All documents

Investorhood Privacy Policy

Version 1.0.3 · August 21, 2026 · CG INVESTORHOOD ENTERPRISE S.R.L.

Version 1.0.3 · August 21, 2026 · CG INVESTORHOOD ENTERPRISE S.R.L. Effective date: upon publication. Public URL: https://www.investorhood.com/app-documents/privacy-policy/

1. About this Policy

This Policy explains how CG INVESTORHOOD ENTERPRISE S.R.L. processes personal data when a person uses the Investorhood mobile application and its associated support channels.

Investorhood is a free application for financial education, information, and indicative market monitoring. It does not execute trades, does not hold funds, does not manage portfolios, and does not provide personalized investment recommendations.

The company's general website and separately contracted services may have additional notices.

2. Data Controller

CG INVESTORHOOD ENTERPRISE S.R.L.
Registered office: Bucharest, Sector 3, Bd. Decebal no. 12, room 1, building S7, entrance 1, 5th floor, apt. 15, Romania
Tax ID (CUI): 49313396
Trade Registry No.: J2023024451401
EUID: ROONRC.J2023024451401
Website: https://www.investorhood.com/

General contact: contact@investorhood.com
Personal data / GDPR: privacy@investorhood.com

3. Our Principles

We process data lawfully, fairly, and transparently; for specified purposes; limited to what is necessary; for periods proportionate to the purpose; and with appropriate technical and organizational measures.

We do not sell personal data.

Investorhood does not use advertising IDs or enable cross-app tracking through the app. Limited first-party usage analytics and limited campaign-measurement technologies may be used as described below. These technologies are not configured by Investorhood to collect the IDFA or Android Advertising ID for cross-app tracking.

4. The Data We Process

4.1. Account, authentication and phone verification data

When creating an account, the following are requested:

  • last name;
  • first name;
  • email address;
  • phone number, with a selectable international prefix;
  • password.

We also process the account's internal identifier, the creation date, and the technical information required for authentication. The password is managed through the authentication infrastructure and is not stored in plain text.

Investorhood uses email and password authentication. New registrations also require verification of the provided phone number through a one-time password (OTP) sent by SMS.

After the user's email address has been confirmed, Investorhood sends a six-digit verification code to the phone number provided during registration. The code is time-limited and is used solely to confirm control of that phone number and to protect the account-registration process.

Authentication and phone verification are handled through Supabase. SMS messages containing the verification code are delivered through Twilio.

For this purpose, the phone number and technical information necessary to send and verify the message are processed by these providers.

We may also process operational phone-verification information, including:

  • the country associated with the phone number;
  • a masked representation of the phone number;
  • verification request and completion timestamps;
  • resend attempts;
  • verification status;
  • rate-limit or temporary lockout events;
  • SMS provider and carrier-delivery status;
  • provider error codes where available.

OTP codes are time-limited and are not displayed in the Investorhood administrative dashboard. OTP codes are not used for marketing purposes.

Phone numbers are normalized and validated using the international E.164 format. SMS availability may depend on the destination country, mobile operator, applicable regulatory requirements, and provider availability.

Phone-verification requirements may differ for accounts created before this functionality was introduced. Existing accounts are not automatically subject to the same onboarding verification requirement as new registrations.

Google Login, Apple Login, and biometric authentication are not public authentication methods in the current version.

Users can change their password. During the verification process, an unverified phone number may be corrected or changed through the available verification flow. Other account information may be subject to security and verification restrictions before it can be changed.

4.2. Educational questionnaire and preferences

After account creation, the app may request answers regarding:

  • experience;
  • markets of interest;
  • educational goals;
  • time horizon;
  • self-declared risk tolerance;
  • level of knowledge;
  • learning preferences.

This data is used to personalize the educational experience and does not constitute KYC, a regulated suitability/appropriateness test, or investment advice.

The watchlist is a monitoring preference and is stored locally on the device.

4.3. Favorites and watch history

Favorites and Watch History are associated with the account and are persisted in the Supabase backend.

We may process:

  • the video identifier;
  • the favorite status;
  • viewing progress/history;
  • the timestamp of the last interaction required by the feature.

Users can remove videos from Favorites and can delete their watch history from within the app.

