Effective and last updated: September 5, 2026 · Policy version: RTRS-PRIVACY-2026-09-05-v12.2.1-play1
1. Scope and responsibility
This Policy describes how Ready to Rock Stocks LLC (“we,” “us,” or “our”) handles information in connection with the RockBot Research Android application, readytorockstock.com, and related support. It describes the app, website, and related services, including company-held legal-acceptance records. It is a notice of data practices, not permission for unrelated uses or a waiver of privacy rights.
RockBot does not require a Ready to Rock Stocks account or brokerage connection. The app does not integrate a publisher-operated advertising or behavioral-analytics SDK or a cloud-AI service. This does not mean that Google, hosting infrastructure, or public-data sources process no technical or operational information.
Providers acting on our behalf process information for the applicable service and purposes described below. Google and other providers can also process information independently under their own policies. We remain responsible for obligations that apply to our processing and our service-provider relationships; calling a company a third party does not eliminate those obligations.
2. Information kept on your device
Watchlists, user-entered option-contract facts, calculated research, local research history, cached public data, source-health records, calendar items, reminder preferences, and notification schedules are ordinarily stored in app-private Android storage. The app also keeps local legal documents, an installation identifier, and an acceptance receipt; acceptance records are additionally transmitted as described below. Entered contract values are evaluated locally and are not sent to a live options provider. Calculated economic estimates and research results are not automatically uploaded to Ready to Rock Stocks.
Choosing a ticker or watchlist is different from entering a financial profile. The current app does not request your brokerage password, bank credentials, government identifier, account balances, income, tax status, risk tolerance, or investment objectives. Do not enter or send those details to support.
Legal documents and acceptance records
Before access, the app checks the current published Terms and acceptance notice through our legal service. When a different Terms revision, changed agreement text, or changed acceptance notice requires fresh acceptance, both acknowledgments are presented again. An ordinary app update with the same accepted agreement and notice does not by itself require new assent. A missing or invalid receipt, clearing app storage, or reinstalling can require acceptance again. The Terms of Use govern contractual acceptance; privacy rights and choices remain governed by this Policy and applicable law.
After you check both acknowledgments and tap Agree & Continue, the app sends a receipt over HTTPS to Ready to Rock Stocks LLC. The receipt records a randomly generated installation identifier and receipt identifier; the Terms revision, document fingerprint, and exact agreement reference; the privacy-notice and acceptance-screen identifiers; both acknowledgment states and the final acceptance action; the app package and version; and the device-reported acceptance time. Our service adds its receipt time and preserves the agreement text and acceptance-screen wording associated with that record.
We store the receipt, the accepted agreement text, and associated purchase-link records in a private database using Cloudflare infrastructure for company recordkeeping. Authorized company personnel and service providers acting for us may access these records for the purposes described here. The acceptance process does not automatically email a copy. We may retrieve or securely export records when needed for administration, a verified request, or a legal matter.
Connecting an agreement with a trial or subscription. The app sends its Google Play purchase token over HTTPS to our service for verification with Google. The service stores a SHA-256 fingerprint of the token rather than the raw token. Associated records include available order identifiers; product, base-plan, and offer identifiers; trial and subscription state; purchase-start and expiry times; server verification and linking times; and a test-purchase marker. These are transaction references and status snapshots, not payment credentials or a complete history of every subsequent renewal or cancellation.
When checkout begins in the app, a random reference supplied to Google can connect the purchase with the existing acceptance record. If that reference is absent or different, such as when restoring a purchase, the record instead shows that the installation presented a Google-verified purchase token. We distinguish a matching checkout reference from token verification without that match; the latter does not establish that this installation initiated the original purchase. This establishes a connection with a verified transaction, not verification of the natural person who used the device or payment method. It does not create a separate publisher sign-in account. A purchase does not replace the two affirmative agreement acknowledgments.
The automated agreement and purchase-verification process does not collect your name, personal email address, card or bank credentials, watchlist, entered option contracts, research results, advertising identifier, or raw IP address into these records. Relevant order or customer information made available separately through Google Play's developer tools, correspondence you provide, or information otherwise lawfully obtained may be associated with a record to handle support, a verified request, or a legal matter. These records are used to document acceptance, verify access, secure the service, and establish, exercise, or defend legal claims; they are not research-model inputs or advertising profiles.
