AscendSX

Privacy Policy

Last updated: 30 August 2026 · Effective: 30 August 2026

In short

  1. Data controller
  2. What data we process
  3. What we do not collect
  4. Purposes and legal bases
  5. Third parties and international transfers
  6. Retention periods
  7. Your rights
  8. Deleting your account
  9. Cookies and similar technologies
  10. Children's privacy
  11. Security
  12. Changes and contact

1. Data controller

[LEGAL ENTITY NAME] ("AscendSX", "we"), which operates the AscendSX mobile app and ascendsx.com, is the data controller under the EU General Data Protection Regulation ("GDPR") and under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK").

Address: [REGISTERED ADDRESS]
Email: [email protected]

2. What data we process

The table below is the complete list of fields that actually exist in the system. It is not a generic "we may collect" list; every row maps to a real field in the database.

Category Data processed When
Account details Email address, first name, last name, username, phone number and your password. All of these are required at sign-up. Your password is never stored in clear text — only an irreversible BCrypt hash is kept. Sign-up and profile updates
Profile and avatar Display name, bio, the X / Telegram / Instagram / YouTube handles you choose to share, and your avatar source (an uploaded picture, or a default avatar generated from your username). When you edit your profile
Security records Hashes of email-verification and password-reset codes, their expiry times, failed-attempt counters, a SHA-256 hash of your session token, account status and last sign-in time. Sign-in, verification, password reset
Simulation data The virtual positions you open, orders, trade history, virtual balance movements, realised and unrealised profit and loss, win rate, XP and level. None of this is real money. Throughout your use of the app
Social content Trades you publish and their captions, hashtags, comments, journal notes, images you upload (up to 5 MB; png, jpg, gif, webp), reactions, bookmarks, predictions, who you follow and who follows you, and the accounts you mute. When you post
Notification data Firebase Cloud Messaging token, a random identifier generated by the app itself, device model name (e.g. "iPhone 15 Pro"), platform, app version and your notification preferences. When you allow notifications
Purchase records The store the purchase was made in (App Store / Google Play), product id, the purchase token issued by the store, amount, currency, status and timestamps. Your card number and payment details never reach us — Apple or Google takes the payment. When you buy virtual balance
Reports The reporting account, the reported content, the reason selected and the description you write. When you report content
Server access logs IP address, request time, requested path and client information. These are standard web server logs, used only for security and troubleshooting, and are not matched against your account. On every request

3. What we do not collect

The following are never requested, read or stored:

Photo library access is requested only when you choose to set a profile picture or attach an image to a post, and only for the single file you pick; the rest of your library is not read.

4. Purposes and legal bases

Purpose GDPR Art. 6 basis
Creating your account, signing you in and running the simulation Art. 6(1)(b) — performance of a contract
Showing the social feed, comments and the leaderboard Art. 6(1)(b) — performance of a contract
Account security, preventing abuse and fake accounts Art. 6(1)(f) — legitimate interests
Reviewing reports and moderating content Art. 6(1)(f) / 6(1)(c)
Sending push notifications Art. 6(1)(a) — consent
Keeping purchase records Art. 6(1)(c) — legal obligation (tax and commercial law)

Notification permission is entirely optional. You can withdraw it at any time from your device settings or the in-app notification preferences; doing so does not restrict the rest of the app.

5. Third parties and international transfers

Some data is fetched directly by your device. In those cases the service in question sees the IP address of your device. Below is exactly who sees what.

Services that receive no identifying information

The one service that receives your username

Our service providers

The Firebase, Apple and Google platforms are located outside Türkiye and the EEA. Those transfers take place under the standard contractual clauses and data processing terms of the providers concerned, in line with GDPR Chapter V and KVKK Art. 9. Beyond this we never sell, rent or share your personal data for advertising. We respond only to lawful requests from competent judicial and administrative authorities.

6. Retention periods

7. Your rights

Under the GDPR and KVKK Art. 11 you have the right to:

Send your request to [email protected] from the email address registered to your account. We answer within 30 days at the latest. If you are not satisfied with the outcome, you may lodge a complaint with your data protection authority, or in Türkiye with the Personal Data Protection Authority (KVKK).

8. Deleting your account

You can permanently delete your account at any time. Deletion cannot be undone; your virtual balance, trade history, posts and comments go with it.

  1. In the app: Profile → Settings → Delete my account. Your account is closed as soon as you confirm.
  2. By email: Write to [email protected] from your registered address with the subject "Account deletion request". Once we have verified your identity we delete it within 30 days at the latest.

The only thing retained after deletion is the purchase records the law requires us to keep, and those are held with the link to you removed. Where one of your comments has been quoted inside someone else's thread, the quote itself belongs to that person's content and is stripped of any link to your identity.

9. Cookies and similar technologies

This site uses no advertising, tracking or profiling cookies. There is no Google Analytics, no pixel and no comparable tracker.

10. Children's privacy

AscendSX is not directed at anyone under 18 and we do not knowingly collect personal data from people under 18. If we learn of such an account we close it and delete the data. If you believe a child has given us data, write to [email protected].

11. Security

If you believe you have found a security vulnerability, please report it to [email protected] before disclosing it publicly.

12. Changes and contact

When we update this policy we change the date at the top of the page. For significant changes we also notify you inside the app.

For any question, request or complaint: [email protected]

© 2026 AscendSX · Home · Terms of Use · Support