Legal
Privacy Policy for Android
This policy covers the app on Android. The app on iPhone, iPad and Mac has its own policy.
Last updated: October 7, 2026
This policy explains what History of Market: Heat Map for Android (“the app”), provided by GREP ADVISORY PTE. LTD. (“we”), sends to our servers, why, and how long we keep it. It covers the app on Android phones, tablets and foldables and its Home screen widgets. We use this data only as described here, and we do not sell it.
What the App Sends
- Device check. On its first launch the app makes a random install id and keeps it in its private storage on the device. To get data, the app asks our server for a one-time challenge, has the device’s secure hardware make a new key bound to that challenge and the install id, and sends our server the key’s attestation certificate chain with the challenge and the install id. The device makes this chain; it states that the key is kept in secure hardware, the app’s package name, version and signing certificate, the version and security patch level of the device’s software, and whether the device starts only verified software with a locked bootloader. It does not contain your name, your accounts, or the device’s serial number or IMEI. The certificates above the key belong to the device’s attestation key and to Google’s root; where that attestation key was installed at the factory, it is shared by many devices, so it does not single out yours. Our server checks the chain against Google’s published root certificates and revocation list, so it can tell requests from our genuine app on a genuine device apart from automated scraping. It keeps neither the chain nor the install id: only a one-way hash of the install id, when it was last seen, how many sessions it opened that day and whether it is blocked. The app deletes the key once the chain is sent. This record is not connected to your name, email, Google Account or IP address. One-time challenge values expire after 5 minutes and are deleted when used or within a day.
- Access tokens. After the device check, our server gives the app a session token that expires after 1 hour and a device token that expires after 30 days, which the app’s widgets use. A token names only the hash above. The server does not store tokens.
- Market data requests. To show prices, charts and market history, the app and its widgets request data from our servers with one of these tokens. Like any internet request, these carry your IP address and a user-agent string; a request for a stock page or a search names the ticker or the search text. Our servers use the IP address only to limit request rates over one-minute windows and do not store it, and they log errors with the address requested. When the main source cannot answer, our server gets the same market data from our backup data service; those requests name the ticker or the search text and nothing about you or your device.
- Purchases. The app asks Google Play, through Google Play Billing, which Supporter plans are offered and whether you have one, and checks this on your device; it confirms each new purchase to Google Play, as Google Play requires. Google Play processes payments and, as for every app, shows us its order records in our developer account. We do not receive your payment details, and our server keeps no record of your purchases.
- Statistics. Our server keeps aggregate counts, such as the number of sessions in a day. They contain no install id, hash, token or IP address and cannot be traced to an installation.
Service Providers
Our servers, database and storage run with a cloud hosting and network provider, which handles the app’s network traffic, including IP addresses, only to provide its service to us. Our backup data service runs with another hosting provider and receives requests only from our servers. Both are bound by data processing terms that require them to protect this data at least as well as this policy does. Google handles Google Play Billing and Android backup under Google’s privacy policy. For the device check our server downloads Google’s revocation list, a request that carries nothing about you or your device.
What Stays on Your Device
- Your watchlists, display settings and the app’s other preferences are saved on the device. If backup is on, Android includes them in your device’s backup to your Google Account and in a transfer to a new device; we cannot read that backup. The install id, the device token and the last Supporter plan the app saw are never backed up or transferred, and neither is cached market data.
- Cached market data and the data the widgets show stay on the device.
- On Android 14 and later, when you take a screenshot in the app, Android tells the app only that a screenshot was taken, and the app may offer a share image of the same screen. The app draws that image itself, does not read your screenshots or photos, and sends it only where you choose.
How Long We Keep It
- An installation’s record is deleted 90 days after the app was last opened on that device. Clearing the app’s storage or reinstalling the app makes a new install id; the old record is then deleted 90 days after its last use.
- Aggregate counts contain nothing about you and are kept as long as they are useful.
Your Choices
- Deleting the app, or clearing its storage in Android’s Settings, deletes everything it saved on the device; its record on our server is then deleted as described above. Google keeps the app’s backup in your Google Account under your backup settings.
- Nothing on our server is linked to your identity, so we cannot look up a record by your name or email.
Children. The app is not directed at children and collects no information about them.
Changes. If we change this policy, we post the new version here with a new date before the app behaves differently.
Contact. hi@historyofmarket.com