Privacy Policy
1. Overview & Architecture
This Privacy Policy explains how Pascual J. Ruiz ("MODUSYN", "we", "us", or "our") collects, uses, processes, and protects your information when you use the MODUSYN mobile application and website (https://modusyn.app).
MODUSYN operates under a privacy-preserving hybrid architecture:
- Local Storage: Your trade records, execution timestamps, P&L amounts, notes, and behavioral metrics remain strictly on your physical device.
- Authentication: We use Google Identity Services to authenticate users without creating or storing a server-side user database.
- Subscriptions: Subscription entitlements are managed via RevenueCat and Google Play Billing using a pseudonymous user identifier.
- AI Coaching: MODUSYN Pro features process ephemeral statistical summaries to generate coaching recommendations without logging raw trade logs.
2. Information We Process
A. Information Stored Locally on Your Device
When you log trades and track behavioral focuses in MODUSYN, the following information is written to your device's private SQLite database (via Room):
- Trade logs: financial symbols, prices, P&L values, execution tags, and user notes.
- Behavioral focus commitments and frozen baseline parameters.
- Deterministic evidence calculations and Before-vs-Since evaluation records.
This data is stored 100% locally and is never automatically synchronized to our servers.
B. Information Processed for Account & Authentication
If you choose to sign in using Google Sign-In:
- Google Account Email: Retrieved via Google Credential Manager and cached in local app preferences solely for user interface display. Our servers do not persist your email address in a database table.
- Google Subject ID (`sub`): Used ephemerally by our stateless Edge AI Gateway to cryptographically derive a pseudonymous identifier (
usr_<base64url>) using a secure server-held secret (HMAC-SHA256). - Google Display Name: We do not request, read, persist, or transmit your Google display name.
C. Information Processed for Subscription Entitlements
If you subscribe to MODUSYN Pro:
- Pseudonymous User ID: Your derived identifier (
usr_<base64url>) is registered with our subscription infrastructure provider, RevenueCat, Inc. - Purchase & Entitlement Data: RevenueCat and Google Play process purchase receipts, expiration dates, renewal status, and subscription state.
- Technical SDK Metadata: RevenueCat automatically processes standard connection metadata, including client SDK version, operating system version, device model, and country/locale derived from your connection IP address.
D. Information Processed for AI Coaching (MODUSYN Pro)
When you request AI Coaching for an observed behavioral pattern:
- A minimal, aggregated statistical payload is sent to the Edge AI Gateway (pattern type, group sample counts, adherence rates, and percentage differences).
- Raw trade history, ticker symbols, prices, execution timestamps, and personal reflection notes are NEVER transmitted.
- MODUSYN Edge AI Gateway: MODUSYN's Edge AI Gateway processes AI Coaching payloads ephemerally and does not persist request payloads (zero application payload retention).
- OpenAI API Inference: AI Coaching requests are sent to OpenAI's API for inference. OpenAI does not use API Platform business data to train its models by default unless the customer explicitly opts in. Under standard API data handling, API inputs and outputs may be retained by OpenAI for up to 30 days to provide the service and identify abuse. MODUSYN does not currently represent its OpenAI integration as operating under Zero Data Retention.
3. How We Use Your Information
We process information solely for the following legitimate purposes:
- App Functionality: Providing local trade analytics, behavioral pattern detection, and progress tracking.
- Entitlement Verification: Ensuring that active MODUSYN Pro subscribers can access premium coaching capabilities.
- Security & Abuse Prevention: Cryptographically verifying Google tokens and protecting gateway infrastructure.
We do NOT sell your data. We do NOT use advertising trackers. We do NOT serve targeted advertisements.
4. Third-Party Service Providers
We work with a minimal set of trusted third-party service providers:
- Google Identity & Google Play (Google LLC): Authentication and in-app billing.
- RevenueCat, Inc.: In-app purchase receipt validation and subscription management.
- OpenAI, L.L.C.: Large language model inference for MODUSYN Pro coaching recommendations. API inputs and outputs are not used for model training by default, and may be retained by OpenAI for up to 30 days under standard API data handling to provide the service and identify abuse. MODUSYN does not represent its OpenAI integration as operating under Zero Data Retention.
- Google Cloud (Cloud Run): Ephemeral hosting for the Edge AI Gateway with standard server infrastructure access logging (IP address, user-agent, HTTP status; zero application payload retention).
5. Data Retention & Deletion Rights
A. Deleting Local Data
You can purge all on-device SQLite trades, notes, and focus history at any time from within the app:
You → Account & Data → Delete Local Data.
Alternatively, uninstalling the application from your Android device immediately purges all local app sandbox data.
B. Deleting Your Account & Subscriber Records
You have the right to delete your pseudonymous subscriber records:
- In-App Deletion: Authenticated users can tap
You → Account & Data → Delete Account & Datato trigger remote RevenueCat customer deletion and purge all locally stored SQLite trade and focus records from the device. - Web Post-Uninstall Deletion: If you have uninstalled the app, you can delete your remotely held subscriber record online at https://modusyn.app/delete-account by signing in with Google. Note that web deletion operates exclusively on remote RevenueCat subscriber records; it does not and cannot remotely access or erase local database files from an installed device.
- Support Deletion: You may email support@modusyn.app with your Google Play Order Number (
GPA.XXXX-XXXX-XXXX-XXXXX) or your MODUSYN User ID (usr_...) to request manual subscriber record erasure in RevenueCat.
6. Governing Law & Jurisdiction
This Privacy Policy and any inquiries or disputes arising under it shall be governed by and construed in accordance with the laws of Spain and applicable European Union data protection regulations (including the GDPR), without prejudice to any mandatory consumer or data protection rights that may apply under the laws of your country of residence.
7. Contact Us
If you have questions, data protection inquiries, or requests regarding this Privacy Policy, please contact:
Pascual J. Ruiz
Email: support@modusyn.app
Website: https://modusyn.app