Skip to content
AirCapital.
HomeDemoFAQContact
Get the app
Privacy policy EnglishTerms of use EnglishCookies and analytics EnglishDelete your data EnglishLegal notice English

AIRCAPITAL · LEGAL

Privacy policy

How AirCapital handles information on the website and in the iOS and Android apps, and how you can exercise your rights.

Last updated: 2026-09-07 · English

1. Who is responsible2. Your exchange data stays under your control3. What we process and why4. Your choice about analytics5. How long information is kept6. Providers and international processing7. Your rights8. Backups and security9. Children, decisions and changes

1. Who is responsible

Tymofii Shkabrov, Stasjonsgata 31j, 3300 Hokksund, Norway.

AirCapital is the product name. The operator above is responsible for the processing described here. Contact: timofii.shkabrov@gmail.com. This policy covers aircapital.app and the AirCapital apps (package tim.AirCapital). Exchanges and app stores have their own responsibilities and privacy policies.

2. Your exchange data stays under your control

The apps store connected account labels, balances, asset allocations, portfolio history, deposits, withdrawals and related preferences locally. API credentials are held in the device’s secure storage. Financial records are encrypted locally with a key in secure storage. We do not operate an AirCapital server that receives your exchange credentials or portfolio records.

When you request synchronisation, the app sends authenticated HTTPS requests directly to the exchange you selected. The exchange receives the authentication information required by its API and your network IP address. A public Coinbase price endpoint may also receive a request and IP address for currency conversion. We do not send your portfolio or exchange credentials to that price endpoint. These services process requests under their own policies.

The operating system performs optional biometric authentication. AirCapital receives the authentication result, not your fingerprint, face image or biometric template. The website demo uses fictional portfolio data and does not accept exchange API keys.

3. What we process and why

App functionality: the local processing and direct exchange requests described above provide the monitoring service you request (Article 6(1)(b) GDPR). Connecting an exchange is optional; without it, you can use the demo. We do not use portfolio data for advertising or automated decisions about you.

Website delivery and security: our hosting provider Railway processes connection information such as IP address, request time, requested URL, browser information and response status to deliver pages, diagnose failures and protect the service. Our legal basis is our legitimate interest in providing a reliable and secure website (Article 6(1)(f)).

Support and privacy requests: if you email us, we receive your email address, message and anything you choose to attach, through our email provider Google. We use this to respond to your request, on the basis of providing requested support, our legitimate interest in resolving enquiries, or compliance with legal obligations for rights requests (Articles 6(1)(b), (f) or (c), as applicable). Please do not send API secrets, identity documents or complete portfolio exports unless a specific, necessary and secure process has first been agreed.

Optional analytics: only if you agree, Google Analytics on the website and Google Analytics for Firebase in the apps process pseudonymous browser or app-instance identifiers, visits or screen views, session and engagement events, device/browser/OS information, language and approximate location derived from network information. Website demo interactions and store-button clicks are also measured. This uses consent (Article 6(1)(a)). Precise GPS location is not requested. We do not send account labels, balances, transaction records, API keys, email addresses or a developer-assigned user ID to Analytics. Advertising identifiers and Google signals are disabled in our configuration.

4. Your choice about analytics

On the website, the Google tag is blocked until you accept analytics. Accept and reject are both available. You can change your choice through Cookie settings in the footer. On iOS and Android, analytics collection is disabled by default and can be changed in Settings. Declining does not prevent monitoring or use of the demo.

Withdrawal stops future analytics collection and clears the relevant website analytics cookies or resets the local app analytics identifier. It does not automatically erase events already sent to Google. Withdrawal does not affect the lawfulness of processing before you withdrew. Contact us about deletion of identifiable historical data; we may need limited information to locate a pseudonymous record, and do not collect extra identity data solely to identify it.

5. How long information is kept

Local portfolio history and credentials remain on the device until you remove the relevant connection or use the app’s Delete all data action. Different deletion actions have different scope; see the deletion guide. Clearing browser storage removes website preferences. Uninstalling an app alone may not remove secure-storage entries or copies managed by the operating system.

Website analytics consent is valid for 180 days before we ask again. Language preferences remain until changed or browser storage is cleared. Google analytics cookies have a default expiry of up to two years, which Google may refresh on use. Browsers may shorten this period.

Our Google Analytics property is configured for two months of event-level retention and 14 months of user-level retention, with the user period renewed on new activity. Google’s scheduled deletion processes apply; these controls do not limit the lifetime of aggregate reports. Provider security, billing and legal records may follow separate periods described in the provider’s policy.

We keep support messages while needed to resolve the enquiry and handle a related dispute or legal requirement. We review retained correspondence and remove messages no longer needed. Hosting logs are retained for the provider’s applicable operational retention period and, where necessary, for investigating a specific security incident. You can ask us for the current retention details applicable to your request.

6. Providers and international processing

Railway provides website hosting. Google provides optional website/app analytics and the email service used for support. Apple and Google provide app distribution and process store-related information under their own terms. Connected exchanges independently process your direct API requests. We do not sell personal data or run an advertising network in the app.

Providers may process information outside the EEA, including in the United States. Their contractual documentation describes applicable transfer mechanisms, such as adequacy decisions or standard contractual clauses, depending on the service and recipient. Contact us for details of the safeguards applying to processing on our behalf and how to obtain a copy. We do not promise that all provider processing takes place in the EU.

  • Railway data processing terms
  • Railway privacy policy
  • Firebase privacy and security
  • Google privacy policy

7. Your rights

Depending on the applicable conditions, you can request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time. Send requests to timofii.shkabrov@gmail.com; you do not need to create an account or pay a fee for an ordinary request. We normally respond within one month. If a lawful extension is needed because of complexity or number of requests, we will explain it within that first month.

We may request proportionate verification when necessary to avoid disclosing someone else’s data. We cannot retrieve records stored only on your device or erase records held independently by an exchange. You may complain to the supervisory authority in your EEA country of habitual residence, workplace or the place of the alleged infringement. This does not require contacting us first.

  • EEA data protection authorities
  • How to delete your data

8. Backups and security

Export is an action you control. The exported JSON contains portfolio information and account labels, but not API keys or secrets. Exported files are not encrypted by AirCapital. The temporary sharing file is removed when sharing finishes; copies you save or share remain under your control and the recipient’s rules. Protect those copies and delete them separately when no longer needed.

Device encryption, secure credential storage, HTTPS and optional biometric protection reduce risks but do not eliminate them. Protect your device, use read-only exchange keys, and revoke compromised keys at the exchange. No support request should require you to reveal an API secret.

9. Children, decisions and changes

AirCapital is a portfolio monitoring utility and is not directed specifically at children. Exchange account eligibility is governed by each exchange and applicable law. If you believe a child has sent us personal information without the required permission, contact us so we can assess and address it.

We do not make solely automated decisions producing legal or similarly significant effects about you. Changes to this policy will be dated on this page. We will seek new consent where a change to optional processing requires it.

AirCapital.

A clearer view of your crypto.

HomeDemoFAQContact
Privacy policyTerms of useCookies and analyticsDelete your dataLegal notice
© 2026 AirCapital
iOS · Android