Privacy Policy
Last updated: 17 September 2026
This policy describes how the Ellis Bogle Android application and its hosted service handle information. Ellis Bogle is published by Calvin Thomas (“I”, “me”).
Information collected
- Account identity: Google supplies a stable account identifier and verified email address when you sign in. The email address is support metadata and is not used as your identity key. Your Google password is never supplied to Ellis Bogle.
- Portfolio information: positions, quotes, values, performance history, benchmarks, roles, targets, rationales and the narrative generated from those facts.
- Trading 212 connection: the API key and secret you submit are stored as an encrypted, tenant-specific AWS secret. They are never stored on your Android device.
- Device information: a revocable device-session token, notification preferences and, if notifications are enabled, a Firebase Cloud Messaging token.
- Operational information: bounded service logs used for security and reliability. Credentials, authorization tokens and provider response bodies are not intentionally logged.
How information is used
The information is used only to authenticate your devices, retrieve and calculate your portfolio, remember your settings and history, generate the Ellis Bogle narrative experience, send notifications you enable, and operate and secure the service. Ellis Bogle does not sell personal data and does not include advertising or third-party analytics SDKs.
Services involved
- Google Identity authenticates your sign-in.
- Trading 212 supplies portfolio data using the API credentials you provide.
- Amazon Web Services hosts the service, encrypted secrets, portfolio records and generated narrative. Amazon Bedrock is used for narrative generation when the configured AI model uses that service.
- Google Cloud (Vertex AI) is also used to generate narrative, including through Google Gemini and partner models such as Grok. Depending on the selected model, Vertex AI or Amazon Bedrock receives a limited factual briefing based on your portfolio, including relevant holdings, performance, saved investment rationales and narrative context. These AI services are not given your Google password or Trading 212 API credentials. Vertex AI uses global endpoints, so AI processing is not restricted to the UK or EU.
- Firebase Cloud Messaging delivers notifications when you enable them.
- Google Play processes app installation and updates under Google’s own policies.
On-device storage and security
The app stores a server-issued device session encrypted with an Android Keystore-backed AES-GCM key, the last successful portfolio response, and local display preferences. Android backup is disabled. Network requests use HTTPS. The Android app never contacts Trading 212 directly.
Retention and deletion
Account and portfolio data is retained while your Ellis Bogle account exists. Short-lived connection previews expire after ten minutes, notification idempotency records expire after 35 days, and pseudonymous operational logs are retained for 14 days.
Deleting your account removes the Google identity mapping, device sessions, notification registrations, portfolio data and history, settings, narrative and stored Trading 212 credentials. It does not delete your Google account or Trading 212 account. Local app data is removed by the in-app deletion flow and can also be removed by clearing app storage or uninstalling.
Delete an Ellis Bogle accountYour choices
You can disable individual notification types, disconnect a device, or permanently delete your account from Settings. You can also request deletion without access to the app using the account-deletion page above.
Children
Ellis Bogle is not directed at children and is not intended for anyone under 18.
Changes and contact
I may update this policy when the product or its data handling changes. Questions can be sent to privacy@ellisbogle.com.
This page describes Ellis Bogle as distributed through Google Play. It is not legal advice.