Backster Privacy Policy
Last Updated: 31 May 2026 Effective Date: 31 May 2026
1. Introduction
This Privacy Policy describes how Backster Enterprise (“Backster”, “we”, “us”, or “our”) collects, uses, discloses, and protects your personal information when you use the Backster mobile application and related services (collectively, the “Service”).
This Privacy Policy applies to all users of the Service, regardless of location. Where the laws of your jurisdiction provide additional rights or protections, those laws will apply in addition to this Privacy Policy.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Privacy Policy, you must not use the Service.
This Privacy Policy should be read together with our Terms of Service.
2. Who We Are — Data Controller
For the purposes of applicable data protection laws:
Data Controller: Backster Enterprise Address: 52-2, Jalan Puteri 1/2, Bandar Puteri, 47100 Puchong, Selangor, Malaysia Country of Operation: Malaysia Contact Email: privacy@backster.app Data Protection Officer (DPO): The Data Protection Officer for Backster is the Founder, who oversees our privacy strategy and compliance with the Malaysian PDPA 2024 and applicable global data-protection laws. You may contact the DPO at privacy@backster.app.
3. What Information We Collect
We collect the following categories of personal information when you use the Service:
3.1 Account and Identity Information
When you create an account using Sign in with Apple, we receive:
- Your full name (or first initial only, if you choose to hide your full name)
- Your email address (or a private relay address if you choose to hide your real email)
- A unique Apple-assigned user identifier
- Your authentication token
We do not receive your Apple ID password or other Apple account credentials.
3.2 User-Generated Content
When you use the Service, we collect content you create, submit, or upload, including:
- Chat messages, prompts, and queries you send to the AI features of the Service
- Trading strategy descriptions and specifications you create or refine
- Strategy parameters you configure (e.g., cryptocurrency pair, timeframe, risk tolerance)
- Backtest configurations and results you generate
- Notes, comments, and feedback you provide
- Other text and data you submit through the Service
3.3 Usage and Activity Data
To operate the Service and enforce your plan’s usage limits, we record certain functional activity associated with your account, including:
- Actions such as strategies created, backtests run, messages sent, and feedback (thumbs ratings) you provide
- Counts and timestamps used to apply your plan’s usage allowances (e.g., monthly usage, last activity)
This information is recorded on our own servers for app functionality and is not collected through third-party analytics tools or used for cross-app tracking.
3.4 Device and Technical Information
We collect limited technical information in connection with your use of the Service:
- Device model and type, operating system and version (e.g., iOS 18), and app version (submitted when your device registers for push notifications)
- A push notification token issued by Apple, used solely to deliver push notifications to your device. This is not an advertising identifier and is not used for cross-app tracking.
- Language and timezone settings, and network connection type
- IP address — received as part of normal network communication and used for security, abuse prevention, and reliability. We do not use it to determine or store your precise location.
- Server-side error and performance diagnostics — when the Service encounters technical problems, our backend monitoring provider (Sentry) records error and performance data. This data is stripped of personal identifiers and is not linked to your identity.
We do not collect precise location data (GPS coordinates). We do not collect the Identifier for Advertisers (IDFA) or the Identifier for Vendors (IDFV), and we do not use the App Tracking Transparency framework to request tracking permission, because we do not engage in cross-app tracking.
3.5 Transaction and Subscription Information
If you purchase subscriptions, in-app purchases, or other paid features:
- Apple processes the payment through its in-app purchase system. We do not receive your payment card information, Apple ID password, or full billing address.
- We receive a confirmation of your purchase, the product purchased, the date, and an Apple-generated transaction identifier.
- We retain subscription status, billing period, and renewal information necessary to provide the paid features.
3.6 Communications
If you contact us for support, feedback, or other purposes, we collect:
- The content of your communication
- Your contact information (email address)
- Metadata about the communication (date, time, channel)
3.7 Information We Do NOT Collect
For clarity, we do not currently collect:
- Your real name or address beyond what Apple provides through Sign in with Apple
- Your phone number
- Your government-issued identification documents
- Your bank account, credit card, or other financial account information (Apple processes payments)
- Your cryptocurrency wallet addresses, private keys, or seed phrases (Backster does not custody assets)
- Your trading activity on third-party exchanges (Backster does not connect to or execute on exchanges)
- Your contacts, photos, microphone, camera, or precise location
- Biometric data
- Health, fitness, or medical information
4. How We Use Your Information
We use the personal information we collect for the following purposes:
4.1 To Provide and Operate the Service
- Authenticating you and managing your account
- Generating, refining, and analyzing trading strategies based on your inputs
- Running backtests against historical market data
- Storing and retrieving your strategies and other content
- Processing your subscriptions and providing paid features
- Sending you transactional and service-related communications
4.2 To Improve the Service
- Identifying and fixing bugs, errors, and performance issues
- Testing and developing new features and improvements
- Reviewing aggregated, de-identified functional metrics to improve the reliability and usability of the Service
We do not use third-party analytics tools, and we do not use your individual, identifiable content to train AI models (see Section 12).
