Effective date: July 30, 2026 · Last updated: July 30, 2026

The Hebrew version of this Policy is the binding version. This English translation is provided for convenience only; in the event of any inconsistency, the Hebrew version prevails.


1. Introduction, Identity of the Database Controller, and Scope

1.1. This Privacy Policy (the "Policy") describes what personal data is collected in connection with your use of the Stockast application (the "App") and its accompanying services, including the official web pages of the service (together, the "Service"); how it is collected; the purposes for which it is used; to whom it is disclosed; how long it is retained; and the rights available to you with respect to it.

1.2. Database controller: The Service is operated by Yarin Zaks, an individual, Israel (the "Operator", "we"). The Operator is the "database controller" (בעל השליטה במאגר) within the meaning of the Israeli Protection of Privacy Law, 5741-1981, including Amendment No. 13 (the "Protection of Privacy Law" or the "Law"), and is the party that determines the purposes of data processing in the Service.

1.3. Controller contact details: email — support@stockast.app. This is also the address for all privacy inquiries, exercise of rights, and complaints, as set out in Sections 9 and 15 below.

1.5. This Policy forms an integral part of the Service's Terms of Use. Terms defined in the Terms of Use and not defined here have the meaning given to them there.

1.6. Use of the Service is not mandatory. Provision of personal data in connection with the Service is made of your own free will and with your informed consent, as set out in Section 2 below. If you do not agree to this Policy — do not register for and do not use the Service.

1.7. Territorial scope: The Service is directed, at this stage, at users in Israel, and during the beta period it is not offered to users located in the European Economic Area (EEA), as set out in Section 1.6 of the Terms of Use. The rights set out in Section 9 are granted to all users; the provisions expressly designated for EEA users (including Section 9.4) will become operative as of the date on which the Service is offered in the EEA, if offered, without this Policy requiring re-drafting.


2. Notice Under Section 11 of the Law — Voluntary Provision of Data and Consequences of Refusal

2.1. You are under no legal duty to provide us with personal data. Provision of data depends on your will and consent. However, some data is required as a practical condition for opening an account and for operating certain Service capabilities, so refusal to provide it has consequences, as set out in the following table:

Data categoryProvisionConsequence of refusalMain purpose
Registration details: email address, username, display name, date of birth, and the sign-in method you chose (password — stored solely as an encrypted hash, see Section 3.1)VoluntaryAn account cannot be opened and the account-based Service cannot be used. The date of birth is required to verify the age condition (18+); without it, registration is refusedOpening and managing the account; identification; age verification; sending operational messages
Sign-in data from an identity provider — Sign in with Apple or Google: identity token, email address (or an Apple private relay address), and basic profile details (see Section 3.1)Voluntary — only if you chose to sign in through that identity providerAn account cannot be opened or signed into through that provider; you may choose another sign-in method, and absent any sign-in method — no account will be openedOpening an account and secure sign-in
Profile photoVoluntary (optional)No consequence; the profile is displayed without a photoDisplaying your profile to other users
Content you create (posts, videos, comments, predictions)VoluntaryYou will not be able to publish content; the rest of the Service remains availableOperating the social feed and displaying content
Direct messages (DMs) and messages in communities and groupsVoluntaryYou will not be able to send messages; the rest of the Service remains availableOperating the messaging capabilities
Watchlists, virtual portfolio, and price alerts you configuredVoluntaryThese capabilities will not be available to you; the rest of the Service remains availableOperating the tracking and simulation capabilities
Push notification tokenVoluntary — only if you allowed notifications at the operating-system levelWe will not be able to send you push notifications (including price alerts you configured)Delivering notifications to your device
Device data, crash reports, and security and usage logsCollected automatically as an inseparable part of operating the ServiceThis collection is required for the proper and secure operation of the Service and cannot be separated from its useOperations, security, troubleshooting
Product analytics events (Mixpanel; production environment only)Subject to the consent posture in Section 13Not enabling analytics does not limit your use of the ServiceProduct improvement
Consent to receive product updates by email (marketing mailing) and the timestamp of that consentVoluntary (optional)No consequence; declining does not limit your use of the ServiceSending product updates, if and when such a mailing channel is activated (see Sections 5.1 and 8)

The provision of data to the identity provider itself (Apple or Google) in the course of signing in through it is made directly with that provider, and is governed by that provider's own terms of use and privacy policy.

