← Back to InvestiqSvenska

Legal · Data protection

Privacy Policy

Applies to the Investiq mobile app, web app, landing site, prelaunch programme and support. Version 2026-08-12.1, last updated 12 August 2026.

Short summary

Investiq does not sell personal data, use advertising trackers, or send your accounts, portfolios, messages or profile images to generative AI models. Optional PostHog analytics remains off until you choose it.

1. Controller and contact2. What Investiq does3. Data we process4. Purposes and legal bases5. Cookies and local storage6. Providers7. Retention8. Your rights9. International transfers10. Children and age11. Security12. Changes13. Contact14. Sweden/EEA supplement

1. Controller and contact

The data controller for the processing described in this policy is:

William UllerstigInvestiqSöderberga Allé 3, 162 52 Vällingby, Swedeninvestiqco@gmail.com

No data protection officer has been appointed because the current operation is not subject to that requirement. Privacy questions go directly to the controller.

2. What Investiq does

Investiq is an account-based educational and social investing simulator with lessons, simulated portfolios, leagues, teams and a prelaunch programme. It does not execute real securities trades, hold customer funds or receive bank or brokerage credentials. Paid preorders may be offered separately through Stripe or an app store.

3. Personal data we process

We receive data mainly from you and your use of the service. Authentication providers, payment providers and your device may also provide the limited data needed for the selected feature.

CategoryExamples
Account and identityName, email address, internal user ID, verification status, authentication provider and session information.
Profile and choicesProfile image, handle, biography, language, theme, investing goals, experience level, risk level and privacy settings.
App activityOnboarding, lessons, quizzes, saved stocks, simulated orders, portfolios, leagues, teams, achievements and progress.
Social contentFriend relationships, blocks, reports, group and direct messages, posts, comments and voluntary feedback.
Content and safety reportsReporter name and email where provided, exact content location and ID, allegation, possible legal basis, correspondence, review events, decisions and affected user.
Prelaunch and purchasesFirst name, verified email, referral code, campaign status, optional profile answers, marketing choice, and order and payment references.
Withdrawal and refund mattersEmail, order reference, contract description, date, optional note, timestamped receipt, handling events and decision.
Technical and securityIP address, user agent, platform, app version, session and device identifiers, push token, timestamps, coarse performance metrics and error codes.
SupportWhat you send to support, contact details and our correspondence.

When reporting content or sending a withdrawal notice, provide only data needed for the matter. Do not send passwords, full card details, medical records or other sensitive data unless strictly necessary to understand a specific safety risk.

What we do not collect

  • No bank logins, brokerage accounts or real portfolio holdings.
  • No precise location, address book, microphone data or camera access.
  • No full payment-card details; those are handled by Stripe or the app store.
  • No sale of personal data and no targeted advertising profiles.

The mobile app requests photo-library access only when you choose a profile image and notification permission when a notification feature is enabled. Investiq receives the selected image or a push token, not your entire photo library.

4. How we use data and our legal bases

PurposeLegal basisWhat this means
Provide the account and serviceContract or steps taken at your requestCreate an account, save progress, display simulated portfolios and provide social features.
Security, troubleshooting and abuse preventionLegitimate interestsProtect accounts, limit abuse, fix errors and keep the service stable. We balance these interests against your privacy.
Content moderation and statutory noticesLegal obligation and legitimate interestsReceive, investigate and document reports, provide receipts and reasoned decisions, protect users and handle review or legal claims.
Optional product analyticsConsentUnderstand named product flows with PostHog on the web and limited first-party events in the mobile app. Analytics remains off until accepted and can be disabled again.
Product updatesConsentSend launch or product emails when you have expressly selected this option.
Preorders and paymentContract and legal obligationAdminister orders, refunds, accounting and consumer rights.
Right of withdrawalContract and legal obligationRecord when you withdraw from a contract, provide a durable receipt and handle a refund or decision.
Legal requirements and claimsLegal obligation or legitimate interestsComply with law, respond to authorities, and establish, exercise or defend legal claims.

Required account data is needed to create and operate an account. Without it, signed-in features cannot be provided. Analytics and marketing are optional and do not affect the core service.

