Draft pending legal review. The operator's legal details will be added before the public launch; until then this text describes how the service actually works.

Privacy Policy

Version 2026-10-01 (draft)

Controller: [OPERATOR — legal name, address], contact [privacy e-mail]. Data is stored in the European Union (servers in Germany).

What we process and why

Data Why Legal basis
E-mail, name, password hash; after Telegram sign-in launches: Telegram id, name, username, photo link, language account and sign-in contract
Language, time zone, theme, notification settings, quiet hours to show the Service and send notifications as you set them contract
Watchlist, muted assets, price levels, in-app notifications the features you use contract
Telegram chat id of a connected chat (after the Telegram bot launches) to deliver notifications contract
Browser notification subscription, only if you switch notifications on in a browser: the address your browser’s notification service issued and two encryption keys to deliver notifications contract; you switch it on and off yourself
Sessions: IP address, browser/app user agent, times keep you signed in, protect the account, show your devices contract, legitimate interest (security)
If you turned on two-factor protection: the authenticator app’s secret and the backup codes (stored encrypted), the “do not ask on this device” mark protect signing in contract, legitimate interest (security)
Accepted versions of Terms, Privacy and Risk Disclosure, with time proof of consent legal obligation, legitimate interest
Plan and, later, subscription and payment status (no card data) provide the paid plan contract
Admin actions on your account (with a /24 IP prefix of the staff member) accountability legitimate interest
Which pages and sections you open and where you meet a plan limit: an event name from a fixed list, the asset and timeframe. No IP address, no browser data see what to improve legitimate interest; the link to your account can be switched off in Settings
Messages you send through the feedback form, and the e-mail you leave there; our answers to them answer you and fix the problem legitimate interest

We do not use advertising trackers, do not sell data and do not build marketing profiles. We count usage ourselves, on our own server, without cookies and without third parties: for guests with no identifier at all, for signed-in users linked to the account until you switch that off in Settings (Settings → Your data). We also skip the count when your browser sends Do Not Track or Global Privacy Control. Third-party product analytics will be enabled only with your separate consent.

Recipients (processors)

Recipient Purpose Status
Hetzner Online (Germany) hosting and database used
Cloudflare DNS, content delivery, protection from attacks used
E-mail delivery provider [name] confirmation and password e-mails used
Telegram bot messages and the Mini App, if you use them not used yet — after the Telegram bot launches
The notification service of your browser (Google, Mozilla, Apple or Microsoft) passes an encrypted notification to your browser; it cannot read the text only if you switched browser notifications on
Stripe; Telegram (Stars) payments when payments are launched
PostHog (EU) product analytics only with your consent, not enabled yet

Market data comes from Binance; no personal data is sent there. The Service has no AI features and sends no data to AI providers; if that changes, this policy will list the provider before it is used.

How long we keep data

  • Account data — until you delete the account.
  • In-app notifications and daily summaries — 90 days; delivery records — 30 days.
  • Price levels — while the account exists: you remove open ones yourself, reached ones stay as history.
  • Sessions — up to 30 days after the last activity; the “do not ask for the code on this device” mark — 30 days.
  • The two-factor secret and backup codes — while the protection is on.
  • Usage statistics and feedback messages — [period — counsel]; usage statistics linked to your account are deleted with the account.
  • Consent records and admin audit records — as long as needed to prove them ([period — counsel]).
  • After deletion, backups roll over within [period].

Your rights

You can access and download your data (Settings → Download my data), correct it, delete your account (Settings → Delete account), object to processing based on legitimate interest, withdraw consent and complain to a supervisory authority. Write to [privacy e-mail] for anything else.