Privacy Policy

Draft. No effective date — this document is not in force.

Placeholder. Not legal text and not legal advice. The headings below are the ones a GDPR-facing privacy policy needs; the text under them is a description of what to write, not the writing. Replace this document entirely before publishing the Google OAuth consent screen, before accepting a payment, and before any real person creates an account.

1. Who we are

The controller's legal name, registered address, and a contact address for privacy questions. If a Data Protection Officer is appointed, their contact details.

2. What we collect

Enumerated by category and by source, distinguishing what a person gives us from what is observed. For this product that includes: the email address and profile fields supplied at sign-up or by an identity provider; a device identifier and public key generated at enrolment; subscription and billing state held by the payment provider; and records of which data ranges were requested, for quota accounting.

3. Why we process it, and on what lawful basis

Each category paired with a purpose and an Article 6 basis — performance of a contract, legitimate interests, consent, or legal obligation. Where legitimate interests are relied on, the balancing test and its conclusion.

4. Who we share it with

Named processors and what each one receives: the identity provider, the payment provider, the cloud and object-storage providers, and the market-data vendors. For each, whether the transfer leaves the EEA and the mechanism that permits it.

5. How long we keep it

A retention period per category, or the criteria used to decide one. Account records, audit records and billing records will not share a period; billing records in particular are usually held for a statutory minimum that outlives the account.

6. Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where consent is the basis. How to exercise each, how long a response takes, and the right to complain to a supervisory authority — named, with its contact details.

7. Automated decision-making

Whether any is carried out, and if so its logic, significance and consequences. Note that trading decisions made by a customer's own strategies on their own machine are not our automated processing of their personal data, and the document should say so rather than leave it ambiguous.

8. Security

A truthful summary of the measures in place — encryption in transit and at rest, access control, and the fact that content encryption keys are held per account. Do not describe controls that are not implemented.

9. Cookies and local storage

What is stored in a browser, by whom, for what, and whether consent is required. If no analytics or advertising technology is used, say so plainly; it is the shortest and best version of this section.

10. Changes to this policy

How changes are notified and from when they take effect. Prior versions remain available.