Invest in Gold like a professional investor

App Privacy Policy

Gold Program — Privacy Policy

Version 1.1 FINAL • 25 May 2026

Last Updated: 25 May 2026

This Privacy Policy forms part of the Gold Program App Terms and Conditions of Use.

1. Who We Are

1.1 The Gold Program application (“the App”) is operated by Brookville Capital Limited (“we”, “us”, “our”), which is the data controller responsible for your personal data.

1.2 Our details:

  • Company name: Brookville Capital Limited
  • Company number: 6578589 (England and Wales)
  • Registered address: Harwood House, 43 Harwood Road, Fulham, London, SW6 4QP
  • Contact address: Mill House, Mill Road, Lewes, East Sussex BN7 2RT
  • Contact email: simonpopple@brookvillecapital.com

1.3 Brookville Capital Limited is registered with the Information Commissioner’s Office (ICO) as a data controller (registration number ZA554151).

2. What Personal Data We Collect

2.1 We collect and process the following categories of personal data:

CategoryData CollectedSource
Account DataEmail address, Password (hashed), Account type, Login timestampsProvided by you at registration
Portfolio DataInvestment holdings (company names, quantities, values), Transaction history, Broker/account names, Purchase dates and prices, Football formation position assignmentsEntered by you or extracted via AI-Assisted Features
Photo/Document DataPhotographs of paper documents, brokerage statements, or screen captures submitted for AI processingSubmitted by you when using photo scanning
Device & Technical DataDevice type and operating system, App version, Crash logs and error reports, IP addressCollected automatically
Usage DataFeatures used and frequency, Screen views, Sync status eventsCollected automatically via Firebase Analytics

2.2 We do not collect any special category data (as defined in Article 9 UK GDPR), such as data about health, race, religion, or sexual orientation.

3. How We Use Your Personal Data

3.1 We process your personal data for the following purposes and on the following legal bases:

PurposeData UsedLegal Basis (Article 6 UK GDPR)
Providing the App services (portfolio tracking, valuations, sync)Account Data, Portfolio DataPerformance of contract (Art. 6(1)(b))
Creating and managing your accountAccount DataPerformance of contract (Art. 6(1)(b))
AI-Assisted Features (ticker lookup, data extraction, OCR scanning)Portfolio Data, Photo/Document DataPerformance of contract (Art. 6(1)(b))
App stability and error resolutionDevice & Technical DataLegitimate interest (Art. 6(1)(f))
Understanding app usage and improving the serviceUsage DataLegitimate interest (Art. 6(1)(f))
Sending transactional emails (password resets, price alerts)Account Data (email)Performance of contract (Art. 6(1)(b))
Complying with legal obligationsAll categories as requiredLegal obligation (Art. 6(1)(c))

3.2 Where we rely on legitimate interest as our legal basis, we have carried out a balancing test to ensure that our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 9).

4. AI-Assisted Features and Automated Processing

4.1 The App includes AI-Assisted Features that use artificial intelligence and optical character recognition (OCR) to help you import and manage your portfolio data. These features include:

  • (a) Photo and document scanning – you photograph a paper document, brokerage statement, or computer screen, and the App extracts investment data automatically;
  • (b) Ticker symbol lookup – you provide a company name and the App identifies the correct stock ticker and exchange;
  • (c) Portfolio calculations – the App calculates valuations, performance metrics, and profit/loss figures.

4.2 When you use photo scanning:

  • (a) Your photograph is transmitted securely (via encrypted connection) to Google’s Firebase AI Logic with Gemini for OCR processing;
  • (b) The AI service extracts text and data from the image and returns the results to the App;
  • (c) The extracted data is presented for your review and confirmation before being saved;
  • (d) We do not permanently store the photographs you submit. Images are retained only for the duration of the processing request.

4.3 OCR processing is performed by Google’s Firebase AI Logic service, which uses Google’s Gemini AI models. Our Firebase project operates on the paid (Blaze) tier. Under the Gemini API Additional Terms of Service (Paid Services) and Google’s Data Processing Addendum for Products Where Google is a Data Processor, Google acts as a data processor on our behalf and does not use your images, the text extracted from them, or our responses to improve its products or train its AI models. Google may retain prompts and responses for a short period solely to detect violations of its Prohibited Use Policy and to meet legal or regulatory requirements.

4.4 None of the AI-Assisted Features make decisions that produce legal effects or similarly significant effects on you. All AI output is presented as suggestions for your review – no data is added to your portfolio without your explicit confirmation.

4.5 You have the right to request human review of any AI-generated output by contacting us at the address in Section 12.

5. Who We Share Your Data With

5.1 We share your personal data only with the third-party service providers necessary to operate the App. We do not sell your personal data to anyone.

5.2 We currently use the following third-party service providers. If providers change, this Privacy Policy will be updated accordingly.

ProviderServiceData SharedLocation
Firebase / GoogleAuthentication, Firestore database, Cloud Functions, Cloud Storage, Analytics, Crashlytics, AI Logic (Gemini)Account Data, Portfolio Data, Photo/Document Data, Usage Data, Device Dataeurope-west2 (London, UK)
Google Gemini / Firebase AI LogicOCR and document processingPhoto/Document Data, Portfolio Dataeurope-west2 (London, UK)
Alpha VantageStock and fund price dataNo personal data (ticker lookups only)US
Metals-APIGold and precious metals spot price dataNo personal data (price requests only)EU
ExchangeRate-APICurrency conversionNo personal data (conversion requests only)EU

5.3 All third-party providers are bound by data processing agreements and are required to process your data only for the purposes we specify.

