Last updated: 10 September 2026
Treapy Ltd ("Treapy", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Please read this policy carefully before using Treapy. By creating an account, you confirm that you have read and understood how we process your personal data.
Treapy Ltd is the data controller responsible for your personal data.
Contact: support@treapy.co
Treapy remembers a referral code to attribute your waitlist signup, using Supabase as its backend provider. The code is sent only when you submit the signup form. This optional attribution uses your consent.
The public website uses first-party localStorage, rather than an analytics cookie. The necessary treapy_privacy_preference entry records only your accept/reject choice, disclosure version and time. The choice expires after 180 days; expired or invalid records are removed when you next use the site. We ask again after expiry or a change to the disclosed purposes or providers. Clearing browser storage also clears your choice. If storage is blocked, the choice lasts only for the current page.
The optional treapy_referral_code entry is neither read nor written before acceptance. It remembers the referral link code and is sent to Treapy via Supabase only when you submit the waitlist form. It is removed when you reject, withdraw, or next use the site after consent expires or becomes outdated. Browser storage is not shared across devices.
Use Privacy choices on every website page to accept, reject or withdraw by choosing Reject optional analytics. Both choices leave signup, authentication and other core features available. We do not prompt again during a valid rejection. Withdrawal stops future attribution and clears the optional browser entry; it does not recall a signup already submitted. Contact support@treapy.co about data already sent.
Necessary authentication and security storage remain separate. Privacy-restricted Sentry error/crash reporting remains available to diagnose failures. Website reports contain a generic error category and build stack locations, excluding user identity, request bodies, headers, cookies, query parameters and free-text error messages. Network providers necessarily receive connection metadata such as an IP address to deliver requests; we do not attach it as a Sentry user identity.
Website Sentry performance tracing, session analytics, Replay, profiling and screenshots are disabled even after acceptance. Acceptance covers only the referral purpose above, not future analytics providers. These browser choices apply to the public website; the native app does not display a web cookie banner.
We process your personal data on the following legal bases under UK GDPR Article 6:
Name, email address
Contract performance (Art 6(1)(b))
Required to create and maintain your Treapy account.
Financial account data, portfolio holdings, transaction history
Contract performance (Art 6(1)(b))
The core portfolio tracking service cannot be delivered without this data.
Cryptocurrency wallet addresses
Contract performance (Art 6(1)(b))
Required to display your on-chain portfolio data.
Device identifiers, push notification tokens
Legitimate interests (Art 6(1)(f))
Delivering push notifications you opt into; detecting fraud and security threats.
IP address
Legitimate interests (Art 6(1)(f))
Security monitoring, fraud prevention, and service operation.
Crash reports and error logs
Legitimate interests (Art 6(1)(f))
Improving app stability and diagnosing technical issues.
Messages in the Tripp AI chat
Contract performance (Art 6(1)(b))
Delivering the Tripp AI assistant feature.
We use the personal data we collect to:
The processors and service providers below receive only the data needed for the selected feature. Availability is limited to reviewed providers and regions. We do not sell personal data.
Receives:Minimised plan, adherence, and review context plus messages you explicitly type in the Tripp interface
Purpose:Powering the Tripp AI assistant
Direct identifiers and linked-account credentials are excluded from server-built prompts; text you type may itself contain identifying information. Contractual retention, training, and transfer terms must be verified for the active environment.
Receives:Privacy-scrubbed crash reports, error metadata, device type, operating system version, and app version
Purpose:Error monitoring and app stability
Treapy filters known direct identifiers and credentials before sending events. Reports may still contain technical metadata needed to diagnose failures.
Receives:All data stored by Treapy, including account data, financial data, portfolio data, and settings
Purpose:Database, authentication, and backend infrastructure
The active project region and applicable backup, subprocessor, and transfer arrangements are recorded in the release processing inventory.
Receives:Push notification tokens
Purpose:Delivering push notifications to your mobile device
Delivery is used only for notification categories enabled by the user and approved for the release.
Receives:Connection identifiers, read-only brokerage account metadata, holdings, and transactions for a connection you approve
Purpose:Connecting and synchronising supported brokerage accounts
Treapy enables only reviewed read-only capabilities for the user, institution, and region.