Investorhood does not allow downloading videos for offline viewing.

4.4. Economic calendar, reminders, and notifications

Users can enable a reminder for an event in the economic calendar. The reminder is tied to the event and scheduled by the app.

Reminder states are kept locally on the device, in the app's storage, and the event notification is scheduled locally through the system notification service. In the current implementation, a reminder may be scheduled approximately 10 minutes before the event.

The app may also register a technical notification/push token and platform metadata required by the notification infrastructure.

User-facing notifications may be used for requested reminders, operational communications, security-related messages, and other app communications permitted by applicable law and the user's notification settings.

Marketing push notifications, if introduced or activated, will be used only where a valid legal basis exists and where any consent required by applicable law has been obtained.

4.5. Hoody AI

Hoody is a text-to-text conversational assistant with an educational purpose.

For it to function, the following are processed:

  • messages sent by the user;
  • generated responses;
  • the conversation/context required for continuity;
  • the conversation identifier and necessary technical metadata.

Hoody conversations and messages are persisted server-side in Supabase. Users can start a New Chat; however, the current version does not provide a screen for individually managing or deleting every historical Hoody conversation.

Access to Hoody AI conversations

Hoody AI conversations may be accessed, when necessary, only by authorized Investorhood personnel for purposes such as providing and improving the service, technical assistance, investigating errors or abusive use, service security, and monitoring its operation. Administrative access is restricted and audited.

The messages required to generate a response are transmitted to the Google Gemini API under the applicable paid-service terms.

Google processes such data under the contractual and data-processing terms applicable to the service used by Investorhood. Google may retain certain information for limited purposes such as abuse detection or legal obligations in accordance with those terms.

Do not enter passwords, card details, private keys, identity documents, or other unnecessary sensitive information into Hoody.

4.6. Support and communications

If you choose to contact Investorhood, we may process:

  • your name and contact details;
  • the content of your email;
  • the content of a WhatsApp conversation if you choose WhatsApp as a communication channel;
  • information communicated by phone;
  • details about the reported issue.

WhatsApp is not used by Investorhood for OTP authentication in the current implementation. WhatsApp is referenced in this Policy only as an optional communication or support channel that a user may independently choose to use when contacting Investorhood.

Where a user chooses WhatsApp, Meta/WhatsApp may process information according to its own applicable privacy terms.

4.7. Technical and security data

For operation and security, the following may be processed:

  • IP address;
  • device type;
  • operating system;
  • app version;
  • session and account identifiers;
  • notification token;
  • date/time of access;
  • authentication and security logs;
  • phone-verification and provider-security events where applicable.

Investorhood does not currently use a third-party Crash Reporting SDK. First-party app usage data is described in Section 4.8. Limited third-party campaign-measurement technologies are described separately in Sections 4.9 and 4.10.

Public app features do not request access to precise location, contacts, camera, photo gallery, or microphone for the functionality described in this Policy. Notification permission may be requested for notification features.

4.8. App usage data and Live Analytics

To understand how Investorhood is used and to improve its functionality, reliability, and user experience, we may process limited information about interactions with the app.

This may include the account identifier, a session identifier, session start, heartbeat and end timestamps, the section of the app being used from a predefined list, the platform (iOS or Android), the app version, and timestamps associated with these interactions.

This information is linked to the user's Investorhood account and may be used to measure active usage, session activity, feature usage, and the performance and adoption of different areas of the app.

Live Analytics does not collect the content of Hoody AI conversations, questionnaire answers, text entered by the user, precise geolocation, advertising identifiers, device fingerprints, contacts, or the content of other private communications.

We do not use Live Analytics data for behavioral advertising or for tracking users across apps, websites, or services owned by other companies, and we do not sell this data for advertising purposes.

Individual Live Analytics activity and session data is retained for approximately 30 days and is automatically deleted through a daily retention process. Aggregated or anonymized information that no longer identifies an individual may be retained for longer for statistical and service-improvement purposes.

The collection of Live Analytics data can be disabled remotely by Investorhood for operational, privacy, or security reasons.