2.2. This notice, together with Section 1 (the controller's identity and contact details), Section 5 (the purposes of processing), Sections 6–7 (the recipients of the data and the purposes of disclosure), and Section 9 (the access and rectification rights under Sections 13 and 14 of the Law), constitutes the notice required under Section 11 of the Protection of Privacy Law.


3. The Data We Collect

3.1. Data you provide to us directly:

3.2. Data created in the course of your use of the Service:

3.3. Data collected automatically:

3.4. What we do not collect: The Service does not include real trading, and we do not collect real financial data — no bank or brokerage account details, no payment instruments, no user funds, and no real transaction data. The portfolio in the Service is virtual and simulated only.


4. What Is Public and What Is Private in the Service

4.1. Public by design: The Service is a social network. Your user profile (username, display name, and profile photo, if uploaded) and the content you publish — posts, videos, comments, and predictions — are visible to users of the Service; that is their purpose.

4.2. Private-account setting: If you enabled the private-account setting, the display of your content and profile is limited to followers you approved, in accordance with the Service's mechanisms.

4.3. Communities and groups: Messages you send in a community or group are visible to the members of that community or group.

4.4. Private: Direct messages (DMs) are not public and are not displayed to users who are not parties to the conversation; however, we may review them in the event of a report or a substantiated suspicion of a violation, for the purposes of enforcing the Service's rules, preventing abuse, and protecting users. Your watchlists and virtual portfolio are private by default and are not displayed to other users — unless you explicitly choose to publish them using the Portfolio/Watchlist stickers in content you share; such publication requires enabling the option in advance in Settings (Settings → Privacy Controls; off by default) and an additional confirmation by you immediately before each publication.

4.5. Remember: content you published publicly may be viewed, saved, or copied by other users while it is displayed. Deleting content removes it from the Service, subject to limited retention of technical copies as set out in Section 10.


5. Purposes of Processing and Legal Bases

5.1. We process personal data for the following purposes and on the following bases — under Israeli law (informed consent and the purposes notified under Section 11 of the Law), and, to the extent the EU General Data Protection Regulation (GDPR) applies to a given user, under the corresponding EU basis:

PurposeRelevant dataBasis — Israeli lawBasis — GDPR (to the extent applicable)
Operating the Service: account management, the feed, communities, messages, watchlists, virtual portfolio, price alerts, courses, and the prediction gameAccount details, content, messages, lists and records you created, push tokenInformed consent; necessity for performing our engagementArt. 6(1)(b) — performance of a contract
Age verification (18+) at signup and an ongoing record of meeting the age conditionDate of birthInformed consent; compliance with the Terms of Use and the Service's age policy; legitimate interest in demonstrating compliance with the age requirementsArt. 6(1)(f) — legitimate interest
Service security, fraud and abuse prevention, moderation, and enforcement of the Service's rulesSecurity logs, content reports, device data, content at the time of its submission for publication (automated screening — see Section 6.1), and messages in the event of a report or suspected violationInformed consent; the legitimate interest of the Operator and of users in a safe serviceArt. 6(1)(f) — legitimate interest
Diagnosing and fixing faults and crashesCrash reports, device dataInformed consent; legitimate interest in proper operationArt. 6(1)(f) — legitimate interest
Product analytics and improvement (production environment only)Usage events (see Section 13)Informed consentConsent (Art. 6(1)(a)); see Section 13
Content personalization and ranking: composing the feed and the content recommendations displayed to youThe aggregated behavior profile and the recommendations log (Section 3.3)Informed consent; legitimate interest in service improvementArt. 6(1)(f) — legitimate interest
Operational communications: alerts you configured, service and security notices, responses to your inquiriesContact details, push token, correspondenceInformed consent; necessity for performing our engagementArt. 6(1)(b) — performance of a contract
Sending product updates by email — if and when such a mailing channel is activated (see Section 8.5); consent may be withdrawn at any time in the App settings or by contacting support@stockast.appEmail address, the consent record and its timestampExpress consent (opt-in)Consent (Art. 6(1)(a))
Compliance with legal requirements, orders of a competent authority, and managing or defending legal proceedingsAs required in the circumstancesLegal duty or authorization; legitimate interestArt. 6(1)(c) / Art. 6(1)(f)

5.2. Express statements: The Service carries no advertising; we do not sell personal data and will not sell it; we do not disclose personal data to third parties for their own marketing purposes; and we do not use data for purposes not set out in this Policy without your further consent.


