
Privacy Policy
Last updated 6 August 2026
We collect what the product needs to work: your account, your trading activity, and the exchange credentials you choose to connect. Credentials are encrypted at rest and never leave that boundary. We do not sell your data, and nothing you trade is published unless you explicitly opt in.
1. What we collect
- Account — email address, password hash (held by our authentication provider, never by us in plaintext), country code, and two-factor enrolment state.
- Exchange credentials — API keys and secrets for the venues you connect, and wallet addresses you link. Keys carrying withdrawal permission are rejected at registration.
- Trading activity — orders, positions, journal entries, risk settings, and the market snapshot behind each decision.
- Product usage — pages visited, features used, and error reports, used to find bugs and understand what to build next.
- Optional integrations — a Telegram chat id if you link Telegram; a wallet address if you pay on-chain.
2. How exchange credentials are protected
API keys and secrets are encrypted at rest with AES-256-GCM under a per-user salt. They are decrypted only in memory, only to place or read orders you asked for.
Plaintext keys are never written to logs, never returned by the API — not even to you — and never sent to any third party. A key that carries withdrawal permission is refused at registration rather than stored.
3. AI processing
Market data and the numeric features derived from it are sent to third-party model providers to produce the agent analysis you see. This is market data — prices, order-book shape, funding, sentiment aggregates.
We do not send your identity, your email, your API keys, or your account balances to model providers.
5. How long we keep it
Account and trading records are kept while your account is open, because they are what your history, statistics and tax records are built from.
Raw market-scan data is pruned on a rolling schedule (90 days by default). Scans attached to a real trade are never pruned — deleting them would break the audit trail behind a position you actually took.
On account deletion we remove your personal data and credentials. Financial records we are required to keep, and anonymised aggregates that cannot be traced back to you, may be retained.
6. Your rights
You can access and export your data from the product, correct your profile, disconnect any integration, and delete your account. Disconnecting exchange credentials removes them from our systems.
Depending on where you live you may have additional rights — access, portability, erasure, objection. Write to [email protected] and we will answer within 30 days.
7. Where data is processed
Our infrastructure providers operate internationally, so your data may be processed outside your country of residence. We use providers that offer standard contractual protections for such transfers.
8. Security, honestly stated
We encrypt credentials at rest, verify tokens locally, enforce row-level database policies, block by geography, and offer two-factor authentication — which we strongly recommend enabling, particularly on accounts trading real money.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you what happened and what to do, without waiting to have a complete picture first.
9. Contact
Privacy questions: [email protected]. The platform is open source under AGPL-3.0, so the data handling described here can be verified against the source rather than taken on trust.