Legal

Privacy Policy

Last updated: July 19, 2026  ·  Applies to: Compounder HQ (iOS) v1.0+

The short version: Compounder HQ does not collect, store, or share any personal information. All your data (accounts, positions, transactions, tax lots, watchlist, settings) lives on your device. No account, no email, no analytics. Optional iCloud sync (CloudKit private database) keeps your devices in sync. The app fetches public market data over the network using ticker symbols only; no personal data is sent. There is one optional feature, off by default, that sends limited data to our servers: opt-in push alerts (your device's Apple push-notification token plus the ticker symbols you hold or watch; symbols only, never quantities, values, or account details; see Section 5). Turning a push-alert toggle off stops delivery immediately, and the server-held registration can be deleted on request.

1. Information We Collect

Compounder HQ does not collect any personally identifiable information. Specifically:

2. Data Stored on Your Device

All app data you enter is stored locally on your device using Apple's SwiftData framework:

This data:

3. Third-Party Market Data Services

Compounder HQ displays market data sourced from the following public APIs. Most of this data reaches the app via MARS Studio’s shared caching service (Section 4); a smaller number of requests are still made directly from your device. In every case, requests contain only stock ticker symbols, ETF identifiers, or date ranges, no personal data is sent:

These services have their own privacy policies governing how they handle the API requests Compounder HQ sends:

4. Shared Cache (Cloudflare Worker)

To reduce upstream API load and speed up launches, most market data, quotes, dividend history, ETF distribution policies, computed Compounder Scores, basic financials, and earnings dates, is read from and written to a shared cache hosted on Cloudflare Workers + D1 (in the EU: Dublin region). The caching service retrieves this data from the upstream sources listed in Section 3 (Finnhub, Yahoo Finance, SEC EDGAR, OpenFIGI) and serves it to the app. The cache is shared across MARS Studio's investment apps. The data flowing through this cache:

Cloudflare's privacy policy applies to data stored on their infrastructure: cloudflare.com/privacypolicy.

5. Notifications & Push Alerts

Compounder HQ uses two kinds of notifications:

Turning a push-alert toggle off stops that alert’s evaluation and delivery immediately. Your device registration and symbol list may be retained on the alert server until overwritten by a later sync, automatically pruned when Apple reports the token invalid (for example, after you uninstall the app), or deleted on request, email chq-privacy@marsstudio.app to have your device’s registration and symbol list removed.

Cloudflare's privacy policy applies to data stored on their infrastructure: cloudflare.com/privacypolicy.

6. Subscriptions (StoreKit)

Compounder HQ is free to download and gives new users 2 weeks of full Pro access with no payment required; after the free access period, an active Pro subscription ($39.99/yr) is required to continue using the app (there is no permanent free tier), and a subscription begins only if you explicitly purchase one. All subscription transactions are processed entirely through Apple's App Store and StoreKit 2. MARS Studio does not receive, store, or process any payment information; we receive only a confirmation that your transaction is valid. Apple's privacy policy governs all subscription transactions: apple.com/legal/privacy.

You can manage or cancel your subscription at any time via iOS Settings > [your name] > Subscriptions or the in-app Settings > Manage Subscription link.

7. CSV Imports

When you import a brokerage CSV (Fidelity, Schwab, Vanguard, IBKR, SBI証券, 楽天証券, マネックス証券, or generic), the file is parsed entirely on your device. The CSV contents are never uploaded: only the resulting positions you choose to commit are saved to your local SwiftData store.

8. iCloud Sync (Optional, Opt-In)

If you enable iCloud sync in Settings, Compounder HQ uses Apple's CloudKit private database (your personal iCloud, scoped to the app) to keep accounts, positions, lots, transactions, watchlist, and settings in sync across your Apple devices signed in to the same Apple ID. MARS Studio cannot read or access this data, the CloudKit private database is end-to-end controlled by your Apple ID. You can disable sync at any time in Settings.

9. Analytics & Crash Reporting

Compounder HQ does not include any third-party analytics SDKs (no Firebase, no Mixpanel, no Amplitude, no Sentry, no Crashlytics, etc.). If you opt in to share crash data with Apple at the iOS level (iOS Settings > Privacy & Security > Analytics & Improvements), Apple may share aggregated, anonymised crash logs with us via App Store Connect, this is governed by Apple's privacy policy and is independent of the app.

