Privacy Policy
The German version of this text as shown in the NadirAlpha Stocks app is legally binding; this page is a copy.
This Privacy Policy applies to the app NadirAlpha Stocks (web app at stocks.nadiralpha.com and mobile app). The German version shown in the app is legally binding. The website nadiralpha.com has its own privacy policy.
1. Controller
Michael Wirl, Hedwigstrasse 2, 80636 Munich, Germany, e-mail nadiralpha.info@gmail.com. No data protection officer has been appointed, as the statutory requirements do not apply.
2. Overview
The app needs little data to run: your e-mail address and a password for the account, the content you create in the app (watchlists, imported lists, saved screens), your consent to the legal texts including the age confirmation, and technical connection data. There is no advertising, no analytics or tracking service, no cookies and no sharing with third parties for their own purposes.
3. What data we process and why
Account data: e-mail address, password (stored only as a cryptographic hash), the invitation code used at registration, time of account creation, e-mail confirmation and sign-ins, session identifiers (tokens). Purpose: sign-in, protection of the account, password reset. Legal basis: performance of the user relationship (Art. 6(1)(b) GDPR). Retention: until the account is deleted.
Content: watchlists, imported lists of security identifiers (ISINs), saved screens (filter and column choices) with their names. Purpose: providing these functions. Legal basis: Art. 6(1)(b) GDPR. Retention: until you delete them or delete your account. This content says nothing about actual securities holdings; we process no brokerage, payment or location data.
Consent record: version of the accepted Terms of Use, Privacy Policy and Risk Disclaimer, your confirmation of legal age (yes/no), time, app and platform (web, iOS, Android). We do not collect a date of birth. Purpose: proof of consent and display in Settings. Legal basis: Art. 6(1)(c) and (f) GDPR (duty to demonstrate consent, legitimate interest in legal certainty). Retention: until the account is deleted.
Technical data: when you open the web app and with every data request, our processors record IP address, time, requested resource, transferred data volume and browser or device type in server logs. Purpose: provision, stability and protection against attacks. Legal basis: Art. 6(1)(f) GDPR. Retention: usually up to 30 days at the processors; logs are not used for profiling.
Error and performance reports: if the app crashes or a data request fails, the app sends a report with the error message, a technical trace (stack), the affected screen, app version and platform, and where technically useful your account ID. In addition, once per session the app sends summarised request timings (count, average, duration, data volume) with platform, app version and time zone, without account ID and without IP address. Timings are sent only in every tenth session and in sessions with noticeably slow requests. Purpose: detecting errors and making the app faster. Legal basis: Art. 6(1)(f) GDPR. Retention: error reports 90 days, timings 30 days. No third parties are involved; the reports are stored in the same database in Frankfurt.
Contact: if you e-mail us, for example with questions about an invitation code or for a deletion, we process your address and the content to handle the request (Art. 6(1)(b) and (f) GDPR). Retention: until the matter is settled, at most one year.
4. Recipients and processors
We use the following service providers as processors under Art. 28 GDPR; they process data only on our instructions:
- Supabase, Inc. (970 Toa Payoh North, Singapore): database and sign-in. The project runs in the Frankfurt am Main (EU) region, where account data, content and the consent record are stored. Any remote access from third countries is covered by the EU Standard Contractual Clauses.
- Resend, Inc. (2261 Market Street, San Francisco, USA; sending through the EU region Ireland): delivery of the e-mails that Supabase generates on our behalf, namely the confirmation of your e-mail address at registration and the password reset; the sender is login@nadiralpha.com. Processed: recipient address, subject and delivery status. Transfer basis: EU Standard Contractual Clauses. There is no newsletter and no marketing e-mail.
- Cloudflare Turnstile (Cloudflare, Inc.): bot protection at registration, sign-in and password reset. The widget checks in the background whether a real browser submits the form; IP address and technical browser characteristics are transmitted to Cloudflare, without cookies and without cross-site recognition. Legal basis: Art. 6(1)(f) GDPR (protection against abuse).
- Cloudflare, Inc. (101 Townsend Street, San Francisco, USA): delivery of the web app (Cloudflare Pages) and protection against attacks. Connection data is processed in data centers worldwide. Transfer basis: EU-US Data Privacy Framework (Cloudflare is certified) and EU Standard Contractual Clauses.
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland): mailbox for our contact address (Gmail). Your e-mails to us are stored there.
- During the test phase the mobile app may run in the development client Expo Go (Expo, Inc., USA); technical device data may reach Expo in that case. If the app is later published through an app store, its privacy terms apply in addition.
Price and master data for securities come from external sources; no user data is transmitted to them. Data is disclosed to other third parties only where we are legally obliged to do so.
5. Storage on your device, no cookies
The app sets no cookies. To keep you signed in, the session token is stored in the browser's local storage (web app) or in the device's protected storage (mobile app). This is technically required (Section 25(2) no. 2 German TDDDG) and is deleted when you sign out. There is no audience measurement, no cross-site tracking, no advertising and no push notifications; the error and performance reports in section 3 serve operation only.
6. Children
The app is intended for persons aged 18 or over. We do not knowingly set up accounts for minors.
7. Data security
The connection is encrypted end to end (TLS). Passwords are stored only as hashes. Each user can read and change only their own rows in the database (row-level access rules). Weekly backups of the user tables are deleted automatically after 90 days.
8. Deleting your account
You can delete your account yourself at any time: Settings, "Delete Account". Account, content and consent record are removed immediately and irreversibly; they remain in backups for at most 90 days. Alternatively, send an e-mail to nadiralpha.info@gmail.com from the address registered with the account.
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6(1)(f) GDPR (Art. 21). Contact the e-mail address above. You also have the right to lodge a complaint with a data protection supervisory authority, for example the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
10. Obligation to provide data
An account cannot be operated without an e-mail address and password. All other data (lists, screens) is voluntary.
11. No automated decisions
There is no automated decision-making within the meaning of Art. 22 GDPR and no profiling. Signals and figures are computed from price data in the same way for all users and do not relate to you as a person.
12. Changes
We update this policy when the app or the legal situation changes. A changed version is brought to your attention at the next start of the app; the current version is stated at the end of this text.
Last updated: September 14, 2026