Privacy
Wallet addresses and verified email addresses are stored as account identities under an internal UUID. Session cookies authenticate your requests. Magic-link tokens and session tokens are stored as hashes, not raw tokens.
We store watchlists, alert preferences, state notifications and subscription-provider metadata. Private keys, wallet signature bodies, SIWE nonces, magic-link tokens and payment card details are not analytics payloads.
First-party usage analytics use a random anonymous session identifier before login and an internal user ID after login. Payloads are restricted to symbol, timeframe, universe and entrypoint. A random first-party visitor cookie links an eligible referral visit to signup for 30 days. Referral and snapshot links use one first-touch attribution chain. Keyed hashes of device identifiers and network addresses support abuse review; a shared IP alone does not disqualify users. Public snapshots expose market observations, not creator email, wallet, user ID, watchlist or private alerts.
Configured email delivery providers receive the destination email address and transactional email content. Payment providers, if enabled later, process payment details independently. This build does not enable payment collection.
Data retention: No automatic account/analytics purge schedule has been enabled in this build. A production retention period must be confirmed before commercial release.
Account deletion requests: a verified support contact must be published before commercial release; this draft does not invent a contact address.