ChartScan AI
Privacy Policy
Last updated: 22 August 2026
This policy explains what ChartScan AI collects, why, who else sees it, and how long
we keep it. It covers the ChartScan AI mobile app and the API behind it at
chartscanai.com.
ChartScan AI is operated by Rashid Mohammed Rashid ("we", "us"), based in Tanzania, who is the data controller for the personal data described here. For anything in this policy, contact support@chartscanai.com.
1. The short version
We do not store your chart images. A chart you upload is held in memory only for as long as the analysis takes, sent to Anthropic's Claude API to be read, and then discarded. It is never written to our disk and never saved in our database.
What we do keep is your email address, a hash of your password, and the results of your scans — the written analysis, not the pictures.
We run no analytics, no advertising SDKs, and no third-party trackers. We do not sell or share your data for marketing, and there is nobody to sell it to.
2. What we collect
Account information
- Email address — your login identity, and how we reach you about your account.
- Password — stored only as a
bcrypthash with a per-user salt. We cannot read your password, and we cannot recover it for you; we can only reset it. - Plan — which subscription tier your account is on.
- Account creation date.
Chart images you upload
Each analysis takes three chart screenshots. When you run a scan, those images are:
- received by our server and held in memory only;
- resized and re-encoded (so we send less data than your phone captured);
- transmitted over TLS to Anthropic's Claude API to be read and analysed;
- discarded when the request finishes.
They are not written to disk, not placed in object storage, and there is no image column anywhere in our database. If you delete a chart from your phone, no copy of it survives with us.
Scan results and history
For each completed scan we store:
- the trading style you selected (scalping, day trading, or swing trading);
- the three timeframe labels involved (for example
4H,1H,15M); - the analysis Claude produced — bias, probability, confidence, confluence score, key factors, support and resistance levels, and the written reasoning;
- the date and time.
This is what populates your History tab. Note that the analysis text can mention the instrument it read from your charts (for example "XAUUSD"), so your history is a record of what you have been analysing.
Usage records
Each analysis attempt is recorded as a timestamp against your account. This is how scan quotas are enforced. It contains no content — only that an attempt happened and when.
Session records
When you sign in we store a hash of your session's refresh token, plus when the session was created, when it expires, when it was last used, and whether it has been revoked. This is what makes "Sign Out All Devices" work. We do not record device names, advertising identifiers, or IP addresses against sessions.
Server logs
Our web server writes a standard access log: IP address, timestamp, the request path, response status, and user-agent string. These exist for security and debugging — spotting abuse, diagnosing outages — and are rotated and deleted on a 14-day cycle. In some jurisdictions an IP address is personal data, which is why it is listed here.
Payment information
Subscriptions are not live yet. When they launch, they will be processed entirely by Google Play Billing. Google handles the payment; we receive confirmation that a subscription is valid and set your plan accordingly. We never receive, see, or store your card number, bank details, or billing address.
3. What we do not collect
- No cookies. The app is not a browser client and sets none. These policy pages set none either.
- No analytics or telemetry SDK in the app. Nothing on your device reports your usage, your behaviour, or crashes to us or to anyone else. Our server reports its own errors to a monitoring service, which is described in section 5 — those reports are about our code failing, not about you.
- No advertising identifiers, and no advertising.
- No location data.
- No contacts, photos library scanning, microphone, or camera access beyond the images you explicitly pick for a scan.
- No cross-app or cross-site tracking.
4. Why we process it
| Data | Purpose | Basis |
|---|---|---|
| Email, password hash | Create and secure your account | Performance of our contract with you |
| Chart images | Produce the analysis you asked for | Performance of our contract with you |
| Scan results | Show your history across devices | Performance of our contract with you |
| Usage records | Enforce plan quotas; control cost and abuse | Legitimate interest |
| Session records | Keep you signed in; allow remote sign-out | Performance of our contract; security |
| Server logs | Security, abuse prevention, debugging | Legitimate interest |
| Subscription status | Grant the capacity you paid for | Performance of our contract with you |
5. Who else is involved
Anthropic (Claude API)
Your chart images and the analysis prompt are sent to Anthropic to be processed. This is the core of what the app does — without it there is no analysis.
Under Anthropic's commercial terms, Anthropic does not train its models on data sent through the API, and rights in the inputs and outputs remain with the customer. Anthropic retains API data for a limited period for safety and abuse monitoring. For the current specifics, see Anthropic's privacy centre and its commercial terms.
Google Play
Distributes the app and, once subscriptions launch, processes payments. Google's own privacy policy governs what it collects when you download or pay. We receive subscription status, not payment details.
Hosting
Our server is a virtual private server rented from Contabo GmbH, a German company, and the machine itself is located in the United Kingdom. They provide the hardware; they do not process your data on their own behalf. Database backups are stored on that machine and copied to the operator's own computer.
