Privacy Policy
Signallen · Updated 16 August 2026
FAQ · Terms · Legal & Risk
The operating entity, its registered address and the applicable supervisory authority are not yet stated here. They will be added once the company is incorporated and this policy has been reviewed by counsel. Until then, treat the contact address at the end of this page as the route for every privacy question or request.
Who we are
Signallen is a cryptocurrency market-analysis and trade-journaling application. This policy explains what data the application stores, who it is shared with, and how long it is kept.
Data we collect
- Account data — your email address and, if you sign in with Google or Facebook, the name and email provided by that provider. Authentication is handled by Supabase; we never see or store your password for social logins.
- Profile settings — display name, avatar, timezone, preferred timeframe, and notification preferences (email address, Telegram username).
- Trading journal data — trades you choose to follow, including entry, stop-loss, take-profit levels and their outcomes.
- Exchange API credentials and account data — keys are encrypted before storage. Read-only features use account access; live automation may require trading permission. Withdrawal permission is never required and should never be granted.
- Content you submit for AI analysis — chart screenshots you upload, the free-text descriptions you write, and, for coaching reports, your recent completed trades. See AI analysis below, because this data leaves our systems.
- Billing data — subscription payments are processed by Stripe; crypto payments by OxaPay. Card details never touch our servers.
- Security records — sign-in attempts, IP address, approximate country, and device description, kept so you can review access to your own account and so we can investigate a compromise.
- Connection failure reports — when your browser cannot reach our servers at all, it records what happened and sends it to us once a connection works again. The report contains the address it tried to reach, the page address it was sent from, the error your browser reported, which version of the app you were running, whether your device said it was online, your browser description and approximate country. It does not contain your email address, your password, anything you typed, or any of your account data — the failure is in the connection, and none of that describes one. It is sent without identifying you, and because these failures usually happen before you are signed in, we normally cannot tell whose browser sent one. So that repeated failures from one device can be told apart from failures across many, each report carries a one-way code derived from your IP address; the address itself is not stored and the code cannot be turned back into it.
AI analysis — what is sent to OpenAI
When you use the Signal Analyzer, the Chart Analyzer or the AI Coach, the content of that request is sent to OpenAI for processing and the response is returned to you. That includes chart images you upload, any text you write in the request, and, for coaching reports, a summary of your recent completed trades.
Your email address, exchange API keys and payment details are never sent. If you would rather no content of yours reached a third-party AI provider, do not use these features — every other part of Signallen works without them.
Who else processes your data
These are the third parties that receive personal data in order for the application to work. We do not sell personal data, and none of these are advertising networks.
| Recipient | What they receive | Why |
|---|---|---|
| Supabase | Account, profile, journal, security and (encrypted) credential records | Database and authentication |
| Render | Everything the application processes, in transit and in memory | Backend hosting |
| Cloudflare | Your IP address and request metadata | Serves the site and fronts the backend |
| OpenAI | Uploaded charts, request text, recent trade history | AI analysis and coaching (see above) |
| Stripe | Email address, payment details you enter with them | Card subscriptions |
| OxaPay | Payment reference and amount | Cryptocurrency payments |
| Telegram | Your Telegram username and the alert content | Alert delivery, only if you link Telegram |
| Our email provider | Your email address and the alert content | Email alerts and account mail |
| Binance (and any exchange you connect) | Requests made with your own API key | Reading your account and placing orders you enable |
| Google (YouTube) | Your IP address, when a training video is played | Academy video playback |
| TradingView | Your IP address, when a chart is displayed | The advanced chart embed |
| Google / Facebook | Sign-in identity, if you choose social login | Authentication |
Market data is also fetched from CoinGecko, alternative.me and the US Bureau of Labor Statistics. Those requests are made by our servers and are not linked to your identity.
Embedded content and cookies
We do not use advertising or analytics cookies, and we do not track you across other websites.
Two features embed content from other companies, and those companies can see your IP address when the content loads:
- YouTube, for Academy videos. We use the no-cookie player, which does not set a cookie until you press play.
- TradingView, for the advanced chart. This loads when you open a chart view and may set its own cookies.
If you would rather avoid these, do not open the Academy videos or the advanced chart.
Where data is stored
Application data is stored in Supabase (PostgreSQL), hosted in the Asia-Pacific (Sydney) region. The backend runs on Render. Some of the recipients listed above operate outside your country, so using Signallen involves international transfers of your data.
Automated trading data
If you connect an exchange, its API key and secret are encrypted before storage and are used only to read your account and, where you have enabled live trading, to place and cancel orders. They are never used to withdraw, and we ask you never to grant withdrawal permission. Orders we place, positions we open or close, and the risk decisions that allowed or refused them are recorded against your account so you can audit what was done in your name. Disconnecting the exchange deletes the stored credentials immediately; the order records remain in your journal until you delete them or the account.
How long we keep it
Records are removed automatically once they are no longer needed:
- Security and sign-in events — 180 days
- Automated-trading activity logs — 180 days
- Records of why a trade was withheld — 365 days
- Device and session records — 90 days
- Notification delivery receipts — 90 days
- Connection failure reports — 90 days
Your trades, the journal and billing records are kept for as long as your account exists, because they are the record of what you did and what you were charged. Deleting your account removes them.
Your rights
- Access and portability — you can download everything the application holds about you, as a single machine-readable file, from the account settings.
- Deletion — you can delete your account from the account settings; see the data deletion instructions. Deletion cancels any active subscription and removes your data after a short grace period during which you can change your mind.
- Correction — profile details can be edited in the application; anything else, use the contact address below.
- Withdrawing exchange access — you can remove your exchange connection at any time from the Account page, which deletes the stored credentials.
- Complaint — you may complain to your local data-protection authority. The lead supervisory authority for Signallen will be named here once the operating entity is incorporated.
What we do not do
- We do not sell or share your personal data with third parties for marketing.
- We do not custody or withdraw funds. Live automation can place supported orders only when expressly enabled by you.
- We do not use third-party advertising or cross-site tracking cookies.
Contact
For privacy questions or requests, contact bensont01081987@gmail.com.