4.9. Apple Ads attribution

On iOS, Investorhood may use Apple's AdServices functionality to determine whether an app installation or download is attributable to an Apple Ads campaign and to measure the effectiveness of Investorhood advertising campaigns.

For this purpose, the app may obtain an attribution token from Apple and transmit it securely to Investorhood's backend, where it is exchanged with Apple's attribution service for available campaign attribution information.

Depending on the information returned by Apple, this may include campaign ID, ad group ID, keyword ID, ad ID, conversion type, click date, country or region, and related attribution metadata.

Attribution information may be associated with the user's Investorhood account for campaign measurement, internal analytics, deduplication, fraud prevention, and evaluation of advertising effectiveness.

Investorhood does not use the IDFA for this Apple Ads attribution process and does not use Apple AdServices to track users across apps or websites owned by other companies.

The raw Apple attribution token is not retained by Investorhood after processing. A non-reversible technical hash or related technical metadata may be retained where necessary for deduplication, security, or processing integrity.

4.10. Meta App Events and campaign measurement

Investorhood may use the Meta SDK and Meta App Events to measure app installations, app activations, and selected conversion events, such as completion of registration, and to understand the effectiveness of Investorhood advertising campaigns on Meta platforms.

This may involve transmitting limited app-event information to Meta, including app activation events, registration-completion events, app/platform information, and technical metadata required for campaign measurement and attribution.

The Investorhood Meta integration is configured with advertising-identifier collection disabled and advertiser tracking disabled.

Investorhood does not intentionally collect the IDFA or Android Advertising ID through this integration and does not enable cross-app tracking through the Investorhood app for this purpose.

The Meta CompleteRegistration event is generated only after the relevant Investorhood registration and onboarding process, including the required account and phone-verification steps, has been completed.

This Meta App Events functionality is separate from WhatsApp. Investorhood does not use WhatsApp as the delivery mechanism for these events or for OTP authentication.

4.11. Marketing

The email address and phone number may be used for commercial communications only on the basis of the applicable legal ground and, where required by law, the user's consent.

Possible communication channels may include email, SMS, phone, or WhatsApp where such a channel is lawfully used and appropriate.

Withdrawing marketing consent does not affect operational communications required for account operation, authentication, security, or delivery of a requested service.

Phone-verification OTP messages delivered through Twilio are operational authentication communications and are not marketing messages.

4.12. Data from third-party services

In providing Investorhood we use:

  • Supabase — backend infrastructure, authentication, persistence, server-side functions, and phone-verification infrastructure;
  • Twilio — SMS delivery and operational delivery status for phone-verification messages;
  • Google Gemini API — Hoody AI response generation;
  • YouTube API Services / Google — delivery and playback of certain video materials;
  • Expo, Apple, and Google — notification/push infrastructure;
  • Apple AdServices — attribution of Apple Ads campaigns on iOS;
  • Meta App Events — limited app-installation, activation, registration-conversion, and campaign measurement;
  • market-data providers used for quotes and calendar information, where requests may be performed server-side without requiring the user's identity.

WhatsApp is not part of Investorhood's OTP infrastructure. If a user independently chooses WhatsApp to communicate with Investorhood, WhatsApp/Meta processes that communication under its applicable terms.

Investorhood uses YouTube API Services for delivering and playing certain video materials. Use of these services may involve processing by Google/YouTube in accordance with the Google Privacy Policy.

5. Data We Do Not Collect Through Public Features

Investorhood does not collect through its public features:

  • broker balances;
  • positions or trades;
  • investment portfolios;
  • full card details;
  • precise location;
  • contacts;
  • uploaded photos or videos;
  • files/documents;
  • audio recordings;
  • biometric data;
  • posts/comments or messages between users.

Do not voluntarily submit such data through Hoody or support channels if it is not necessary.

6. How We Collect Data

Data is obtained:

  • directly from the user;
  • through use of app features;
  • from the device for permitted technical functions;
  • from authentication, communications, attribution, and integrated service providers strictly to the extent necessary for the relevant service.