4.3 To Communicate With You
- Responding to your inquiries and support requests
- Sending service announcements, security alerts, and other transactional messages
- Notifying you of changes to our terms or policies
- Sending marketing communications (only with your consent, where required by law)
- Conducting surveys and soliciting feedback
You can opt out of marketing communications at any time using the unsubscribe mechanism in our emails or by contacting us.
4.4 To Protect the Service and Our Users
- Detecting and preventing fraud, abuse, and unauthorized access
- Enforcing our Terms of Service and other policies
- Investigating security incidents
- Complying with legal obligations, including responses to lawful requests from authorities
4.5 To Meet Legal and Regulatory Obligations
- Complying with tax, accounting, anti-money laundering, and other regulatory requirements
- Responding to legal process, including subpoenas, court orders, and government investigations
- Defending or asserting legal claims
- Cooperating with law enforcement when required by law
5. Legal Bases for Processing (for EEA, UK, and Similar Jurisdictions)
Where applicable laws require us to identify a legal basis for processing personal information (such as under the GDPR), we rely on the following bases:
| Purpose | Legal Basis |
|---|---|
| Providing and operating the Service | Performance of contract (our Terms of Service) |
| Authentication and account management | Performance of contract |
| Processing payments and subscriptions | Performance of contract |
| Improving the Service and developing new features | Legitimate interests (operating and improving our business) |
| Sending marketing communications | Consent (where required by law) |
| Detecting fraud and preventing abuse | Legitimate interests (protecting the Service) |
| Complying with legal obligations | Legal obligation |
| Defending legal claims | Legitimate interests |
You have the right to object to processing based on legitimate interests. See Section 9 for details on how to exercise your rights.
6. How We Share Your Information
We do not sell your personal information. We share your information only in the limited circumstances described below:
6.1 Service Providers (Processors)
We engage trusted third-party service providers to perform services on our behalf. These providers have access to your information only as necessary to perform their functions and are contractually obligated to maintain the confidentiality and security of your information. Our service providers include:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Anthropic PBC | AI language model processing for chat features and strategy generation | Chat messages, strategy descriptions, and prompts you submit | United States |
| Supabase Inc. | Database hosting and backend infrastructure | All stored user data | Singapore (asia-southeast1) |
| Google Cloud Platform | Application hosting (Cloud Run), build infrastructure, and cloud services | All transmitted and processed data | asia-southeast1 (Singapore) |
| Sentry (Functional Software, Inc.) | Backend error and performance monitoring | Redacted error reports, performance and device metadata (not linked to your identity) | United States / EU |
| Apple Inc. | App distribution, Sign in with Apple, in-app purchases, push notification delivery | Apple-managed account data, purchase records, push notification token | Various |
We have entered into data processing agreements with our service providers where required by applicable law.
6.2 Legal and Safety Disclosures
We may disclose your information without your consent when we believe in good faith that disclosure is necessary to:
- Comply with applicable laws, regulations, legal process, or governmental requests;
- Enforce our Terms of Service or other agreements;
- Detect, prevent, or address fraud, security, or technical issues;
- Protect the rights, property, or safety of Backster, our users, or others;
- Respond to an emergency that we believe in good faith requires us to disclose information.
6.3 Business Transfers
If we are involved in a merger, acquisition, sale of assets, bankruptcy, or similar transaction, your information may be transferred as part of that transaction. We will notify you (for example, through a notice within the Service) before your information is transferred and becomes subject to a different privacy policy.
6.4 Aggregated and Anonymized Information
We may share aggregated or anonymized information that does not identify you with third parties for research, analytics, and other purposes. Such information is not subject to this Privacy Policy.
6.5 With Your Consent
We may share your information with third parties for other purposes with your explicit consent.
6.6 What We Do NOT Do
We do not:
- Sell your personal information to third parties
- Share your personal information with advertising networks for targeted advertising
- Share your trading strategies, chat content, or backtest results with other users or third parties without your consent
- Use your information to make automated decisions that have legal or similarly significant effects on you, except as necessary to provide the Service (such as fraud detection or account authentication)
7. International Data Transfers
Backster operates primarily from Malaysia, but our service providers are located in various countries including the United States, Singapore, and the European Union.
When we transfer your personal information across borders:
- For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the relevant authorities, adequacy decisions where available, or other legally recognized transfer mechanisms.