6. Recipients of the Data: Service Providers and Other Parties

6.1. We use external service providers who process data on our behalf and under our instructions only ("holders" within the meaning of the Law; "processors" in EU terminology):

ProviderRoleMain processing location
SupabaseDatabase hosting and management, file storage, and authentication services (hosting)Production environment: United States — us-east-1 (N. Virginia), on managed AWS infrastructure. Development and testing environments: Frankfurt, Germany (eu-central-1)
SentryFault and crash monitoringUnited States
MixpanelProduct analytics (production environment only)United States
Expo (Expo Application Services)Two flows: (a) push notification delivery infrastructure; (b) EAS Update — delivery of application code updates, in the course of which your device contacts Expo's servers on each update check and exposes its IP address to themUnited States
SendGrid (Twilio)Operational email delivery (verification, service notices) — when a SendGrid key is configured, the message is sent through it; otherwise it is sent through ResendUnited States
ResendOperational email delivery (verification, service notices) — used when SendGrid is not configuredUnited States
CloudflareBot and abuse protection at signup (Turnstile challenge): during the challenge it receives the IP address and browser/device signals; transient verification only — it stores no at-rest account dataUnited States
MuxVideo hosting and streaming — staged rollout: the infrastructure is provisioned and the deletion pipeline already covers it, but no user video is stored there today; actual activation will be accompanied by an update of this Policy under the material-change mechanism (Section 14)United States
OpenAIAutomated analysis of user-authored content, for two distinct purposes: (a) moderation and safety — screening against violating content; (b) classification — assigning a financial-relevance score to content, which is stored alongside the content and used as an input to an automated decision whether to permit its publication in the Service. The score is not used to determine the order in which content is displayed in the feed. A third-party artificial-intelligence providerUnited States
AnthropicGeneration of market-summary content from aggregated market data only (stock tickers, prices, and news headlines). ⚠️ A path also exists in the code intended to attach prediction records published by users to those requests — staged deployment, in the same posture as Mux and Stripe: the path is not operative, and no prediction record whatsoever is transmitted to Anthropic; actual activation will be accompanied by an update to this Policy under the material-change mechanism (Section 14). On no path is a username, account identifier, or user-authored free text sent to itUnited States
StripePayment and subscription processing — staged deployment, in the same posture as Mux: the checkout pipeline exists in the code, but as of today no purchase can be made in the Service and no user data is transmitted to Stripe; actual activation will be accompanied by an update to this Policy under the material-change mechanism (Section 14)United States
Apple (APNs) / Google (FCM)The device platform's push notification relaysPer the platform's infrastructure

Express disclosure — sharing with third-party artificial-intelligence providers: User-authored text — posts and content submitted for publication in the Service — is sent to the API of OpenAI, an external artificial-intelligence provider, for two distinct purposes: (a) moderation and safety — automated screening against violating content, as part of the Service's content-safety framework; and (b) classification — assigning a financial-relevance score to the content. The score is stored alongside the content and used as an input to an automated decision whether to permit the content's publication in the Service; it is not used to determine the order in which content is displayed in the feed. Both purposes alike are covered by your consent to this Policy at signup. To Anthropic, which is used to generate market summaries, aggregated market data only is sent (stock tickers, prices, and news headlines). ⚠️ A path exists in the code intended to attach prediction records published by users (ticker, direction, entry price, target price) to those requests, but it is in staged deployment and is not operative — no prediction record whatsoever is transmitted to Anthropic; its activation will be accompanied by an update to this Policy under the material-change mechanism (Section 14). On no path is a username, account identifier, or other identifying particular sent to it, and no user-authored free text is sent to it.

6.2. Identity providers (Apple and Google): If you chose to sign in with Sign in with Apple or with Google, the identity provider discloses to us the sign-in data set out in Section 3.1 — that is, the data flows from the identity provider to us; we do not disclose data about you to the identity provider beyond what is required to perform the authentication (OAuth) transaction itself. Use of the identity provider's sign-in service is governed by that provider's own terms and privacy policy.

6.3. Equivalent level of protection: Our service providers are contractually bound to us to confidentiality, to data security, and to using the data solely to provide their services to us — at a level of protection no lower than that set out in this Policy. We do not disclose data to a provider that is not so bound.

6.4. Authorities and law: We will disclose data if required by law, a judicial order, or an authorized demand of a competent authority; and to the extent reasonably necessary to manage or defend a legal proceeding, or to protect our rights, the safety of users, or the public.

6.5. Business transfer: If the operation of the Service is transferred to another party (including in a merger, acquisition, or transfer of assets), the data will be transferred to that party subject to its assuming the commitments of this Policy toward you; we will notify you in advance of any change in the identity of the database controller.

