Transparency
Imprint & privacy
Who runs this service, which data is processed along the way and where the figures come from. As of 14 August 2026.
This is a translation for your convenience. The imprint under section 5 of the German Digital Services Act and the privacy information under article 13 GDPR are given in German. In case of any difference, the German version is the binding one.
Information under section 5 DDG
Imprint
Sole trader
Erlenhain 16
88480 Achstetten
Germany
DE358210689
There is no entry in the commercial register; the service is run as a sole trader. Professional indemnity insurance or a professional authorisation is not required for the information service offered here, because no financial service requiring authorisation is provided. See the section no investment advice on this.
Editorial responsibility
Responsible for journalistic and editorial content under section 18(2) of the German Interstate Media Treaty: Larisa Schlosser, address as above.
Mandatory notice
No investment advice
All content of this service serves information and your own opinion forming only. It is expressly not investment advice, investment broking, contract broking, portfolio management, an investment strategy recommendation or an investment recommendation within the meaning of the German Securities Trading Act and the Market Abuse Regulation. No personal recommendation is made and no individual investment situation is examined.
Quotes and key figures can be delayed, incomplete, out of date or wrong. Calculations such as returns, valuations or portfolio analyses rest on the entries recorded and on the market data available. They are no substitute for your broker's statement and no substitute for a tax assessment.
Securities and other financial instruments are subject to price fluctuations. Losses up to the complete loss of the capital invested are possible. Past performance is not a reliable indicator of future performance. Investment decisions are yours alone. If in doubt, consult an authorised adviser.
Consumer information
Dispute resolution
We are neither obliged nor willing to take part in dispute resolution proceedings before a consumer arbitration body (section 36(1)(1) of the German Consumer Dispute Resolution Act).
The European Commission's former platform for online dispute resolution was shut down on 20 July 2025. A reference to it is therefore no longer included; older imprints that still link to it lead nowhere.
Responsibility
Liability for content and links
We are responsible for our own content under the general laws. Under sections 8 to 10 of the German Digital Services Act, however, we are not obliged as a service provider to monitor third party information that is transmitted or stored, or to investigate circumstances that indicate unlawful activity. Obligations to remove or block the use of information under the general laws remain unaffected. Liability in that respect is possible only from the moment a specific infringement becomes known.
Our offering contains references to external websites of third parties, in particular to the primary sources of news items. We have no influence over their content. The respective provider is always responsible for that third party content. At the time of linking, the pages were checked for recognisable legal infringements. Permanent monitoring of content without specific grounds is not reasonable. If we become aware of infringements, we remove the links concerned.
Copyright
The content and works created by us are subject to German copyright law. Reproduction, adaptation, distribution and any kind of exploitation outside the limits of copyright require our written consent. Downloads and copies are permitted for private, non commercial use. Where content was not created by us, the copyrights of third parties are respected and third party content is marked as such.
Information under article 13 GDPR
Privacy policy
This policy describes which personal data is processed when you use StockLife, for what purpose, on what legal basis, who receives it and how long it stays.
The short overview
- Watchlist and portfolio journal sit on your device only, without an account.
- Device sync transfers only blocks that were encrypted on your device before upload. We cannot read them.
- After sign in we discard your name and email address and keep only a user hash that cannot be reversed.
- This website shows advertising from Google AdSense. In the EEA, the United Kingdom and Switzerland, ads and the cookies they need run only after your consent, which you give through Google's dialog and can change at any time through privacy in the footer. Details in item 7.
- A third party analytics service is not used.
- Everything that is not technically necessary runs on opt in and can be withdrawn at any time.
1. Controller
Erlenhain 16
88480 Achstetten, Germany
Email: support@stocklife.io
No data protection officer has been appointed, because the conditions of section 38 of the German Federal Data Protection Act are not met. A representative under article 27 GDPR is not required, because the controller is established in the European Union.
2. Visiting the website and server logs
When you visit, the technically necessary connection data your browser transmits is processed: IP address, date and time, the address requested, the volume transferred, the status code, the referrer and information about browser and operating system. Without this data the page cannot be delivered. StockLife stores no user IP in its application data.
Purpose: delivering the service, operational security, defence against attacks and automated access.
Legal basis: article 6(1)(f) GDPR; our legitimate interest lies in a secure and available service.
Retention: see item 14.
