Privacy Policy

Last updated 15 August 2026

1. Who we are

This policy explains how we handle personal data when you use this website and the services offered through it (the "Service"). The controller of that data is the operator identified at the end of this page, referred to below as "we", "us" and "our".

If you have any question about this policy, or want to exercise any of the rights in section 9, write to the address shown at the end of this page.

2. What we collect

Account data. Your email address, your username and display name, an avatar if you set one, and a password hash if you signed up with a password rather than through Google. We never store your password itself.

Authentication and security data. Login and session records, and a hashed form of your IP address together with the user agent your browser reports. We hash the IP rather than storing it in the clear, and we use these records to detect abuse and to investigate security incidents.

Content you create. Strategies, blocks and their parameters, backtest configurations and results, trade records, bots, notes, journals, and anything you post in community areas or send through in-app messages.

Broker connection data. If you connect a broker account we store the account identifiers the broker returns and the OAuth access and refresh tokens that let the Service act on that account. Those tokens are encrypted at rest. We never receive or store your broker password.

Payment data. Your subscription plan, its status and billing period, and the identifiers our payment provider assigns to you. Card numbers are entered on our payment provider's systems and never reach ours.

Wallet address. If you choose to link a crypto wallet for payouts, we store the public address.

Support and communication data. Messages you send us, and records of notifications and emails we send you.

Technical data. Basic request and error information generated when you use the Service, used to keep it working.

3. Why we use it, and on what basis

To provide the Service — running your account, executing backtests, operating bots you start, connecting to your broker, storing your content. Legal basis: performance of our contract with you. This is not consent-based: it is what you asked us to do, and it cannot be switched off while you have an account.

To take payment and manage subscriptions. Legal basis: performance of our contract, and compliance with our tax and accounting obligations.

To keep the Service secure — detecting abuse, rate limiting, investigating incidents. Legal basis: our legitimate interest in protecting the Service and its users.

To communicate with you about your account, security matters, and material changes to our terms. Legal basis: performance of our contract, and our legal obligations.

To improve the Service — understanding which features are used and where errors occur. Legal basis: our legitimate interest, and your consent where the tool involved requires it.

Marketing email, if we send it, only with your consent, and every such message carries a one-click unsubscribe.

We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.

4. Cookies

Cookies and similar technologies are covered separately in our Cookie Policy, including which categories exist, what each one does, and how to change your choice. Non-essential cookies are set only after you consent.

5. AI and automated processing

Parts of the Service use large language models ("LLMs") hosted by third parties. The in-app assistant (Nodi) and the strategy-analysis and metadata features are the current examples: they take an input from you, send it to an LLM provider, and show you the reply.

What leaves our servers. When you use one of these features we send the LLM provider the specific input the feature needs — the text of the message you type to the assistant, the configuration of the strategy you asked to be analysed, and a summary of its backtest metrics. We do not send your account credentials, your broker tokens, or content from other users.

Why. To produce the reply, summary or analysis you asked the feature to produce. Legal basis: performance of our contract with you — you triggered the feature and this is what carrying it out requires.

Which providers. These features may be routed to any of Anthropic, OpenAI, Google, xAI, OpenRouter or NVIDIA NIM, on API tiers whose published terms state that prompts and outputs are not used to train their models. Not every provider is active at every moment — the router picks one based on availability and the specific feature — and the list can change as we add or remove providers. The current live list is available on request, and material changes are covered by the amendment clause in section 12.

Provider-side retention. Providers may keep the request briefly for their own abuse detection under their own terms; we do not persist the provider-side copy, and the chat and analysis we do keep on our side is covered by section 8.

No automated decision with legal effect. These features surface suggestions and text for you to read. They do not place trades, change your account settings, or otherwise take a decision that produces a legal or similarly significant effect on you, and nothing in this section overrides the sentence in section 3 to that effect.

6. Who we share it with

We share personal data only with service providers who process it on our behalf, under contract, and only as needed to run the Service:

  • Payment processing — our payment provider handles checkout, subscriptions and card data.
  • Hosting and infrastructure — providers who host the application, the database and the website.
  • Network and security — a content delivery and protection provider that sits in front of the site.
  • Error monitoring and analytics — providers that help us find faults and understand usage.
  • Email delivery — the provider that sends transactional email.
  • AI and language-model inference — the providers described in section 5, used to produce the assistant's replies and the strategy-analysis output.
  • Your broker — where you have connected an account, so that instructions you configure can be carried out.

A current list of the specific subprocessors sitting behind each category, with their role and region, is available on request — we keep that list outside this document so it can change when we swap a vendor without asking you to re-accept the policy over an operational choice.

We may also disclose data where the law requires it, to establish or defend legal claims, or to protect the rights and safety of users or the public. If the business is reorganised, sold or merged, data may transfer as part of that, and this policy continues to apply until you are told otherwise.

7. International transfers

Some of these providers operate outside the European Economic Area. Where data is transferred outside the EEA we rely on an adequacy decision where one covers the destination, and otherwise on the European Commission's standard contractual clauses together with the additional safeguards the provider offers. You can ask us for details of the safeguards that apply to a specific transfer.

8. How long we keep it

We keep account data and the content you create for as long as your account exists. When you delete your account we delete or irreversibly anonymise your personal data, except where we must keep something longer:

  • Records needed for tax and accounting, kept for the statutory period.
  • Security and abuse records, kept for a limited period so a deleted-and-recreated account cannot be used to evade a block.
  • Anything we must retain to establish, exercise or defend a legal claim, kept until that need ends.
  • Copies inside routine backups, which expire on their own schedule.

Broker tokens are deleted when you disconnect the account or delete your own.

9. Your rights

You have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased; restrict how we process it; object to processing carried out on the basis of our legitimate interests; receive the data you gave us in a portable, machine-readable form; and withdraw consent at any time where processing is based on consent, without affecting what was done before you withdrew it.

European and UK law require this of us. We extend the same rights to everyone, wherever you live, because we run one system rather than a weaker one for readers outside Europe. Where your own country gives you more — and several do — you keep that as well.

To exercise any of these, write to the address at the end of this page. We answer within one month, and will tell you if we need longer because the request is complex. We do not charge for this unless a request is manifestly unfounded or excessive.

You also have the right to complain to a supervisory authority — the one where you live, where you work, or where you think the problem happened. If you are in the European Union or the EEA, the full list of authorities is at edpb.europa.eu; if you are outside it, your own country's privacy regulator is the one to approach. We are established in Portugal, so ours is the Comissão Nacional de Proteção de Dados (CNPD).

10. Security

We protect personal data with measures appropriate to the risk, including encryption in transit, encryption at rest for broker tokens, hashed passwords, hashed IP addresses, access controls on administrative functions, and rate limiting.

No system is completely secure, and we do not claim otherwise — see the beta section of our Terms. If a breach occurs that is likely to result in a risk to your rights and freedoms, we notify the supervisory authority within 72 hours of becoming aware of it, and we notify you directly where the law requires it.

11. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

Each version of this policy is published with a version number and an effective date, and every earlier version stays available at its own permanent link with a note describing what changed. Where a change materially affects how we use your data we will tell you by email or in the Service before it takes effect.

13. Contact

Data protection questions, and any request under section 9, go to the address shown at the end of this page.

Operator: Nodlow.ai

Contact: [email protected]