Privacy Policy
Last updated: 6 July 2026
1. Who we are
Bullio is the trading name of the developer of the Bullio portfolio tracking app for iOS and Android. We are based in Queensland, Australia. Contact: support@getbullio.app.
2. What data we collect
Data that stays on your device (never sent to us)
All portfolio data is stored locally in a SQLite database on your device, encrypted at rest using SQLCipher (AES-256). This includes:
- Holdings — metal type, purity, weight, cost basis, labels, notes, storage location
- Transactions — buy and sell records, prices paid, fees, realised P&L
- Realised sales history
- Holding photos you attach to a holding — stored as local file references only, never uploaded. (AI Import is a separate, opt-in flow — see Device Permissions below.)
- Portfolio value history
- App settings — home currency, biometric lock preference, screenshot-safe mode
- Price alert configurations — metal, threshold, direction. Never sent to our servers.
The following security material is also stored on your device only:
- The database encryption key — a 256-bit random key in the device's hardware-backed secure storage (iOS Keychain / Android Keystore), marked device-only and never synced.
- If you enable the optional app passphrase: the wrapped (sealed) form of the data key. The raw key is deleted once sealed; only your passphrase can unseal it.
An install_id (a random UUID generated at first launch) and install_date
are stored locally in the database. These are device-local identifiers and are not transmitted
to our servers in routine operation.
Data sent to our servers
When you request a price update, your app sends:
- Your selected currency (e.g.
"AUD") - The metals you are tracking (e.g.
"AU","AG")
No portfolio values, holding counts, purchase prices, or any financial data are included in price requests.
When validating a premium subscription, your app sends:
- An anonymous device identifier
- Your App Store or Google Play purchase receipt token
No name, email, or portfolio data is sent during subscription validation.
If you submit your email address through the "notify me at launch" form on this website, that address is sent to Formspark, our form-processing provider, so we can contact you about launch. It is not linked to any portfolio data and is not collected through the app itself.
Crash reports
Bullio does not currently send any crash or diagnostic data. The app contains no active crash-reporting SDK. We may introduce privacy-respecting crash reporting in a future update; if we do, we'll update this policy first.
Analytics
We do not currently collect analytics. No analytics SDK is active in the app. This section will be updated if and when analytics are introduced.
3. Third-party services
The following third-party services receive data in connection with operating Bullio:
4. Device permissions
Camera and photo library
Holding photos. Photos you attach to a holding are stored locally on your device and are never uploaded to our servers.
AI Import (optional). If you use AI Import, the single photo you choose to scan is sent — over an encrypted connection, through our own backend — to our AI provider, Anthropic, which reads it to extract the item's details (such as product name, price, and date). We do not store the image: our backend processes it in memory and retains no copy. Anthropic processes the image to fulfil the request under its own terms; we do not control its retention. Only the photo you explicitly choose to import is ever sent — never your portfolio, and never any other holding photo. AI Import is an opt-in feature you turn on before first use.
Biometric authentication (Face ID / Touch ID)
Used only for app lock when you enable it in Settings. Biometric data never leaves your device — biometric verification is handled entirely by the iOS or Android operating system. Bullio never has access to raw biometric data.
Notifications
Bullio may request notification permission to deliver local price alerts. Permission is only requested when you create your first alert — not at app launch — after a short in-app explainer, so the system prompt is never shown without context.
These notifications are generated entirely on your device. Price alert thresholds are stored only in the local database on your device and are never sent to Bullio's servers. The background check that evaluates your alerts fetches current spot prices from the same public price endpoint the app uses normally; it does not transmit any information about your alert configuration or portfolio. No personal data leaves your device to deliver an alert.
You can revoke notification permission at any time in your device's system settings (iOS: Settings → Notifications → Bullio; Android: Settings → Apps → Bullio → Notifications). Revoking permission disables alert delivery but does not delete your saved alerts.
5. Data backup
When you initiate a backup in Settings, the app encrypts your data on-device and writes the encrypted file to iCloud Drive (iOS) or Google Drive (Android). Bullio's servers are not involved in this process and cannot read the contents of a backup file.
Backup files are encrypted using Argon2id + XChaCha20-Poly1305 (libsodium) with a passphrase you choose at backup time. This is authenticated encryption — a wrong passphrase or a tampered file is rejected before any data is decrypted. Bullio does not store your backup passphrase and cannot recover a forgotten one.
6. Data retention
All your data lives on your device. Using Settings → Wipe all data, or deleting the app entirely, permanently erases your local database and any photos you've attached to holdings. Backup files you have saved to iCloud Drive or Google Drive are under your control and are managed through those platforms, not by us.
Bullio holds no copy of your portfolio data and has nothing to delete on your behalf.
7. Your rights
Because your portfolio data never leaves your device, you already hold it in full. To export a portable copy: Settings → Export → CSV. This is always available at no cost, on every version.
For any other privacy queries, email support@getbullio.app. We will respond within a reasonable time.
8. Children
Bullio is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided personal data to us, please contact us and we will take appropriate action.
9. Changes to this policy
Material changes to this privacy policy will be announced in-app before they take effect. The "last updated" date at the top of this page will be updated with each revision.
10. Contact
For privacy questions or concerns:
support@getbullio.app
This policy reflects how Bullio handles your data today. We'll update it as the app evolves and announce material changes in-app before they take effect.