3. Storage on your device and consent
Watchlist, portfolio journal, view settings and the session state are kept in the local storage of your browser. This data does not leave your device as long as you do not switch on device sync under item 5.
Section 25 of the German Telecommunications Digital Services Data Protection Act applies to storing information on your device and accessing it:
- Technically necessary storage, meaning session, security, your own entries and the language setting, happens under section 25(2)(2) without consent, because the service does not work without it.
- Everything else, meaning the advertising under item 7 and the anonymous counters under item 8, is switched on solely after your consent under section 25(1) and article 6(1)(a) GDPR: opt in, separately for each purpose, with nothing preselected.
For Google's advertising, consent is obtained and managed through the dialog described in item 7; for everything else the setting in the application applies. Both can be withdrawn at any time, and the withdrawal takes effect for the future. For an active account sign in we use a technically necessary session cookie only. It is encrypted or signed, can only be transmitted over HTTPS, is inaccessible to JavaScript (HttpOnly), is restricted against cross site transmission (SameSite) and expires automatically. We set no advertising, analytics or tracking cookies. You can delete local data and the session cookie at any time through your browser or by signing out.
4. Account and sign in
An account is required for device sync and for paid features. Sign in is handled by the service provider WorkOS, Inc., 300 Delaware Ave, Wilmington, DE 19801, USA, as a processor. You can sign in through Apple or through Google, or use an email address.
If you choose to sign in through Apple or Google, a separate process takes place between you and that provider: the provider verifies your identity and, depending on what you choose there, passes us an identifier and possibly an email address. Apple offers the option of using a forwarded relay address. Apple and Google are themselves responsible for the processing in their own systems, and their privacy notices apply.
After the sign in service responds, StockLife discards the name and the email address. In its own session it stores nothing but a user hash formed with a server secret, which cannot be reversed, along with an expiry time. The server of this service therefore does not know your email address.
Purpose: authentication, matching the vault and the entitlements purchased.
Legal basis: article 6(1)(b) GDPR.
5. Voluntary device sync (vault)
If you switch on sync, portfolio and watchlist data is encrypted on your device with a key derived from your recovery code. Only the encrypted blocks are transferred and stored, along with technical details of version, size, number of blocks and a check value. Before encryption the blocks are padded to a uniform size, so that their length reveals nothing about the content either.
The server knows neither your recovery code nor the content of your portfolio and cannot reconstruct either. If you lose the recovery code, the stored data is permanently unreadable, for us as well.
Legal basis: article 6(1)(b) GDPR.
6. Paid subscriptions
Entitlements are managed through RevenueCat, Inc., 633 Taraval St. #2, San Francisco, CA 94116, USA. From us, RevenueCat receives nothing but a pseudonymous identifier, not your name and not your email address.
If you buy through the Apple App Store or through Google Play, the payment takes place with Apple or Google. Those companies are independently responsible for the data arising there. We receive no payment data from them, only the information whether an entitlement exists.
If you buy through this website, the payment is handled by Creem. Creem acts as merchant of record, meaning it is your contracting party for the payment and accounts for value added tax. You enter your payment details directly there. StockLife stores no card numbers, no bank details and no other means of payment.
To Creem we transmit nothing but a pseudonymous identifier and which product is being bought, not your name and not your email address. You provide the contact details needed for the purchase to Creem yourself. All we get back is whether an entitlement exists, when it ends, and a customer number through which you can manage and cancel the subscription.
Abandoned orders. If you break off the payment process, Creem sends a short series of reminder emails to the address entered there. These are advertising within the meaning of section 7 of the German Act Against Unfair Competition. You receive them only if you consented during the payment process. You can withdraw that consent at any time with effect for the future, among other ways through the unsubscribe link in each of those emails. StockLife receives neither the email address nor the content of those messages.
Legal basis: article 6(1)(b) GDPR for handling the subscription, article 6(1)(a) GDPR for the reminder emails after an abandoned order, and for invoicing records article 6(1)(c) GDPR together with section 147 of the German Fiscal Code and section 257 of the German Commercial Code.
7. Advertising
This website is financed among other things through advertising. Since 14 August 2026, Google AdSense has been integrated for that, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the data arising for its own purposes and is independently responsible in that respect; there is no processor relationship.
What happens technically
A script from pagead2.googlesyndication.com is embedded in every page of this website. It loads when the page is opened and at first serves one purpose only: to show the consent dialog and to check whether a decision from you exists. Ads are delivered only after that.
