Back to Home

Privacy Policy

Effective Date: July 25, 2026

Last Updated: August 19, 2026

Company: Bucko Labs LLC

support@bucko.ai

Mobile notice

Bucko iOS 2.0 and Mobile Privacy

This section explains the data used by Bucko's iPhone app. It adds to the rest of this Policy. A mobile feature that is turned off does not collect data through that feature. Before we turn on a new mobile data flow, we will update the in-app notice, this Policy, and our App Store privacy answers when required.

Account and profile

  • When you create or use an account, Firebase Authentication processes your email address, Bucko user ID, login provider, and authentication records. If you use Apple or Google, Bucko does not receive your Apple ID or Google password.
  • You can provide an age group, goals, interests, experience level, markets you follow, challenges, account-size range, prop-firm context, and coaching preferences. Bucko asks for an age group, not a full birth date.
  • Most onboarding, VibeList, Bucko IQ, and preference answers are stored on your iPhone in the current release. They personalize what the app shows. We do not use account size, experience, or hard answers to make your Bucko IQ score look better.

Camera, photos, and chart images

  • Bucko asks for camera access only after you tap a camera action. Photo-library access is limited to the image you choose.
  • Look Around and the basic chart reader inspect images on the iPhone in the current release. Look Around does not upload the raw photo to Bucko. It may keep a one-way image fingerprint, company match, confidence, time, and private XP event on the phone to limit duplicate scans.
  • If you choose to save a chart review, the prepared screenshot, recognized chart text, ticker, timeframe, and notes stay on that iPhone until you delete the review or clear your Bucko account data.
  • Remote P&L-calendar, Prop Desk, and AI screenshot uploads are off in the iOS 2.0 release. If a later version enables them, Bucko will show a clear notice before upload that names what is sent, the provider purpose, and the retention period.

Location and audio

  • Location collection is off in the current iOS 2.0 release. The built-in location design is optional, adult-only, and limited to a one-time approximate location while you use the app. It does not request background or always-on location, create a movement trail, or store coordinates, an address, a city, or a ZIP code. If enabled later, Bucko keeps only a broad country and state or province after you opt in.
  • The onboarding voice preview only plays a fixed Bucko sample, either from the app or Bucko's server. It does not turn on the microphone or record you.
  • Live conversational voice is off in the current iOS 2.0 release. If enabled later, microphone audio would be sent in real time to the named voice provider only after you start a session. The app will explain transcript and retention choices before that feature is turned on.

Watchlist, journal, quests, XP, and market research

  • Your Watchlist can be stored on the phone. When signed-in sync is available and the app says Synced, Bucko also stores the ticker, company name, asset type, and time added in your account so the web and iOS versions can match.
  • Journal entries, session plans, learning progress, private quests, and private XP are stored on the phone in the current release. Public player profiles and a public player leaderboard are off.
  • When you search for a ticker or request a quote or chart, Bucko sends the symbol, range, and request details to Bucko's server and a market-data provider. Bucko also uses your account ID for access checks, cost limits, and abuse prevention. Market prices may be delayed, and search or chart history is not a record that you own that investment.

Subscriptions, Firebase, and app security

  • Apple processes iOS payments through StoreKit. Bucko receives purchase and subscription details such as the product, status, transaction identifiers, renewal or expiration status, and refund or revocation events. Bucko does not receive your full payment-card number from Apple.
  • Firebase and Bucko's servers use your Firebase ID token plus App Check and, when enabled for the signed release, App Attest signals to verify your account and that a request came from a genuine copy of the app. Standard security logs may include the request time, app version, device or OS category, network address, response status, and abuse signals.
  • Bucko uses these records to unlock the right membership, restore purchases, prevent fraud, enforce limits, protect deletion requests, and troubleshoot service errors.