AI and automated decisions

Investiq does not send personal data such as account data, simulated portfolios, messages or uploaded images to generative AI models and does not use it to train AI models. The service does not make decisions with legal or similarly significant effects based solely on automated processing. Market and educational content may include automated calculations and is not personal financial advice.

5. Cookies, device storage and analytics choices

Essential storage is used without analytics consent for sign-in, security, language and features you request. PostHog is not loaded and does not set analytics storage until you choose Accept all or enable analytics under Manage choices. The mobile app does not create, queue or send analytics events until you enable Usage analytics in the app's privacy settings.

NameTypePurposeDurationHow to opt out
Better Auth sessionEssentialKeeps you signed in and protects your session.Normally 7 days or until you sign out.Sign out or clear browser/app data. Signed-in features will then stop working.
investiq.privacy-consentEssentialStores your analytics choice and the policy version.12 months.Clear site data; we will ask for your choice again.
investiq.analytics-consentEssentialMakes your analytics choice available to server features without exposing other storage.12 months.Change the choice under Privacy choices or clear site data.
investiq.localePreferenceRemembers the selected language.12 months.Change language or clear site data.
investiq-device-idEssentialDistinguishes signed-in devices so that you can review and sign out sessions.Until you clear site data.Clear site data; the device receives a new ID on the next sign-in.
investiq.se.attribution / visitEssential for referralsConnects a referral visit to the correct campaign code and prevents duplicate credit.30 days or until registration is completed.Clear site data; the referral may then not be credited.
investiq.se.* prelaunch statePreferenceRemembers campaign steps, a referral code and whether an offer was shown or completed.Until the campaign ends or you clear site data.Clear site data.
news_viewer_idAnalyticsPrevents the same browser from being counted repeatedly for a news view.12 months; created only after consent.Disable Analytics under Privacy choices. The cookie is removed on the next view call.
App and web cacheEssential/preferenceStores local choices, notes and cache on your device. Sensitive authentication credentials use the mobile device's secure storage.Until replaced, the account is deleted, or you clear app/browser data.Clear app or site data in your device or browser settings.
onboarding_v2_analytics_queue / onboarding_v2_anon_idAnalyticsQueues named mobile-app events and an analytics identifier for delivery to Investiq's own backend.Created only after consent; the queue and identifier are removed locally when consent is withdrawn.Disable Usage analytics in the app's privacy settings.
PostHog storage (ph_*)AnalyticsAssociates consented analytics events with the same browser without session recording.Up to 12 months; created only after consent.Choose Reject or disable Analytics under Privacy choices.

You can reopen Privacy choices on the site or the app's privacy settings at any time and withdraw analytics consent. In the app, the local analytics queue and identifier are then removed. You may also clear cookies/local storage in your browser and app data in device settings. We use no advertising cookies or tracking across different companies' sites and apps. On the web, we respect Do Not Track by not starting PostHog or counting news views when that signal is active.

6. Recipients and processors

We share data only with providers needed for the relevant function, or where required by law. Depending on the service and agreement, a provider may act as our processor or as an independent controller. Better Auth is software operated inside Investiq's own environment and is not a separate processor.

ProviderFunctionPrivacy
Microsoft AzureCore API, authentication database, app data, profile images, email and real-time features. Core resources are deployed in Sweden Central.Policy
CloudflareDelivery and protection of the landing site, Workers logs and the D1 preorder database. The D1 database was created with EU jurisdiction.Policy
PostHog EUOptional web analytics after consent. Automatic click collection and session recording are disabled.Policy
ExpoRegistration and delivery of push notifications to devices on which you have allowed notifications.Policy
AppleSign in with Apple, APNs push notifications and App Store distribution.Policy
GoogleGoogle Sign-In, FCM push notifications and support email through Gmail.Policy
Logo.devDisplay of company logos. When a logo is requested, Logo.dev may receive the IP address, requested domain and request timestamp.Policy
StripeSecure checkout and payment administration if paid preorders are enabled. Investiq does not store full card details.Policy
UpstashShort-lived caching and controls against abuse or excessive API requests.Policy