If you consent, Google can store and read cookies and similar identifiers on your device, process your IP address, evaluate information about browser, operating system and approximate location, and record which ad was shown, seen and clicked. Depending on the extent of your consent, Google can also use this information to show you personalised advertising and to build a corresponding profile, possibly across several websites and devices. Third parties, meaning advertisers and providers of advertising technology, are involved in this as well and are listed individually in the dialog.
Your consent
In the European Economic Area, the United Kingdom and Switzerland we obtain your consent through a consent management platform certified by Google under the Transparency & Consent Framework of IAB Europe. The dialog appears when you first visit. There you can consent, refuse consent, or choose individual purposes and providers separately. Without consent no advertising cookies are set and no personalised ads are delivered.
You can change your decision at any time with effect for the future through the entry privacy in the footer of every page. Independently of that you can also switch personalisation off in your Google account at myadcenter.google.com and delete cookies through your browser at any time.
Purpose: financing the free service through advertising, measuring delivery, billing and fraud detection.
Legal basis: for storing and reading information on your device section 25(1) of the German Telecommunications Digital Services Data Protection Act, for the subsequent processing article 6(1)(a) GDPR, in each case your consent.
Transfer to third countries: Google also transfers data to Google LLC in the United States; see item 13.
More on how Google processes data from the use of websites is in Google's privacy policy and at policies.google.com/technologies/partner-sites.
Our own ad slot
Independently of that, there is a contextual ad slot in individual places that works without Google: which ad appears there is decided by the content of the page currently shown, and nothing else. It is delivered from our own origin and shown in a sandboxed frame that has no access to the surrounding page, to your account or to your local data. This slot too stays empty as long as you do not release it in the settings of the application, and it respects a Global Privacy Control signal where one is set.
In the apps
No advertising network is integrated in the mobile apps. Google's script runs solely on this website and not in the app versions. Should that change, this policy will be extended beforehand and your consent obtained separately.
8. Anonymous counters
Aggregated usage counters are kept only if you expressly consent. The IP address transmitted by the network is combined with a secret key that changes daily into a value for that day. Only this pseudonymous value is stored; the IP address itself is not kept. Because the key changes daily, a value from yesterday cannot be matched to a value from today.
A third party analytics service is not used.
Purpose: protection against misuse and aggregated rankings.
Legal basis: article 6(1)(a) GDPR, section 25(1) of the German Telecommunications Digital Services Data Protection Act.
9. Price alerts and push notifications
For a price alert we store the push endpoint provided by your browser in encrypted form, a time zone name and the rule you set. A randomly generated token authorises changing or deleting the alert. Delivery runs through the push service of your browser or operating system provider, in the case of Apple and Google their respective service, which processes data independently in doing so.
Legal basis: article 6(1)(a) GDPR.
10. Newsletter
The newsletter is activated solely through the double opt in procedure: after you sign up you receive an email with a confirmation link, and sending begins only when you open it. Your address is stored encrypted; separate keys are used for matching identity and for one time links. To document consent, the time of sign up and of confirmation is logged.
Legal basis: article 6(1)(a) GDPR. You can unsubscribe at any time through the link in every email.
11. Market data
Quotes and key figures are delivered identically to all users as a public file. The request contains no account data and no identifier leading back to you, so a request cannot reveal which holdings you follow. Obtaining the data happens solely on our servers. Your device makes no connection to any data supplier, and no personal data is transmitted to one.
12. Recipients and processors
We pass on personal data only where that is necessary. Contracts under article 28 GDPR are in place with all processors.
| Recipient | Function | Location | Access to content |
|---|---|---|---|
| WorkOS, Inc. | Sign in and identity management | USA | No |
| RevenueCat, Inc. | Managing subscription entitlements | USA | No, a pseudonymous identifier only |
| Creem | Payment handling on the web as merchant of record, invoicing, reminder emails after an abandoned order | European Union | Independent controller for payment and contact details; from us a pseudonymous identifier only |
| Apple Inc. / Google Ireland Ltd. | Sign in, purchase and billing in the stores, push delivery | USA / Ireland | Independent controllers, no processor relationship |
| Google Ireland Ltd. (AdSense) | Delivering and measuring advertising, consent dialog | Ireland, with transfer to the USA | Independent controller; receives data only after your consent. No access to account, portfolio or vault. |
| Hostinger International Ltd. | Mailbox of the contact address | Lithuania (EU) | Yes, the content of emails addressed to us |
Beyond that we pass on data where we are legally obliged to do so or where it is necessary to enforce our rights.
