
  • Account creation: no.

Confirm the form against Play’s current definitions. “Collected” usually means transmitted off the device.

16. Solana app store notes

The App does not connect to Solana RPC, does not request wallet signatures, and does not custody tokens. If the Solana store asks whether you collect wallet addresses or on-chain identifiers: no for v1.0.

17. Changes

We will post an updated policy and change the effective date when we add accounts, cloud sync, analytics, ads, or new permissions. Material changes will be noted in the store listing or an in-app notice.

18. Contact

Privacy questions: bull@bullatschool.com
Publisher: Bull at School


Last updated: 25 September 2026