Privacy Policy — Volatly
1. Data controller
The controller of your personal data is Volatly, S.L. You can contact us regarding data protection by writing to [email protected].
2. Scope of this policy
This policy applies to the Volatly mobile application and the volatly.com website (together, "Volatly" or "the service"). Your use of Volatly is also governed by the Terms of use and legal notice, which form part of the contractual framework between you and us. Volatly is an information and analysis platform: its content is for informational purposes only and does not constitute investment advice or a recommendation to buy or sell securities. Investing involves risks.
3. What data we process and for what purpose
- Account data. Your email address and your password (stored protected with a hashing algorithm —bcrypt— and never in plain text). Purpose: to create and manage your account, authenticate you and give you access to the service.
- Subscription and payment data. Your plan, subscription status, trial usage and the payment provider's customer identifiers. Your full card details are processed directly by the payment provider (Stripe); Volatly does not store them. Purpose: to manage your subscription, billing and fraud prevention.
- Notification identifier (push token). If you enable notifications in the app, we process your device's token. Its delivery is carried out through Firebase Cloud Messaging (Google) and your device's operating system notification services. Purpose: to send you informational notifications about the status of published analyses and simulations.
- Technical and access data. Your IP address, which we process in pseudonymized form via hashing for aggregate access analytics, together with basic technical data about the device or app and a device identifier we use to maintain your session and prevent fraudulent use of trial periods. Purpose: security, abuse prevention and aggregate usage measurement.
- Record of terms acceptance. The version of the terms you accept, the date and the platform. Purpose: to evidence your acceptance of the terms in force.
- Communications. If you write to us (support or enquiries), we process the content of your message and your contact address. Purpose: to assist you and keep a record of the matter.
- Problem reports sent from the app. If you report a problem through the app's report form, we process the text you write, up to 2,000 characters, and a context block with your email address, your user identifier, your plan, the app version, the platform and the date. That form is an open box and we do not filter what you write in it: it may contain personal data about you or about other people if you include it. The first 60 characters of the text are repeated in the subject line of the email. Purpose: to deal with the problem you tell us about. The message reaches a mailbox of ours and is not stored in our database. If our mail server does not respond because of a failure at its provider, the message goes out through Brevo (Sendinblue) instead, a French company that sends emails on behalf of other companies and that processes the data inside the European Union, under the GDPR.
- Newsletter. If you subscribe, we process your email address and, when signing up from the blog, the language you want it in. Purpose: to send you the communication you request. Sign-up is confirmed by double opt-in: you receive a confirmation email and nobody is added without confirming it. Brevo acts as the processor handling delivery.
4. Legal basis for processing
- Performance of a contract (Art. 6.1.b GDPR): account data, subscription and provision of the service, including the notifications that are part of the service itself.
- Compliance with legal obligations (Art. 6.1.c GDPR): retention of billing and tax data.
- Consent (Art. 6.1.a GDPR): subscription to the newsletter, analytics cookies and, where applicable, non-essential notifications. You can withdraw your consent at any time, without affecting the lawfulness of prior processing.
- Legitimate interest (Art. 6.1.f GDPR): security of the service, fraud and abuse prevention, and aggregate, pseudonymized usage analytics.
5. We do not profile you or make automated decisions
The analysis Volatly provides relates to listed assets and market events, not to your personal behavior. The content is generic, distributed identically to all users, and does not take into account your objectives, financial situation or personal circumstances. Accordingly, Volatly does not build profiles about you nor make automated decisions producing legal effects on you or similarly significantly affecting you.
6. Recipients and processors
To provide the service we share data, only to the extent strictly necessary, with providers acting as processors under contract:
- Stripe — payment processing and subscription management.
- Brevo (Sendinblue) — sending transactional emails and newsletter delivery.
- Hetzner — hosting of the service infrastructure.
- Vercel — hosting of the website.
- Google — site usage analytics (Google Analytics), font loading (Google Fonts) and delivery of push notifications in the app (Firebase Cloud Messaging).
- The app distribution platforms (Google Play and App Store) process data under their own policies when you download or update the app.
Brevo is also involved in the app's problem report form, and only in one case: when our own mail server does not respond because of a failure at its provider, for example if it does not answer or if a key or a certificate of its own is halfway through a change. The message you wrote then goes out through Brevo so that we can receive it, together with the context block that comes with it. Brevo sees that text and also the subject line of the email, which repeats the first 60 characters of what you wrote; those 60 characters stay readable in the provider's delivery logs. If the failure is in the message itself, nothing goes out through Brevo. While our mail server is working, your report does not pass through any third party. We do it this way so that you can tell us about a problem even when our server is down.
We do not sell your personal data or transfer it to third parties for advertising purposes.
7. International transfers
Some of our providers (for example, Stripe, Google or Vercel) may process data in the United States or other countries outside the European Economic Area. In those cases, transfers are covered by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses or, where applicable, the provider's adherence to the EU-US Data Privacy Framework.
8. Retention periods
- Account data: while your account is active. After it is closed, we delete or anonymize it, unless we must retain it by legal obligation.
- Billing data: for the periods required by applicable commercial and tax law.
- Record of terms acceptance: while the account is active and for a reasonable period afterwards, as evidence of acceptance.
- Technical data / pseudonymized IP: for a limited period, for security and aggregate analytics purposes.
- Communications: for as long as necessary to handle your request and evidence its management.
9. Your rights
You can exercise your rights of access, rectification, erasure, restriction of processing, portability and objection at any time, as well as withdraw any consent given. To do so, write to us at [email protected]. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) if you believe your data is not being processed in accordance with the law.
10. Security
We apply reasonable technical and organizational measures to protect your data, including hashing of passwords and encryption of communications in transit. No system is completely infallible, but we work to maintain a level of protection appropriate to the risk.
11. Minors
Volatly is intended exclusively for people over 18. We do not knowingly collect data from minors. If we detect that we have processed a minor's data without a proper basis, we will delete it.
12. Cookies and local storage
The website uses cookies and local storage. Necessary cookies allow the site to function (for example, remembering your language) and do not require consent. Analytics cookies (Google Analytics) are only enabled if you give your prior consent through the cookie notice. When loading fonts or, where applicable, the payment process, providers such as Google or Stripe may receive technical data such as your IP address. You can manage or change your choice at any time from "Cookie settings" in the footer. You will find the details in our Cookie Policy.
13. Changes to this policy
We may update this policy to reflect legal or service changes. We will publish the current version on this page with its update date. If the changes are substantial, we will inform you by appropriate means.
14. Contact
For any questions about this policy or about the processing of your data, write to us at [email protected].
Last updated: June 25, 2026.