Skip to content
Legal

Privacy Policy

Last updated 5 September 2026

i
Plain-language template pending review by counsel. Complete the [bracketed] details and confirm your lawful basis and data-transfer position before relying on this.

1. What we collect

  • Account: email, password (hashed with PBKDF2-SHA256, never stored in plain text), account timestamps.
  • Subscription & billing: plan, status, payment-provider subscriber and subscription identifiers, billing dates. We do not store card numbers or PayPal passwords — those stay with the payment processor.
  • Configuration: the Telegram channel identifiers and labels, MT5 account labels, and risk settings you enter.
  • Hosted execution (opt-in only): your broker email and password, encrypted at rest with AES-GCM using a key held only as a server secret.
  • Operational: license-key check times and IP, last-known account balance reported by your own bot, execution events and timestamps, and audit logs of access-control changes.
  • Telegram linking (opt-in): your Telegram user ID, once you complete the linking flow.

2. Signal-source privacy

The identifier of an originating Telegram channel is stored only as an internal processing attribute, used for troubleshooting, duplicate detection, abuse prevention and dispute handling. It is not exposed through the customer-facing app, notifications, exports or API, and it is not shown to White Label operators through customer-facing surfaces.

3. Why we process it

To provide and secure the Services, execute your configuration, process payments, provide support, meet legal obligations, and prevent abuse. Where required, our lawful basis is performance of our contract with you and our legitimate interest in operating and securing the platform.

4. Sharing

We share data only with service providers that run the platform — hosting and edge infrastructure (Cloudflare), the payment processors (PayPal; a crypto processor), and email delivery — each processing on our instructions. We do not sell personal data. We may disclose data where legally required.

5. Retention

Account and configuration data is kept while your account exists and for a reasonable period afterward for legal and dispute purposes, then deleted or anonymised. Hosted-execution credentials are deleted when you disable hosted mode or close your account. Audit logs are retained for [period].

6. Security

Passwords are hashed; hosted credentials are encrypted at rest; secrets are never placed in client code or logs; payment webhooks are signature-verified and idempotent; access to sensitive endpoints is separately gated. No system is perfectly secure, and you are responsible for your own credentials.

7. Your rights

Subject to your jurisdiction, you may request access, correction, deletion, export, or restriction of your personal data, and may object to certain processing. Contact [email protected]. You may also complain to your local data-protection authority.

8. International transfers

Our infrastructure and processors may store or process data outside your country. Where required we rely on appropriate safeguards such as standard contractual clauses. [Confirm specifics.]

9. Cookies

The marketing site uses no advertising or analytics cookies. The dashboard uses local browser storage to keep you signed in and remember interface preferences; this never leaves your device except as an authentication token sent to our API.

10. Changes & contact

Material changes are notified by email or in-dashboard. Questions: [email protected].