13. Transfer to third countries
Some of the recipients named above are established in the United States. Processing outside the European Union cannot be ruled out there. We base these transfers on:
- standard contractual clauses of the European Commission under article 46(2)(c) GDPR,
- where the recipient is certified, additionally the EU-US Data Privacy Framework under article 45 GDPR,
- supplementary technical measures, in particular the encryption of vault contents on your device, so that only unreadable ciphertext reaches a third country.
You can request a copy of the safeguards agreed at support@stocklife.io.
14. Retention and deletion
| Data | Period |
|---|---|
| Server logs | Briefly, according to the rules of the network provider, then deleted or aggregated. Raw IP addresses are not stored permanently by the application. |
| Account and session data | For the duration of the account; sessions expire automatically after a short time. |
| Vault blocks | Until you delete them or until the account is deleted. |
| Anonymous daily counters | Kept briefly; the daily key change makes older values unlinkable in any case. |
| Alert and push endpoint | Until you unsubscribe or until the endpoint is permanently unreachable. |
| Newsletter address | Until you unsubscribe; the record of consent is kept to defend against legal claims. |
| Invoicing records | Up to ten years under section 147 of the German Fiscal Code and section 257 of the German Commercial Code. During those periods processing is restricted, not deleted. |
15. What you can do yourself
You can exercise the most important rights without going through us:
- Export: your portfolio and watchlist data sits in plain text on your device and can be exported there in a common format. That is the most complete route to your data, because only you hold the key.
- Deletion: you can delete individual entries, the entire vault or your account yourself. Deleting the account requires signing in again, removes every vault object first and then the account at the sign in service. Data on other devices has to be deleted there separately.
- Consent: you change Google's advertising through privacy in the footer. Our own ad slot, the anonymous counters, alerts and the newsletter can each be switched off individually in the settings.
16. Your rights
Under the General Data Protection Regulation you have the following rights, where their conditions are met:
- Access to the data processed about you (article 15 GDPR)
- Rectification of inaccurate data (article 16 GDPR)
- Erasure (article 17 GDPR)
- Restriction of processing (article 18 GDPR)
- Data portability in a common format (article 20 GDPR)
- Objection to processing based on a legitimate interest (article 21 GDPR)
- Withdrawal of consent once given, with effect for the future (article 7(3) GDPR)
Please note that in many cases we cannot identify you, because we store no identifying features. Under article 11(2) GDPR we may then request additional information or be unable to fulfil a right. The vault, for example, is not accessible to us in terms of its content.
Independently of that you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement (article 77 GDPR). The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
17. No automated decision making
Automated decision making including profiling with legal effect under article 22 GDPR does not take place. Content recommendations within the application rest on calculations that run on your device and have no legal effect.
18. Changes to this policy
We adjust this policy when the service or the law changes. The version available here applies in each case; the date of the last change is at the top of this page.
Editorial standard
How content comes about
Before publication, content is checked for plausibility, for the separation of fact and assessment, and against the legal requirements that apply. Missing or contradictory information stays unpublished. Automatically generated or edited text is marked where transparency obligations require it. Every figure in a news item comes from a linked primary source and is checked against it by machine before publication.
Note on data
Data availability
Market and news data is shown only where reliability, usage rights and the necessary mandatory information have been settled. Otherwise the field concerned stays empty. An empty space is preferable to a figure whose right to be displayed is unsettled. Specific mandatory information and source citations are added at the place prescribed for them.
Limits of the safeguards
What the protective measures achieve
Vault blocks are authenticated and encrypted before upload with a key derived from the recovery code. Public data files carry checksums and an Ed25519 signature.
These measures do not protect against a device that is already compromised, against malicious browser extensions, or against faults in the operating system and the supply chain. Security updates, dependency checks, key rotation and recovery tests therefore remain ongoing duties on our side, and careful handling of the recovery code on yours.
Traceable
Corrections
Errors of substance are not quietly overwritten. Articles show the nature and the time of the correction, and the correction log stays publicly traceable. There are no published entries at present.
Contact
Report content
If you consider a piece of content unlawful or incorrect, please report it to support@stocklife.io. Describe the address concerned and the reason. We examine every report, remove or correct unlawful content without delay once we become aware of it, and tell you the outcome.