Sentry (error monitoring)
When our server hits an unexpected error, a report is sent to Sentry so the fault can be found and fixed. This is about our code failing, not about you: it runs on our server only, and there is no Sentry code inside the app on your phone.
A report contains the error, the line of our code that failed, and the request path that triggered it. It is deliberately configured so that it does not include your email address, your account identifier, your IP address, your session or authorization token, the contents of your request, or your chart images. In particular the values held in memory at the moment of the failure are excluded, because those can contain a password being checked.
Reports are stored in Sentry's European region, in Frankfurt, Germany, and are deleted after 30 days. See Sentry's privacy policy.
That is the complete list. We use no other processors, and we do not sell, rent, or trade personal data to anyone.
6. How long we keep it
| Data | Retention |
|---|---|
| Chart images | Not retained — discarded when the scan completes |
| Account (email, password hash, plan) | Until you delete your account |
| Scan results and history | Until you delete your account, or ask us to clear your history |
| Usage records | Until you delete your account |
| Sessions | Expire after 30 days; revoked immediately on sign-out |
| Server access logs | 14 days, then automatically deleted |
| Server error reports (Sentry) | 30 days, then automatically deleted |
| Database backups | 14 days on the server, plus off-box copies held by the operator |
About backups. When you delete your account, your data is removed from the live database immediately. Backups taken before that point still contain it, and those roll off on the retention schedule above. We do not edit historical backups, because a backup you have altered is a backup you cannot trust to restore. Your data is fully gone once the last backup containing it expires.
7. Security
- All traffic between the app and our server uses HTTPS/TLS. The app talks to no other host.
- Passwords are hashed with bcrypt and never stored or logged in plain text.
- Session refresh tokens are stored hashed, so a database leak does not hand over live sessions. Sessions rotate on every refresh and can be revoked instantly.
- Access tokens are short-lived (15 minutes), limiting the damage if one is intercepted.
- The application connects to the database as a restricted role, not as an administrator.
- Chart images are never persisted, which removes an entire category of breach.
No system is perfectly secure, and we will not claim otherwise. If you believe you have found a vulnerability, please email support@chartscanai.com before disclosing it publicly.
8. Your rights
Depending on where you live, you may have the right to:
- Access — get a copy of the personal data we hold about you.
- Export — receive it in a portable, machine-readable format.
- Correction — have inaccurate data fixed.
- Deletion — have your account and its data erased.
- Objection and restriction — object to processing based on legitimate interest.
- Complaint — lodge a complaint with your local data-protection authority.
To exercise any of these, email support@chartscanai.com from the address your account uses, or use Send Feedback in the app's Profile tab, which opens a message to the same inbox. We will respond within 30 days.
We may ask you to confirm you control the account's email address before acting. This is to stop someone else deleting your account or obtaining your history, not to create an obstacle.
Deleting your account
In the app: open the Profile tab and tap Delete Account. You will be asked to re-enter your password — deletion is irreversible, so we confirm it is really you and not someone holding an unlocked phone. Once confirmed, your account, scan history, usage records, and sessions are erased from the live database immediately. Nothing is queued for review and nothing is retained in a "deactivated" state.
Step-by-step instructions, what is erased, and how to cancel a subscription are on the Delete Your Account page.
By email: if you cannot sign in, write to support@chartscanai.com with the subject "Delete my account" from your account's email address, and we will do it for you within 30 days.
Either way, deletion is permanent and cannot be undone — we cannot restore an account or its history afterwards. The email address becomes free to register again, but that creates a new, empty account. Backups behave as described in section 6.
An active subscription must be cancelled separately in Google Play — deleting your ChartScan AI account does not cancel a Google subscription, because only Google can do that.
9. Children
ChartScan AI is not intended for anyone under 18, and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, email us and we will delete it.
10. International transfers
Our server is in the United Kingdom. Anthropic processes API requests in the United States. Server error reports stay in the European Union, in Frankfurt. Google operates globally. If you use ChartScan AI from outside these regions, your data will be transferred to and processed in them.
If you are in the EEA, this means your data leaves it. Transfers to the UK are covered by the European Commission's adequacy decision for the United Kingdom; transfers onward to Anthropic in the United States are governed by the safeguards in Anthropic's data processing terms.
11. Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect your rights — new categories of data, a new third party, a longer retention period — we will notify you in the app or by email before they take effect.
12. Contact
Rashid Mohammed Rashid, Tanzania — data controller for ChartScan AI.
support@chartscanai.com
Email is the fastest way to reach us and the address to use for any request under section 8. If you need a postal address for a formal legal or regulatory matter, ask by email and we will provide it.