Retention, deletion, and features that are off

  • Phone-only content stays on the device until you delete it or complete a Bucko sign-out or account-deletion flow that clears local account data. Synced account data is kept while your account is active, subject to the retention rules in this Policy.
  • You may ask Bucko to delete your account and account-linked personal data, except limited records we must keep for tax, fraud, disputes, security, or other legal duties. The public iOS release is required to let a signed-in user start this request inside the app. You may need to sign in again to protect the account.
  • Deleting a Bucko account does not cancel an Apple subscription. Apple controls that billing relationship, so you must manage or cancel it in your App Store subscription settings.
  • Plaid bank connections, public player leaderboards, live voice sessions, remote Prop Desk image analysis, background location, and ad tracking are off in the current iOS 2.0 release. Bucko does not collect bank transactions, public-player identity, microphone recordings, remote screenshots, or background location through those disabled features.

The iOS app does not include an advertising SDK, does not ask for permission to track you across other companies' apps or websites, and does not sell personal information or share it for cross-context behavioral advertising.

1. Introduction

Bucko Labs LLC ("Bucko," "we," "us," or "our") respects your privacy and is committed to protecting the information you share with us. This Privacy Policy explains how we collect, use, store, and share your information through the Bucko website, web application, iOS app (together, the "App"), and related services.

2. What Information We Collect

a) Information You Provide

  • Email address or Apple or Google account information (if used to register)
  • Optional profile name or preferences
  • Name, email address, chart configuration, and referral details you submit when using Bucko Charts; marketing email is optional and requires a separate opt-in
  • Financial information you enter manually, including income, expenses, debts, assets, goals, and financial priorities
  • Transaction corrections, category changes, notes, Board resolutions, completed actions, and AI explanation consent

b) Banking & Transaction Data (via Plaid)

When you connect a financial institution, we use Plaid Inc. to securely access:

  • Account balances
  • Transaction history
  • Merchant names
  • Spending categories

We never store or see your banking credentials. All credentials are securely transmitted to Plaid.

c) Broker & Trading Data (Tradovate, Prop Firms)

When you connect a brokerage or prop-firm account (Tradovate and the firms that use it, including AlphaFutures, Apex, Lucid, Traidify, and others), we receive an OAuth access token and use it to read and, if you enable it, place orders on the accounts you authorize.

  • Account identifiers, names, and environment (live or demo)
  • Balances (net liquidation, cash, daily P&L, weekly P&L)
  • Positions, fills, orders, and working orders
  • Distance-to-bust, auto-liq counters, and prop-firm risk signals
  • Trade events generated by Monko (placed, filled, cancelled, blocked, stand-down), including the rationale and signal IDs the model used

OAuth access tokens are encrypted at rest. We never see your broker password. You can disconnect at any time from the station UI; revoking the token stops all further reads and trade activity from Bucko.

d) Trading Signal & Behavioral Telemetry

  • Bucko Indicator signal events you receive (symbol, grade, timeframe, direction, TP/SL)
  • AI briefings produced by Scout, Warden, Coach, Oracle, the Guide, Herald, and Monko
  • Your in-app preferences (risk caps, grade filter, trailing-stop config, consistency rule mode)
  • Disclaimer acknowledgments, including timestamps and the version of the disclaimer signed

e) Automatically Collected Data

  • Device type and OS version
  • App usage patterns and feature interaction
  • Crash reports and performance diagnostics

3. How We Use Your Information

We use the information we collect to:

  • Generate a personalized watchlist of publicly traded companies
  • Generate, privately reopen, and—only when you choose—publish a shareable Bucko Charts result
  • Help you visualize your spending in relation to investment opportunities
  • Calculate deterministic financial metrics, hierarchy placement, reason codes, bottlenecks, and next-step resolutions for Bucko Board
  • Provide AI explanations of reviewed Board results only after you give the required consent
  • Provide a tailored and educational app experience
  • Monitor and improve the App's performance
  • Respond to inquiries and provide customer support

We do not use your data for advertising or sell it to third parties.

4. How We Share Your Information

We may share limited data with:

  • Plaid Inc., to access and process your financial account information
  • Skool, Whop, Stripe, Apple, and their payment providers, for handling membership access and payment services
  • Infrastructure providers, such as analytics and crash reporting tools

These parties are bound by confidentiality and security obligations.

