Legal information
Privacy Policy
A clear explanation of the limited data Rate Atlas needs to provide currency information, alerts, and purchases.
Effective date: 24 August 2026
Your privacy at a glance
Rate Atlas does not require an account and does not sell personal data or use it for targeted advertising. We store only the information needed to operate the app, protect the service, deliver requested exchange-rate alerts, and manage purchases.
1. Controller and contact
Controller: Ausianovich Kanstantsin, Lithuania.
Support and privacy contact: [email protected]
This policy applies to the Rate Atlas iOS app and the public and protected services that support it.
2. Data we process
On your device
- Selected currencies, display order, and cached exchange-rate data for offline use.
- Non-sensitive app preferences, including notification choice, premium status, paywall launch count, and review-prompt state.
- Information you enter to make a conversion. It remains in the app unless it is needed for an exchange-rate alert you choose to create.
On our server
- An App Attest installation key identifier, public key, and verification counter to protect the API from abuse.
- If you enable alerts: APNs device token, notification environment, and limited delivery-retry metadata.
- If you create an alert: currency pair, threshold or percentage, baseline and target rates, creation time, and an alert identifier linked to the installation.
- Limited technical and security logs, such as IP address, request time, route, request identifier, and error category where generated by our hosting or network infrastructure.
Purchases
- Because Rate Atlas has no account, RevenueCat generates and caches a pseudonymous anonymous App User ID for the installation.
- RevenueCat processes that identifier, device technical information, purchase and transaction history, Apple purchase receipt information, and entitlement status needed to show and restore access.
- Apple processes payment information. We do not receive or store your payment-card or bank details.
3. How and why we use data
- Provide the app and requested features: cache currency data, display conversions, maintain selections, and create, list, or delete alerts. Our basis is performance of the agreement with you under Article 6(1)(b) GDPR.
- Deliver notifications: register an APNs token and send an alert only when you enable notifications and use the alert feature. Our basis is performance of the agreement with you under Article 6(1)(b) GDPR. You can withdraw this choice in iOS Settings or in the app; alerts will then no longer be delivered.
- Protect and operate the service: verify App Attest requests, prevent misuse, investigate errors, and keep the service reliable. Our basis is legitimate interests under Article 6(1)(f) GDPR.
- Manage purchases: read entitlement information from RevenueCat and Apple so that subscriptions, restoration, and lifetime access work. This is necessary to provide the purchase you request.
What is required and what is optional: App Attest is required to access protected Rate Atlas server APIs; without it, currency data and server-backed features cannot be provided. Notifications, alert creation, and a purchase are optional. Without notifications and an alert, Rate Atlas cannot send an exchange-rate alert; without a purchase, Premium features and restoration are unavailable.
We do not use your information to make automated decisions with legal or similarly significant effects, and we do not sell personal data.
4. Service providers and sharing
We share data only with providers needed to run Rate Atlas:
- DigitalOcean: hosts our Vapor server and database in the AMS3 region, Amsterdam, the Netherlands. See the DigitalOcean Data Processing Agreement.
- Apple: provides the App Store, StoreKit purchases, and Apple Push Notification service (APNs). See the Apple Privacy Policy.
- RevenueCat: processes the anonymous App User ID and purchase, subscription, and entitlement information on our behalf. See the RevenueCat Privacy Policy and Data Processing Addendum.
- FxRatesAPI: supplies currency data to our server. Requests to it originate from our server and do not include your account, purchase, or alert information.
DigitalOcean stores Rate Atlas server data in the European Economic Area. Apple and RevenueCat may process data outside the European Economic Area. Apple states that its EEA transfers are governed by Standard Contractual Clauses. RevenueCat makes Standard Contractual Clauses available for restricted transfers under its Data Processing Addendum. DigitalOcean's Data Processing Agreement provides for the EU-U.S. Data Privacy Framework or, where applicable, Standard Contractual Clauses. You can review those safeguards through the links above.
5. Retention and deletion
- Server data associated with an installation is retained while the relevant feature is active and for no longer than 12 months after its last successful authenticated request. A daily server cleanup removes inactive installations and their associated notification registrations and alerts.
- Disabling notifications removes the associated APNs registration. Deleting an alert removes that alert from the active service record.
- Technical logs are retained for up to 30 days. Backups are retained for up to 30 days and deleted data disappear from backups at the end of that cycle.
- Support correspondence is retained for up to 90 days after the matter is closed, unless a longer period is required to establish, exercise, or defend legal claims or comply with law.
- Device-only data can generally be removed by deleting the app or changing the relevant app or iOS setting.
6. Security
We use reasonable technical and organisational measures designed to protect data against unauthorised access, loss, alteration, and disclosure. No transmission or storage system can be guaranteed completely secure.
7. Your GDPR rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability of personal data we process about you. You may also withdraw consent where processing is based on consent. Email [email protected]; we may ask for information reasonably needed to verify that a request relates to your installation.
You may lodge a complaint with the State Data Protection Inspectorate of Lithuania or your local supervisory authority.
8. Age requirement
Rate Atlas is not directed to children and is not intended for anyone under 16 years old. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data, contact us so that we can take appropriate action.
9. Changes to this policy
We may update this policy when the app, its providers, or legal requirements change. We will publish the updated version here and change the effective date. Material changes will be communicated in the app where appropriate.