CoinFlow

CoinFlow Privacy Policy

Last updated: September 1, 2026

CoinFlow is a portfolio tracking application that allows users to follow the cryptocurrency market and record their own portfolio transactions. This policy explains what data CoinFlow processes, where it is stored, and the choices available to users.

1. Data We Process

Registered Accounts

When you create or sign in to a CoinFlow account, the following information may be processed:

Your password is not visible to the CoinFlow developer and is not stored in the CoinFlow database. Password-based registration, sign-in, reauthentication, and password reset operations are handled by Google Firebase Authentication.

Portfolio and Favorites

For registered users, portfolio transactions entered manually in the app—including the crypto asset name and symbol, buy or sell type, amount, unit price, and transaction date—and favorite cryptocurrency identifiers are stored locally on the device and transmitted to Google Cloud Firestore for synchronization across the user’s devices. These records are associated with the user’s account identifier.

CoinFlow does not connect to bank or cryptocurrency exchange accounts and does not collect bank account details, payment card details, wallet private keys, or recovery phrases. Portfolio records are entered manually by the user.

Guest Use

When you select “Continue as Guest,” CoinFlow does not transmit portfolio transactions or favorites to Firestore. They remain stored only on the device. If a Firebase session is active when guest mode is selected, that session is signed out first.

Information Stored on the Device

Language, currency, biometric lock preference, onboarding status, and information needed to display the current session may be stored on the device. CoinFlow does not receive or store Face ID or Touch ID biometric data; biometric verification is performed by Apple’s operating system.

Technical and Market Data Requests

CoinFlow may send network requests to third-party market data services to display cryptocurrency prices and market information. As a natural part of network communication, those services may process limited technical information such as the IP address, request time, and device or network information.

2. How We Use Data

Data is processed only to:

CoinFlow does not use personal data for behavioral advertising, track users across third-party apps or websites, or sell personal data.

3. Service Providers and International Processing

CoinFlow uses the following Google Firebase services:

When these services are used, data may be processed on infrastructure operated by Google outside the user’s country. The processing and storage location depends on the Firebase project configuration and Google’s infrastructure.

For more information about Google’s practices, see:

Data may also be disclosed to authorized public authorities when required by applicable law.

4. Retention and Deletion

Information associated with a registered account may be retained in Firebase Authentication and Cloud Firestore while the account remains active and for as long as needed to provide the service.

Users can initiate deletion of their account and associated data through Profile → Delete Account in the app. When deletion succeeds:

If a technical failure occurs during deletion, the account may remain active. To prevent data loss, a temporary recovery copy created immediately before deletion is used only to restore the operation and is not retained as an additional permanent copy after the process completes. If an error is shown, the user may try again later or contact us using the address below.

Uninstalling the app alone does not automatically delete a registered Firebase account or its cloud data. The in-app account deletion option must be used to delete them.

Guest data remains only on the device and may be removed when the app is uninstalled or local application data is cleared.

5. Data Security

Firebase connections use encrypted connections during transmission. Firestore access is restricted by security rules designed to allow signed-in users to access only the data stored under their own user identifiers. However, no method of electronic storage or transmission can be guaranteed to be completely secure.

6. User Rights

Depending on applicable law, users may have rights to request information about, access, correct, delete, restrict the processing of, or object to the processing of their personal data. Users in Türkiye may have rights under Law No. 6698 on the Protection of Personal Data, and users in the European Economic Area may have GDPR rights where applicable.

When submitting a request, you may be asked to provide the email address associated with your CoinFlow account. Only the information necessary to verify your identity and fulfill the request will be requested.

7. Children’s Privacy

CoinFlow is not specifically directed to children and does not knowingly seek to collect personal data from children. If you believe that data belonging to a child has been processed, please contact us to request its deletion.

8. Changes to This Policy

This policy may be updated when application features, service providers, or legal requirements change. The current version will be published on this page and the “Last updated” date will be revised.

9. Contact

For questions about privacy practices, personal data, or deletion requests:

Email: eceakcay.dev@gmail.com

Application: CoinFlow

This policy is provided for general informational purposes and does not constitute legal advice.