◈ IOSTTERMINAL / privacy

Privacy Policy

UPDATED: September 21, 2026

This Privacy Policy explains what the independently developed IOST Terminal project ("we", "us") collects, why we collect it, and the choices you have. We do not sell your data. Passwords are hashed and saved exchange credentials, if enrollment is separately enabled, are encrypted.

LAUNCH SCOPE — The public Service is paper-only by default. Live (real-money) trading stays off unless the account itself has passed a separate operator review and enablement, and any venue credentials used are your own and remain revocable by you at the venue. No token, conversion, staking, liquidity, or public-chain action is available.

1. What we collect

2. How we use data

To operate and secure the Service: authenticating you, running your paper account, generating simulated actions and AI analyses from market data, and preventing abuse. Market data and AI outputs shown in the Service are derived from public third-party feeds, not from your personal data.

3. What we do NOT do

4. Data sharing

We share data only with service providers strictly necessary to run the Service (hosting), and only where required by law or to protect the rights and safety of the Service and its users. A list of processors and their purposes is available on request.

If you explicitly verify a Kraken connection, Kraken receives authenticated API requests from our infrastructure and processes them under its own policies. Your IOST account password is not sent to Kraken. Public market lookup sends only market identifiers, not your entered order quantities or account credentials.

5. Security practices

6. Retention and deletion

If you select the optional held-funds check, we query extended Kraken balances and show only a positive, zero, negative or unavailable USD cash indication, excluding borrowed credit. Balance amounts are not returned or saved. This indication does not establish order affordability, fees or eligibility.

If you select the optional BTC/USD fee check, we query Kraken's account fee schedule. Only maker/taker percentages or an unavailable result are returned; trading volume and tier thresholds are not returned or retained. The draft cash + fees check also compares the draft total with reported cash after holds and used credit, returning an indication without a balance amount. Neither check establishes a final execution fee, full affordability or eligibility. IOST Terminal's platform fee is currently $0.

Account and paper-trading data are kept while your account is active. You may request deletion of your account and associated data at any time via iostcallister@hotmail.com; we will delete or anonymize the data within 30 days, except where law requires retention (for example, security records required for fraud prevention).

Unsaved credential candidates are encrypted in process memory and expire after two minutes. A timer removes the expired candidate when the event loop runs; expiry also prevents saving. JavaScript memory cannot be guaranteed to be immediately zeroized. No unsaved candidate is intentionally written to disk.

Disconnect removes the active saved exchange credential from IOST. It does not revoke the key at Kraken or cancel any exchange orders. Encrypted historical backups may retain a credential after disconnect; there is no automatic backup-erasure guarantee. Revoke retired keys at Kraken. A documented backup retention and deletion schedule, including off-host copies and recovery testing, must be finalized before customer credential onboarding is enabled. Contact us about a deletion request that includes backups.

7. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise them, contact iostcallister@hotmail.com.

8. Changes to this policy

We will post any changes here with a revised effective date. Material changes will be announced in the Service.

9. Contact

Privacy questions: iostcallister@hotmail.com.