7. Purposes and Legal Grounds

Purpose Data examples Primary legal ground
Account creation and administration name, email, phone, authentication performance of the service/contract
Phone verification and account security phone number, OTP verification status, resend attempts, delivery status, security events performance of the service; legitimate interest in account security, fraud prevention, and abuse prevention
Questionnaire and educational personalization answers, interests, level performance of the service; legitimate interest, as applicable
Favorites and Watch History video interactions performance of the service
Calendar / reminders / notifications local reminder, push token performance of the requested feature; device permission
Hoody AI messages, responses, conversation performance of the requested feature
Support messages and contact details performance of the service; legitimate interest
Security IP, logs, sessions, authentication events legitimate interest; legal obligations
App usage analytics and service improvement session identifiers, section interactions, timestamps, platform, app version legitimate interest in understanding, securing, maintaining, and improving the service
Apple Ads attribution and campaign measurement campaign, ad group, keyword, conversion, and attribution metadata legitimate interest in measuring and improving Investorhood advertising campaigns
Meta App Events and campaign measurement app activation, registration-completion events, and associated technical metadata legitimate interest in measuring campaign effectiveness and improving user acquisition
Marketing email, phone, communication preferences consent or another legally permitted ground

8. Mandatory and Optional Data

The last name, first name, email, phone number, and password are mandatory for account creation.

For new registrations subject to the current phone-verification flow, successful verification of the provided phone number is required before the registration and onboarding process can be considered complete.

Consent to marketing is not a condition for using the app.

9. Public Content and Visibility

Investorhood does not allow users to publish posts, comments, images, portfolios, or messages visible to other users.

Favorites, Watch History, Hoody conversations, phone-verification information, and account-security information are not made visible to other users.

10. Who We Disclose Data To

We may transmit data, strictly to the extent necessary, to:

  • Supabase — backend, authentication, storage, server-side functions, and phone-verification infrastructure;
  • Twilio — SMS delivery and operational status of phone-verification messages;
  • Google Gemini API — text required to generate Hoody responses;
  • Google/YouTube — video playback and related third-party player functions;
  • Expo, Apple, and Google — notification/push infrastructure;
  • Apple — Apple Ads attribution through AdServices, where applicable;
  • Meta — limited app-event and campaign-measurement information through Meta App Events;
  • WhatsApp/Meta — only when a user independently chooses WhatsApp as a support or communication channel;
  • email and other communication providers used for support or operational communications;
  • consultants, lawyers, accountants, or authorities, where a legal ground exists.

We do not sell personal data.

The up-to-date public list of relevant providers is documented separately on the Sub-processors page.

11. International Transfers

The Supabase project used by Investorhood is hosted in West Europe (London), eu-west-2. The United Kingdom benefits from a European Commission adequacy decision in force as of the date of this version.

Some providers, including Google, Twilio, Meta, and Apple, may process certain data outside the EEA. In such cases, applicable legal transfer mechanisms may include adequacy decisions, the EU-US Data Privacy Framework for eligible entities, and/or Standard Contractual Clauses, according to the applicable provider contracts and legal requirements.

12. Data Retention

We apply the storage-limitation principle.

  • Account and profile: for as long as the account is active; after deletion, data that does not need to be retained by law is deleted or anonymized.
  • Questionnaire, Favorites, Watch History, and Hoody conversations: associated with the account and deleted or anonymized together with the account, to the extent there is no legal reason for retention.
  • Phone verification: OTP codes are time-limited. Verification events, delivery information, rate-limit information, and related operational records are retained only for as long as reasonably necessary for account security, fraud and abuse prevention, troubleshooting, compliance, and defense of legal rights.
  • Support data: retained as long as necessary to resolve the request and meet legal obligations.
  • Security logs: retained proportionately to the security purpose and defense of legal rights.
  • App usage / Live Analytics: individual activity and session data is retained for approximately 30 days and automatically deleted through a daily retention process. Aggregated or anonymized information that no longer identifies an individual may be retained for longer for statistical and service-improvement purposes.
  • Advertising attribution and campaign measurement: attribution and app-event information is retained only for as long as reasonably necessary for campaign measurement, analytics, deduplication, fraud prevention, and service improvement, subject to applicable Investorhood and provider retention rules.
  • Marketing: until consent is withdrawn or an objection is raised, with a minimal record of the unsubscription retained where necessary to honor the user's choice.
  • Local data: data stored locally in the app/device may be removed through available features, by clearing app data, or by uninstalling the app.

