Privacy and retention

Updated 4 October 2026. Natalyst stores your account credential, account settings, Portfolios, Investments, Investment Transactions, calculated Realized PnL Records, income, expenses, monthly plans and value snapshots to operate your portfolio tracker.

The app stores its account credential and token in browser local storage, including the native WebView. Portfolio snapshots and response data are stored locally for continuity. Biometric locking controls local display; it does not encrypt these stores. Protect your device and save your secret in a password manager.

The API runs on OVH, uses MongoDB Atlas, and is reached through Cloudflare. Market-price requests may contact Yahoo Finance (including BIST), CoinGecko, Finnhub, Binance TR and Binance futures, Fibabanka, exchange-rate services, GoldPrice and Kitco. These receive market symbols/currencies and server network information; financial history is not intentionally sent to them. Provider approval for public redistribution is still a release gate.

Application diagnostics include request IDs, User IDs, paths, statuses, timing and sanitized errors. Up to 1,000 log entries are retained in backend memory; infrastructure/container logs and monitoring have separate operator retention which must be verified before public release. No advertising or product analytics SDK is configured in this repository. Infrastructure operators may process network metadata.

Confirmed account deletion removes live account-owned records and credentials and closes active account streams. Successful in-app deletion clears this device’s private snapshots, response data and credential. Other devices may still have offline copies: clear their app/browser storage.

Encrypted database archives are retained about 30 days on the VPS. Existing Mac copies have historically been retained indefinitely. A 35-day Mac expiry implementation is available but is not verified as activated. Therefore no finite end-to-end backup-erasure period is promised. Planned offsite backups also require lifecycle verification. Backups cannot be selectively rewritten to erase one account.

Minimal deletion metadata (original User ID, a SHA-256 digest of the account secret, deletion state and timestamps) is retained indefinitely in MongoDB and a separate persistent deletion ledger to prevent old restores from reactivating deleted accounts. It contains no raw device secret or JWT signing key. Restores require the current ledger and are blocked if it is unavailable.

Account access is recovered only with the saved device secret. Natalyst has no email/password recovery. Possession of the secret grants access and authorizes deletion. Read deletion instructions.

Contact: [email protected]. Never email your device secret, token or financial history.