MeritValue

Privacy Policy

MeritValue has no accounts, asks for no personal details, and ships no analytics or advertising SDK. This explains the little it does collect, and why.

Last updated August 2, 2026

The short version

The app has no accounts. It asks for no name, no email address, no phone number and no location. It contains no advertising SDKs and no third-party analytics SDKs of any kind.

What we do keep is a record of which companies were looked up, tied to a random identifier generated on your device — not to you. That record exists to enforce usage limits and to decide which companies to cover next.

Data controller

Akos Komuves, Hungary

Email: komuvesakos@icloud.com

This policy covers the MeritValue iOS app (the “App”) and this website (the “Site”). We comply with the General Data Protection Regulation (GDPR) and applicable Hungarian data protection law.

What you give us

A share price, when you choose to type one. The App never shows a market quote — you enter the price you want to test, and it is sent to our server to compute an implied return. We do not store that price in our database. As with any web service, our hosting provider's standard request logs may briefly contain the request address it appeared in.

That is the only information the App asks you for. There is no account, no sign-up and no profile.

What is collected automatically

  • An install identifier. On first launch the App generates a random UUID and stores it in your device's Keychain. It is not derived from your device, your hardware, your Apple ID or you, and it is not the advertising identifier. Deleting the App and reinstalling produces a new one.
  • An API key. Your install exchanges that identifier for its own key, stored in the Keychain. We store only a cryptographic hash of it, never the key itself.
  • Request records. For each request we record the endpoint called, the company ticker requested, the response status, the time, and which key made the call. This is how usage limits are enforced and how we decide which companies to prioritise.
  • Registration records. When your install registers we record a salted cryptographic hash of the IP address, a hash of the install identifier, the platform, the outcome and the time. We do not store raw IP addresses. The hash exists so one network cannot mint unlimited keys.

What stays on your device

Your follow list and your recently opened companies are stored on your device and are never transmitted to us. There is no sync and no backup on our side. Deleting the App deletes them.

What we never collect

  • No name, email address, phone number or postal address
  • No location data
  • No contacts, photos, calendar, health or payment data
  • No advertising identifier (IDFA), and no advertising or attribution SDKs
  • No third-party analytics SDK inside the App
  • No cross-app or cross-site tracking. We do not sell personal data.

This website

The Site uses PostHog (EU-hosted) for aggregate traffic analytics — page views and navigation — configured not to create profiles for anonymous visitors. This applies to the website only; the App contains no analytics SDK.

How we use it

  • To serve valuations and company data to the App
  • To enforce per-install usage limits and prevent abuse of the API
  • To understand which companies are in demand, so coverage extends where it is used
  • To diagnose faults and improve the service

Legal basis (GDPR)

  • Contract performance — processing necessary to deliver the App's functionality (Article 6(1)(b))
  • Legitimate interests — preventing abuse of the API, keeping the service available, and deciding which companies to cover (Article 6(1)(f))

Who processes data for us

We do not sell your data and we do not share it with advertisers or data brokers. We use these processors:

ServicePurposeData processedPolicy
VercelApplication hosting and deliveryRequest metadata, IP address (transient, in standard server logs)Vercel
SupabaseDatabaseInstall identifier hash, key hash, request records, IP hashSupabase
PostHog (EU)Website analytics only — not used in the AppPage views, browser and country-level metadataPostHog

We may disclose information if required by law or in response to a valid legal request by a public authority.

How long we keep it

  • Request and registration records — no longer than necessary for usage limits, abuse prevention and coverage planning, then deleted or aggregated.
  • Key records — while the key is active. Re-registering an install revokes the previous key.
  • On-device data — until you delete the App or clear it in the App.

Your rights

As an EU resident you have the right to:

  • Access — request a copy of your personal data
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data
  • Restriction — request limited processing
  • Portability — receive your data in a portable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing relies on it

To exercise these rights, write to komuvesakos@icloud.com. We respond within 30 days.

Because the App has no accounts, the data we hold is pseudonymous and we usually cannot connect it to a person. Where we cannot identify you from what we hold, Article 11 GDPR applies and we may be unable to action a request unless you can supply something that identifies the records — your install identifier, for instance. We will not ask you for additional identifying information solely to comply.

Security

  • All data encrypted in transit (TLS)
  • API keys stored only as cryptographic hashes on the server, and in the device Keychain on your phone — scoped so they do not ride a backup to another device
  • IP addresses salted and hashed rather than stored
  • Access controls on our data systems

No method of transmission over the Internet is completely secure, and we cannot guarantee absolute security.

International transfers

Your data may be transferred to and processed outside the European Economic Area, including in the United States, where our service providers operate. Those transfers are protected by Standard Contractual Clauses and by the providers' compliance with applicable data protection frameworks.

Children

The App is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.

Changes

We may update this policy. We will change the date above, and for significant changes we will say so in the App. Continued use after a change means you accept it.

Contact

Akos Komuveskomuvesakos@icloud.com

You also have the right to complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), or to your local data protection authority.

Privacy · Terms · Home