10. Advertising

Compounder HQ contains no advertisements and does not use any advertising identifiers (IDFA).

11. Children's Privacy

Compounder HQ is intended for adults aged 18 or older and is not directed at children. The app does not knowingly collect information from children under 13. Investment tracking inherently requires adult financial accounts and tax-classification context that is unsuitable for minors.

12. International Users

Compounder HQ is available globally on the App Store. The app is designed to support investors holding US-listed securities regardless of their country of residence (NRIs, US expats, IBKR International / Schwab International / Moomoo US users). The shared cache (Section 4) is hosted in the EU (Dublin region): if your residency selection touches a residency-specific tax engine, those calculations remain entirely on your device. Apart from opt-in push-alert registrations (Section 5), no personal data crosses borders via our infrastructure.

13. European Users (GDPR) & California Users (CCPA/CPRA)

Lawful basis (GDPR Art. 6). Compounder HQ stores all portfolio data (positions, accounts, transactions, journal entries, alert thresholds) locally on your device and may optionally sync it to your private iCloud container (Section 8). Where we process symbol-level data via the shared public-data cache (Section 4), no personal data is included; an Art. 6 lawful basis is therefore inapplicable. For the opt-in push-alert feature (Section 5), the lawful basis for processing your APNs token, alert symbols, and thresholds is your explicit consent (Art. 6(1)(a)), given via the in-app toggle; you may withdraw consent at any time by disabling the alert in Settings, and may request deletion of the server-held registration by emailing chq-privacy@marsstudio.app.

Your rights. European users have the right to access, rectify, erase, restrict, port, and object to processing of any personal data we hold (GDPR Art. 15-22). California users have equivalent rights to know, delete, correct, and limit use under CCPA/CPRA. To exercise any of these rights, contact chq-privacy@marsstudio.app; we respond within 30 days. Your portfolio data lives only on your device (or in your private iCloud container), so deleting the app and clearing the iCloud container in Settings removes it. If you enabled push alerts, email us to have your device’s alert-server registration (Section 5) deleted as well; because we do not collect names or emails, we may need additional context (such as the approximate date you enabled alerts) to locate any record about you.

We do not sell or share your personal information for cross-context behavioural advertising or any other purpose. There is no "Do Not Sell or Share My Personal Information" link because we have no sale or sharing flow to opt out of.

Supervisory authority. European users may lodge a complaint with their local data-protection authority. The shared public-data cache infrastructure (Section 4) is hosted on Cloudflare in the EU (Dublin region); the lead authority for cross-border issues is the Irish Data Protection Commission (dataprotection.ie).

MARS Studio is a small independent developer and has not appointed a Data Protection Officer or EU representative; the volume and nature of our data processing falls below the GDPR thresholds requiring either (Art. 27, Art. 37). Indian users have equivalent rights under the Digital Personal Data Protection Act 2023.

14. App Lock (Face ID / Touch ID / Passcode)

Compounder HQ offers an optional App Lock that requires Face ID, Touch ID, or your device passcode to open the app. This is handled entirely by Apple's on-device LocalAuthentication framework. The app does not collect, store, transmit, or otherwise have access to your biometric data: Face ID / Touch ID data never leaves Apple's Secure Enclave on your device, and Compounder HQ receives only a success or failure result. App Lock is off by default and can be toggled in Settings.

15. Live Activity (Lock Screen & Dynamic Island)

Compounder HQ offers an optional Live Activity that displays your portfolio's total value and today's change on the Lock Screen and in the Dynamic Island when you choose to start it. This information is rendered on your device from data already stored locally; it is not transmitted to MARS Studio or any third party. The Live Activity is off unless you start it and can be dismissed at any time.

16. Referral Program Data

If you use the optional referral program, we store a small amount of data server-side solely to operate the program: a hashed identifier derived from your iCloud account (used to ensure each person redeems only one referral code), your referral code, and redemption timestamps. This data is not linked to your name, email, or portfolio, is never used for tracking or advertising, and is not shared with any third party. You can request deletion of your referral records at any time by emailing chq-privacy@marsstudio.app.

17. Changes to This Policy

If we make material changes to this policy, we will update the "Last updated" date above and (where the change is material) surface a notice in the app on next launch. Continued use of the app after changes constitutes acceptance of the updated policy.

18. Contact

Questions about this policy? Contact us at chq-privacy@marsstudio.app or write to us at MARS Studio, marsstudio.app.