Opening Bell

Opening Bell — Privacy Policy

Effective: September 13, 2026

Operator: Frederick Fermin (“we”, “us”)

Contact: frederickfermin123@gmail.com

Opening Bell turns your habits into tickers on a personal stock exchange. This page says what the app collects, why, who processes it, and how to get it out again. The short version: your market data is the product, it is yours, you can export or delete it at any time, and we do not sell it, show ads against it, or track you across other companies’ apps.

What we collect

Your account. On first launch the app creates an anonymous account with a random identifier. Nothing else is needed to use it. If you choose to link Sign in with Apple or Google, we receive the email address and name that provider shares with us (Apple may share a private relay address). We never see or store a password.

Your market. Everything you create in the app is stored so it can follow you between devices and survive a reinstall once linked: the listings you create (habit names and tickers), their weights, your check-ins, the weekly guidance you set, your risk factors, your fund’s name, symbol and manager name, and the prices, index values, earnings reports, halts and circuit breakers the exchange derives from them.

Device and settings. Your time zone, market hours, sound and haptics preferences, and, only if you turn alerts on, a push-notification token that lets us deliver them. Widgets and the Live Activity read a snapshot that stays on your device.

Social. Invite codes you generate or redeem, the exchanges you create or join, and the shareholder links you accept. Shareholders and fellow exchange members can see your fund symbol, fund name, manager name, display name, index level, daily change and closing-bell time. For every listing you set to Open (the default for most habits) they also see its ticker, name, price history, daily move, halt state and miss streak; the price history shows which days moved it up or down. A listing you set to Private never appears to them and only moves your index. They cannot see your earnings reports, your risk factors or the labels you wrote for your habits. The Street shows aggregate figures per habit (how many funds hold it, completion rates, halts) and only once at least ten funds hold it, so no single fund is identifiable.

Purchases. Opening Bell Plus is sold and billed by Apple. We never receive your card or bank details. RevenueCat processes the App Store receipt and tells us whether Plus is active, together with your account identifier, the product, the store, the relevant dates and whether the purchase was in Apple’s sandbox. We keep those events as a billing ledger so your entitlement can be reconstructed.

Product analytics. We use PostHog to understand how the app is used: which screens are reached, which onboarding steps are completed, whether the paywall was shown or dismissed. Events are explicit and named; there is no automatic capture of taps, no session replay, and no advertising identifier. Events carry your account identifier, device type, operating system version and app version. This is first-party analytics and is not used to track you across other companies’ apps or websites, so the app does not ask for App Tracking Transparency permission.

Crash reports. We use Sentry to learn when the app crashes. A report carries the stack trace, device model, operating system and app version. Personal data is not attached, and performance tracing is off.

The analyst note (Plus, only if you allow it). Each week a short note is written about your fund’s earnings. If you allow AI coverage (the app asks once on the Earnings tab, and Settings → The earnings call → AI analyst note is the switch), that week’s report is sent to Anthropic to write it: your fund symbol, fund and manager name, each listing’s name, guidance, sessions, verdict and price move, whether it was halted, held by a circuit breaker or rallied, the prior week’s move, and the names of your risk factors. Anthropic generates the text under its commercial API terms, and the note is stored with your report. Until you allow it, and from the moment you turn it off, nothing is sent and the standard note is written on our own servers.

Reports. If you report a fund or an exchange, we keep your report (the reason and any note you wrote) together with a copy of the names you reported, so we can review it. The person or exchange you report is not told who reported them.

Why we use it

To run your exchange and keep it in sync across devices; to deliver the alerts you turned on; to sell, deliver and restore Plus; to understand which parts of the app work and which do not; to find and fix crashes; and to write the analyst note. Where data-protection law asks for a legal basis: performing our contract with you, our legitimate interest in keeping the app working and improving it (which includes reviewing reports), and your consent for notifications, for linking a sign-in provider and for the AI-written analyst note.

Who processes it

We use the following providers, each only for the purpose named:

Provider Purpose Where
Supabase Database, authentication and server functions AWS, us-east-1 (United States)
Expo Delivering push notifications you turned on United States
Apple Sign in with Apple, App Store purchases and billing Apple’s terms apply
Google Sign in with Google, if you choose it Google’s terms apply
RevenueCat Subscription status and receipt validation United States
PostHog Product analytics United States (US cloud)
Sentry Crash reporting United States
Anthropic Writing the analyst note for Plus funds United States

We do not sell personal data, share it with advertisers or data brokers, or use it for advertising.

How long we keep it

For as long as your account exists. Anonymous accounts that never finished onboarding are removed automatically thirty days after they were created. Billing events are kept as long as the account they belong to. Crash reports and analytics events are kept for the retention period of the provider named above and then discarded.

Your data, your controls

Export. In the app, open Settings → Account → Export my data. You receive everything the exchange holds about your fund in JSON; Plus adds Export my statement (CSV).

Delete. In the app, open Settings → Account → Delete account & history. This removes your account, your market and your ledger from our systems, and asks RevenueCat to forget your subscriber record. An active Plus subscription is billed by Apple and is not cancelled by deleting the account: cancel it in your Apple ID subscription settings.

Alerts. Turn notifications off in Settings under Market hours & alerts, or in iOS Settings; the push token is dropped when you do.

AI analyst note. Turn it off in Settings → The earnings call → AI analyst note. Nothing further is sent to Anthropic once it is off.

Your rights. Depending on where you live you may have the right to access, correct, export, delete or restrict the use of your personal data, and to complain to a supervisory authority. Write to us at the contact address above and we will respond.

Children

Opening Bell is not directed at children under 13 (or the age of digital consent where you live) and we do not knowingly collect their data.

Security

Data travels over TLS, is stored with row-level access rules so one account cannot read another’s market, and server credentials are kept out of the app. No system is perfectly secure; if we learn of a breach that affects you we will tell you.

Changes

If this policy changes we will publish the new version at this address with a new effective date. Material changes are also announced in the app.

Contact

frederickfermin123@gmail.com