Privacy policy
Last updated: 2026-08-31
In short: we collect the minimum the service needs, we sell data to nobody, we use no advertising networks and we put no marketing trackers on the site.
1. What we collect
| Category | What it contains | Why |
|---|---|---|
| Account | E-mail address, username, plan and period | Creating the account, signing in, access to paid features |
| Authentication | Short-lived sign-in codes, the public keys of your passkeys, a session cookie | Two-step verification and keeping you signed in |
| Preferences | Language, timezone, panel layout, your chart drawings and notes | So the app looks the same next time |
| Notifications | Your Telegram bot token and your per-signal subscriptions | Sending signals to your own channel |
| Payments | Invoices, the amount, the network and the public transaction id | Confirming payment and accounting records |
| Analysis requests | The text of your request and any chart crop you send | Producing the answer you asked for |
| Technical logs | IP address, request time and browser agent | Security, abuse prevention and debugging |
We do not collect card data, bank account numbers or biometric data (a passkey keeps the biometrics on your device, we only receive a public key), and we never ask for access to your brokerage account.
2. Legal basis
- Performance of the contract - the account, the plan, signal delivery, invoices.
- Legitimate interest - security of the service, abuse prevention, technical logs.
- Legal obligation - retention of financial records.
- Consent - connecting your Telegram bot, which you can withdraw at any time by deleting the token.
3. How long we keep it
- Account data: as long as the account exists, plus 30 days after a deletion request.
- Sign-in codes: minutes.
- Technical logs: 90 days at most.
- Financial records: the period required by tax law.
- Analysis requests and drawings: until you delete them or the account is deleted.
4. Who we share it with
We do not sell or rent personal data. We share it only with the providers the service strictly needs:
- The transactional e-mail provider - receives your address and the message content in order to deliver the sign-in code. Its servers are in the European Union.
- Cloudflare - proxy and bot protection in front of the site; it sees the request IP.
- Telegram - receives the messages sent to the bot you created, under their terms.
- The hosting provider - runs the servers the application sits on, in the European Union.
Cryptocurrency payments are recorded on public networks; the amount and the address are visible to anyone by their nature, but they carry none of your identifying data.
5. No advertising tracking
We use no Google Analytics, no social network pixels, no retargeting and no ad networks. The public site loads no third-party scripts other than the anti-bot check on the contact form.
6. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with the supervisory authority (in Romania, ANSPDCP). Details and how to exercise them: the GDPR page.
7. Contact
For any request about your data: the contact form or (the address appears with JavaScript on — or write through the form).