Receives:OAuth consent identifiers and read-only bank account, balance, and transaction data for a connection you approve
Purpose:Connecting and synchronising supported Open Banking accounts
OAuth attempts are actor-bound, short-lived, and single-use.
Receives:Email address and transactional or support message content, which may include a user-configured alert label or value
Purpose:Sending transactional and support email
Treapy does not send linked-account credentials in email delivery requests.
Receives:API-authenticated read-only account requests when you explicitly connect a supported Binance account
Purpose:Validating and synchronising the connected exchange account
Treapy requires read-only credentials and does not request withdrawal or trading permissions.
Receives:Public wallet addresses, chain identifiers, and requested on-chain asset queries
Purpose:Reading supported public blockchain portfolio data
Wallet addresses can be personal data when associated with an account. Treapy never sends a wallet private key.
Receives:Public Solana wallet addresses and requested on-chain asset queries
Purpose:Reading supported public Solana portfolio data
Wallet addresses can be personal data when associated with an account. Treapy never sends a wallet private key.
Receives:Requested public asset identifiers and market-data queries
Purpose:Providing public cryptocurrency prices and market data
Treapy does not include your account identity or provider credentials in market-data queries.
Receives:Short-lived service rate-limit and operational cache keys
Purpose:Abuse prevention and bounded operational caching
Private portfolio payloads are not stored in shared rate-limit keys.
A read-only connection is offered only when its configuration is approved for your account and region. The consent screen identifies the processor and data involved before you connect.
Account data
Targeted for deletion when the request is completed; restricted backups and legally required records follow their disclosed retention schedule
Financial sync data (bank, brokerage, exchange)
Removed or restricted according to the provider's reviewed disconnect mode and disclosed retention period
Push notification tokens
Deleted upon account deletion or when you disable notifications in app settings
Support communications
Retained for 3 years from the date of the last communication
Audit logs
Retained for 7 years to meet legal and regulatory obligations
Account deletion is not described as instantaneous or universal. A minimal non-identifying completion record may be retained, and restricted backups, provider copies, support records, fraud evidence, or legal-hold records follow the applicable disclosed retention schedule.
Under UK GDPR, you have the following rights in relation to your personal data:
Right of access
Request a copy of the personal data we hold about you (Art 15).
Right to rectification
Request correction of inaccurate or incomplete personal data (Art 16).
Right to erasure
Request deletion of your personal data, subject to our legal retention obligations (Art 17).
Right to restriction
Request that we limit how we process your data in certain circumstances (Art 18).
Right to portability
Receive your personal data in a structured, machine-readable format (Art 20).
Right to object
Object to processing based on legitimate interests at any time (Art 21).
To exercise any of these rights, email us at support@treapy.co. We will respond within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Treapy is not intended for use by anyone under 18 years of age. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact support@treapy.co and we will delete it promptly.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
No method of data transmission or storage is 100% secure. If you have reason to believe your Treapy account has been compromised, contact support@treapy.co immediately.
Treapy does not sell personal data and does not operate an advertising-funded service. As a result:
The Tripp AI assistant is powered by Anthropic's Claude API. When you interact with Tripp, the following applies:
Treapy records the active hosting region and every international data flow in its release processing inventory. Some providers operate infrastructure outside the United Kingdom.
A provider or region is not enabled until the applicable transfer mechanism and contractual safeguards have been reviewed and recorded. Contact support for the current mechanism applicable to a particular provider or request a copy of the relevant information.
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. If we make material changes, we will notify you by email at least 30 days before the changes take effect, and we will update the "Last updated" date at the top of this page.
This notice explains our processing; continued use does not grant consent to optional website analytics. New optional purposes or providers require an updated disclosure and a new choice before collection starts. You can withdraw optional consent using Privacy choices without closing your account.
For any questions about this Privacy Policy, or to exercise your data subject rights, please contact us:
Treapy Ltd
Email: support@treapy.co
You also have the right to contact the Information Commissioner's Office directly if you have a complaint about how we handle your personal data: ico.org.uk or 0303 123 1113.