Privacy Policy
How Capitelize handles your personal data.
Last updated: 20 August 2026
Capitelize is an application for technical and fundamental analysis of listed companies. This policy explains what personal data we collect when you use it, why we collect it, who else sees it, and what you can ask us to do about it. It covers the Capitelize web application at capitelize.com and the Capitelize apps for Android, iOS and macOS.
1. Who is responsible for your data
The controller for the purposes of the EU General Data Protection Regulation (GDPR) is:
Pavon Mason GmbH
Gassergasse 22/19
1050 Vienna, Austria
Commercial register: FN 647577 w, Handelsgericht Wien
Email: support@capitelize.com
We have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR. Address any data protection question to the email above.
2. What we collect
Account data
When you create an account we collect the username, email address and password you provide, and optionally your first name and last name. Passwords are stored only in hashed form and are never readable by us.
Your profile page lets you add further details, all of them optional: a phone number, a LinkedIn address, an X (Twitter) address, and whether you want to receive emails and notifications from us. We store what you choose to enter there, and you can change or clear any of it at any time.
Sign-in through Google or Apple
If you choose Sign in with Google or Sign in with Apple, that provider tells us your email address, your name where you allow it, and a stable identifier for your account with them, which we store so we can recognise you on your next sign-in. We never receive your password for those accounts. Apple lets you hide your email address, and we support that.
Subscription and payment data
Subscriptions are processed by our payment providers, not by us. We never see or store your full card number, and we never store payment credentials of any kind. We do receive and store the status of your subscription — which plan, whether it is active, and when it renews or ends — together with the transaction identifier issued by the payment provider, which we need in order to unlock paid features and to answer billing questions.
Usage data
We store the content you create in the app on our servers, so that it follows you between devices. Today that means your list of favourite companies. Our servers also keep ordinary web-server logs of requests, including IP address, timestamp and the requested address, which we use to operate and secure the service.
We also record how the app itself is used, so we can see which parts work and which do not. These events are our own and are sent to our own servers: which screen you opened, which company symbol a chart or analysis was opened for, which tab was chosen, how long a run in the game lasted, and how far you got through the introduction. Each event carries its name, those details and the time it happened.
Each event carries a random identifier that the app creates the first time it needs one. That identifier is not your name, your email address or your account number, and it is never shared with anyone outside our own servers.
It is not anonymous, though, and we would rather say so than let the word “random” do work it cannot do. When you are signed in, the request carrying these events also carries your login token, so events recorded while you are signed in can be associated with your account. The identifier itself also stays on your device when you sign out — it is cleared only when you uninstall the app or clear the site's data — so on a shared device it spans whoever uses that browser or installation.
Crash and error reports
When the app hits an unexpected error it can send a report so we can fix it. The report describes what went wrong — the error, where in the code it happened, and what the app was doing shortly beforehand — together with your device type, operating system and app version. Web addresses in these reports have their query strings removed and known sensitive fields are stripped before sending, so the report describes the fault rather than your data. These reports are processed by Sentry on our behalf; see section 5.
Data stored on your own device
The app keeps the following on your device, and none of it is sent anywhere except as already described above:
- a refresh token, used to keep you signed in. On mobile and desktop it is held in the operating system's secure store — the Keychain on Apple platforms, the Android Keystore — and it is replaced with a new one each time it is used;
- a cached copy of your own profile, so the app can show your details before it has reached the network;
- your language choice;
- whether you have seen the introduction, and whether you have acknowledged the risk disclaimer, so that neither is shown to you twice;
- the countries you last viewed in the macro dashboard, to offer them again;
- any subscription receipt our server has not yet confirmed, so that a purchase interrupted by a lost connection is not lost with it;
- the random analytics identifier described above.
The short-lived access token used for each request is not stored at all: it is held in memory and obtained afresh from the refresh token when the app starts.
Signing out deletes the refresh token and the cached copy of your profile. The remaining items are settings rather than account data, and stay until you uninstall the app or clear the site's data in your browser.
We do not use cookies to track you, and there are no advertising or third-party analytics cookies. The analytics identifier described above is not a cookie and is never sent to another company, but it is stored on your device and we describe it here rather than leaving it to the word “cookie” to cover.
3. What we do not do
- We do not use third-party analytics or advertising SDKs. The product analytics described in section 2 are our own: the events go to our own servers and to no one else.
- We do not display advertising and there are no advertising networks in the app.
- We do not track you across other apps or websites, and we do not build advertising profiles.
- We do not sell your personal data, and we do not share it with data brokers.
