Privacy Policy
Last updated: 17 September 2026
Rateory is operated by Northbird, a business registered in the Netherlands (KvK 42164736). Privacy questions and data-rights requests can be sent to [email protected].
1. What Rateory processes
Rateory does not require a user account and does not ask you to provide your name, email address, payment details, or precise location to use the currency converter.
- Local website data: favorites, recent conversions and web alert settings can be stored in your browser's local storage. They are not sent to Rateory's push service.
- Local mobile data: favorites, recent conversions, language choice and alert settings can be stored on your device.
- Optional push data: only after you choose to enable mobile notifications, Rateory sends a random device identifier, a Firebase Cloud Messaging token, platform information, and your alert settings (currency pair, target, direction and timestamps) to the Rateory push service.
- Optional crash diagnostics: crash reporting is off by default. If you choose to enable it, Google Firebase Crashlytics may receive crash stack traces, relevant app state, device and operating-system metadata, app version information, and Crashlytics/Firebase installation identifiers so we can diagnose failures. Rateory does not set a Crashlytics user ID and does not include Google Analytics in the app.
The mobile app creates a device secret locally. The push service stores only a hash of that secret for authentication, rather than the secret itself.
When you access Rateory, hosting and network providers may process ordinary technical data needed to deliver and secure the service, such as IP address, request metadata, timestamps and security signals.
2. Why we process data
- To provide currency conversion, history and the features you request.
- To register an opted-in mobile device and deliver target-rate notifications.
- To diagnose app crashes only when you opt in to crash diagnostics.
- To secure, troubleshoot and maintain the service.
- To prevent abuse and protect Rateory's infrastructure.
- When website advertising is enabled, to fund the service while respecting applicable consent requirements.
Depending on the processing activity, the legal basis is performance of the service you request, our legitimate interests in secure and reliable operation, and your choice or consent for optional notifications and crash diagnostics where applicable.
3. Service providers
Rateory uses Cloudflare for hosting, network delivery, security and push-service storage, Google Firebase Cloud Messaging to issue and deliver mobile notification tokens and messages, and Google Firebase Crashlytics for optional crash diagnostics after opt-in. When website advertising is enabled, Google AdSense may process advertising, consent and anti-fraud data. Exchange-rate requests are served through Rateory and may use third-party reference-rate sources.
These providers may process data outside the European Economic Area. Where required, international transfers are covered by applicable provider terms and transfer safeguards, such as standard contractual clauses or other recognized mechanisms.
4. Retention and deletion
Local browser or app data remains until you remove it, clear application/browser storage, or uninstall the app. Server-side push registration and alert data is configured to expire no later than 180 days after its last relevant update.
For optional crash diagnostics, Firebase states that Crashlytics retains crash stack traces and associated identifiers for 90 days before starting removal from live and backup systems. When diagnostics are off, crash information may be kept locally on the device by the Crashlytics SDK; Rateory deletes unsent reports before enabling diagnostics and again when you turn diagnostics off.
You can delete mobile notification data earlier from the Rateory app by choosing Disable & delete notification data. This removes the device registration and alert records stored by the Rateory push service and disables the app's FCM token.
5. Cookies, consent and advertising
Rateory does not use advertising or analytics SDKs in the mobile app. Optional Firebase Crashlytics is used only for crash diagnostics after opt-in and is not used for advertising or behavioral analytics.
The website is technically prepared for Google AdSense. Until advertising is enabled, the AdSense advertising script is not loaded. When advertising is enabled, Google and its partners may use cookies, local storage or similar technologies for ad delivery, measurement, fraud prevention and related purposes. Where consent is required, advertising that depends on consent will be gated through an appropriate Google-certified consent management flow before it is served.
Browser local storage is also used for functional preferences and locally saved Rateory features such as favorites, recent conversions and alert settings.
6. Your rights
Where the GDPR or another applicable data-protection law applies, you may have rights to access, correct, delete, restrict or object to processing, and to data portability where relevant. You may withdraw consent where processing relies on consent without affecting earlier lawful processing.
To exercise a right, contact [email protected]. You may also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or another competent authority.
7. Sharing and sale
Rateory does not sell personal data. Data is shared with service providers only as needed to operate, secure and deliver the service, or where required by law.
8. Changes
We may update this policy when Rateory's features or legal obligations change. The current version and update date will remain available on this page.
9. Contact
Northbird · KvK 42164736 · Netherlands
Email: [email protected]