Privacy Policy

Last updated: September 3, 2026

1. What we collect

  • Account data — your email address, username, avatar and profile details you add, plus a phone number if you verify one
  • Financial activity — deposits, withdrawals, orders, positions and balances on the Service, and the wallet addresses you use for crypto transfers
  • Identity data — where a transfer or regulation requires it, the verification data collected by our identity partner
  • Usage data — pages and screens viewed, features used, device and app version, and IP address
  • Content — posts, replies, polls, media and messages you create in the app
  • Safety data — reports you file, accounts you block, and the moderation decisions attached to your account
  • Notification tokens — a device push token, if you turn notifications on

We collect this when you provide it directly, automatically as you use the Service, and from payment and identity partners when you fund your account.

Face ID and biometrics

Biometric sign-in is performed entirely by your device's operating system. SOAR asks the OS to authenticate you and receives only a pass or fail result. We never receive, see, or store your fingerprint or face data.

Photos

Photo library access is used only for images you pick yourself — an avatar or a post attachment — and to save share cards you choose to export. We do not read or index your library.

2. How we use it

  • Operate the Service — match orders, settle markets, maintain balances and history
  • Keep the platform safe — fraud prevention, market-integrity monitoring, reviewing reports and blocks, and enforcing our Terms of Use
  • Improve the product — aggregate analytics on how features are used, and crash diagnostics
  • Communicate — transactional email and SMS (sign-in codes, fills, transfers) and, with your consent, push notifications and product updates

We do not sell your personal information, and we do not use it for third-party advertising.

3. Sharing

We share data with service providers who help us run the Service, each bound by contract to use it only on our instructions:

  • Cloud hosting and databases
  • Payment, banking and blockchain transfer providers
  • Identity verification providers
  • Email and SMS delivery providers
  • Product analytics (Mixpanel) and error monitoring (Sentry)

We also share data with authorities when required by law, with a party to a corporate transaction if we are ever acquired, and in aggregate or de-identified form that cannot reasonably identify you.

If you sign in with Apple, Apple sends us only what is needed to complete the sign-in. Apple's Hide My Email relay addresses are supported and work the same as any other address.

Your public profile — username, avatar, posts, and, where you enable it, positions and trade activity shown on social surfaces — is visible to other users by design. You control the trade and position toggles in Settings, under Privacy.

4. Retention & security

We retain account and transaction records for as long as your account exists, and afterwards for as long as financial record-keeping laws require. Reports and block records are kept while your account exists so we can act on repeated behaviour.

Data in transit is encrypted (TLS); access to production data is restricted and audited. In the mobile apps your session token is held in the device's secure enclave-backed store — the iOS Keychain or the Android Keystore — not in ordinary app storage.

5. Your choices

  • Access and correct your profile data from Settings
  • Delete your account from Settings, under Delete Account — this schedules your account and its content for deletion, subject to records we are required to keep
  • Control who sees your trades and positions in Settings, under Privacy
  • Turn push notifications off in Settings, under Notifications, or in your device settings
  • Opt out of non-essential email from the notification settings

Depending on your jurisdiction (for example GDPR or CCPA), you may have additional rights — to access, port, correct, delete, or object to processing. To exercise them, contact us at the address below. We will not discriminate against you for exercising a privacy right.

6. Cookies & local storage

On the web we use a session cookie to keep you signed in and local storage for interface preferences (theme, layout choices). In the mobile apps the equivalent state is stored on the device. We do not use third-party advertising cookies.

7. Children's privacy

SOAR is for adults. The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If we learn that we have collected information from someone under 18, we delete it and close the account. If you believe a child has given us information, contact hello@trysoar.com.

8. International transfers

We operate from the United States, and our service providers are located there and in other countries. If you use the Service from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction. Where required, we rely on standard contractual clauses for these transfers.

9. Changes & contact

We'll announce material changes to this policy in-app before they take effect. Questions, privacy requests, and security disclosures: hello@trysoar.com.