Effective date: August 2, 2026 Last updated: September 4, 2026

This Privacy Policy explains how Ironwood Technology Group LLC, a Colorado limited liability company (“BitClock,” “we,” “us,” or “our”), collects, uses, and shares information in connection with the BitClock mobile apps, widgets, web dashboard, and website (collectively, the “Service”).

BitClock displays a proprietary market-pressure metric (a depth-ratio number) derived from public Bitcoin order-book data. It is an informational and visualization tool, not a financial service — the Service does not execute trades, does not hold funds, and does not require or process brokerage or trading account information. That scope shapes what data we do and don’t collect, described below.


1. Summary (plain language)

  • BitClock’s free experience — the live ratio, live BTC price, and 24h stats (volume, % change, high/low) — can be used without creating an account, and we do not collect financial or trading data of any kind.
  • Threshold alerts are also free, but require an account: we collect the minimum information needed to run them — an email address and a password (which we store only as a salted Argon2 hash, never in plain text) — plus a device push-notification token if you enable alerts.
  • Subscriber-only features (the ratio’s daily extremes, R-HOD and R-LOD; live bid/ask depth; and, coming soon, ratio history) additionally involve a subscription-status record, provided to us by the payment platforms described below.
  • We do not sell or “share” your personal information (as those terms are defined under California and other US state privacy laws), and we do not use it for cross-context behavioral (“targeted”) advertising. We do not use third-party advertising trackers, and we do not embed general-purpose analytics SDKs that harvest behavioral data beyond what is necessary to keep the Service running.
  • Our marketing website (bitclock.net) uses Plausible Analytics, a cookieless service that counts page views and referral sources without storing IP addresses or identifying individual visitors. It is not loaded in the apps or the web dashboard.
  • Payment card and billing details are handled entirely by Google Play Billing, Apple’s App Store In-App Purchase system, or Stripe (for web subscriptions) — BitClock never receives or stores your full card number.
  • Our servers are located in the European Union (Germany and Finland); encrypted backups are replicated to the United States. See §9 for how we handle these international transfers.
  • The market data displayed in BitClock is sourced from a major cryptocurrency exchange’s public market-data feeds. BitClock is an independent product. It is not affiliated with, endorsed by, or sponsored by any exchange or data provider, and does not use any exchange’s name or marks as part of its own branding.

The sections below give the full detail, including the region-specific rights available to residents of the European Union, the United Kingdom, California, Colorado, and other US states with comprehensive privacy laws.


2. Information We Collect

2.1 Information you provide directly

  • Account credentials: an email address and a password. Your password is never stored in plain text — we store only a salted Argon2 hash of it (see §8). Where we offer sign-in with a third-party identity provider (e.g., Google or Apple), we receive an identity token rather than a password.
  • Subscription status: whether you have an active subscription, its tier, and renewal date — provided to us by Google Play, the App Store, or Stripe as part of purchase/entitlement validation (see §2.4).
  • Alert configuration: any price/ratio thresholds you configure, and your alert history. Alerts are evaluated on our servers, not on your device, so this data must be stored for alerts to work at all.
  • Support correspondence: if you email [email protected] or contact us, we retain your message and contact details to respond and keep records of the request.

2.2 Device and usage data

  • Push notification tokens: a device-specific token issued by Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS), used solely to deliver alerts you’ve opted into. Uninstalling the app or disabling notifications invalidates this token.
  • Minimal technical/diagnostic data: basic operational data needed to keep the Service reliable (e.g., app version, OS version, and crash or error diagnostics). Both the iOS and Android apps use Firebase Crashlytics (a Google service) to capture crash and error reports so we can diagnose and fix stability problems; Crashlytics transmits crash diagnostics and a Crashlytics-generated installation identifier to Google, acting as our processor (see §4). On iOS we additionally use Apple’s on-device MetricKit framework as a supplementary diagnostic layer. We do not use this data for advertising, profiling, or cross-app tracking, and we do not install general-purpose analytics SDKs beyond what is necessary for this minimal operational purpose.

2.3 What we do NOT collect

  • We do not collect brokerage, exchange-account, wallet, or trading credentials. BitClock does not connect to your exchange or brokerage account, does not execute trades, and does not hold or transmit funds of any kind — it only displays a computed market metric.
  • We do not collect precise device location.
  • We do not use third-party behavioral-advertising trackers, and we do not sell or “share” personal information to or with data brokers or advertisers.
  • We do not knowingly collect sensitive personal information (such as government IDs, precise geolocation, biometric identifiers, health data, or racial, religious, or similar characteristics).
  • We do not store your full payment card number, bank account, or other raw payment credentials (see §2.4).

2.4 Payment information

Subscription payments are processed entirely by:

  • Google Play Billing (Android in-app subscriptions),
  • Apple’s App Store In-App Purchase / StoreKit (iOS subscriptions), or
  • Stripe (web subscriptions purchased directly on BitClock’s website).