7. How long data is kept

CategoryRetention
Account, profile and active app dataFor as long as the account is active. Following a valid deletion request, active data is deleted or anonymised within 30 days.
Security and error logsNormally 30 days. Relevant material may be kept longer where a specific incident or legal claim requires it.
Product analyticsPostHog events, consented news-view events and any first-party mobile-app events are kept for up to 12 months from collection, or less after consent is withdrawn where deletion can technically be linked to your analytics identifier.
Support email24 months after the matter is closed, unless needed longer for a legal claim.
Content reports and moderation decisionsNormally three years after the matter is closed. Data may be kept longer for an active authority matter, safety need or legal claim, and for less time where it is no longer needed.
Withdrawal and refund mattersThe request itself is normally kept for three years after closure. Order, refund and accounting evidence is kept for the longer statutory period below.
Prelaunch and referralsUntil the campaign and promised rewards have been administered, normally no longer than 12 months after the campaign ends. Marketing data is removed when consent is withdrawn.
Order and accounting recordsFor the period required by Swedish accounting and tax law, normally seven years after the end of the calendar year in which the financial year closed.
BackupsAfter active data is deleted, residual copies may remain in rolling backups for up to 7 additional days and are not restored to active use.

Public or shared content may need to be anonymised rather than deleted if removing it would damage other users' conversations, leagues or safety matters. In that case, the name, profile image and active account link are removed.

8. Your data protection rights

Under the GDPR, depending on the circumstances, you may request access, correction, deletion, restriction and portability, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing.

Email investiqco@gmail.com. We may ask you to verify that the request relates to the correct account. We normally respond within one month; complex or numerous requests may be extended by two further months under the GDPR after notice.

You may also complain to the Swedish Authority for Privacy Protection (IMY): imy.se.

Investiq does not sell or share personal data for behavioural advertising, so there is no separate “Do Not Sell or Share” link.

9. International transfers

Core data is configured in EU-based Azure resources and the preorder database is restricted to Cloudflare's EU jurisdiction. Global providers may still provide limited support access, deliver authentication or notifications, or process metadata outside the EEA. Ordinary internet traffic may also transit other regions.

Where a transfer outside the EEA occurs, European Commission adequacy decisions, Standard Contractual Clauses and supplementary security measures are used under the provider agreements. You may request a copy or further information using the contact address below.

10. Children, young people and minimum age

You must be at least 13 and have reached the age at which you can consent to an information-society service in your country of residence. In Sweden that age is 13; in other EEA countries it may be as high as 16. Anyone below the applicable local threshold may not create an account through the standard registration flow.

We do not collect a full date of birth for age checks. Registration instead requires confirmation of the age requirement. If we learn that an account was created in breach of this rule, it will be disabled and the data deleted or anonymised under the periods above. A parent or guardian may contact us.

11. Security and incidents

We use measures including HTTPS/TLS, provider-managed encryption at rest, secure session cookies, the mobile device's SecureStore, access controls, rate limits, logging and separated production secrets. No internet service can promise absolute security. If a personal-data breach occurs, we notify the authority and affected people where required by law.

12. Changes to this policy

When this policy changes, the version and date at the top of the page are updated. Material changes affecting how existing data is used will also be communicated in the app, on the site or by email where appropriate. Please review the policy periodically.

13. Privacy contact

Send questions or requests using the details below. We normally acknowledge and respond to a verified data-protection request within one month.

William UllerstigInvestiqSöderberga Allé 3, 162 52 Vällingby, Swedeninvestiqco@gmail.com

14. Sweden and EEA supplement

Investiq currently has Sweden/the EEA as the service's regional scope. Depending on the purpose, processing relies on GDPR Article 6(1)(a) (consent), 6(1)(b) (contract or pre-contract steps), 6(1)(c) (legal obligation) and 6(1)(f) (legitimate interests). The balancing test mainly covers security, abuse prevention, troubleshooting and legal claims.

Rights under GDPR Articles 15–22 are summarised in section 8. The controller is established in the EEA, so an Article 27 representative is not required. No data protection officer has been appointed because the current processing is not considered to trigger that requirement. You may complain to IMY or the supervisory authority where you live.

Legal reviewThis policy describes the current technical and operational processing. It should be reviewed by Swedish privacy counsel before a major commercial launch or when processing changes materially.
PrivacyTermsCommunity rulesChild safetyReport contentWithdrawal and refundsAccessibilitySecuritySupport