- For transfers from Malaysia, we comply with Section 129 of the PDPA and any applicable cross-border transfer requirements established by the Personal Data Protection Commissioner. In particular, for Malaysian Users, personal data is transferred to and stored in Singapore (via Supabase on Google Cloud Platform, asia-southeast1) on the basis that Singapore provides a level of protection at least equivalent to the PDPA, and we require our processors to implement technical and organizational security standards that meet or exceed the Security Principle under the PDPA 2024.
- For transfers from other jurisdictions, we comply with applicable local data transfer laws.
By using the Service, you understand that your information will be processed in countries other than your country of residence, including countries that may have different data protection laws than your home country.
8. Data Retention
We retain your personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
Specific retention periods:
| Data Type | Retention Period |
|---|---|
| Account information | For the duration of your account, plus up to 90 days after deletion for backup retention |
| Chat messages and AI inputs | For the duration of your account, plus up to 90 days after deletion |
| Strategy specifications and backtest results | For the duration of your account, plus up to 90 days after deletion |
| Functional usage records | Up to 24 months, then aggregated or deleted |
| Crash and error logs | Up to 12 months |
| Subscription and transaction records | As required by applicable tax and accounting laws, typically 7 years in Malaysia |
| Communications with support | Up to 24 months after the most recent communication |
| Legal compliance records | As required by applicable law |
When you delete your account, it is immediately disabled and scheduled for permanent deletion 30 days later. During this 30-day window you can cancel the deletion and restore your account simply by signing in again. If you do not sign in within 30 days, your account is permanently deleted: we will delete or anonymize your personal information within 90 days, except for information we are required to retain for legal, regulatory, or legitimate business purposes (such as transaction records for tax purposes, or records of suspected fraud or abuse).
Aggregated and anonymized data may be retained indefinitely.
9. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. We honor all rights to which you are entitled under applicable law.
9.1 Rights Available to All Users
Regardless of jurisdiction, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your personal information, subject to legal retention requirements
- Export your data in a portable format
- Withdraw consent where processing is based on consent
- Object to certain types of processing
- Contact us with privacy-related questions or complaints
9.2 Additional Rights for European Economic Area, United Kingdom, and Switzerland Users (GDPR)
If you are located in the EEA, UK, or Switzerland, you also have the right to:
- Restrict processing of your personal information in certain circumstances
- Object to processing based on our legitimate interests, including profiling
- Not be subject to automated decision-making that produces legal or similarly significant effects on you (with limited exceptions)
- Lodge a complaint with your local data protection authority
9.3 Additional Rights for California Users (CCPA/CPRA)
If you are a California resident, you also have the right to:
- Know what categories of personal information we have collected and how it is used
- Delete personal information we have collected
- Correct inaccurate personal information
- Opt out of “sale” or “sharing” of personal information (we do not sell or share for cross-context behavioral advertising)
- Limit use of sensitive personal information
- Non-discrimination for exercising your privacy rights
9.4 Additional Rights for Malaysian Users (PDPA)
If you are a Malaysian resident, the PDPA grants you the right to:
- Access your personal data held by us
- Correct inaccurate, incomplete, misleading, or out-of-date personal data
- Withdraw consent to the processing of your personal data
- Prevent processing likely to cause damage or distress
- Prevent processing for direct marketing
- Data portability (introduced by the 2024 PDPA Amendment Act) — receive your strategy configurations and account data in a structured, commonly used, machine-readable format (such as JSON); you may request this export by emailing privacy@backster.app, and we will fulfil the request within 21 days
9.5 How to Exercise Your Rights
To exercise any of your privacy rights, please contact us at privacy@backster.app. We will respond to your request within the timeframes required by applicable law, typically:
- 30 days under PDPA (Malaysia)
- 30 days under GDPR (EEA/UK)
- 45 days under CCPA (California), with one possible 45-day extension
We may need to verify your identity before fulfilling your request. We may charge a reasonable fee for requests that are manifestly unfounded or excessive, as permitted by applicable law.
If we are unable to fulfill your request, we will explain why.
10. Security of Your Information
We implement reasonable technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS (HTTPS)
- Encryption of data at rest in our databases
- Authentication and access controls limiting access to personal information on a need-to-know basis
- Regular security reviews and updates
- Use of reputable cloud service providers with established security practices
- Application-level security measures including input validation, secure coding practices, and dependency management
- Incident response procedures
However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.
10.1 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:
- We will notify you and the relevant supervisory authorities without undue delay, and where feasible within 72 hours of becoming aware of the breach, as required under GDPR.
- We will notify the Personal Data Protection Commissioner of Malaysia and affected data subjects in accordance with the PDPA 2024 Amendment Act’s mandatory breach notification requirements; specifically, in accordance with Section 12A of the PDPA, we will notify the Commissioner within 72 hours of becoming aware of a breach that may pose a risk of harm to Users, and will notify affected Users by in-app alert or email where their data is compromised.
