Qué datos, por qué y durante cuánto tiempo.

Este texto explica qué datos recogen la app TradingScope y el sitio tradingscope.net, por qué los tratan, con quién los comparten y cómo se eliminan. Está escrito a partir del código que realmente ejecuta la app; no se recoge ningún dato que no esté descrito aquí. (El texto completo está disponible por ahora en turco e inglés.)

Última actualización: 4 de octubre de 2026

Data controller: the team operating the TradingScope app (see Team). For any request concerning this policy: kvkk@tradingscope.net

Resumen

  • Your account is created with your phone number. There is no password; you sign in with a one-time code sent by SMS.
  • We use no ad networks, analytics SDKs, cookies or cross-app tracking. For that reason iOS App Tracking Transparency (ATT) is never requested.
  • We do not sell data or transfer it to third parties for marketing.
  • To run the service we must share some data with service providers: SMS verification, push delivery and AI analysis. Each is listed below.
  • You can delete your account yourself in the app or at tradingscope.net/hesap-sil; deletion cannot be undone.

Datos que tratamos

1. Account and authentication

DataDescription
NameThe name you enter at sign-up. Shown on your profile and on analyses you share.
Phone numberThe unique identifier of your account; used to sign in. Stored in international format.
SMS verification recordsOne row per code request: phone number, a cryptographic hash of the code (the code itself is never stored) or the provider's verification marker, expiry, wrong-attempt count, whether it was used, and the requesting IP address. The IP is used only for rate limiting, to prevent SMS flooding of a number or from one source. These records are tied to the phone number, not the account (see Retention and deletion).
Consent timestampWhen you accepted the privacy notice. Legal proof of consent, kept on the server.
Account statusSign-up date, last sign-in, account type (member / expert), status and an in-app engagement score.

2. Content you create in the app

DataDescription
PortfolioEvery purchase you enter: instrument, quantity, unit cost and (if entered) date. Used only for calculations; never sent to a broker or third party.
Watchlist and followsYour favourite instruments, the experts and famous investors you follow.
Price alertsLevel, direction, whether active and when triggered.
Content interactionsAnalyses/news you liked or saved and the text of comments you write.
Chart imageIf you take or pick a chart photo for AI analysis, the image is sent to Anthropic to be processed only for that request and is not stored. The camera opens only when you choose to and grant permission.
Analyses you shareTitle, text, target instrument, direction and entry/target/stop levels; moderation decision and reason.
NotificationsTitles and bodies of notifications sent to you and their read state.
Reports and blocksWhat you reported, the reason, your note and review status; the list of users you blocked. The reported person never sees who reported them.

3. Preferences

Interests chosen on the welcome screen (instruments and sectors), light/dark/system theme and which notification types you keep on.

4. Push tokens

If you allowed notifications: the token generated for your device, platform (ios/android), device name (as set by the operating system) and first/last-seen times. The token is deleted when you turn notifications off or sign out.

5. Usage logs

Server-side activity log: your actions recorded by category (sign-in, instrument views, investor views, analysis and content interactions, AI usage, device/platform, portfolio actions). Each row holds the action type, target and time.

Telemetry sent by the app: only six events (app open, screen view, instrument view, analysis read, news read, AI use) with the target's id, up to 1 KB of extra data and the time. No telemetry is collected from signed-out users.

6. Invite links

If you signed up with an invite code, the code and date are recorded on your account. Invite-link clicks count only time and a coarse device class (ios/android/desktop/bot); the clicker's IP address and browser identity are deliberately not stored.

Datos que no recogemos

  • Location is never requested or collected.
  • Contacts, calendar and microphone permissions are never requested. The camera is used only when you choose to take a chart photo for AI analysis and grant permission at that moment.
  • Advertising identifiers (IDFA/GAID) are not read; there is no ad network or analytics SDK in the app.
  • We store no passwords; there is no password field in the system.
  • No identity, bank or card details are requested; no payments are taken in the app.
  • The website uses no cookies, no visitor analytics and no third-party scripts. Fonts are served from our own server.

Finalidades y base legal

  • Creating the membership and verifying sign-in — phone number, verification records. Basis: performance of a contract (Turkish KVKK art. 5/2-c; GDPR art. 6(1)(b)).
  • Providing the service — portfolio, alerts, watchlist, content interactions. Basis: performance of a contract.
  • Sending notifications — push token, alert and follow data. Basis: performance of a contract; explicit consent for announcement-type notifications (can be switched off in the app).
  • Security and abuse prevention — IP and attempt counters in verification records. Basis: legitimate interest.
  • Improving and personalising the service — usage logs and preferences. Basis: legitimate interest.
  • Legal obligations — requests from competent authorities. Basis: legal obligation.