The app may keep an unsent receipt locally while retrying a connection. It shows acceptance recording as pending until the service confirms storage; a pending attempt is not represented as a confirmed company record. Purchase verification and linking are separate checks required for research access. A completed local receipt and purchase-link confirmation can persist across ordinary launches. Canceling a trial or subscription does not remove the company record, even if no paid renewal occurs. Clearing app storage or uninstalling removes app-owned local copies, including the installation identifier and pending receipt, but does not delete a receipt already held by the company or its purchase link. See retention and privacy-request information below.
The current app is configured to exclude its app-owned data from Android cloud backup and device transfer. A user-created export, screenshot, email, or shared copy is outside that app-storage boundary and may be backed up or retained by the chosen destination.
3. Information sent for research and legal services
Research requests transmit the requested ticker or other public-source query details and ordinary technical metadata, which can include IP address, request time, requested URL or path, app or user-agent information, response status, and connection information. Requested symbols and timing may be categorized as in-app search activity in platform disclosures. The Ready to Rock Stocks Market Gateway and relevant source or network providers receive the information needed to serve those requests and may maintain access, security, or diagnostic records.
Market-history requests use the Market Gateway. SEC research requests public issuer and filing information from official SEC hosts. Calendar workflows request official schedules, releases, and communications from BLS, BEA, the Federal Reserve Board, and SEC. For option evaluation, requests for underlying history or filing evidence use the ticker and technical request information—not the exact entered option contract fields. Public release history may be cached locally for on-device economic-estimate calculations.
When enabled, background SEC filing checks make limited requests for selected symbols after the applicable access check. Economic-release and earnings reminders use locally stored events to schedule Android notifications; they do not create an advertising profile. Permissions, connectivity, Android scheduling, source availability, and subscription status can affect these features.
Legal-document checks, acceptance submissions, and purchase verification make requests to our legal service on readytorockstock.com. Purchase verification also sends the purchase token to Google over HTTPS. Hosting and security infrastructure necessarily processes connection metadata. To limit abusive requests, our legal service uses the connecting IP address transiently to produce a rotating, keyed security bucket; its application database retains the bucket, counters, and expiry for up to approximately 48 hours, not the raw IP address. Acceptance and purchase-link records exclude that bucket and address. Cloudflare infrastructure can separately process or retain connection and security records under the applicable service settings, contracts, and legal duties. Disabling application payload logs does not mean that all infrastructure records are absent.
4. Market-data source and attribution
The current delayed daily market-history path uses the Ready to Rock Stocks Market Gateway with IEX Historical Data provenance. Data provided for free by IEX. By accessing or using IEX Historical Data, you agree to the IEX Historical Data Terms of Use. IEX data reflects IEX Exchange activity, not the consolidated U.S. market. See the Financial & Market Data Disclosures for coverage and use limitations.
5. Google Play, subscriptions, and diagnostics
Google Play processes subscription offers, trial eligibility, checkout, account and purchase information, payment credentials, and relevant device and technical information under Google's terms and Privacy Policy. RockBot receives purchase and entitlement information to determine access. During checkout, the app supplies a random agreement-related reference to Google so a resulting purchase can be associated with its acceptance record. The app uses a purchase token to acknowledge a transaction to Google Play and sends it to our service for verification as described above. Raw purchase tokens are used transiently in that process; they are not intentionally written to research records, acceptance receipts, purchase-link database rows, or application payload logs. Google Play manages its own purchase information. We do not receive your card or bank credentials through this process.
Starting a trial through Google Play is a subscription transaction even if you cancel before a paid renewal. Once recorded, the connection between that transaction and your agreement remains subject to our retention rules. A purchase check records the state Google reports at that time; it is not a claim that we continuously monitor every account or transaction change.
Google Play and supporting Google or Android components may process operational diagnostics and app-interaction information for delivery, functionality, reliability, security, compatibility, and platform analytics. Google may make developer-facing purchase, financial, crash, or operational reports available under its services. The absence of a publisher analytics SDK does not disable those platform processes.
