Signa

Privacy Policy

Last updated: October 7, 2026

Signa helps you follow your investments. This policy explains what we collect, why, who we share it with and the choices you have. Questions: contact@mysigna.app.

1. Who we are

Signa (“we”) runs the Signa app and this site. For anything about your data, including requests under Brazil’s LGPD and Canada’s PIPEDA and Quebec’s Law 25, write to contact@mysigna.app. The same address reaches the person responsible for personal information (encarregado de dados).

2. What we collect

Only what the app needs to work:

  • Account: your username, your password (stored only as a one-way hash, never readable), and your email if you add one.
  • Settings: display name, country, home currency, language, theme and your other preferences.
  • Portfolio data you enter: accounts (like TFSA or RRSP), the names you give to people who share a portfolio with you, holdings, transactions and notes, fixed income, followed stocks, price alerts and goals, plus daily snapshots Signa calculates from them.
  • Sign-in and security: the device name, app version, IP address and browser or app identifier of each sign-in, kept to protect your account.
  • Notifications: your iPhone’s notification token, if you turn notifications on.
  • Telegram, if you link it: your chat ID and Telegram username.
  • Problem reports you send: your message, plus the app version, iOS version, iPhone model, language and technical details about the last error.
  • How you found us: your answer to “how did you hear about Signa”, campaign tags in the link you used, and Apple Search Ads attribution.
  • Usage: one record for each day you open the app.

We do not collect your bank or broker passwords, your location, your contacts, your phone number or your birth date. Signa never connects to your bank or broker: you add your holdings yourself or import a file.

3. Why we use it

  • To provide the app: show your portfolio, dividends, goals and alerts (to perform our contract with you).
  • To keep your account safe: sign-in, two-step sign-in, spotting unusual sign-ins and abuse (legitimate interest and legal obligations).
  • To send the notifications and messages you turn on (your consent, which you can withdraw at any time).
  • To answer your support requests and fix problems.
  • To understand which channels bring people to Signa and how often the app is used, in aggregate (legitimate interest).

We do not sell your data, show ads or use your data to train AI. Signa has no advertising trackers and the app uses no cookies.

4. Who we share it with

Only service providers that help run Signa, each for its own task:

  • Supabase: hosts our database.
  • Apple: delivers notifications to your iPhone (with “Hide amounts” on, the lock screen shows no amounts or tickers) and confirms which Apple Search Ads campaign led to a download.
  • Telegram: delivers alerts and sign-in codes, only if you link Telegram.
  • Our email provider: delivers sign-in and recovery codes to your email.

To get prices and rates we ask Yahoo Finance and the Banco Central do Brasil for market data. Those requests contain only ticker symbols, currencies and index names, never information about you.

Siri: when you use Signa with Siri, Apple processes your voice request under Apple’s privacy policy; Signa receives only the question and answers it from your account.

We may disclose data if the law requires it. Our providers may store data outside your country; we choose providers that protect it to the standards required by the LGPD and PIPEDA.

5. How long we keep it

  • Your account and portfolio data: while your account exists.
  • When you delete your account, it is scheduled for deletion and you are signed out everywhere. You can restore it by signing in within 30 days. After that, your account and all its data are permanently deleted.
  • After deletion we keep, without your identity: security logs for up to 180 days, and the text of problem reports you sent (closed reports are deleted after a year). Your username stays reserved for 90 days so no one can impersonate you.
  • Sign-in sessions expire after inactivity; sign-in codes expire within minutes; server logs are kept for 14 days and store only a shortened IP address.

6. Your rights

You can, at any time:

  • Get a copy of your data: Profile → Privacy → Download my data.
  • Correct it in the app, or ask us to.
  • Delete your account: Profile → Delete account.
  • Turn off notifications, Siri or Telegram, and withdraw any consent.
  • Ask what we hold about you, how we use it and who we share it with.

The download includes your account, settings, portfolio, fixed income, problem reports and devices. Security records (IP addresses and sign-in history) and Apple Search Ads campaign IDs are left out; ask for them at contact@mysigna.app. Passwords and sign-in codes are never shown to anyone.

Write to contact@mysigna.app for anything the app doesn’t cover. You can also complain to your data protection authority: the ANPD in Brazil, the Office of the Privacy Commissioner of Canada, or the Commission d’accès à l’information in Quebec.

7. Security

Passwords are stored with bcrypt, sign-in sessions use short-lived, rotating tokens, and you can add two-step sign-in, Face ID and “Hide amounts”. No system is perfectly secure; if a breach puts your data at risk, we will tell you and the authorities as the law requires.

8. Children

Signa is meant for adults. We do not knowingly collect data from anyone under 18; if you believe a minor has an account, contact us and we will delete it.

9. Changes

If we change this policy, we will update the date above and, for important changes, tell you in the app before they apply.