5. Use of Plaid

Connecting an account is optional. If you choose to connect through Plaid Inc., you authorize Bucko to receive data from the accounts you select, including account details, balances, and up to 730 days of available transactions. We use that data for cash-flow, spending, recurring-income, and debt analysis.

Plaid connections are read only. Bucko cannot move money through this connection. Transaction updates may continue while the connection is active. Your bank may return less than 730 days of history, and Bucko will show the actual coverage it receives.

Connected data may produce estimates, but those estimates do not change your Bucko hierarchy classification until you review and save your financial picture. AI explanations do not replace Bucko's deterministic calculations. If connected information will be shared with an AI provider, Bucko asks for separate consent.

Plaid's handling of your information is governed by Plaid's End User Privacy Policy.

You may disconnect accounts, export your Board data, or delete your Board financial records at any time. Disconnecting revokes the Plaid Item and removes its imported Board transactions.

5a. Cookies, Analytics & Similar Technologies

We and our service providers use cookies, local storage, session storage, web beacons, pixels, and similar technologies to operate the App, remember your preferences, keep you logged in, secure your session, measure performance, detect abuse, and understand feature usage.

We use the following categories:

  • Strictly Necessary — authentication, session, CSRF protection, subscription state. These cannot be disabled.
  • Functional — UI preferences (risk profile, default symbol, dark-mode, dismissed disclaimers, Monko preferences).
  • Analytics & Performance — aggregated usage, error monitoring, crash reporting.
  • Security — bot detection, rate-limit signals, anomaly detection.

You can control cookies through your browser settings. Disabling cookies may break core functionality (for example, logging in or keeping a Monko session active).

5b. Subprocessors & Third-Party Providers

To operate Bucko, we engage subprocessors and third-party providers that process personal or account data on our behalf under contract. Categories and representative providers include:

  • Identity & auth: Firebase Authentication (Google LLC), Sign in with Apple (Apple Inc.)
  • Application database & storage: Firebase Firestore & Storage (Google LLC)
  • Hosting & edge: Vercel Inc.
  • Payments & subscriptions: Skool, Whop, Stripe, Inc., and Apple Inc.
  • Banking data (optional): Plaid, Inc.
  • Market data & brokerage APIs: Polygon, Alpaca Securities LLC, Tradovate LLC, Kalshi, Polymarket, and associated prop-firm partners
  • AI / LLM inference: OpenRouter, and its upstream model providers (including Google, Anthropic, and OpenAI)
  • Non-custodial wallets (Oracle): Turnkey and Safe (Gnosis Safe) infrastructure
  • Email & support: Beehiiv for optional marketing email, plus transactional email providers used for receipts and account notices
  • Embedded video: YouTube's privacy-enhanced player (Google LLC), which is loaded only after you choose to play a video

These providers are bound by contractual confidentiality and security obligations and process data only as needed to deliver the services we request.

6. How We Protect Your Data

We implement industry-standard safeguards, including:

  • End-to-end encryption
  • HTTPS-secured connections
  • Minimal data retention practices
  • Access control and internal policy enforcement

No security system is completely impenetrable, but we work hard to protect your information.

6a. Data Retention

We retain personal information only for as long as needed to provide the App, comply with legal obligations, resolve disputes, and enforce our agreements:

  • Account & profile data: retained while your account is active and for a reasonable period after closure.
  • Bucko Charts: signed guest sessions are retained for about 32 days, private chart results, transactional email delivery records, checkout click records, and quota records for about 400 days, public shares and aggregate share statistics for up to 2 years, and pseudonymous share-visitor records for about 32 days. Private replay tokens and result-scoped grants expire after about 30 days; only token hashes are stored. Daily-deduplicated funnel metrics are retained for about 400 days, while their pseudonymous deduplication and abuse-budget records are retained for about 8 days. Lead and consent records are retained for customer communication, consent auditing, and deletion requests.
  • Bucko Board records: retained while you use the Board unless you delete them through the Board account controls or request deletion.
  • Subscription & billing records: retained as required by applicable tax, accounting, and anti-fraud rules (typically 7 years).
  • Disclaimer acknowledgments & Monko session logs: retained indefinitely as compliance records.
  • Broker tokens & derived balances: deleted shortly after you disconnect the linked account.
  • Support correspondence: retained for a reasonable period after resolution.
  • Aggregated / de-identified analytics: may be retained indefinitely.

