KovaViewKova Investment ResearchHome

KovaView

Privacy Policy

Last updated: September 2, 2026. KovaView is a portfolio-tracking and trading-research application operated for Kova Investment Research members and registered users. This policy explains what we collect, why we use it, and how to contact us.

Summary

KovaView collects account email, user ID, and the positions, equity, watchlist, and trade-journal data you provide or generate in the app. We use it for login, portfolio tracking, leaderboard, alerts, risk controls, and service security. Kova AI questions, plus a summary of the holding when you ask about your own position, go to third-party AI providers to generate the answer. Linking Discord or Interactive Brokers is optional; the broker credential is read-only and encrypted. A bug report from the iOS app includes an automatic screenshot you can remove before sending. We do not sell personal information or run third-party ad tracking. To access, correct, or delete personal information, contact privacy@kovaview.com.

Information we collect

Account information: email address, user ID, display name, username, avatar (a preset, or an image you upload), login method, membership or access status, and password hash when you choose email login. We never store your plain-text password.

Portfolio and trading information you provide or generate in the app: account settings, cash values, positions, average costs, stops, watchlists, trade-journal entries, chart drawings, equity snapshots, deposits or withdrawals you classify, and leaderboard profile choices.

Market and app activity needed to run the service: ticker queries, followed traders, notification preferences, device/browser metadata, security logs, and basic diagnostics.

Billing status from payment providers when applicable. Payments are processed by third-party providers; KovaView does not store full card numbers.

Connected accounts, only when you choose to link them. Discord: we ask Discord for your account identity and for permission to add you to our server, then store your Discord user ID and display name. We do not receive your Discord password, messages, or friend list, and we do not keep a Discord access token after the link is made. Interactive Brokers: you supply a Flex Web Service query ID and token — a read-only reporting credential. The token is stored encrypted and is never shown again beyond its last four characters.

Support and bug reports: what you write in the report form, the page or screen you were on, your browser or device information, your app language, and any images attached to the report. In the KovaView iOS app, opening the report form automatically captures a screenshot of the screen you were on and attaches it to the draft. You can delete that screenshot — and any photo you add from your photo library — before you send, and nothing is uploaded until you tap Send.

How we use information

To provide core app functionality: authentication, portfolio and equity-curve views, Kova watchlists, leaderboard access, follower-gated holdings, alerts, and account administration.

To answer your Kova AI questions. When you ask a question, we send it to third-party AI providers so they can generate a reply. If you ask about a position you hold, we also include a short summary of that position — the ticker, the average cost and share count on record, when it was opened, and how far the price sits from your stop — so the answer addresses your actual position instead of a generic one. We keep your question and the answer to review answer quality, act on your thumbs-up or thumbs-down, and investigate abuse. Kova AI is not investment advice.

To protect the service: prevent unauthorized access, enforce rate limits, investigate abuse, keep audit records, and maintain data integrity.

To improve reliability and product quality through aggregate diagnostics and operational monitoring.

We do not sell personal information and we do not use it for third-party advertising or cross-app tracking.

Sharing

We share information only with service providers required to operate KovaView, such as hosting, database, authentication, payment, market-data, file-storage, AI, and notification infrastructure.

AI providers. Kova AI questions are processed by OpenRouter, which passes them to the model that writes the answer, and by xAI — for questions that need real-time web and X search, and as a failover when the primary provider is unavailable. The models we use on OpenRouter are pinned to a named list of inference providers with automatic fallback switched off, and the open-weight models among them are restricted to US-hosted providers, so a question cannot be silently re-routed to a host we have not approved.

Interactive Brokers. If you link a brokerage account, we use your Flex credential to pull your positions, trades, and cash balances from Interactive Brokers on a schedule and when you press Sync. The credential is read-only — it can request statements and nothing else, so KovaView cannot place, change, or cancel an order. Unlinking deletes the stored credential.

Discord. If you link Discord, we send your Discord user ID to Discord to add you to our server and to grant or remove the role that matches your subscription. Unlinking removes that role and deletes the link.

Files. Images attached to a bug report — including the automatic screenshot — and any avatar you upload are held by our file-storage provider. Those links are unlisted rather than password-protected: anyone who has the exact link can open the file.

Public leaderboard views are limited by product rules: they may show display names, avatar presets, percentage-based performance, risk metrics, and follower-gated holdings. They do not show private account dollar amounts to the public.

We may disclose information if required by law, to enforce our rights, or to protect users and the service.

Retention and deletion

We keep account and portfolio records for as long as needed to provide the service, maintain auditability, resolve disputes, comply with legal obligations, and protect against fraud or data tampering.

You can request access, correction, export, or deletion of your personal information. Some records may be retained where legally required or where deletion would compromise security, audit, or anti-fraud obligations.

Security

KovaView uses HTTPS, access controls, signed sessions, password hashing, and provider-side secret management. A linked broker's Flex token is stored as AES-256-GCM ciphertext and decrypted only server-side when a statement is pulled. No internet service can be guaranteed perfectly secure, but we work to keep sensitive trading and account data protected.

Children

KovaView is not intended for children under 13. If you believe a child provided personal information, contact us so we can review and delete it where appropriate.

Contact

For privacy requests or questions, email privacy@kovaview.com. We may need to verify your identity before acting on account-specific requests.