These providers handle your payment method directly under their own privacy policies. BitClock receives only a purchase/subscription status token (e.g., “active,” “expired,” tier) from these providers to unlock features — we never receive or store your card number, bank details, or other raw payment credentials.

2.5 Categories of personal information (for US state-law disclosures)

For the purposes of the California Consumer Privacy Act (as amended by the CPRA) and comparable US state laws, in the past 12 months we have collected the following statutory categories of personal information:

  • Identifiers — email address; if you enable alerts, a device push token; and a crash-reporting installation identifier (Firebase Crashlytics).
  • Customer records / account information — hashed account password and subscription status.
  • Commercial information — records of the subscription product you purchased.
  • Internet or other electronic network activity — limited, operational: in-app alert configuration and minimal diagnostic/technical data (§2.2).

We collect these categories from you directly and from the payment platforms in §2.4, for the business purposes described in §2A below. We do not collect the categories of “sensitive personal information,” precise geolocation, biometric information, or financial account/trading data.


2A. How and Why We Use Information

We use the information above for the following purposes:

  • to create and authenticate your account and keep it secure;
  • to evaluate and deliver the alerts you configure;
  • to validate your subscription and unlock subscriber features;
  • to provide customer support and respond to your requests;
  • to maintain the reliability, security, and integrity of the Service and to detect, prevent, and address fraud, abuse, or technical problems;
  • to comply with legal obligations and enforce our Terms of Service; and
  • with your consent, to send you marketing communications — such as product news, launch and feature announcements, newsletters, offers, and occasional surveys about BitClock and other products and services offered by Ironwood Technology Group LLC. Marketing messages are separate from the transactional and service messages above (account, security, alert delivery, billing, and legal notices), which you receive as a necessary part of using the Service. You can opt out of marketing communications at any time — see “Your marketing choices” below — without affecting your account or those transactional messages.

We use your email for marketing only where we have your consent to do so, and we do not use your personal information to build advertising profiles or make decisions producing legal or similarly significant effects about you through solely automated processing.


3. Third-Party Data Sources

BitClock’s core metric is computed from public Bitcoin order-book market data made available via a major cryptocurrency exchange’s public market-data APIs. This is market data about the Bitcoin order book — it is not personal information about BitClock’s users, and no information about you or your BitClock usage is sent to that exchange.

To be clear about the nature of this relationship: BitClock is an independent product built by Ironwood Technology Group LLC. It is not affiliated with, endorsed by, sponsored by, or operated in partnership with any exchange or data provider. Any references to a third-party exchange in this policy or elsewhere in the Service describe the public data source only, not a business relationship.


4. How We Share Information

We do not sell personal information, and we do not “share” it for cross-context behavioral advertising. We disclose information only to the service providers/processors that help us operate the Service, and only for that purpose:

  • Cloud hosting and infrastructure: Hetzner Online GmbH (servers in Germany and Finland) for hosting, and Backblaze, Inc. (United States) for encrypted off-site backups. See §9 on international transfers.
  • Push notification delivery: Firebase Cloud Messaging (Google) and Apple Push Notification service.
  • Payment processing: Google, Apple, and Stripe, as described in §2.4.
  • Diagnostics/crash reporting: Firebase Crashlytics (Google) on both iOS and Android, which receives crash diagnostics and a Crashlytics installation identifier as our processor; on iOS, Apple MetricKit additionally operates on-device (see §2.2).

Each service provider is bound by a contract (including, where required, a data processing agreement) that limits its use of personal information to providing services to us. In addition, we may disclose information:

  • For legal purposes: to comply with a legal obligation, respond to lawful requests, enforce our Terms of Service, or protect the rights, property, or safety of BitClock, our users, or others.
  • In a business transfer: if BitClock is involved in a merger, acquisition, or asset sale, user information may be transferred as part of that transaction, subject to this Policy’s protections continuing to apply (or you being notified of a materially different policy).

We do not use general-purpose third-party analytics or advertising SDKs that harvest data beyond the minimal operational scope described in §2.2; the cookieless page-view counter on our marketing website (Plausible Analytics, described above) identifies no one.


5. Data Retention & Deletion

We keep personal information only as long as we need it for the purposes in §2A, then delete or anonymize it. Our default retention periods are:

  • Account data: retained for as long as your account is active. After you close your account (or after a verified deletion request), we delete or anonymize your account personal data from live systems within 30 days. Residual copies in encrypted backups are overwritten on our normal backup-rotation cycle, within a further 90 days, after which they are no longer recoverable.
  • Alert history: retained on a rolling 90-day window, then deleted, unless you delete individual alerts or your account sooner.
  • Billing/transaction records: minimal records of subscription status and transactions may be retained for up to the period required by applicable tax, accounting, and anti-fraud law. We do not hold your card data; the payment platforms in §2.4 retain their own billing records under their own policies.
  • Ratio/market-data history: the underlying market-pressure dataset is aggregate market data, not personal information about any individual user, and is retained indefinitely as BitClock’s core dataset asset — this does not implicate user privacy rights.
  • Account deletion: you can request deletion of your account and associated personal data in the app (Settings → Delete Account) or through the Account Deletion page, or by contacting us at the address in §11. We will verify your request and then delete or anonymize your personal data on the schedule above, except where retention is required by law.