6.6. Beyond the above, we will not disclose personal data to any third party except with your express consent. This Section concerns disclosure BY US. It does not apply to requests your device sends directly to third parties, to which we are not a party and in which we disclose nothing to them — those are set out in Section 7.1.


7. Transfer of Data Outside Israel

7.1. Personal data in the Service is stored and processed outside Israel, as follows:

7.2. Basis under Israeli law: Transfers of data outside Israel are made in accordance with the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001, principally: (a) Regulation 2(4) — a contractual undertaking by the data recipient to comply with the conditions for the holding and use of data applicable to a database in Israel (data-processing agreements with each of the service providers); and (b) Regulation 2(1) — your consent to the transfer, given as part of your consent to this Policy, which sets out the transfer destinations and purposes.

7.3. Users in the European Union / EEA: Without this constituting an admission that the GDPR applies (see Section 9.4), transfers of data to the United States rest on the data-processing agreements concluded with the service providers, which incorporate contractual transfer mechanisms including Standard Contractual Clauses (SCCs), and, as applicable, on the EU-US Data Privacy Framework where the provider is certified under it. You may contact us at support@stockast.app to receive information about the safeguards applicable to a specific transfer.

7.4. Data originating in the European Union: The European Commission recognizes Israel as a destination providing an adequate level of protection for personal data (an adequacy decision reaffirmed in a review published in January 2024), so that transfers of data from the European Union to Israel are recognized under EU law.

7.5. Hosting relocation plan: We are working to relocate the primary hosting of Service data to the European Union (Frankfurt, Germany). Upon completion of the migration, this Policy will be updated in accordance with the material-change notice mechanism in Section 14.


8. Direct Mailing, Operational Messages, and Advertising Material

8.1. Operational messages — not direct mailing: Messages sent to you as part of the operation of the Service — price alerts you configured yourself, notifications about messages and social activity concerning you, security notices, and essential service notices — are not "direct mailing" and are not advertising material. You can manage them in the App's notification settings and in your device's operating-system settings.

8.2. Direct mailing: To the extent we approach you personally based on your belonging to a characterized group ("direct mailing" within the meaning of Section 17C of the Law), each such approach will state, as required by Section 17F(a) of the Law: (a) that the approach is direct mailing; (b) your right to be deleted from the database used for direct mailing, and the address for sending the demand: support@stockast.app; (c) the identity and details of the database controller, and the sources of the data on which the approach is based.

8.3. Deletion from a mailing database: Any person may demand in writing that data relating to them be deleted from the database used for direct mailing. We will honor the demand and send you written confirmation of its execution.

8.4. Advertising material: "Advertising material" will be sent by email or text message only with prior express consent, in accordance with Section 30A of the Communications Law (Telecommunications and Broadcasts), 5742-1982, with the message labeled as an advertisement, the advertiser's details stated, and an unsubscribe option available at all times.

8.5. Current state: As of the effective date of this Policy, the Service carries no advertising and we do not send direct mailing or advertising material. Sections 8.2–8.4 will apply if and when such a channel is activated.


9. Your Rights in the Data

9.1. Rights under Israeli law

9.2. In-app rights — for every user, under this Policy

In addition to the rights under law, we grant every user, as a contractual commitment:

9.3. Exceptions to deletion

Notwithstanding the above, we may retain: (a) data we are required to retain by law; (b) security and enforcement logs for a limited period, for the purposes of preventing abuse, ban evasion, and protecting users; (c) data reasonably necessary to manage or defend legal proceedings; (d) aggregate statistical data that does not identify you.

9.4. Users in the European Union / EEA

Without this constituting an admission that Regulation (EU) 2016/679 (the "GDPR") applies to the Service or to the Operator, we grant users located in the European Union and the EEA, as a contractual commitment, the following rights with respect to their personal data: access; rectification; erasure; restriction of processing; objection to processing; and data portability (receipt of the data in a structured, commonly used format). We will respond to a request within one month. To the extent processing rests on consent — you may withdraw your consent at any time, without affecting the lawfulness of processing carried out until that time. You also have the right to lodge a complaint with a data protection supervisory authority in your country of residence.

9.5. How to exercise the rights

Rights may be exercised from within the App (export and deletion) or by contacting support@stockast.app. To protect your data, we will require reasonable identity verification before disclosing data or performing an irreversible action.


