Last updated: 30 August 2026 · Effective: 30 August 2026
[LEGAL ENTITY NAME] ("AscendSX", "we"), which operates the AscendSX mobile app and ascendsx.com, is the data controller under the EU General Data Protection Regulation ("GDPR") and under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK").
Address: [REGISTERED ADDRESS]
Email: [email protected]
The table below is the complete list of fields that actually exist in the system. It is not a generic "we may collect" list; every row maps to a real field in the database.
| Category | Data processed | When |
|---|---|---|
| Account details | Email address, first name, last name, username, phone number and your password. All of these are required at sign-up. Your password is never stored in clear text — only an irreversible BCrypt hash is kept. | Sign-up and profile updates |
| Profile and avatar | Display name, bio, the X / Telegram / Instagram / YouTube handles you choose to share, and your avatar source (an uploaded picture, or a default avatar generated from your username). | When you edit your profile |
| Security records | Hashes of email-verification and password-reset codes, their expiry times, failed-attempt counters, a SHA-256 hash of your session token, account status and last sign-in time. | Sign-in, verification, password reset |
| Simulation data | The virtual positions you open, orders, trade history, virtual balance movements, realised and unrealised profit and loss, win rate, XP and level. None of this is real money. | Throughout your use of the app |
| Social content | Trades you publish and their captions, hashtags, comments, journal notes, images you upload (up to 5 MB; png, jpg, gif, webp), reactions, bookmarks, predictions, who you follow and who follows you, and the accounts you mute. | When you post |
| Notification data | Firebase Cloud Messaging token, a random identifier generated by the app itself, device model name (e.g. "iPhone 15 Pro"), platform, app version and your notification preferences. | When you allow notifications |
| Purchase records | The store the purchase was made in (App Store / Google Play), product id, the purchase token issued by the store, amount, currency, status and timestamps. Your card number and payment details never reach us — Apple or Google takes the payment. | When you buy virtual balance |
| Reports | The reporting account, the reported content, the reason selected and the description you write. | When you report content |
| Server access logs | IP address, request time, requested path and client information. These are standard web server logs, used only for security and troubleshooting, and are not matched against your account. | On every request |
The following are never requested, read or stored:
Photo library access is requested only when you choose to set a profile picture or attach an image to a post, and only for the single file you pick; the rest of your library is not read.
| Purpose | GDPR Art. 6 basis |
|---|---|
| Creating your account, signing you in and running the simulation | Art. 6(1)(b) — performance of a contract |
| Showing the social feed, comments and the leaderboard | Art. 6(1)(b) — performance of a contract |
| Account security, preventing abuse and fake accounts | Art. 6(1)(f) — legitimate interests |
| Reviewing reports and moderating content | Art. 6(1)(f) / 6(1)(c) |
| Sending push notifications | Art. 6(1)(a) — consent |
| Keeping purchase records | Art. 6(1)(c) — legal obligation (tax and commercial law) |
Notification permission is entirely optional. You can withdraw it at any time from your device settings or the in-app notification preferences; doing so does not restrict the rest of the app.
Some data is fetched directly by your device. In those cases the service in question sees the IP address of your device. Below is exactly who sees what.
The Firebase, Apple and Google platforms are located outside Türkiye and the EEA. Those transfers take place under the standard contractual clauses and data processing terms of the providers concerned, in line with GDPR Chapter V and KVKK Art. 9. Beyond this we never sell, rent or share your personal data for advertising. We respond only to lawful requests from competent judicial and administrative authorities.
Under the GDPR and KVKK Art. 11 you have the right to:
Send your request to [email protected] from the email address registered to your account. We answer within 30 days at the latest. If you are not satisfied with the outcome, you may lodge a complaint with your data protection authority, or in Türkiye with the Personal Data Protection Authority (KVKK).
You can permanently delete your account at any time. Deletion cannot be undone; your virtual balance, trade history, posts and comments go with it.
The only thing retained after deletion is the purchase records the law requires us to keep, and those are held with the link to you removed. Where one of your comments has been quoted inside someone else's thread, the quote itself belongs to that person's content and is stripped of any link to your identity.
This site uses no advertising, tracking or profiling cookies. There is no Google Analytics, no pixel and no comparable tracker.
ascendsx.lang, which remembers the language you picked. You can clear it from
your browser settings and the site keeps working.
AscendSX is not directed at anyone under 18 and we do not knowingly collect personal data from people under 18. If we learn of such an account we close it and delete the data. If you believe a child has given us data, write to [email protected].
If you believe you have found a security vulnerability, please report it to [email protected] before disclosing it publicly.
When we update this policy we change the date at the top of the page. For significant changes we also notify you inside the app.
For any question, request or complaint: [email protected]
© 2026 AscendSX · Home · Terms of Use · Support