You can manage billing through Google Play subscriptions. Uninstalling or deleting local data does not cancel recurring charges or delete Google's purchase and account records. We use information made available to us for access support, billing administration, accounting, fraud prevention, compliance, and dispute handling—not to tailor securities research to your financial circumstances.
6. Website, hosting, cookies, and external links
The website's first-party code contains no advertising pixel, cross-site behavioral-analytics script, or marketing-cookie logic. It uses locally hosted images, video, styles, and scripts. Cloudflare delivers and protects the site and may process requested pages, IP address, browser metadata, timestamps, referrers, and security or performance information. Essential challenge or security cookies may be used by the hosting service. See Cloudflare's Privacy Policy.
The app's embedded web content has cookies disabled. Opening a legal or source link launches the external browser, where browser settings and the destination's cookies and privacy practices apply. Clicking an email link opens your email application. A destination may collect information independently when you choose to visit it; merely listing a link does not load that destination's tracking code into this website.
7. Purposes, recipients, and voluntary sharing
We process information for the purposes connected to its source: delivering requested content and research; maintaining local settings and bounded caches; checking trial or paid access and connecting it with the recorded agreement; providing user-enabled reminders; responding to support and correction requests; measuring operational reliability through applicable platform reports; securing the service; administering billing and accounting; honoring privacy requests and valid legal choices; and complying with law or establishing, exercising, or defending legal claims.
Depending on the interaction, recipients include Google Play; hosting, gateway, network, security, and email providers; requested public-data sources; professional advisers; and authorities where disclosure is legally required or reasonably necessary and lawful to protect rights, security, or safety. Information may also be involved in a merger, acquisition, or business transfer subject to applicable safeguards and continuing privacy obligations. This is not permission to sell personal information for advertising.
We receive your sender address, message, attachments, and information you volunteer when you email us. Mail can include a name, return address, and correspondence. A privacy request, billing inquiry, or legal notice may include an order number or local receipt identifier if you choose to supply it. Such records are used to address and document the matter, not as research-model inputs. Do not send passwords, private keys, full card numbers, government identifiers, or brokerage credentials.
A research export is shared only when you invoke Android sharing and select a destination. It can include selected symbols, entered contract values, calculated results, source facts, and timestamps. The destination controls its copy. We cannot recall a copy you have sent to another person or service.
8. Advertising, sale, and tracking choices
We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not offer a financial incentive for providing personal information or use it to profile users for decisions with legal or similarly significant effects. Subscription charges pay for access to the service, not a discount in exchange for advertising data.
Because we do not engage in those sale, sharing, or targeted-advertising practices, a browser Do Not Track or Global Privacy Control signal does not change them. We do not authorize third-party cross-site advertising tracking through this site's first-party code. If practices change, we will provide required notice and choices, honor legally required opt-out signals, and obtain consent where required before the changed processing.
