Last Revised: 2026-06-27
This policy explains what information Insider Desk handles and the data flows that leave your device. The app does not require an account, and we do not run a backend. It does not contain advertising, cross-app tracking, or third-party analytics or advertising SDKs. The Company Logo feature uses a third-party provider over HTTPS, which we disclose below.
1. The Short Version
- No accounts. The app does not require sign-up. We do not ask for your name, email, or contact information.
- Nothing comes back to us. We do not run a backend and do not gather usage analytics. The app is a client: to show you market data, your device connects directly to third-party sources, including the public data providers (SEC, CFTC, Treasury, BLS) and, when you enable company logos, Elbstream. Each request includes your device's IP address. An IP address is personal information under several privacy laws. We do not receive your IP address.
- No tracking. No advertising identifier, no cross-app tracking, no third-party analytics or advertising SDKs.
- On your device. Your watchlist, filters, and preferences are stored only on your device. Deleting the app removes them.
- Direct connections. To show market data, your device connects directly to public data sources. Those services receive a standard web request from your device. We are not the recipient of those requests and do not log them.
2. Information and Where It Lives
We do not run a backend, and we do not maintain user accounts or a user database. Your device connects directly to public data sources to show market data; the one flow we set up to a commercial provider for our own feature is the optional company-logo request to Elbstream (Section 3). This section explains what stays on your device and what we do not gather.
2.1 Stored Only on Your Device
Your watchlist, filter configurations, display themes, ordering preferences, and notification settings are stored locally on your device through Apple's standard storage, encrypted at rest by iOS. They leave your device only where you explicitly export or share them (Section 5). We cannot read them.
2.2 What We Do Not Gather
- Names, email addresses, or contact information.
- User accounts or any user database.
- Usage analytics, screen views, or interaction data.
- Device identifiers for analytics or advertising.
- Advertising or attribution data.
We do not sell or share personal information, and we do not keep a record of which SEC filings or screens you view. When company logos are enabled, the app fetches each displayed company's logo from Elbstream (Section 3). We do not receive those requests.
3. Data That Leaves Your Device
Insider Desk is a client app with no backend of its own. To show public market data, your device makes direct, encrypted (HTTPS) requests to public data sources, and when you enable company logos, to a logo provider. Every such request includes your device's IP address, which is the network address a server uses to return its response to your device. Each service listed below therefore receives your IP address, along with the specific data the request asks for, as a function of your device connecting to it. We are not the recipient of these requests and do not log them.
- SEC EDGAR (
sec.gov) — public filings and company data. The SEC's privacy practices apply: https://www.sec.gov/privacy - CFTC (
cftc.gov) — Commitments of Traders futures positioning. The CFTC's privacy practices apply: https://www.cftc.gov/WebsitePrivacyPolicy - U.S. Treasury (
home.treasury.gov) — daily Treasury yield-curve data. The Treasury's privacy practices apply: https://home.treasury.gov/subfooter/privacy-policy - U.S. Bureau of Labor Statistics (
bls.gov) — inflation (CPI) series. The BLS's privacy practices apply: https://www.bls.gov/bls/pss.htm - Elbstream (
api.elbstream.com) — when company logos are enabled, the app fetches each logo by ticker. As with the public sources above, Elbstream receives your device's IP address (the standard part of any request); the part specific to this feature is the ticker symbols whose logos it fetches: the app requests a logo for each company it displays. Because we build this request into the app and set its purpose (showing a company logo), we are responsible for this data flow, even though we do not receive, log, or store the data. Elbstream is an independent recipient that handles the request under its own privacy terms; it is not our processor, and we do not have an agreement requiring it to limit logging or retention. We do not link this request to your identity and do not use it for tracking. Company logos are off by default. Turning the Company Logos switch on in Settings starts these requests; turning it off stops them.
None of the SEC, CFTC, Treasury, or BLS endpoints is an analytics, advertising, or tracking service. We disclose them so you know where the app connects.
Logo images fetched while the feature is on are cached on your device so they need not be re-fetched. The logo request and that on-device cache rely on your choice to turn Company Logos on in Settings. Turning the switch back off stops all further logo requests; logos already cached stay on your device until you clear them with the Clear cached logos control in Settings, or until you delete the app.
