Legal
Privacy Policy
Last updated
What we store
- Account email + auth identity (Supabase, EU region by default).
- Settings, scripts, alerts you choose to sync to the cloud (Pro).
- Webhook secrets — sealed with AES-GCM at rest.
- Usage analytics (Google Analytics 4 + Meta Pixel), loaded only when you accept the consent banner — IPs anonymised, no PII collected. See the cookie policy for details.
What we don't store
- Broker passwords. Auto-orders use broker-issued API keys you scope yourself.
- Local scripts unless you explicitly opt to sync them.
- Free-tier desktop usage — the binary is fully offline-capable.
Account deletion
Profile → Delete account triggers an Edge Function that removes every owned row and the auth.users identity itself. GDPR-compliant. Backups roll off in 30 days.
Contact
Questions or data-subject requests: [email protected].