Skip to content
Candle Wars
Checking account

Privacy policy

Privacy Policy

Contents

Controller and purpose

The service provider identified below is the controller. We use account and security data to provide the beta, authenticate you, enforce the access clock, prevent fraud, answer support and document terms acceptance.

What we store

Email, salted password hash, sessions, the access ledger, proof records, support threads, terms acceptance and audit entries. Optional callsign and optional marketing consent. If product analytics is separately accepted and its release gate is enabled, analytics is account-bound and limited to fixed page and first-action buckets; it excludes firm, instrument, price, quantity, account and credential metadata. A beta bug report stores its written answers and, when the newer reporter is used, a bounded structured report, normalized annotation geometry, allow-listed diagnostics and a server-rendered Codex brief. The reporter allow-list is a separate support purpose and covers product and browser facts such as release identifiers, route without its query string, symbol, timeframe, session, connection class (local PAPER, prop-firm connection or none), data/readiness state and viewport.

Prop-firm credentials

For a firm-authorized connection, reusable credentials are stored only in the external firm-connection gateway, not in this application's database. This Worker does not establish authenticated encryption over those secrets. Reusable secrets and firm tokens are never returned to the browser; it receives only an opaque session reference. The selected firm account and purpose remain server-owned. Deleting the stored credential enqueues a gateway revoke that is retried until the gateway confirms sessions are revoked.

What automatic context never reads

The beta reporter does not read prop-firm passwords, API keys, session tokens, broker account IDs, order payloads, prices, quantities, P&L or browser storage. Unknown diagnostic fields are rejected at the server.

Screenshots and annotations you choose to send

A bug screenshot is never captured automatically. You deliberately open the reporter and may generate a masked support frame or choose an image, mark it locally and review it before sending. Redaction marks are flattened into the submitted pixels in your browser. Before private staff storage, the upload service verifies the actual image format and dimensions, decodes and canonically re-encodes it, strips metadata and requires a clean malware scan. Normalized annotation geometry is stored with a V2 report so staff can understand the marks without receiving additional terminal state.

Retention

Account data is kept for the account lifetime plus 30 days; signed-in sessions idle-expire after 24 hours. Ordinary users have a 14-day absolute limit, while staff, admin and owner sessions have a 24-hour absolute limit. Admin mutations require a fresh 15-minute password-authenticated mutation lease; an owner may renew that authority with a recent passkey step-up, and higher-risk owner actions always require that step-up. Ordinary security network/audit data is kept 90 days and material security audit up to 24 months. Raw error data and all consented analytics generations, including the legacy event and first-action tables, are kept 30 days; aggregates up to 13 months. Support closes plus 12 months, while support/security cases may remain 24 months. Proof and bug images are limited to 90 days after adjudication/closure. Accounting records are retained for the legally required period, currently planned as five years after financial-year end subject to counsel confirmation.

Your rights

You may request access, correction, deletion, restriction, portability or object to processing. You may withdraw optional analytics and advertising on the Privacy Preferences screen, and optional email consent on the Email Preferences screen or through the unsubscribe link in that message, without affecting earlier lawful processing. Account erasure removes both legacy and current account-bound analytics rows. You may complain to Datatilsynet, the Norwegian Data Protection Authority.

Processors and transfers

Hosting and storage use Cloudflare Workers, D1 and private R2. Transactional email is intended to use Migadu; Stripe is the planned payment service. Optional Sentry and PostHog remain disabled pending EU configuration, contracts and transfer review. Public Spot charting may open a direct browser connection to Binance, Coinbase or OKX for curated market data; those venues receive the request from your device and are not processors of your account. Any firm-connection processor, its location, DPA and applicable transfer safeguards govern international access through that connection.

Contact

Manage privacy and email choices on the Preferences screen. Open other privacy requests through the signed-in Support page. We may ask for enough information to verify that the account is yours before acting on an account-data request.

Manage privacy and email preferences · Cookies and storage