4. Diagnostics and Performance
Diagnostics stay on your device.
- Device-local logs. The app writes diagnostic logs through Apple's unified logging system. They remain on your device. The only way any leave is if you tap Share Diagnostics in Settings and choose a destination yourself.
- Apple's diagnostics (Xcode Organizer). The app embeds no crash-reporting or analytics SDK and does not use MetricKit. If your iOS Share With App Developers setting is on, Apple aggregates crash, hang, and performance data at the system level and provides it to us in anonymized, summarized form through Xcode Organizer. This is Apple's collection under Apple's controls, not ours; we do not receive anything directly from your device and cannot tie it to you. You control it in Settings → Privacy & Security → Analytics & Improvements.
We do not run a crash-reporting or analytics service of our own.
5. Your Data and Your Controls
Your data is stored on your device, and we do not run a backend, so you hold it directly.
- Delete everything. Delete the app to remove all locally stored preferences and cached data, including any cached company logos.
- Export your watchlist. Insider Desk Professional can export a watchlist to a CSV file generated on your device, which you save or share to a destination you choose.
- Share diagnostics. You can share device-local diagnostic logs from Settings. This is always user-initiated.
- Company logos. The Company Logos switch in Settings turns the Elbstream request on or off.
- Clear cached logos. A control in Settings erases every company logo cached on your device immediately, whether the feature is on or off.
- Preferences. Notification and data-use preferences are adjustable in Settings.
We cannot access, retrieve, correct, or delete data on your device remotely, because we do not receive it.
6. Subscriptions
Subscriptions are sold and managed entirely by the Apple App Store. We do not process payments and do not see your payment details. We receive only your entitlement level (which tier is active) from Apple, used to unlock features on your device. If you obtain Insider Desk through an educational or volume program (Apple School Manager / Volume Purchase Program), Apple manages distribution and we do not receive student or institutional personal data.
7. Children's Privacy
Insider Desk is a general-audience educational tool with no age-restricted content, and it carries an App Store rating of 4+. It is not specifically directed to children. Its subject matter is securities research and financial analysis of insider transactions, institutional holdings, futures positioning, and company financials, all oriented to adults. The app has none of the features COPPA weighs as child-directed: no games, animated characters, child-oriented activities or incentives, and no advertising. We design it for people researching the markets, so it is neither a child-directed nor a mixed-audience service under COPPA. There are no accounts and no communication between users. When company logos are enabled, the app fetches each displayed company's logo from Elbstream (Section 3); you can turn this on or off in Settings. We do not knowingly collect personal information from children under 13, and because the app does not use accounts and we do not run a backend, we do not hold child data to delete. Deleting the app removes all on-device data, and turning Company Logos off stops the logo request to Elbstream (Section 3). If we ever gain actual knowledge of personal information from a child under 13, such as through a support email, we will delete it immediately. Contact privacy@insiderdesk.info with any questions.
8. U.S. State Privacy Rights
Residents of California and other U.S. states with comprehensive privacy laws (including Texas, Virginia, Colorado, and Connecticut) have rights to know, access, correct, delete, and opt out of the sale or sharing of personal information. We do not run a backend, do not maintain a user profile, and do not sell or share personal information or use it for cross-context behavioral advertising, so there is no profile to disclose or delete. The optional company-logo request to Elbstream (Section 3) can be turned off in Settings. We extend the same posture to residents of all such states, regardless of any revenue or volume threshold in the applicable law.
9. Do Not Track and Opt-Out Signals
A Do Not Track signal is a browser request with no agreed legal meaning, and the app does not respond to it. Global Privacy Control is a request under the California Consumer Privacy Act and similar state laws to opt out of the sale or sharing of personal information. Because we neither sell nor share personal information, a GPC signal has nothing to opt you out of. If our practices ever change, we will treat a valid GPC signal as such a request.
10. Changes to This Policy
We may update this policy. Material changes carry an updated "Last Revised" date and an in-app notice, and we ask you to review them. Non-material updates take effect when posted with an updated date.
11. Contact
Insider Desk is operated by Singularity Inc.
- Privacy questions: privacy@insiderdesk.info
- Support: support@insiderdesk.info