Legal
Privacy Policy
How Citrine handles local app data, Coinbase connectivity, subscription verification, support requests, and website access.
Effective date: August 12, 2026
Company: Citrine Edge. Address: Mailing address available upon request. Contact: support@citrineedge.com.
Overview
Citrine is a local-first Android application. Most app settings, imported Coinbase credentials, cached market data, backtest data and results, trading state, and account-derived display values remain on the user's device. Citrine Edge does not sell personal data, use advertising SDKs, or build advertising profiles.
Local app data and credentials
Coinbase API credentials are imported through Android's document picker. Imported credential profiles are stored in app-private encrypted storage backed by Android Keystore. They are not included in the app package and are not sent to Citrine Edge for remote custody. The app may also store preferences, subscription state, backtest history, cached archive data, logs, selected-account state, and position-protection state locally so its features can operate and recover safely.
Local app data can generally be removed by deleting it inside the app where that option is available, clearing Citrine's app data, or uninstalling Citrine. Android backup and device-transfer rules are configured to exclude Citrine's private app data and imported credentials.
Coinbase account and trading data
When a user imports a Coinbase API key or uses connected features, Citrine sends signed requests directly from the device to Coinbase. Coinbase may receive the API key identifier, request signature, market or product request, and user-authorized account, position, or order instructions. Citrine retrieves the account, portfolio, position, order, fee, product, and market information needed to provide the requested display, backtesting, monitoring, and automation features. Citrine Edge does not receive the user's Coinbase API secret or centrally store the user's Coinbase account and order history.
Coinbase controls Coinbase accounts, eligibility, API-key creation, derivatives access, custody, and trading services. Coinbase processes information under its own terms and privacy policy.
Subscription and app-integrity verification
For users with a Google Play purchase, Citrine may send a Google Play purchase token, a random app-install identifier, the app version, a one-time request identifier, and a Play Integrity token over an encrypted connection to Citrine's entitlement-verification service. The service sends the verification request to Google to confirm subscription state, app recognition, licensing, signing identity, request integrity, and device integrity.
The Citrine entitlement service does not use a database or analytics store and does not persist verification request bodies, purchase tokens, or install identifiers. It returns a short-lived signed entitlement lease to the device. Google and infrastructure providers may retain data or technical request metadata under their own policies and fixed retention schedules.
Support communications
If a user submits an in-app support request, Citrine sends the message, category, and any optional name or reply email the user enters. It also includes limited diagnostics: app version, app version code, Android version, device manufacturer and model, package name, and a non-secret support request identifier. Support requests are delivered to Citrine Edge's support mailbox and retained as needed to answer the request, maintain service records, prevent abuse, and meet legal obligations.
Do not send Coinbase login credentials, API keys, private key material, passphrases, seed phrases, account identifiers, raw order history, or other secrets in a support message, screenshot, export, or email. Citrine applies secret-pattern redaction to support text, but users remain responsible for reviewing what they submit.
Archive, notices, and network data
Citrine downloads historical backtest archives and a read-only notices feed from Citrine Edge services. Those requests may include ordinary network information such as IP address, user agent, app version targeting, request time, and cache headers that hosting and security providers process to deliver and protect the service. Citrine does not use those requests for advertising or cross-app tracking.
Website data
The public Citrine Edge website does not require a user account and does not connect to a visitor's Coinbase account. The hosting provider may process ordinary request information such as IP address, browser type, requested page, and request time to deliver and secure the site. If a visitor emails Citrine Edge, the visitor's email provider and Citrine Edge's email provider process that communication.
Service providers and data sharing
Citrine uses Coinbase for user-requested account and trading functions, Google Play for distribution, billing, licensing, and integrity verification, Android for operating-system and security services, Cloudflare for website and app-service infrastructure, and email providers for support communications. These providers process data to perform their services and under their own terms. Citrine Edge does not sell user data or share it with data brokers, advertisers, or unrelated marketing partners.
Retention and deletion
Entitlement verification request bodies are processed without application-level persistent storage. Support communications are retained only as reasonably needed for the purposes described above. A user may request deletion of support information controlled by Citrine Edge by emailing support@citrineedge.com. The request should identify the relevant support request or reply email. Citrine Edge may retain information where required for security, fraud prevention, dispute resolution, accounting, or law.
Google, Coinbase, Android, hosting providers, and email providers control their own records and deletion processes. Requests concerning data held by those providers must be directed to the applicable provider.
Security
Citrine uses encrypted transport for network requests, Android Keystore-backed encryption for imported credentials, app-private storage, secret redaction, and signed entitlement verification. No security system is perfect. Users should secure their device and Coinbase account, use only the minimum API permissions Citrine requires, and revoke an API key if a device or credential may be compromised.
Children
Citrine is intended only for adults who are legally eligible to use the connected financial products. It is not directed to children.
Updates
This policy may be updated when Citrine's features, providers, or legal obligations change. The effective date at the top identifies the current version. Material changes may also be communicated through Citrine's Notices section or Google Play listing.