Terceros

We use the providers below to run the service. Each receives the data transferred to it only for the job described. Most of them have servers outside Türkiye; these transfers are therefore international data transfers, and using the service means you consent to them.

Twilio — SMS verification

Transferred: your phone number. Twilio (Twilio Verify) generates the verification code, sends the SMS and checks the code. An SMS cannot be sent without the number. In case of a provider outage, Google Firebase Authentication or sent.dm may be used as a fallback; your phone number would then be transferred to that provider and this text updated. Twilio privacy policy

Anthropic — AI analysis

Transferred: the market data used in an analysis (price, period changes, technical indicators) and, for "analyse from image", the image you upload; for news summaries, the headline and body of the news item. Not transferred: your name, phone number, account id or portfolio. Uploaded images are not stored on our server. anthropic.com/legal/privacy

Expo, Apple and Google — push delivery

Transferred: your device's push token with the title and body of the notification. Notifications go through Expo's push service to Apple (APNs) or Google (FCM). The app also downloads its updates from Expo's servers; during that your device's IP address, app version and platform are visible to Expo. Expo privacy policy

Telegram — operational alerts

Transferred: when a new member signs up, a message with the name and a masked phone number (e.g. +90 533***) is posted to the team's private Telegram channel, to monitor that sign-up works. Usage data, portfolios and content never go to this channel.

Our hosting provider

The server and database run on a single rented virtual server (Germany). The hosting provider is technically able to access data but may not process it for its own purposes under contract. Backups are kept on the same infrastructure.

Addresses images are fetched from directly

When an image is loaded directly from its source, your device's IP address and general device information are visible to that address: Google's favicon service and icon.horse for company logos, Wikimedia Commons for investor photos, the publishing site for news images. Your name, number or account id is never sent to them.

Sources we read from and never send data to: prices, news and investor filings are read from sources such as Alpaca, Finnhub and the SEC (US Securities and Exchange Commission). No user data is sent to these sources.

Beyond this, your data is never transferred to or sold to third parties for marketing. It is shared only on a lawful request from a competent public authority, limited to the data requested.

Conservación y eliminación

We keep your data for as long as your account exists. You can delete your account in the app (Profile › Account details › Delete account) or at tradingscope.net/hesap-sil. Deletion cannot be undone and takes effect immediately.

Deleted permanently when the account is deleted

  • Name, phone number and all profile data
  • Your portfolio: all positions and purchase records
  • Your watchlist, followed experts and investors
  • Your price alerts
  • Likes, saves and your comments
  • Notification history and device push tokens; notifications stop
  • Activity log and usage telemetry
  • Interest, theme and notification preferences

Not deleted

Published analyses stay in the feed, detached from you and anonymised, because retroactively deleting a published analysis would alter the history other users have seen. Write to destek@tradingscope.net before deleting your account if you want them removed. Reports you submitted may be kept for the integrity of moderation; they contain neither your name nor your number.

SMS verification records

Verification rows are tied to the phone number, not the account, and may remain after deletion for abuse control (the hourly code quota). They never contain the code itself. If you want them deleted too, write to kvkk@tradingscope.net; we resolve the request within 30 days.

Database backups rotate; deleted data leaves the backups within 30 days.

Seguridad

  • All traffic between the app and the server is encrypted with TLS.
  • Verification codes are never stored in plain text. A code is valid for 5 minutes and locks after 5 wrong attempts.
  • Session tokens are signed and expire after 30 days; a new SMS verification is then required.
  • Server access is limited to authorised team members.
  • No system can guarantee absolute security; if you find a vulnerability, report it to destek@tradingscope.net.

Tus derechos

Under Article 11 of Turkish Law No. 6698 on the Protection of Personal Data you have the right to learn whether your personal data is processed, to request information if it is, to learn the purpose of processing, to know the third parties it is transferred to, to request correction of incomplete or inaccurate data, to request deletion, to request that corrections and deletions be notified to third parties, to object to a result produced against you by automated analysis, and to claim compensation for damage caused by unlawful processing.

Send requests to kvkk@tradingscope.net; they are answered within 30 days. To verify that the request is yours, include the phone number registered to your account. If you live in the European Union, the equivalent rights under the GDPR can be exercised through the same address.

Menores y cambios

TradingScope is not intended for anyone under 18 and we do not knowingly collect data from children. If we learn that a child's data has been processed, we delete the record; you can report such a case to kvkk@tradingscope.net.

This text is updated whenever a new feature enters the app or a provider we use changes, and the date above changes with it. Significant changes are also announced inside the app.

Contacto

Privacy questions: gizlilik@tradingscope.net
Data-protection requests: kvkk@tradingscope.net
General support: destek@tradingscope.net