- We will provide information about the nature of the breach, likely consequences, and measures taken or proposed to address it.
10.2 Your Role in Security
You are responsible for:
- Keeping your account credentials confidential
- Using Sign in with Apple’s security features (Face ID, Touch ID, strong passwords)
- Promptly notifying us of any suspected unauthorized access to your account
- Logging out of the Service on shared devices
11. Children’s Privacy
The Service is not intended for individuals under eighteen (18) years of age. We do not knowingly collect personal information from individuals under 18.
If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us at privacy@backster.app. We will take steps to delete such information from our systems.
12. AI and Automated Processing Disclosure
The Service uses artificial intelligence to provide its core functionality. We want to be transparent about how AI is used in connection with your personal information.
12.1 What AI Does in the Service
AI is used to:
- Generate trading strategy specifications based on your natural language descriptions
- Classify the intent of your messages (e.g., asking a question, requesting a strategy, requesting an edit)
- Provide explanations, analyses, and educational content
- Refine and modify strategies based on your feedback
12.2 Third-Party AI Provider
We use Anthropic PBC’s language models (including Claude) to process your inputs and generate AI outputs. When you use AI features:
- Your chat messages, prompts, and related context are transmitted to Anthropic for processing
- Anthropic processes your inputs in accordance with its own privacy and data handling policies
- We have entered into a commercial agreement with Anthropic that includes data protection provisions
- Anthropic’s policies regarding data retention and use for model training are available at https://www.anthropic.com/legal
12.3 Use of Your Data for AI Training
We do not use your individual, identifiable content to train AI models. To the extent we work to improve the Service, we rely on aggregated, de-identified functional data, not your identifiable strategies or chat content. Backster uses Anthropic’s API under commercial terms that do not permit Anthropic to use your prompts and outputs to train its general models. Your strategy inputs and outputs remain your proprietary data and are not used to improve third-party AI models.
12.4 Limitations of AI
AI outputs are probabilistic and may be inaccurate, incomplete, biased, or otherwise unsuitable. Please refer to our Terms of Service Section 5 and our Risk Disclosure for important information about the limitations of AI-generated content.
12.5 Your Rights Regarding AI
You have the right to:
- Understand how AI is used in connection with your personal information
- Request human review of any AI-generated output that significantly affects you
- Object to processing of your personal information by AI systems for purposes other than providing the Service
- Withdraw consent for use of your data in AI improvement (where consent was the basis for such use)
13. Cookies and Similar Technologies
The Service is a mobile application and generally does not use traditional web cookies. However, we and our service providers may use similar technologies, including:
- Local storage on your device to remember your preferences and app state (via iOS UserDefaults)
- Authentication tokens to keep you signed in between sessions
- A push notification token (issued by Apple) used solely to deliver notifications
We do not use the IDFV or IDFA, third-party analytics SDKs, or cross-app tracking technologies.
If you access any Backster website (e.g., to view our Privacy Policy or Terms of Service), that website may use cookies as described in a separate cookie policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Email: privacy@backster.app Mailing Address: 52-2, Jalan Puteri 1/2, Bandar Puteri, 47100 Puchong, Selangor, Malaysia Data Protection Officer: the Data Protection Officer (the Founder) at privacy@backster.app
You also have the right to lodge a complaint with a data protection supervisory authority, including:
- Malaysia: Personal Data Protection Department, Ministry of Communications and Digital
- European Union: Your local data protection authority
- United Kingdom: Information Commissioner’s Office (ICO)
- California: California Attorney General’s Office or California Privacy Protection Agency
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last Updated” date at the top of this Privacy Policy
- Notify you through the Service, by email, or by other reasonable means
- For material adverse changes, provide reasonable advance notice (typically at least 30 days) where required by law
- Where required by law, obtain your fresh consent before implementing changes that materially expand our processing of your personal information
Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the updated terms.
16. App Store Privacy Declarations
In accordance with Apple App Store requirements, we declare the following categories of data collection in our App Store privacy information. Each category below is linked to your identity and used only for App Functionality; none is used for tracking.
| Data Category | Linked to You | Used for Tracking | Purpose |
|---|---|---|---|
| Name | Yes | No | App Functionality |
| Email Address | Yes | No | App Functionality |
| User ID | Yes | No | App Functionality |
| Device ID (push notification token) | Yes | No | App Functionality |
| Purchase History | Yes | No | App Functionality |
| User Content (chat messages, strategies) | Yes | No | App Functionality |
| Product Interaction | Yes | No | App Functionality |
We do not collect Financial Info, precise or coarse Location, Contacts, Health data, or Advertising data, and we do not use your data for tracking as defined by Apple’s App Tracking Transparency framework. Crash and performance diagnostics are collected only on our backend (server-side), are stripped of personal identifiers, and are not linked to your identity.