You can request earlier deletion at any time (see Section 7).

6b. International Data Transfers

Bucko is operated from the United States, and our subprocessors may process data in the United States and other countries. If you access the App from outside the United States, you understand and consent to the transfer, storage, and processing of your information in the United States and other jurisdictions whose data-protection laws may differ from those of your country. Where required, we rely on appropriate legal mechanisms (such as Standard Contractual Clauses) for international transfers.

6c. Data Breach Notification

In the event of a confirmed security incident that materially affects your personal information, we will notify affected users without undue delay and in accordance with applicable law, describe the nature of the incident and the categories of data involved, and outline the steps we are taking and recommendations for protecting yourself.

7. Your Rights

You have the right to:

  • Request to view or delete any personal information stored by us
  • Export your Bucko Board data in a portable format
  • Disconnect linked accounts from Plaid
  • Manage direct Bucko Investor, Super, or Omni billing through the Stripe controls linked from your Bucko profile. Legacy Skool or Whop memberships remain manageable on those platforms
  • Use Delete Account to ask Bucko to stop linked Stripe and Whop renewals before removing your account. If either provider cannot confirm cancellation, Bucko keeps the account and data intact so the billing issue can be resolved safely

To make any request, email: support@bucko.ai

7a. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what categories of personal information we collect, use, disclose, and (if applicable) sell or share.
  • Access the specific pieces of personal information we hold about you.
  • Delete personal information we hold about you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Limit the use and disclosure of sensitive personal information.
  • Opt out of the "sale" or "sharing" of personal information. Bucko does not sell personal information and does not share personal information for cross-context behavioral advertising.
  • Non-discrimination for exercising any of the above rights.

To exercise any of these rights, email support@bucko.ai. We may need to verify your identity before fulfilling a request.

7b. GDPR / UK GDPR / Other International Rights

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with comparable data-protection law, you have the rights of access, rectification, erasure, restriction of processing, objection to processing, data portability, and withdrawal of consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.

Our legal bases for processing include: performing the contract with you (running your account and subscription), our legitimate interests (securing the App, improving features, preventing abuse), complying with legal obligations (tax, anti-fraud), and, where applicable, your consent (for optional data categories such as Plaid-linked bank data).

7c. Do Not Track

Some browsers transmit "Do Not Track" signals. Because there is no common industry standard for interpreting these signals, Bucko does not currently respond to them. As described elsewhere in this Policy, we do not sell personal information or use it for third-party advertising.

8. Payment Processing

Direct Bucko Investor, Super, and Omni web subscriptions are billed through Stripe. Legacy memberships may continue through Skool or Whop. iOS subscriptions may be billed through Apple using StoreKit. Bucko does not store or access your full card details. Billing and cancellations are processed through those providers' secure payment infrastructure.

Manage a direct Bucko Investor, Super, or Omni subscription through the Stripe controls linked from your Bucko profile. Manage a legacy Whop membership through Whop Profile and Orders, and an iOS subscription through Bucko's subscription controls or your App Store subscription settings. Deleting a Bucko account does not by itself cancel a Skool- or Apple-managed subscription.

9. Children's Privacy

Bucko is not intended for children under the age of 13. We do not knowingly collect personal information from children. If you believe we have unintentionally collected such data, please contact us immediately.

10. Educational Use Only

Bucko is designed for educational and informational purposes only. We do not provide financial, legal, or investment advice. Any insights or content provided by the app should not be interpreted as a recommendation to buy, sell, or hold securities.

Always conduct your own research or consult a licensed financial advisor before making investment decisions.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted within the App and on our website with the revised effective date.

12. Contact Us

For any questions or privacy-related requests, contact:

Bucko Labs LLC

Email: support@bucko.ai

Terms of Service →Disclaimer →Back to Home →