5.4 We may also disclose your data if required to do so by law, regulation, or court order, or to protect our rights, property, or safety.

6. Where Your Data Is Stored

6.1 Your primary data (account information, portfolio data, and synced content) is stored on Google Firebase servers in the europe-west2 (London) region within the United Kingdom.

6.2 Certain processing activities may involve transferring data outside the United Kingdom: Firebase Authentication may process your email address in the United States when sending password-reset or account-related emails.

6.3 Where data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR Chapter V, including Standard Contractual Clauses or reliance on adequacy decisions where applicable.

7. How Long We Keep Your Data

7.1 We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

Data CategoryRetention PeriodReason
Account DataDuration of account + 12 months after deletionAllow for account reactivation; comply with legal obligations
Portfolio DataDuration of account + 12 months after deletionAllow for data export before permanent deletion
Photo/Document DataDuration of AI processing only (not permanently stored)Images deleted after extraction is complete
Transaction historyDuration of account + 6 years after deletionHMRC record-keeping requirements for Capital Gains Tax
Device & Technical Data12 months rollingApp stability and error analysis
Usage Data (Analytics)14 months (Firebase default)Understanding usage patterns

7.2 When your account is deleted or expires, we will delete or anonymise your personal data within the retention periods specified above. You may request earlier deletion (see Section 9).

8. How We Protect Your Data

8.1 We take the security of your personal data seriously and have implemented appropriate technical and organisational measures, including:

  • Data encrypted in transit (TLS/HTTPS) and at rest (Firebase server-side encryption)
  • Secure authentication via Firebase Auth with password hashing
  • All API keys stored server-side in Firebase Cloud Functions configuration – never exposed in client-side code
  • Access to the admin dashboard restricted to authorised personnel
  • Regular security updates to app dependencies
  • Offline-first architecture stores data locally on your device with sync to encrypted cloud storage

8.2 While we take all reasonable precautions, no method of electronic storage or internet transmission is 100% secure. We cannot guarantee absolute security of your data.

8A. Data Breach Notification

8A.1 In the event of a personal data breach, Brookville Capital Limited will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of a qualifying personal data breach, as required by UK GDPR.

8A.2 Where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will notify those individuals without undue delay.

8A.3 A record of all personal data breaches will be maintained, including the facts relating to the breach, its effects, and the remedial action taken.

9. Your Rights

9.1 Under UK GDPR, you have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you (Subject Access Request)
RectificationRequest correction of inaccurate personal data
ErasureRequest deletion of your personal data (“right to be forgotten”), subject to any legal obligations requiring retention
RestrictionRequest restriction of processing in certain circumstances
Data PortabilityReceive your data in a structured, commonly used, machine-readable format (CSV or JSON)
ObjectionObject to processing based on legitimate interest
Automated ProcessingRight not to be subject to decisions based solely on automated processing that produce legal effects. Note: our AI-Assisted Features do not make such decisions – all output requires your confirmation
Withdraw ConsentWhere processing is based on consent, withdraw that consent at any time

9.2 To exercise any of these rights, contact us at the address in Section 12. We will respond within one month of receiving your request, as required by UK GDPR.

9.3 We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse the request.

9.4 If you request deletion of your account, please note that:

  • (a) Your portfolio data will be permanently deleted after the retention period in Section 7;
  • (b) We recommend exporting your data before requesting deletion (export feature available in the App);
  • (c) Some data may be retained longer where we have a legal obligation to do so (e.g., transaction records for HMRC purposes).

10. Children’s Privacy

10.1 The App is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children.

10.2 If we become aware that we have collected personal data from a child under 18, we will take steps to delete that data as soon as possible. If you believe a child has provided us with personal data, please contact us at the address in Section 12.

11. Cookies, Analytics, and Tracking

11.1 The App does not use web cookies. However, the App uses the following analytics and monitoring services:

ServicePurposeData CollectedRetention
Firebase AnalyticsUnderstanding how features are used to improve the AppAnonymous usage events, screen views, feature interactions14 months
Firebase CrashlyticsDetecting and resolving app crashes and errorsDevice type, OS version, crash stack traces, anonymised user identifiersDefault (varies)

11.2 Firebase Analytics data is retained for 14 months by default. This data is aggregated and does not directly identify you.

12. Contact Us and Complaints

12.1 If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Brookville Capital Limited
Mill House, Mill Road
Lewes, East Sussex BN7 2RT

Email: simonpopple@brookvillecapital.com

Registered office: Harwood House, 43 Harwood Road, Fulham, London SW6 4QP
Company Registration Number: 6578589

12.2 If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF

Website: ico.org.uk
Telephone: 0303 123 1113

13. Changes to This Privacy Policy

13.1 We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • (a) Displaying a notice within the App;
  • (b) Sending you an email notification where practicable.

13.2 The “Last Updated” date at the top of this policy will always reflect the most recent revision.

13.3 Your continued use of the App after changes to this Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with any changes, you should stop using the App and contact us to request deletion of your data.

14. Document History

VersionDateChanges
1.0April 2026Initial Privacy Policy incorporating ICO registration, named third-party providers, data breach notification, and Firebase AI processing provisions.
1.1 FINAL25 May 2026Added ICO registration number ZA554151. Replaced Section 4.3 with confirmed Firebase AI Logic / Gemini paid-tier data-processor wording. Aligned the document with the app’s free-and-bundled distribution model. Document moved from DRAFT to FINAL.

Document Version 1.1 FINAL • 25 May 2026