Skip to content
Bullio Bullio
Security Changelog Support
App Store Google Play
Bullio
Security Changelog Support

App — coming soon

Privacy Policy

Privacy Policy

Last updated: 6 July 2026

1. Who we are

Bullio is the trading name of the developer of the Bullio portfolio tracking app for iOS and Android. We are based in Queensland, Australia. Contact: support@getbullio.app.

2. What data we collect

Data that stays on your device (never sent to us)

All portfolio data is stored locally in a SQLite database on your device, encrypted at rest using SQLCipher (AES-256). This includes:

  • Holdings — metal type, purity, weight, cost basis, labels, notes, storage location
  • Transactions — buy and sell records, prices paid, fees, realised P&L
  • Realised sales history
  • Holding photos you attach to a holding — stored as local file references only, never uploaded. (AI Import is a separate, opt-in flow — see Device Permissions below.)
  • Portfolio value history
  • App settings — home currency, biometric lock preference, screenshot-safe mode
  • Price alert configurations — metal, threshold, direction. Never sent to our servers.

The following security material is also stored on your device only:

  • The database encryption key — a 256-bit random key in the device's hardware-backed secure storage (iOS Keychain / Android Keystore), marked device-only and never synced.
  • If you enable the optional app passphrase: the wrapped (sealed) form of the data key. The raw key is deleted once sealed; only your passphrase can unseal it.

An install_id (a random UUID generated at first launch) and install_date are stored locally in the database. These are device-local identifiers and are not transmitted to our servers in routine operation.

Data sent to our servers

When you request a price update, your app sends:

  • Your selected currency (e.g. "AUD")
  • The metals you are tracking (e.g. "AU", "AG")

No portfolio values, holding counts, purchase prices, or any financial data are included in price requests.

When validating a premium subscription, your app sends:

  • An anonymous device identifier
  • Your App Store or Google Play purchase receipt token

No name, email, or portfolio data is sent during subscription validation.

If you submit your email address through the "notify me at launch" form on this website, that address is sent to Formspark, our form-processing provider, so we can contact you about launch. It is not linked to any portfolio data and is not collected through the app itself.

Crash reports

Bullio does not currently send any crash or diagnostic data. The app contains no active crash-reporting SDK. We may introduce privacy-respecting crash reporting in a future update; if we do, we'll update this policy first.

Analytics

We do not currently collect analytics. No analytics SDK is active in the app. This section will be updated if and when analytics are introduced.

3. Third-party services

The following third-party services receive data in connection with operating Bullio:

Service Data received
Metals.Dev Privacy policy ↗
Currency code, metal identifier — no portfolio data
ExchangeRate-API Privacy policy ↗
Currency pair request — no portfolio data
Anthropic Privacy policy ↗
The image data of the single photo you choose to import. Nothing else about your portfolio.
RevenueCat Privacy policy ↗
Anonymous device identifier + App Store/Play receipt Active when premium subscriptions launch
Sentry Privacy policy ↗
Nothing today — no crash-reporting SDK is initialised in the app We’ll update this row if/when crash reporting is introduced
Cloudflare Privacy policy ↗
Standard server logs including IP addresses in transit
Formspark Privacy policy ↗
The email address you submit to be notified about launch
Apple App Store / Google Play
Governed by Apple and Google policies

4. Device permissions

Camera and photo library

Holding photos. Photos you attach to a holding are stored locally on your device and are never uploaded to our servers.

AI Import (optional). If you use AI Import, the single photo you choose to scan is sent — over an encrypted connection, through our own backend — to our AI provider, Anthropic, which reads it to extract the item's details (such as product name, price, and date). We do not store the image: our backend processes it in memory and retains no copy. Anthropic processes the image to fulfil the request under its own terms; we do not control its retention. Only the photo you explicitly choose to import is ever sent — never your portfolio, and never any other holding photo. AI Import is an opt-in feature you turn on before first use.

Biometric authentication (Face ID / Touch ID)

Used only for app lock when you enable it in Settings. Biometric data never leaves your device — biometric verification is handled entirely by the iOS or Android operating system. Bullio never has access to raw biometric data.

Notifications

Bullio may request notification permission to deliver local price alerts. Permission is only requested when you create your first alert — not at app launch — after a short in-app explainer, so the system prompt is never shown without context.

These notifications are generated entirely on your device. Price alert thresholds are stored only in the local database on your device and are never sent to Bullio's servers. The background check that evaluates your alerts fetches current spot prices from the same public price endpoint the app uses normally; it does not transmit any information about your alert configuration or portfolio. No personal data leaves your device to deliver an alert.

You can revoke notification permission at any time in your device's system settings (iOS: Settings → Notifications → Bullio; Android: Settings → Apps → Bullio → Notifications). Revoking permission disables alert delivery but does not delete your saved alerts.

5. Data backup

When you initiate a backup in Settings, the app encrypts your data on-device and writes the encrypted file to iCloud Drive (iOS) or Google Drive (Android). Bullio's servers are not involved in this process and cannot read the contents of a backup file.

Backup files are encrypted using Argon2id + XChaCha20-Poly1305 (libsodium) with a passphrase you choose at backup time. This is authenticated encryption — a wrong passphrase or a tampered file is rejected before any data is decrypted. Bullio does not store your backup passphrase and cannot recover a forgotten one.

6. Data retention

All your data lives on your device. Using Settings → Wipe all data, or deleting the app entirely, permanently erases your local database and any photos you've attached to holdings. Backup files you have saved to iCloud Drive or Google Drive are under your control and are managed through those platforms, not by us.

Bullio holds no copy of your portfolio data and has nothing to delete on your behalf.

7. Your rights

Because your portfolio data never leaves your device, you already hold it in full. To export a portable copy: Settings → Export → CSV. This is always available at no cost, on every version.

For any other privacy queries, email support@getbullio.app. We will respond within a reasonable time.

8. Children

Bullio is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided personal data to us, please contact us and we will take appropriate action.

9. Changes to this policy

Material changes to this privacy policy will be announced in-app before they take effect. The "last updated" date at the top of this page will be updated with each revision.

10. Contact

For privacy questions or concerns:
support@getbullio.app


This policy reflects how Bullio handles your data today. We'll update it as the app evolves and announce material changes in-app before they take effect.

Bullio Your portfolio data never leaves your device.
Privacy Terms Security Changelog Status
App coming soon
© 2026 Bullio. Not financial advice.
api.getbullio.app — checking