The data controller is […], […]. Contact: […].
Account data: your email address, a salted password hash (never the password itself), your language preference, and account timestamps.
Exchange data: trades, funding payments and wallet balances read from the exchange accounts you connect, plus the encrypted API keys themselves.
Content you create: strategy names, position notes and emotion/mistake tags.
Technical data: your IP address is used transiently for rate limiting and abuse protection. We do not run third-party analytics, advertising or tracking scripts.
We never receive your exchange password, your withdrawal permissions, your seed phrase, or your card details. Card payments are handled entirely by our payment provider.
To provide the Service you asked for (contract): syncing your trades and computing your statistics. To keep it secure (legitimate interest): rate limiting, abuse prevention, error logs. To bill you (contract) and to meet accounting obligations (legal duty).
We do not sell your data, and we do not use it to train models.
We set two cookies: a session cookie that keeps you logged in, and a language cookie that remembers your interface language. Both are strictly necessary for the Service to function; we set no advertising or analytics cookies.
Hosting: our server provider. Email delivery: our transactional email provider (verification and password reset messages). Payments: our payment provider. Exchange APIs are contacted directly to read your data. Each receives only what it needs.
API keys and Telegram tokens are encrypted at rest with AES (Fernet). Passwords are hashed with PBKDF2-HMAC-SHA256 (200,000 iterations, per-user salt). Traffic is served over HTTPS. Sessions expire and are invalidated when you change your password.
No system is perfectly secure. This is one reason we require read-only API keys: even in the worst case, a key we hold cannot move your funds.
We keep your data while your account exists. Deleting your account removes your users, settings, exchange accounts, trades, funding, strategies, tags and notes from the live database. Backups are rotated and expire within 30 days. Invoice records are kept as long as tax law requires.
Depending on where you live (GDPR / KVKK and similar laws), you may request access, correction, deletion, restriction, objection and portability. You can export your trades and positions as CSV at any time from the dashboard, and delete your account yourself from Settings. For anything else, write to […]; we respond within 30 days.
You also have the right to complain to your local data protection authority.
Our providers may process data outside your country. Where required, transfers rely on standard contractual clauses or an equivalent safeguard.
The Service is not intended for anyone under 18.
If we change this policy materially we will notify you by email or in the app before it takes effect.