NYTSHIFT privacy policy
This implementation draft describes the current technical data boundary for the NYTSHIFT web product and native Android app. It requires an accountable publishing entity, verified privacy contact, processor and retention audit, and qualified legal review before Google Play submission or broad public launch.
Review status: engineering draft. No claim of owner or legal approval is made, and no verified privacy-inquiry or deletion-request channel is published yet.
Scope and responsible entity
This draft applies to NYTSHIFT at nytshift.xyz and the candidate native Android application xyz.nytshift.app. The legal publishing entity and its privacy point of contact have not yet been owner-verified for publication. That missing identity and contact are release blockers; this draft must not be entered in Play Console as an approved policy.
Data handled by the Android app
Public market requests
The Android app sends bounded HTTPS requests to nytshift.xyz for public market observations. Requests can include allowlisted venue, symbol, market ID, interval, pagination and limit values plus a fixed app user-agent. The app does not require a customer venue credential for those reads. Hosting, CDN, WAF and application services may process network metadata such as IP address, request time and security signals; their exact fields, purposes, retention and processors still require an owner audit.
Local PAPER and preference data
Deterministic PAPER orders, fills, positions, protection plans and policy state, descriptive strategy specifications, density and chart preferences are stored in bounded app-private storage with Android backup disabled. The current client does not upload local PAPER or strategy state. These records are simulations, not venue orders, assets, custody records, tax records or guarantees.
Device-bound authentication and read-only account data
If the production mobile gateway is configured, a user can scan or paste a short-lived pairing payload, compare and approve a code, and create a device-bound DPoP key in Android Keystore. NYTSHIFT issues a short-lived encrypted device-session lease and processes opaque customer, account, installation, session and device-key references. Authenticated responses can contain bounded balances, positions, open orders, fills, funding and transfer activity for read-only display. The Android app cannot sign, submit, retry or cancel venue orders and has no funding, transfer, withdrawal, wallet, signer or mainnet authority.
Google Code Scanner
The Android app uses Google Code Scanner in QR-only mode for optional pairing. Google Play services owns the scanner interface and camera access; NYTSHIFT requests no Android camera permission and receives the decoded result. The Google Code Scanner documentation says scan-image processing occurs on-device and that Google does not retain scan results or image data. Google's current ML Kit data disclosure also identifies device or per-installation identifiers, application/device information, performance metrics, API configuration, input/output size, feature version, event type and error codes for diagnostics and usage analytics. The exact signed bundle and current processor disclosure must be reconciled before submission.
User-directed exports
PAPER PDF/CSV files and strategy JSON exports are written to dedicated cache paths and leave the app only when the user selects a recipient through the Android share chooser with temporary read permission. NYTSHIFT cannot control the recipient app's retention or onward handling.
Web identity, wallets and public-chain reads
If configured, Privy processes authentication and linked-wallet evidence under its own terms. NYTSHIFT verifies short-lived provider tokens and derives opaque customer identifiers; raw access and identity tokens are not intended for durable application storage. A wallet address supplied for inspection is public-chain or venue query input, and blockchain activity is public by design. Private customer routes bind verified wallets through keyed digests; they do not give NYTSHIFT custody of a wallet or its key.
Uses, sharing and service providers
Data is used to provide requested public reads, secure device pairing, authenticated read-only account views, user-directed exports, fraud and abuse prevention, service reliability and incident investigation. NYTSHIFT does not claim to sell personal data and has no app-configured advertising, product-analytics or crash-reporting SDK in the current Android source. Hosting, CDN/WAF, identity, database, venue, wallet, RPC, chart, bridge, Google Play services and support providers may process only the data required for their configured role. The exact production provider list and whether any Play-defined sharing exception applies remain owner/legal audit items.
Security
The Android app requires HTTPS, disables cleartext traffic and backups, keeps device keys in Android Keystore, encrypts the short-lived session lease, uses DPoP-bound requests and prohibits private keys, exchange keys, unrestricted session material and signer secrets from app persistence and logs. These controls reduce risk but do not guarantee absolute security.
Retention and deletion
Local PAPER data can be permanently deleted through Profile → Reset local PAPER. Signing out attempts to revoke the device session and clears local session material; forgetting a device or uninstalling the app does not by itself prove deletion of an NYTSHIFT account or server-held data. User-directed export copies can remain with the selected recipient. Exact server, security-log, processor, backup and legally required retention periods are not yet owner-approved.
The current Android candidate authenticates existing customers but does not create an account in the app. Its account-deletion action remains visibly unavailable. Owner/legal must decide the applicable Play account-deletion answer and publish a functional request channel before submission; any future in-app account creation requires a readily discoverable in-app deletion path and a working external resource. See the account and data deletion status.
Your choices and requests
You can use public views without pairing, decline the QR scanner and paste a valid pairing payload instead, reset local PAPER state, sign out and revoke the current device session, remove browser-local preferences, disconnect provider identity and stop using the service. A verified contact for access, correction, deletion, objection or privacy questions is not yet published. Do not send credentials, private keys, tokens, wallet secrets, pairing payloads or account identifiers to an unverified address or public issue tracker.
Third parties and changes
Venue, identity, hosting, wallet, RPC, chart, bridge and Google service providers operate under their own terms and privacy notices. Robinhood Chain publishes jurisdiction-specific privacy statements in its official documentation. Any material change to app data handling, SDKs, account creation, analytics, support intake or execution scope requires this policy and the Play Data safety form to be reviewed and updated before release.