9. Retention and deletion
Retention depends on the information and its purpose. The following describes categories and criteria rather than promising that every record is deleted on a fixed date:
| Category | Retention and deletion boundary |
|---|---|
| Device-local research and settings | Bounded by feature purpose, cache replacement, and validity checks. Eligible research results can restore for the same local date and exact watchlist; calendar and reminder records can remain longer. Clear local app data removes the state identified by its confirmation. Android Clear storage or uninstall removes app-owned storage. |
| Local legal documents, installation identifier, receipt, and access state | Legal documents and the current receipt can remain until replaced or cleared; a pending submission can remain while completion is retried. The installation identifier remains for that installation. Android Clear storage or uninstall removes app-owned copies, not company or provider records. A bounded Google Play entitlement status may remain or be recreated after an in-app clear until Play is checked again; it is not a purchase token. |
| Company acceptance and purchase-link records | The legal service normally schedules receipt and associated purchase-link deletion approximately six years after the original server receipt time, subject to a documented legal hold or another applicable preservation obligation. Linking or rechecking a purchase does not by itself restart that period. Cancellation, including cancellation during a trial before a paid renewal, does not trigger deletion. Any administrative exports, correspondence, or provider backups are managed separately; deleting a database receipt does not automatically delete those copies. Records should be retained only as reasonably necessary for the applicable recordkeeping, legal, or dispute purpose. Agreement text may be archived separately without a personal acceptance record. Contact us about access or deletion, subject to applicable verification requirements and lawful exceptions. |
| Legal-service abuse-prevention buckets | Rotating keyed identifiers and request counters expire within approximately 48 hours and are removed by scheduled cleanup. Raw IP addresses are not stored in the legal-service receipt database. Separate infrastructure logs follow the network-record criteria below. |
| Support, corrections, privacy requests, legal choices, and billing records held by us | Kept as reasonably necessary to resolve and document the matter, honor continuing choices, meet accounting or legal obligations, and address applicable claim periods or preservation duties. Unneeded information is deleted or de-identified where appropriate. A legal hold can delay deletion. |
| Network, hosting, and platform records | Retention depends on the applicable service settings, operational/security purpose, contracts, and legal duties. Provider-controlled purchase or diagnostic records follow that provider's practices. Local app deletion does not remove remote records. Contact us for requests concerning records processed for us. |
| User-shared copies | The recipient or selected service determines retention of its copy. Contact that destination separately. |
10. Security and sensitive information
The current app uses HTTPS for the described network requests, app-private storage, and backup exclusions for app-owned data. We use safeguards appropriate to the information and service. No transmission, device, provider, or storage system is infallible; we cannot promise absolute security or confidentiality. This limitation does not excuse our security or incident-notification obligations under applicable law.
Keep your device and operating system updated, secure your Google account, and review information before sharing it. To report a suspected security issue, email admin@readytorockstock.com with a minimal description. Do not include credentials, unnecessary personal information, or other users' data. A contact address is not authorization to access systems or data without permission.
11. Privacy rights and choices
Depending on your location and the law applicable to our processing, rights may include confirmation or access; correction; deletion; a portable copy; restriction or objection; an appeal; and choices concerning sale, sharing, targeted advertising, certain profiling, or sensitive information. We do not discriminate against you for exercising an applicable privacy right. The dispute-resolution provisions in the Terms do not remove nonwaivable privacy rights.
Send requests to admin@readytorockstock.com or the mailing address below. A subject line is helpful but not required. Describe the interaction and request without sending sensitive identification unnecessarily. We may request proportionate information to verify identity or an authorized agent's authority and locate records. If applicable law provides an appeal, reply to our decision requesting one. You may contact a competent privacy regulator or attorney general.
Some local data is accessible only on your device; use the app or Android deletion controls for that information. A receipt or installation identifier from the app, or a Google Play order number, can help us locate an acceptance record and its purchase link without collecting unnecessary identity documents. Relevant customer or order information available through Google Play may also help us locate a transaction. Possession of an identifier alone does not always establish authority to obtain or delete a record. If you have already uninstalled, provide the order number or other context you still have; locating a particular record is not guaranteed. Do not send a raw purchase token, password, or card details. We may also be unable to identify particular infrastructure records without additional context, and requests can be subject to lawful exceptions. We will address requests concerning information we control or that providers process for us. For records a provider holds independently, its request process may also be needed.
12. Children and geographic scope
The service is intended for adults aged 18 or older, not children. We do not knowingly collect personal information from children under 13. If you believe a child has provided such information, contact us so we can review and take appropriate steps, including deletion where required. An adults-only statement is not a claim that the app verifies every user's age.
The service is directed to the United States. Providers may process information in the United States and other locations where they operate. Access from another country does not waive mandatory local rights; any legally required transfer safeguards remain applicable.
13. Policy changes
We will identify revisions with a new date and provide additional notice or obtain consent where required. Posting revised text does not retroactively authorize materially incompatible uses of information already collected. Applicable prior commitments and legal rights remain relevant. This Policy does not change the version of a contract recorded as accepted in the app.
14. Contact
Ready to Rock Stocks LLCAttn: Privacy
1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
admin@readytorockstock.com · Terms of Use · Financial & Market Data Disclosures