1.Data controller
The controller of your personal data is Celsmar, based in Madrid, Spain. Contact for any privacy matter: [email protected].
2.What data we process
- Account data: email, password (stored as a secure hash, never in plain text) and, if you choose to provide them, name and profile photo. If you sign in with Google, we receive from Google your email, name and profile photo to create or authenticate your account (see section 3).
- Application usage data: your portfolio, watchlists, language/theme preferences and settings. With cloud sync enabled they are stored in your profile; otherwise they stay only in your browser.
- Billing data: if you purchase a paid plan, Stripe processes the payment and we receive only the necessary metadata (plan, subscription status, country, last 4 card digits). We never store your full card number.
- Support data: the content of messages you send us via the contact form or email.
- Technical data: IP address and minimal access logs, used for security, abuse prevention and usage limits.
We do not process special categories of data (health, ideology, etc.) and we do not make automated decisions with legal effects on you.
Cookies and local storage: we only use strictly necessary technical storage in your browser (session, language and theme). We use no advertising, profiling or third-party analytics cookies, so we display no consent banner (Art. 22.2 of the Spanish LSSI-CE).
3.Sign-in with Google (Google user data)
Celsmar lets you authenticate via Google OAuth (“Continue with Google”). This section explains how we access, use, store, share and delete Google user data, in line with the Google API Services User Data Policy.
Data Accessed
When you choose to sign in with Google, we request only the minimum scopes needed (openid, email, profile) and receive:
- Your Google email address.
- Your Google profile name.
- Your Google profile photo URL (if you have one set).
- A Google account identifier required to authenticate you securely.
We do not request access to Gmail, Drive, Calendar, Contacts, or any other Google data beyond the above.
Data Usage
We use that data solely to:
- Create or sign you into your Celsmar account.
- Identify you in the application and display your name and avatar in the profile / user menu.
- Send transactional account-related communications (e.g. security or support) when applicable.
We do not use Google user data for advertising, remarketing, data sales, credit scoring, or to train artificial-intelligence models (ours or third parties’).
Data Sharing
Data obtained from Google is processed within Celsmar and hosted with our authentication and database provider (Supabase), acting as a data processor under contract. We do not sell Google user data or share it with third parties for advertising or marketing analytics. AI providers we use for market analysis receive market queries only (ticker and financial data), with no user-identifying data and no Google user data. We would disclose data to public authorities only where legally required.
Data Storage & Protection
Account data originating from Google is stored in our database with encryption in transit (TLS), per-user isolation via row-level security (RLS) policies, short-lived session tokens, and provider keys held exclusively server-side. We do not store your Google account password.
Data Retention & Deletion
We retain Google data linked to your account while the account is active. You may request deletion at any time:
- From the app: My account → Data (delete your account and data).
- By writing to [email protected] from your account email.
After a request, we erase your profile and state (including data obtained from Google) within 30 days; backups rotate within 90 days at most. You may also revoke Celsmar’s access to your Google account in Google’s security settings (myaccount.google.com/permissions); that does not automatically delete data already stored in Celsmar — use the account deletion path above for that.
4.Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing the service / authentication (email or Google) | Account, Google data, application usage | Performance of contract (Art. 6(1)(b)) |
| Managing subscriptions and billing | Billing | Contract (Art. 6(1)(b)) and legal tax obligation (Art. 6(1)(c)) |
| Support and inquiries | Support | Contract / legitimate interest (Art. 6(1)(b), 6(1)(f)) |
| Security and abuse prevention | Technical | Legitimate interest (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) — we currently send no marketing |
5.Who we share data with
We do not sell your data or share it with third parties for advertising. To operate the service we rely on technology providers acting as data processors, under contract and on our instructions, in the following categories:
- Authentication and database (Supabase): hosting your account, profile, application state and, if you use Google, the identity data received via OAuth.
- Identity provider (Google): only when you choose “Continue with Google”; Google authenticates your identity and provides the data described in section 3.
- Payment processing: managing subscriptions and billing.
- Infrastructure, security and email: DNS, abuse protection and message routing.
- AI analysis generation: market queries only (ticker and financial data), with no user-identifying data.
We may also disclose data to public authorities where legally required.
6.International transfers
Some of these providers (including Google and infrastructure providers in the United States) process data outside the European Economic Area. Such transfers rely on appropriate safeguards under Chapter V of the GDPR: Standard Contractual Clauses approved by the European Commission and/or the provider's participation in the EU-U.S. Data Privacy Framework.
7.Retention periods
- Account and usage data (including Google data): while your account is active. Upon deletion, we erase your profile and state within 30 days (backups rotate within 90 days at most).
- Billing: up to 6 years, under Spanish commercial and tax law (Art. 30 of the Commercial Code).
- Support messages: up to 2 years from the last interaction.
- Technical security logs: up to 12 months.
8.Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability:
- From the app itself: My account → Data (export or delete your data).
- By writing to [email protected] from your account email. We will reply within one month at most.
If you believe we have not properly handled your rights, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.
9.Security
We apply appropriate technical and organisational measures: TLS encryption on all connections, securely hashed passwords, per-user data isolation via row-level security (RLS) policies, short-lived session tokens, and provider keys held exclusively server-side.
10.Minors
The service is intended for people aged 18 or over. We do not knowingly collect data from minors; if we detect a minor's account we will delete it.
11.Changes to this policy
If we make material changes to this policy, we will notify you by email or through an in-app notice before the change takes effect. The current version date appears at the top of this page.