Rheme Signals

Privacy Policy

RhemeSignal Privacy Policy

Last updated: July 23, 2026

This Privacy Policy explains what personal data is collected, how it is used, with whom it is shared, and what your rights are when using the RhemeSignal mobile application ("Application").

1. Data Controller

RhemeSignal is not a corporate company, but is developed and operated by Murat YENER as a natural person. This is the person acting as the data controller under the Law No. 6698 on the Protection of Personal Data ("KVKK").

  • Contact: contact@rhemelabs.com

For detailed legal grounds regarding the processing of your personal data, you can review the KVKK Clarification Text.

2. Collected Data

2.1 Account and identity data

  • Email address, full name (when logging in with email/password, Google Sign-In, or Sign in with Apple via Firebase Authentication).
  • Profile information shared by these providers during Google/Apple sign-in (name, email, profile photo — depending on your provider settings).

2.2 Financial data (Core functionality of the Application)

  • Portfolio, debt, watchlist data: stock/crypto positions, debt records, and watchlists that you enter manually.
  • Bank statement uploads: Bank statements you upload to the Application in PDF/CSV/XLSX format and the transaction (spending) data extracted from these statements. These files are stored in a secure object storage and transactions are processed with a local model (when necessary, with a local AI model) for spending category estimation — see Section 4.
  • This data is used directly to provide the core service of the Application (dashboard, portfolio/debt tracking, AI stock recommendation).

2.3 Device and usage data

  • Crash/error reports and diagnostic data (via Firebase Crashlytics).
  • Device notification token (FCM token) for sending push notifications.
  • Advertising ID: Permission to access the advertising ID provided by the Android operating system is requested by the Application; this ID may be used by third-party SDKs we use (Firebase, RevenueCat) for device/analytics identification purposes. The Application does not show ads on its own or sell data to ad networks.

2.4 Subscription and purchase data

  • Your in-app subscription status, purchase history, and related transaction IDs are processed through our payment infrastructure provider RevenueCat. Your credit card/payment instrument information is entered directly into Google Play's payment system, not to us or RevenueCat; we cannot access this information.

2.5 External market/news data

  • Stock, crypto, fund, and news data you view are pulled from general/public market sources. This data stream does not contain personal data belonging to you; it is only content displayed to you by the Application.

3. Purposes of Data Collection

Your personal data is processed for the following purposes:

  • To create your account, verify your identity, and keep your session secure.
  • To offer portfolio, debt, watchlist, and dashboard features tailored to you.
  • To process bank statements you upload and generate spending categories and summaries.
  • To calculate AI stock recommendations (Random Forest-based prediction model) and news impact analysis.
  • To send push notifications (e.g., price alert, debt reminder).
  • To manage your subscription status and verify your access to premium features.
  • To detect and fix Application errors (Crashlytics, server-side error tracking).
  • To comply with legal obligations and prevent misuse.

4. Artificial Intelligence Features and Data Sharing

Some features of RhemeSignal (spending categorization, news impact analysis) use artificial intelligence/machine learning models. These models run locally on our servers; your data is not sent to third-party cloud AI services like OpenAI, Google Gemini for these operations. The AI stock recommendation model is also trained and operated on our own infrastructure.

5. Parties with Whom Data is Shared

Your personal data is shared to a limited extent with the following service providers in order to provide the service:

  • Google Firebase (Authentication, Crashlytics, Cloud Messaging, Firestore): For authentication, crash reporting, and push notification purposes; shared data types are email, identity token, device/crash data, FCM token.
  • RevenueCat: For subscription/purchase management purposes; shared data types are user ID (anonymized), purchase/transaction data.
  • Sentry: For server-side error tracking purposes; shared data types are error/diagnostic data (stripped of personal data as much as possible).
  • Cloud storage (S3/MinIO compatible infrastructure): For secure storage of uploaded bank statements; shared data type is uploaded statement files.

Your data is not sold to advertising networks or shared with third parties for marketing purposes other than those listed above.

6. Data Retention Period

Your data is retained for as long as your account is active and to the extent necessary to provide the service. When you delete your account, your associated personal data (including uploaded statements) will be deleted from our systems within a reasonable time; records with legal retention obligations (e.g., if required by accounting/tax legislation) may be retained for the period prescribed by the relevant legislation.

7. Data Security

Your data is stored in a database and object storage infrastructure protected by industry-standard encryption (TLS in transit). Access is limited strictly to system components required for the operation of the service.

8. Your Rights (KVKK Art. 11)

Under KVKK; you have the right to learn whether your personal data is processed, to request information if processed, to learn the purpose of processing and whether it is used in accordance with its purpose, to know third parties to whom it is transferred domestically/abroad, to request correction if processed incompletely/incorrectly, to request deletion/destruction under conditions foreseen by KVKK, and to request notification of these operations to third parties to whom data is transferred. You can submit these requests in writing to contact@rhemelabs.com. For details, see the KVKK Clarification Text.

You can directly submit your request to delete your account and data from within the Application.

9. Children's Privacy

RhemeSignal is not intended for individuals under 18 years of age and does not knowingly collect data from users under 18. If we become aware of such a situation, we will delete the relevant data.

10. Changes to This Policy

This Privacy Policy may be updated from time to time. In case of significant changes, notifications will be provided within the Application or via this page. The current version will always be published at this address.

11. Contact

For your questions: contact@rhemelabs.com

Cookies & Privacy

We use cookies to provide a better experience on our site. For details, review our and Cookie Policy.