Privacy Policy
Last updated: 2026-08-27. This policy describes the public website and optional account services.
1. Controller
The controller is the provider named in the Imprint.
2. Hosting
RubikVault is hosted on Cloudflare Pages (Cloudflare, Inc., USA). When the website is accessed, Cloudflare processes technically required connection data to deliver the site and protect availability and security. The legal basis is legitimate interest in secure and reliable operation.
3. Server Logs
Technical access data may be processed, including IP address, date and time, requested resource, status code, referrer and user agent. This processing is performed by the hosting provider for delivery, abuse prevention and security. RubikVault does not use these logs to identify individual visitors.
4. External Resources
Core public pages use self-hosted fonts and do not load Google Fonts. Main pages, legal pages and methodology pages may include Cloudflare Web Analytics through Cloudflare Pages. Links to external social platforms are normal outbound links; data is transferred to those platforms only after an active click.
Some specialized legacy analysis pages may load chart libraries from public CDNs when opened directly. Those pages are not required for the core public experience and should be treated as separate technical analysis surfaces.
Google Analytics is disabled. RubikVault does not load the Firebase Analytics SDK. Firebase Crashlytics collection is disabled in public release builds; any later public activation requires prior legal review and an updated notice.
5. Cookies, Local Storage and Analytics
RubikVault does not use non-essential cookies, heatmaps or session recording on the core public website. Cloudflare Web Analytics may process aggregate page-view, device and performance metrics for operational analytics. Cloudflare states that this analytics product does not use cookies or localStorage to track visitors across sites. RubikVault also records allowlisted first-party aggregate events such as page area, navigation action, search, save/share action, coarse error class and web/iOS/Android channel. These events contain no raw IP address, user agent, free-form error message, session replay, heatmap, or persistent anonymous visitor identifier. Account-linked lifecycle events are retained for at most 90 days; anonymous reports contain aggregates only. RubikVault creates no attribution cookie. When a visitor deliberately starts account creation from a tagged RubikVault link, allowlisted UTM source and campaign values may travel directly in that explicit sign-in request and become first-touch account data after signup. They contain no visitor identifier and can be exported or deleted with the account. Local browser storage may be used for convenience features such as local preferences or watchlists; browser-local watchlists remain on the visitor's device unless the visitor signs in and explicitly uploads them to optional cloud sync.
6. Optional Accounts, Billing and Notifications
If accounts are activated and a visitor chooses to sign in, Google Firebase Authentication processes the login method, provider subject identifier, verified email address and optional display name. With email login, Firebase receives and verifies the password; RubikVault does not receive or store it. Google sign-in transfers data only after the visitor starts that sign-in flow. RubikVault account sessions use a strictly necessary secure, HttpOnly cookie. Cloud watchlists, private notes, alert preferences, registered notification devices and consent records are stored in Cloudflare KV only after the visitor uses the respective feature.
Authenticated users may voluntarily send structured feedback or diagnostics with explicit consent. Fixed category, reason, rating, feature area, severity/error code, app surface/version, consent version and a pseudonymous RubikVault account ID are stored in Google Cloud Firestore for up to 90 days. Reports contain no free text, email, name, raw route, content/ticker identifier, raw IP address, user agent, password, authentication token, payment, portfolio, brokerage, session or anonymous visitor data. Direct client access is denied; a narrowly scoped RubikVault server gateway creates, exports and deletes reports. Users may export their own records; account deletion removes them, and other users cannot read them. RubikVault's operator reviews them through protected account infrastructure. Account deletion re-authenticates, removes these records and the RubikVault account, then removes the Firebase identity. A failed final identity removal is retained as a local retry action. A recent sign-in may be required by Firebase for this security-sensitive action.
If Premium billing is activated, Stripe processes payment and billing details. RubikVault stores only the Stripe customer/subscription identifiers and entitlement state needed to provide Premium; full card data is not stored by RubikVault. Account-scoped Cloudflare Durable Objects serialize the one-trial state and native-store transaction ownership across Web, Apple and Google. Account deletion removes that trial state; no person-lifetime trial tombstone remains. A pseudonymous account/customer deletion guard expires after 180 days and only stops delayed signed billing events from recreating deleted account data. If email delivery is activated, the configured delivery provider processes the email address and message delivery metadata. Browser push notifications require an explicit browser permission and store the generated push subscription until removed.
Newsletter subscriptions use double opt-in and remain separate from account service messages. Referral attribution stores an opaque account identifier, referral code and claim timestamp; no financial reward is active. Learning-challenge progress stores answers, completion counts and streaks. Native iOS and Android apps use the same account authority and may register an app push token only after explicit permission.
7. Legal Basis and Retention
Processing is based on legitimate interest in operating a secure informational website. Technical log data is retained only as long as required for operation, security and troubleshooting by the respective provider. Optional account and Premium processing is used to perform the requested service or contract; marketing email, browser push, and voluntary feedback submission require the applicable consent. Session records expire automatically. Structured feedback and diagnostic records are read-blocked after 90 days and removed by a daily owner-controlled purge or with account deletion; statutory evidence duties remain unaffected. Account data can be exported and deleted from the Account page. Account deletion is not blocked by an active app-store subscription; store subscriptions remain separately manageable with Apple or Google. Web billing is terminated before account deletion so charges are not orphaned. Commercial and tax records are retained only where a statutory duty requires it.
8. Your Rights
Depending on applicable law, you may have rights to access, rectification, deletion, restriction, portability, objection, withdrawal of consent and complaint. The competent authority for the controller's location is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia. Requests can be sent to the contact address listed in the Imprint.
9. Detailed Processing Inventory and Data Provision
The versioned processing inventory lists purposes, legal bases, data categories, recipients, international-transfer status, retention criteria, whether provision is required, and the consequence of not providing data. RubikVault does not use personal data for automated decisions that produce legal or similarly significant effects. Public market classifications concern assets, not users.
10. Updates
This policy will be updated if the website's data processing changes.