Privacy Policy
We respect every user's privacy and protect their data with appropriate technical and organisational measures.
1. Data we collect
- name and email address
- phone number (optional)
- IP address, device type and browser
- sign-in history and activity log
- subscription data and activation code
- technical and security logs
- open position data as read from the exchange you have connected
- a record of your acceptance of these terms and of this policy, with its date, version number and originating address
2. How the data is used
To create and manage your account, manage your subscription, secure the account and detect intrusion attempts, operate the guardian service itself, improve the platform, provide support, and comply with legal obligations where applicable.
Your data is not used for third-party marketing and is not sold.
3. Exchange API keys
This section describes what the system actually does:
- your keys are stored encrypted with AES-256-GCM before they are written, and are never held in readable form anywhere
- the encryption is bound to your account specifically, so one account's record cannot be decrypted with another's
- the master key is held outside the database, so a database backup alone cannot decrypt anything
- once saved, the key is never displayed again — not to you and not to an administrator
- keys are forcibly stripped from every log, so they cannot appear in an error or diagnostic trace
- encrypted storage is mandatory, because protection has to continue after the browser closes — without it, guarding would stop when the tab does
We ask for read and trade permissions only. Withdrawal permission is not required, and there is no code path in the system capable of withdrawing or transferring your funds. We strongly recommend leaving withdrawal disabled on the key and restricting it to the server's IP address.
You may disconnect your account at any time, at which point the stored keys are deleted.
4. Data protection
We use appropriate technical and organisational measures to protect data against unauthorised access, alteration, disclosure or destruction — including encryption in transit and at rest, password hashing, access restriction, and a tamper-evident audit log.
No method of electronic transmission or storage can be guaranteed 100% secure.
5. Cookies
The platform uses cookies that are necessary for session management, protecting forms against forgery, and remembering your language preference. It uses no advertising or tracking cookies.
6. Sharing
We do not sell personal data.
Data is shared only with the infrastructure providers required to run the service (hosting), with the exchange you have connected, to the extent needed to carry out your instructions, or where there is a legal obligation or an order from a competent judicial authority.
7. Retention
Account data is kept for as long as the account is active. After deletion, personal data is removed, while security, audit and consent records are retained for as long as legal obligations or the defence of a legal claim require.
8. Account deletion
You may request deletion of your account in accordance with the platform's policies, subject to any legal or regulatory obligation to retain certain records for a defined period.
9. Changes to this policy
Where this policy is changed materially, the new version is presented to you and your acceptance is required before you continue to use the service.
10. Consent
By using the platform, you acknowledge that you have read, understood and fully accepted this privacy policy.