Privacy Policy
Last updated: September 15, 2026
CryptoSage AI (“the app”, “we”, “us”) is an iOS app for tracking a crypto portfolio, reading market data and asking an AI about both. This policy describes exactly what data the app touches, what stays on your iPhone, and names the companies that receive any of it. The short version: we do not sell your data, the app shows no ads, and an account is optional.
1. What stays on your device
- Exchange API keys and secrets are stored in the iOS Keychain on your iPhone — the same system that protects your saved passwords. The app does not upload your exchange credentials to our servers.
- AI provider API keys you add yourself (see section 3) are also stored in the iOS Keychain.
- Your app-lock PIN and biometric setting never leave the device.
- Manually entered holdings, preferences and cached market data live on the device. If you never create an account, everything in section 2 stays on the device too.
We never ask for, receive or store exchange passwords, seed phrases or private keys. Wallets are tracked by public address only.
2. If you create an account (optional)
You can use CryptoSage without an account. If you sign in — with Apple, Google or an email address and password — sign-in is handled by Google Firebase Authentication, so Google processes the sign-in and we receive your email address, a display name and an account ID.
With an account, app data syncs to Google Cloud Firestore so it follows you between devices. That synced data includes:
- your watchlist and favorites,
- your price alerts, and the device push token needed to deliver them (section 7),
- your AI chat conversations,
- your paper-trading balances and simulated trade history,
- your AI prediction-tracking history, and
- your profile fields — display name, bio, phone number and avatar image — plus any AI memory or personalization you set up.
Your portfolio holdings, transactions and exchange connections do not sync. They stay on this device, and the exchange keys themselves stay in the iOS Keychain — they are never written to our servers, with or without an account.
Plain statement: when you are signed in, your AI chat history and paper-trading records are stored on our servers (Google Cloud Firestore), not only on your phone. Signed out, they stay local.
3. AI questions go to AI companies
The AI features are not computed on your iPhone. Depending on the feature, your question and the context needed to answer it (for example a summary of your portfolio, or the coin being discussed) are sent to one of these providers:
- OpenAI — answers the built-in AI chat and related per-user AI features.
- DeepSeek, OpenRouter or OpenAI — shared AI features such as market sentiment summaries, coin insights and price predictions are generated on our backend (Google Firebase Cloud Functions), which currently uses whichever of these providers is available, in that order.
- A provider you choose — if you connect your own API key in Settings (OpenAI, DeepSeek, xAI/Grok or OpenRouter are supported), those requests go directly from your device to that provider under your own account and their terms.
Screenshots in the AI chat. If you attach screenshots or photos to a chat message, they are sent with that one message through our backend (Google Firebase Cloud Functions) to OpenAI so the assistant can read them. We do not store them on our servers, and they are not sent again with later messages. The copy in your chat history stays on your iPhone: when your conversations sync, the image itself is not uploaded, only its file name.
What these companies do with text and images after they reach them is governed by their own terms, not ours. We hold no zero-retention agreement with them, so we will not promise on their behalf that your words or screenshots are discarded. Please don’t type or attach anything to the chat you would not want processed by a third-party AI provider — crop out account numbers, API keys and balances you would rather keep private.
4. Market data, news and blockchains
Prices, charts, news and on-chain balances are fetched by your device directly from the services that publish them, so those services see your IP address under their own privacy policies. The main ones are:
- Market data and charts: CoinGecko, Binance, Coinbase, Kraken, KuCoin, Bybit, OKX, Gemini and TradingView.
- News: CryptoCompare, Google News and Yahoo Finance.
- Blockchain data for wallet addresses you track: public services such as Etherscan, Solscan and Ankr RPC endpoints.
- Your connected exchanges receive requests for your balances and holdings. These are read requests, with one exception: in the Premium derivatives tools, with Binance Futures keys you have given trading permission, closing a position or changing leverage sends an instruction you triggered.
5. Analytics and crash reports
We use Google Firebase Analytics for usage statistics (which screens and features are used, device model, iOS version, session length) and Google Firebase Crashlytics for crash and stability reports. These events do not contain your portfolio contents, chat text, keys or credentials. The data is processed by Google under Google’s terms.
Both are on by default. You can turn analytics off in the app under Settings › Privacy & Analytics, and the app stops sending those events. Crash reporting has no separate switch in this build, so turning analytics off leaves Crashlytics running — we would rather say that than let the sentence above imply a control that is not there.
6. Advertising: none
The app shows no third-party ads and sends no data to advertising networks. Google’s Mobile Ads SDK and the advertising identifier were removed: the current build links no advertising SDK, requests no ads, and shows no App Tracking Transparency prompt. We do not track you across other companies’ apps or websites. If ads are ever introduced, this policy will be updated first.
7. Notifications and price alerts
Push notifications are optional and controlled by iOS. If you use price alerts while signed in, the alert definitions and your device’s push token are stored on our backend so alerts can fire while the app is closed. Notifications are delivered through Apple’s push service and Google’s Firebase Cloud Messaging.
8. Purchases
Subscriptions are bought through Apple. Apple handles the payment and shares no card details with us; our backend receives the App Store receipt only to confirm which plan is active. Refunds are handled by Apple — see the support page.
9. Security
- Exchange and AI credentials are stored in the iOS Keychain, not in app files.
- Network connections use HTTPS (TLS) encryption in transit.
- Exchange connections are for portfolio tracking; the app never asks for withdrawal or transfer permissions, and we recommend creating read-only API keys — a read-only key cannot place, close or modify anything on your account.
- Optional Face ID / Touch ID app lock, enforced on your device.
10. Deleting your data
- Disconnect an exchange or wallet at any time from
Settings › Linked Accounts; removing a connection removes its stored credentials from your device. - Delete conversations from the AI chat screen; if you are signed in, this also removes the synced copy.
- Delete your account from inside the app. This deletes your synced data on our servers (Firestore) and the sign-in record itself.
- Delete the app to remove its local data from your iPhone.
- Or email hypersageailabs@gmail.com and we will do it for you.
11. Your rights (California, EEA/UK and elsewhere)
Wherever you live, you can ask us what data we hold about you, ask for a copy, ask us to correct it, or ask us to delete it — the in-app tools above cover most of this instantly, and the email address below covers the rest. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. California residents may exercise CCPA rights, and EEA/UK residents GDPR rights (access, rectification, erasure, restriction, portability, objection), by emailing hypersageailabs@gmail.com with “Data Request” in the subject line.
12. Children
CryptoSage is not intended for anyone under 18 and we do not knowingly collect information from children. If you believe a child has provided us personal information, email us and we will delete it.
13. This website
This website (cryptosageai.io) is a separate surface from the app, and it does two things worth naming:
- It uses Google Analytics to count visits, which processes your IP address and browser information under Google’s terms.
- If you submit your email in the “Keep me posted” form at the bottom of the home page, that email address (with the time and your browser’s user-agent string) is stored in our Google Cloud Firestore database and used only to contact you about CryptoSage. Email hypersageailabs@gmail.com to be removed.
14. Changes to this policy
If we change what the app collects or who receives it, we will update this page and its date first. Significant changes will also be announced in the app.
15. Contact
Privacy questions and data requests: hypersageailabs@gmail.com. A real person reads every message.