Controller and purpose
The service provider identified below is the controller. We use account and security data to provide the beta, authenticate you, enforce the access clock, prevent fraud, answer support and document terms acceptance.
Privacy policy
The service provider identified below is the controller. We use account and security data to provide the beta, authenticate you, enforce the access clock, prevent fraud, answer support and document terms acceptance.
Account, session, terminal and transactional-email processing is necessary to provide the service you request. Security, fraud prevention and minimal operational logs rely on our legitimate interests in operating a safe beta. The optional day-3 partner and connection email is sent only with your separate consent, which you may withdraw at any time without losing account access.
Email, salted password hash, sessions, the access ledger, proof records, support threads, terms acceptance and audit entries. Optional callsign and optional marketing consent. If product analytics is separately accepted and its release gate is enabled, analytics is account-bound and limited to fixed page and first-action buckets; it excludes firm, instrument, price, quantity, account and credential metadata. A beta bug report stores its written answers and, when the newer reporter is used, a bounded structured report, normalized annotation geometry, allow-listed diagnostics and a server-rendered Codex brief. The reporter allow-list is a separate support purpose and covers product and browser facts such as release identifiers, route without its query string, symbol, timeframe, session, connection class (local PAPER, prop-firm connection or none), data/readiness state and viewport.
For a firm-authorized connection, reusable credentials are stored only in the external firm-connection gateway, not in this application's database. This Worker does not establish authenticated encryption over those secrets. Reusable secrets and firm tokens are never returned to the browser; it receives only an opaque session reference. The selected firm account and purpose remain server-owned. Deleting the stored credential enqueues a gateway revoke that is retried until the gateway confirms sessions are revoked.
The beta reporter does not read prop-firm passwords, API keys, session tokens, broker account IDs, order payloads, prices, quantities, P&L or browser storage. Unknown diagnostic fields are rejected at the server.
A bug screenshot is never captured automatically. You deliberately open the reporter and may generate a masked support frame or choose an image, mark it locally and review it before sending. Redaction marks are flattened into the submitted pixels in your browser. Before private staff storage, the upload service verifies the actual image format and dimensions, decodes and canonically re-encodes it, strips metadata and requires a clean malware scan. Normalized annotation geometry is stored with a V2 report so staff can understand the marks without receiving additional terminal state.
The host-only HttpOnly session cookie is necessary. Optional product analytics, advertising, email marketing and publicity are independent choices. Product analytics and advertising remain technically disabled during the security review even if accepted. Reject all is as prominent as Accept all, a persistent Privacy choices control lets you reopen or withdraw, signed-in grants wait for server confirmation, and Global Privacy Control forces analytics and advertising denial. The exact storage list is in /legal/cookies.
Account data is kept for the account lifetime plus 30 days; signed-in sessions idle-expire after 24 hours. Ordinary users have a 14-day absolute limit, while staff, admin and owner sessions have a 24-hour absolute limit. Admin mutations require a fresh 15-minute password-authenticated mutation lease; an owner may renew that authority with a recent passkey step-up, and higher-risk owner actions always require that step-up. Ordinary security network/audit data is kept 90 days and material security audit up to 24 months. Raw error data and all consented analytics generations, including the legacy event and first-action tables, are kept 30 days; aggregates up to 13 months. Support closes plus 12 months, while support/security cases may remain 24 months. Proof and bug images are limited to 90 days after adjudication/closure. Accounting records are retained for the legally required period, currently planned as five years after financial-year end subject to counsel confirmation.
You may request access, correction, deletion, restriction, portability or object to processing. You may withdraw optional analytics and advertising on the Privacy Preferences screen, and optional email consent on the Email Preferences screen or through the unsubscribe link in that message, without affecting earlier lawful processing. Account erasure removes both legacy and current account-bound analytics rows. You may complain to Datatilsynet, the Norwegian Data Protection Authority.
Hosting and storage use Cloudflare Workers, D1 and private R2. Transactional email is intended to use Migadu; Stripe is the planned payment service. Optional Sentry and PostHog remain disabled pending EU configuration, contracts and transfer review. Public Spot charting may open a direct browser connection to Binance, Coinbase or OKX for curated market data; those venues receive the request from your device and are not processors of your account. Any firm-connection processor, its location, DPA and applicable transfer safeguards govern international access through that connection.
Manage privacy and email choices on the Preferences screen. Open other privacy requests through the signed-in Support page. We may ask for enough information to verify that the account is yours before acting on an account-data request.