Skip to the main content

Legal

Privacy policy

Last updated

This document is a general template and does not constitute legal advice; review by a qualified lawyer is recommended.

This policy says what personal data this service collects, why it collects it, who else touches it, and what you can ask us to do about it. Read it alongside our terms of service.

1 Who this covers

It covers everybody who uses this service: visitors who only look, people who hold an account, and people who connect a wallet. Where this policy says we, it means the operator of this service, whose contact address is in clause 13.

2 What we collect

Account identifiers. If you hold an account, we store the name you sign in with, an internal account identifier, your role, and a hashed credential. Sign-in is by name, so we do not ask for an email address and there is no field on the form to give us one.

Usage and technical logs. Our hosting and application layers record ordinary server information: the routes requested, the time, the response, the IP address the request came from, the browser and device it reports, the referring page, and errors. Some of this is generated automatically and we cannot switch it off without switching off the service.

Wallet addresses. If you connect a wallet, we store its public address and the items you save against it, such as your starred instruments and any plan you commit. We never receive, request or store your private keys or your seed phrase, and there is no place in this service to type either. A public address and its on-chain activity are public by nature and were public before they reached us.

What you send us. Bug reports, questions you type into research surfaces, and anything you write into a form, along with the context we attach to make it useful, such as which screen you were on. Bug reports can be filed without an account, so we may hold a report that is not linked to any identity.

Preferences held in your browser. Small settings like your light or dark theme choice and layout preferences. These sit in your own browser storage and are not personal data about you.

3 What we never collect

We do not ask for your national identity number, your passport, your date of birth, your bank account or your card number, and there is no field anywhere in this service to give us any of them. We never see your private keys, your seed phrase or your wallet password.

4 Why we use it

To run the service and keep it working: signing you in, keeping you signed in, showing you what you saved, answering your bug report, and getting data onto the screen.

To keep it up and keep it safe: finding and fixing faults, applying rate limits, detecting abuse, and protecting the service and its users.

To understand it: aggregate, non-targeted counts of which parts of the product get used, so we know what to build next.

Where data protection law of the kind in force in the European Economic Area or the United Kingdom applies to you, we rely on performing our contract with you for the first of those, on our legitimate interests in running a secure and functioning service for the second and third, and on your consent where consent is what the law requires. You can withdraw consent at any time, and withdrawing it does not affect what was lawful before you did.

5 Cookies

We use cookies for session and authentication only. One signed cookie keeps you signed in, and a small preference value remembers your theme. That is the extent of it.

There are no advertising cookies, no third-party tracking pixels, no cross-site profiling and no data broker tags on this service. Blocking the session cookie will stop sign-in from working, because signing in is what it is for.

6 Who else processes it

We use third-party providers to run the service, and they process data on our behalf and under our instructions. By role, they are: our hosting and content delivery provider, our managed database and authentication provider, the market data and social data providers whose feeds the product displays, and an AI provider used by the analysis features. Each is engaged under its own commercial terms, which we do not reproduce here.

These providers may store or process data in countries other than yours, including outside the European Economic Area and the United Kingdom. Where the law requires a safeguard for that transfer, we rely on the provider’s standard contractual protections.

We may also disclose data where the law requires it, where a valid legal request compels it, or where it is necessary to establish or defend a legal claim or to protect the safety or rights of anyone.

7 We do not sell your personal data

We do not sell your personal data, and we do not share it for cross-context behavioural advertising or targeted advertising. We have not done either, and if that ever changed this policy would say so before it happened.

8 How long we keep it

Account data is kept while your account exists, and is deleted when the account is deleted or when you ask us to delete it, except where we have to keep something to meet a legal obligation or to resolve a dispute.

Server, security and error logs are kept for a limited operational period and are then deleted or reduced to aggregates that no longer identify anyone. Content you sent us, such as a bug report, is kept while it is still useful for fixing the thing it reported.

Data written to a public blockchain is not ours to delete. It is outside our control and outside this policy.

9 Security

We take reasonable technical and organisational measures to protect the data we hold, including transport encryption, hashed credentials, signed sessions and restricted access to production systems. No service is perfectly secure, and we cannot guarantee that ours is. The security of your wallet, your seed phrase and your own device remains yours.

10 What you can ask for

You can ask us to tell you what personal data we hold about you, to give you a copy of it, to correct it, to delete it, to restrict what we do with it, or to stop processing it where we rely on legitimate interests. You can ask us to delete your account.

If data protection law in the European Economic Area or the United Kingdom applies to you, those rights are yours under it and you can also complain to your national supervisory authority. If you are a California resident, you have rights to know, to delete, to correct, to portability, and to opt out of the sale or sharing of your personal data, and we will not treat you differently for exercising them. As clause 7 says, there is no sale or sharing here to opt out of.

Wherever you live, ask us and we will do our best to help. Write to [CONTACT EMAIL]. We may need to confirm who you are before we act, so that we do not hand somebody else your data.

11 What this policy does not claim

This policy uses the language of the General Data Protection Regulation and of California privacy law because those are the words readers expect, and because the practices it describes are meant to sit comfortably with both. It is not a statement that this service has been certified, audited, registered or found compliant under either regime, or under any other. It describes what we do.

12 Children

This service is not intended for children, and it is not directed at anyone under the age at which they could use it lawfully where they live. We do not knowingly collect personal data from a child. If you believe a child has given us data, write to us and we will delete it.

13 Changes, and how to reach us

We may update this policy. The date at the top of this page is when it last changed, and the version on this page is the version that applies. Where a change is significant we will make it visible in the product rather than only here.

Privacy questions and requests go to [CONTACT EMAIL]. The operator of this service and the controller of the data described here is the entity identified in our terms of service, under the law of [JURISDICTION].