[DATE]The data controller is [LEGAL NAME], registry code [REG NO], [ADDRESS], Estonia. For any privacy question or request write to [EMAIL].
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Email address, password hash | To create an account and let you sign in | Art. 6(1)(b) — contract |
| Display name, rating (RP), colour | To show you in the rankings | Art. 6(1)(b) — contract |
| Training progress: virtual balance, trade journal, settings, knowledge-base progress | To keep your progress across devices | Art. 6(1)(b) — contract |
| Anonymised trade parameters (prices, times, direction) sent for the AI review | To generate the written review of your trade | Art. 6(1)(b) — contract |
| Subscription status and period | To give paid features to those who paid | Art. 6(1)(b) — contract |
| Technical logs: IP address, browser, time of request | Security, abuse prevention, fault diagnosis | Art. 6(1)(f) — legitimate interest |
We do not collect real-money account data, identity documents, location or biometrics. We do not profile you for advertising.
Payments are handled by [PAYMENT PROVIDER]. Card details never reach us — they go straight to the payment provider. We receive only the fact of payment, the plan, the period and an identifier that links the payment to your account. Invoices and tax documents are issued by the provider.
Some of these operate outside the EU. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or on an adequacy decision.
Settings, guest progress and knowledge-base progress live in your browser's localStorage. That is not a cookie and is sent nowhere unless you sign in. We use no advertising or analytics cookies. Clearing browser data removes this local copy; an account keeps the cloud copy.
Under the GDPR you may: get a copy of your data, correct it, delete it, restrict or object to processing, and receive it in a portable format. Write to [EMAIL] — we answer within 30 days. You may also complain to the Estonian Data Protection Inspectorate (aki.ee).
Fastest route for deletion: write from the address the account is registered to and ask for it to be deleted.
The Service is for people 18 and older. We do not knowingly collect data from children. If such data reaches us, we delete it.
Access is restricted at the database level (row-level security: an account sees only its own rows). Traffic is encrypted (HTTPS). Passwords are stored hashed by the authentication provider and are not visible to us.
This policy may be updated; the current version always lives on this page with its date. Material changes are announced inside the Service.