4. Why we use your data, and on what legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and running your account; giving you the features you ask for | Account data, usage data | Performance of a contract — Art. 6(1)(b) |
| Processing your subscription and giving you access to paid features | Subscription status, transaction identifier | Performance of a contract — Art. 6(1)(b) |
| Service emails: account activation, password reset, billing notices | Email address | Performance of a contract — Art. 6(1)(b) |
| Keeping the service secure and preventing automated abuse of sign-up and password reset | IP address, server logs, reCAPTCHA signals | Legitimate interests — Art. 6(1)(f) |
| Understanding how the app is used, so we can improve it | Analytics events and the random identifier described in section 2 | Legitimate interests — Art. 6(1)(f) |
| Finding and fixing faults and crashes | Crash and error reports, device and app version | Legitimate interests — Art. 6(1)(f) |
| Keeping records required of us by tax and company law | Transaction records | Legal obligation — Art. 6(1)(c) |
5. Who else processes your data
We use the following providers. Each acts on our instructions as a processor, except where noted, and each receives only what it needs for its own function.
| Provider | Function | What it receives |
|---|---|---|
| Google Ireland Ltd. / Google LLC — reCAPTCHA | Distinguishing people from bots on sign-up and password reset | IP address, browser and device signals, interaction data. Loaded only when you open sign-up or password reset, not on every page. |
| Google — Sign-In | Optional sign-in method | Only used if you choose it. Google acts as an independent controller for your Google account. |
| Google — Play Billing | Subscriptions purchased in the Android app | Payment details, which Google holds as an independent controller. We receive only the purchase status and identifier. |
| Apple Inc. — Sign in with Apple, App Store purchases | Optional sign-in method; subscriptions purchased in the iOS and macOS apps | As above. Apple acts as an independent controller. |
| Stripe, Inc. / Stripe Payments Europe Ltd. | Card payments made through the web app | Your payment details, entered on Stripe's own checkout page. We never receive them. |
| Functional Software, Inc. (Sentry) | Receiving crash and error reports so we can fix faults | The report contents described in section 2: the error, where it happened, recent app activity, device type, operating system and app version. Query strings and known sensitive fields are removed before sending. |
| Contabo GmbH, Germany | Hosting the application and its database | All data described in this policy, on servers in the European Union |
Market, company and fundamentals data shown in the app comes from third-party data sources. That is information about listed companies, not about you, and no personal data is sent to those sources.
6. Transfers outside the EU/EEA
Our servers are in the European Union, so ordinary use of the service involves no transfer of your data outside the EEA.
Google, Apple, Stripe and Sentry are US companies and may process data outside the EEA. We use each of them on their standard terms, which incorporate the European Commission's standard contractual clauses and, where the provider participates, certification under the EU–US Data Privacy Framework. We have not negotiated separate arrangements with them, and we have no influence over how they process data as controllers in their own right.
7. How long we keep it
We keep your account data for as long as your account exists. When you delete it — see section 8 — we erase or anonymise your personal data, except records we are required to retain, principally billing records, which Austrian law requires us to keep for seven years.
Web-server logs are kept no longer than necessary for the security and operation of the service, and are then deleted.
Usage events and crash reports are kept only for as long as they are useful for the purpose they were collected for — understanding how the app is used, and fixing faults — after which they are deleted. Crash reports are held by Sentry under its own retention period for our account.
Deleting your account does not by itself erase past usage events, because the identifier they carry is not stored against your account and we cannot reliably find them from it. If you want those removed as well, ask us using the contact details in section 13 and we will handle it as an erasure request.
8. How to delete your account
You can delete your account yourself, at any time, without asking us.
In the app: open Settings and choose Delete account. You will be asked to confirm your identity — by entering your password, or by signing in again with Google or Apple if that is how you sign in — because the deletion cannot be undone.
Without the app: if you cannot sign in, write to support@capitelize.com from the address on the account. We will verify who you are and delete it for you, and we answer within one month, as Art. 12(3) GDPR requires.
Deletion takes effect immediately. Your name, email address, username, phone number and any profile links are erased or anonymised, your sign-in identifiers are removed, you are signed out on every device, and any subscription billed through this website is cancelled. The billing records we are legally required to keep are retained for seven years and nothing else is.
One thing we cannot do for you. If you subscribed inside the iOS or Android app, that subscription is held by Apple or Google, not by us, and deleting your account does not cancel it. Cancel it in your App Store or Play Store account settings, or it will keep renewing.
9. Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you, and receive a copy (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data deleted (Art. 17);
- have processing restricted (Art. 18);
- receive your data in a portable, machine-readable form (Art. 20);
- object to processing based on our legitimate interests (Art. 21);
- withdraw consent at any time, where processing rests on consent, without affecting what was done before you withdrew it.
Write to support@capitelize.com to exercise any of these. We answer within one month, as Art. 12(3) requires. To delete your account you do not need to write to us at all — see section 8.
If you believe we have handled your data unlawfully, you may complain to a supervisory authority. In Austria that is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
10. Children
Capitelize is not intended for children. You must be at least 16 years old to create an account. We do not knowingly collect data from children, and we delete any such account we become aware of.
11. Security
All traffic between the app and our servers is encrypted with TLS. Passwords are stored hashed. Refresh tokens are held in your device's secure store, and rotate on use, so a captured token has a short useful life. Access to production systems is limited to the people who need it.
12. Changes to this policy
We will update this page when our processing changes, and we will change the date at the top. If a change materially affects you, we will tell you in the app or by email before it takes effect.
13. Contact
Questions about this policy or about your data: support@capitelize.com.