6. Your Rights and Choices

Depending on where you live, you have some or all of the rights described below. To exercise a right, use the in-app tools or contact us at the address in §11; we will verify your request before acting on it, and we will not discriminate against you for exercising a privacy right. You may use an authorized agent where the law allows. If we decline a request, you may appeal by replying to our response; we will respond to appeals within the timeframe your jurisdiction requires.

6.1 European Union & United Kingdom (GDPR / UK GDPR)

If you are in the EU or the UK, Ironwood Technology Group LLC is the controller of your personal data. We rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to create and run your account, evaluate and deliver alerts you configure, and provide subscriber features you purchase.
  • Legitimate interests (Art. 6(1)(f)) — to keep the Service secure and reliable and to prevent fraud and abuse; you may object to this processing.
  • Consent (Art. 6(1)(a)) — where you grant your device’s push notification permission (you may withdraw it at any time in your OS settings), and where you opt in to marketing communications (you may withdraw it at any time via the unsubscribe link in any marketing email or by contacting us).
  • Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with law.

You have the right to access, rectify, erase, restrict, or object to processing of your personal data, and the right to data portability. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).

[PLACEHOLDER — EU/UK Article 27 representative, if one is required: to be determined by counsel and named here.]

6.2 California (CCPA/CPRA)

California residents have the right to know/access the personal information we collect and how we use it, to delete it, to correct it, and to opt out of sale or sharing — though, as noted, we do not sell or share personal information, so there is nothing to opt out of. We also do not use or disclose sensitive personal information for purposes that would trigger a right to limit it. We will not discriminate against you for exercising these rights. See §2.5 for the statutory categories we collect.

6.3 Colorado (Colorado Privacy Act)

As a Colorado LLC serving Colorado residents, we honor the Colorado Privacy Act. Colorado residents have the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising, sell personal data, or engage in profiling with legal or similarly significant effects; nonetheless, we recognize universal opt-out mechanisms, including the Global Privacy Control (GPC) browser signal, as a valid opt-out request. You may appeal a denied request as described above.

6.4 Other US states

Residents of other US states with comprehensive privacy laws now in effect (including, among others, Virginia, Connecticut, Utah, Texas, Oregon, Montana, and additional states whose laws take effect in 2025–2026) have analogous rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising, sale, and profiling. We extend the same rights described in this §6 to those residents.

You can also control push notifications at any time through your device’s operating-system settings, and disable specific alerts within the app.

Your marketing choices. If you have opted in to marketing communications, you can opt out at any time by clicking “unsubscribe” in any marketing email or by contacting us at [email protected]. Opting out of marketing does not stop transactional or service messages (such as account, security, billing, alert-delivery, and legal notices), which are necessary to operate your account.


7. Children’s Privacy

The Service is intended for adults and is not directed to children. You must be at least 18 years old to create an account or subscribe (see Terms of Service §2). We do not knowingly collect personal information from anyone under 18, and in particular we do not knowingly collect personal information from children under 13 in violation of the U.S. Children’s Online Privacy Protection Act (COPPA) or from minors under the higher age thresholds set by the GDPR (13–16, depending on the EU member state) or other applicable law. If we learn that we have collected personal information from someone below the applicable age without appropriate consent, we will delete it. If you believe a child has provided us information, contact us using the details in §11.


8. Security

We use reasonable administrative, technical, and physical safeguards designed to protect the information we hold. TLS is used for all client-server connections; no cleartext endpoints are shipped in any client. Account passwords are stored only as salted Argon2 hashes and are never held in plain text. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.


9. International Data Transfers

BitClock’s production infrastructure is hosted with Hetzner Online GmbH on servers located in the European Union (Germany and Finland). Encrypted backups are replicated to Backblaze, Inc. in the United States for disaster-recovery purposes. Because personal data of users outside the EU may be processed on our EU servers, and because EU/UK personal data may be copied to our US backups, the Service involves international data transfers.

  • For transfers of EU/UK personal data to the United States (our backup location), we rely on the European Commission’s Standard Contractual Clauses (2021) — and, for the UK, the UK International Data Transfer Addendum — together with a transfer-impact assessment and appropriate supplementary measures (including encryption of backups). Where a US recipient is certified under the EU-US Data Privacy Framework, we may additionally rely on that adequacy mechanism.
  • For users located outside the EU, personal data processed on our EU servers is handled under this Policy and protected by the same safeguards.

You may request a copy of the relevant transfer safeguards by contacting us at the address in §11.


10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app, by email (if we have one on file), or by posting a notice on our website prior to the change taking effect. The “Last updated” date at the top of this Policy reflects the most recent revision.


11. Contact Us

If you have questions about this Privacy Policy or want to exercise a privacy right described above, contact us at:

[email protected]

Ironwood Technology Group LLC PO Box 514, Hotchkiss, CO 81419