Privacy
Version 1, 13.08.2026. Short because we collect little.
What we store
| Data | Why | How long |
|---|---|---|
| Sign-in by magic link, receipts, service notices | While the account exists | |
| API key hashes | Authentication; the key itself is shown once and never stored | Until you revoke the key |
| Usage log (endpoint, bytes, timing) | Quotas, billing, capacity planning | Rolling, aggregated daily |
| Your strategies and run reports | So you can re-open and compare them | While the account exists |
| Support tickets | Answering you and keeping the history | While the account exists |
| Payment records (amount, tx reference) | Accounting and refunds | As required for accounting |
What we do not do
- No third-party analytics, no ad pixels, no external fonts or CDNs — every byte of these pages comes from our own domain.
- No selling or sharing of your data with third parties.
- No training on your strategy code, and no trading on it.
Cookies
One cookie: dp_s, your session. HttpOnly, Secure, SameSite=Lax,
30 days. No tracking cookies exist here, so there is no consent banner to
click away.
Processors
Email delivery and the payment gateway are external services and see only what is needed to do their job: your address for a letter, the amount and transaction reference for a payment. Our infrastructure runs on our own servers.
Your rights
Ask for an export or deletion of your data through a ticket. Deletion removes the account, its keys, strategies, runs and tickets; payment records are kept where accounting law requires it.
Security
Keys are stored as SHA-256 hashes. Client code runs in an isolated process without network access. Incidents that touch user data are published on status.