10. Data Retention

10.1. We retain personal data for as long as your account is active, and for as long as necessary for the purposes set out in this Policy. The retention period is determined by the following criteria: the existence of the account and the Service; legal requirements; the need to prevent abuse and to enforce; and the management or defense of legal proceedings.

10.2. Upon deletion of your account — Sections 9.2–9.3 above apply: the personal data will be deleted within the period stated there, except for the exceptions listed, including limited retention of security logs and removal from routine backup cycles.

10.3. Date of birth: The date of birth is collected to verify your compliance with the age condition (18+) at registration, and is retained for the life of the account as an ongoing record of meeting the age condition — including for the purpose of examining and defending against claims regarding age raised after the fact. The basis for retention: your informed consent at registration and the Operator's legitimate interest in demonstrating its compliance with the age requirements. Upon deletion of the account, the date of birth is deleted together with the rest of the data, as set out in Section 9.2. For accounts opened before the age gate and its server-side enforcement took effect, a date of birth may not be on record; for such accounts the Operator retains the right to require proof of age, as set out in Section 4.3 of the Terms of Use.

10.4. Aggregate data: Aggregate or anonymized statistical data that does not enable the identification of a person is not "personal data," and we may continue to hold it without time limitation.


11. Data Security

11.1. We implement reasonable and accepted organizational and technological security measures, in accordance with the Privacy Protection Regulations (Data Security), 5777-2017, at the security level applicable to the database, including, among other things: encryption of data in transit; access controls and need-based permissions; storage of authentication details in non-readable form; rate limits on identification mechanisms; and monitoring of security events.

11.2. No absolute security: No security measure is completely immune. We work continuously to reduce the risks, but we cannot guarantee absolute immunity of the data from unauthorized access.

11.3. Handling security events: Data security events are documented and handled. In the event of a severe security event, we will act in accordance with the reporting duties under law, including reporting to the Privacy Protection Authority where required, and we will notify affected data subjects in accordance with the provisions of law or an instruction of the Authority.


12. Children's Privacy

12.1. The Service is intended for persons aged 18 and over only and is not directed at minors. At signup, a date of birth is required, and registration is blocked for anyone under 18.

12.2. We do not knowingly collect personal data from minors under 18. If we learn that an account was opened by a person under 18 — we will cancel the account and promptly delete the personal data associated with it. We reserve the right to require proof of age at any stage.

12.3. If you are a parent or guardian and believe that a minor in your care has provided us with personal data — contact us at support@stockast.app so that we can investigate and act accordingly.


13. Analytics, Fault Monitoring, and Tracking Transparency

13.1. Mixpanel (product analytics): We use Mixpanel to collect product usage events (such as screen views and feature usage), to understand how the Service is used and to improve it. Analytics run in the production environment only. The analytics data is not used for advertising, is not sold, and is not disclosed to any third party for marketing purposes.

13.2. Sentry (fault monitoring): Upon a crash or technical fault, a fault report is sent that includes technical data about the device and the App's state at the time of the fault, solely for diagnosing and fixing the fault.

13.3. No cross-app tracking: We do not track you across other parties' apps or websites, and we do not use cross-app advertising identifiers. Accordingly, the App does not request tracking permission under Apple's App Tracking Transparency mechanism.

13.4. Cookies: The App itself is not a website and does not use browser cookies; the analytics and monitoring tools operate through app-level identifiers as described above.

13.5. Consent and choice: To the extent that the law applicable to you requires consent for the activation of analytics tools (in particular for users in the EU/EEA, under ePrivacy rules), they will be activated only after your consent is obtained, and you may withdraw it at any time. Not enabling analytics does not limit your use of the Service.


14. Changes to This Policy

14.1. We may update this Policy from time to time. A material change will take effect no earlier than 7 days after notice of the change is given in the App and/or by email to the address on your account; a non-material change takes effect upon publication of the updated version and update of the "Last updated" date. A change required by law takes effect on the date prescribed by law.

14.2. The effective date and the last-updated date will always appear at the top of the Policy. Your continued use of the Service after a change takes effect constitutes acceptance of the updated version; where the law requires express consent to a change — we will request it.


15. Contact and Complaints

15.1. For any question about this Policy, including exercising rights and privacy complaints: support@stockast.app. We will respond within the periods prescribed by law (and no later than 30 days for access requests).

15.2. If you believe your rights under the Protection of Privacy Law have been violated, you may lodge a complaint with the Israeli Privacy Protection Authority (through the contact channels on gov.il).

15.3. Users in the EU/EEA — see also Section 9.4 regarding complaints to a supervisory authority in their country of residence.



עברית