Technical backup copies may exist temporarily under the normal backup cycle, without being reused for incompatible purposes.

13. Cookies and SDKs

The native app does not use browser cookies as a primary mechanism, but it uses local storage, native platform frameworks, and SDKs in order to function.

Investorhood does not intentionally collect advertising IDs or enable cross-app tracking through the app.

First-party app usage analytics is described in Section 4.8.

Investorhood may use third-party SDKs or platform frameworks required for specific functions described in this Policy, including Meta App Events for limited campaign measurement and Apple's AdServices framework for Apple Ads attribution.

These integrations are configured by Investorhood without enabling IDFA or Android Advertising ID collection for cross-app tracking.

Investorhood does not currently use a third-party Crash Reporting SDK.

The YouTube player and other embedded web services may use their own technologies under their providers' policies.

For the website, cookie rules are described separately in the Cookie Policy.

14. Marketing and Unsubscribing

You can withdraw your marketing consent through the mechanism included in a marketing message or by contacting privacy@investorhood.com.

Marketing opt-out requests do not apply to communications strictly necessary for authentication, account security, or provision of a service requested by the user.

OTP verification messages delivered by SMS through Supabase and Twilio are service/security communications and cannot be opted out of where phone verification is required to complete registration.

If WhatsApp is used as a marketing communication channel in the future, it will be subject to the applicable legal basis and consent requirements. This is separate from the current OTP system, which uses SMS rather than WhatsApp.

15. Automated Systems and Artificial Intelligence

Hoody generates responses automatically and can make mistakes.

We do not use Hoody to make legal or similarly significant decisions about the user, and we do not present it as a personalized investment-advisory system.

The exact Gemini model may change at the technical configuration level; for this reason, this Policy identifies the provider and purpose rather than promising a fixed model.

16. Security

We apply measures appropriate to the risk, including authentication, phone verification where applicable, access control, encrypted communications in transit, separation of roles, rate limiting, provider-security controls, and incident-response procedures.

No system can guarantee absolute security.

Incidents or vulnerabilities can be reported to security@investorhood.com.

17. Data Incidents

We investigate incidents and fulfil our notification obligations towards the supervisory authority and affected individuals whenever the GDPR or another applicable law so requires.

18. Your Rights

Under the conditions of the GDPR, you may request:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection;
  • withdrawal of consent;
  • information about the processing;
  • lodging a complaint.

19. Exercising Your Rights

Send your request to privacy@investorhood.com.

You may also request a copy of your personal data even though Investorhood does not currently include a PDF/CSV/Excel export button.

We may request reasonable verification to prevent disclosure of data to an unauthorized person.

20. Account Deletion

The account can be deleted directly from the app:

  1. open Profile / Settings;
  2. choose account deletion;
  3. confirm your intention;
  4. enter the confirmation text "ȘTERGERE" (Romanian for "DELETE");
  5. complete the operation.

If you no longer have access to the app, you can request deletion at privacy@investorhood.com from the email address associated with the account.

Upon deletion, the account and associated server-side data that does not need to be retained by law are deleted or anonymized.

21. Data About Other People

Do not provide data about another person unless you have the right to do so and it is necessary.

22. Minors

Investorhood is intended exclusively for users aged 18 or older.

The app is not intended for minors.

23. Third-Party Links and Services

External services and providers may process information under their own applicable privacy terms and contractual roles.

Relevant examples include Google/YouTube, Supabase, Twilio, Apple, and Meta.

Meta is used separately for Meta App Events campaign measurement. WhatsApp is only relevant where a user independently chooses WhatsApp as a support or communication channel.

Depending on the processing operation, a provider may act as a processor/service provider or as an independent controller.

24. Changes

We may update this Policy when the app, providers, processing activities, or legislation change.

The updated version will be published on the website and accessible from the app.

25. Complaints

You can contact privacy@investorhood.com first.

You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or another competent authority under the conditions of the GDPR.

26. Contact

CG INVESTORHOOD ENTERPRISE S.R.L.
Website: https://www.investorhood.com/
GDPR email: privacy@investorhood.com
General email: contact@investorhood.com