Trakkr (trakkr.co) is a personal-finance and Dhaka Stock Exchange portfolio tracker. This policy explains what we store about you, why, who else can see it and the choices you have. Questions: trakkrbd@gmail.com.
What we collect
- Account details: your name, email address and password. Passwords are stored only as a salted bcrypt hash, so we can't read them.
- Phone number, if you add one in Settings. It is used only so people you lend to or borrow from can link a loan to your account, and it isn't shown to other users.
- The financial records you enter: accounts and balances, transactions, trades and holdings, budgets, goals, savings schemes, loans, notes, journal entries, watchlists and price alerts. Trakkr doesn't connect to your bank or broker; everything comes from what you type, import (for example a statement or a backup file) or send through our bots.
- Pro payments: the method (bKash, Nagad or bank transfer), amount, transaction ID, any screenshot you upload, and our support conversation about the payment.
- Community content: your community display name, posts, votes, chat messages and anything you share there.
- Connected services: if you link the Telegram or Discord bot, your chat or user ID and username there; if you give an AI agent access (MCP), the access token's name and permissions, and a log of what the agent did.
- Usage and technical data: the pages you open and actions you take in the app, and, when something fails, the request, time, IP address and browser type. This is stored on our own servers; we don't use third-party analytics or advertising trackers.
How we use it
- To run your account and show your data back to you, with live DSE prices.
- To send the notifications you turn on (in the app, and on Telegram or Discord if linked) and password-reset emails.
- To check Pro payments by hand and help you when something goes wrong.
- To keep Trakkr secure and working: limiting repeated sign-in attempts, stopping abuse and fixing errors.
We don't sell your data and we don't use it for advertising.
Who else can see it
- Other Trakkr users see only what you post in the community (under your display name), portfolios or watchlists you share with them, and loans you record with them or share by link.
- Telegram or Discord receive the messages our bot sends you there.
- Our email provider delivers password-reset emails.
- Apps you connect through "Authorize access" (MCP) can read your data, and change it if you allowed that, until you revoke them in Settings → MCP / Agent Access.
- Hosting providers that run our servers, only to operate the service.
- Authorities, when Bangladeshi law requires it.
Cookies and browser storage
We set one cookie, session_id, to keep you signed in (it can't be read by scripts and lasts up to 30 days).
Your browser also keeps display preferences such as the theme and sidebar layout; these are cleared when you sign out.
Keeping and deleting your data
We keep your data while your account exists. You can download a full backup any time in Settings → Data Export, and delete your account in Settings → Account → Delete account. Deleting removes your account and the data listed above straight away. Community posts and chat messages stay visible to the people in those threads, shown as "Deleted user". Copies in server backups are removed as those backups are replaced (backup retention period to be confirmed).
Security
Passwords, agent tokens and reset links are stored hashed or expire quickly, and sign-in attempts are rate limited. No system is perfectly secure: if you find a problem, please tell us at trakkrbd@gmail.com.
Age
Trakkr is meant for adults (minimum age to be confirmed).
Changes to this policy
When this policy changes we'll update the date above, and announce significant changes in the app.