Privacy Policy
This Privacy Policy explains what data IOST Terminal ("we", "us"), operated by [Company Name], collects, why we collect it, and the choices you have. In short: we collect the minimum needed to run the Service, we never sell your data, and we store secrets in hashed or encrypted form.
1. What we collect
- Account data: email address, a hashed password (bcrypt — plaintext passwords are never stored or logged), and optional two-factor authentication (2FA) configuration.
- Trading data: paper-trading positions, journal entries, autopilot configuration and actions, and — if you enable live trading — your own exchange API keys, stored encrypted, plus records of orders routed through the Service.
- Session data: a session cookie (
iost.sid, httpOnly, SameSite=Lax, Secure when served over HTTPS) so you stay signed in. We do not use third-party advertising cookies or tracking cookies. - Technical logs: brief server-side audit entries (timestamp, method, path, API key label or "anon") used to detect abuse. No request bodies are logged.
2. How we use data
To operate and secure the Service: authenticating you, running your paper account, executing orders you authorize, generating AI analyses from market data, and preventing abuse. Market data and AI outputs shown in the Service are derived from public third-party feeds, not from your personal data.
3. What we do NOT do
- We do not sell, rent, or trade your personal data.
- We do not use your data for advertising or ad targeting.
- We do not share your exchange API keys with any third party. Orders are submitted directly from the Service to the venue you designate.
4. Data sharing
We share data only with service providers strictly necessary to run the Service (hosting), and only where required by law or to protect the rights and safety of the Service and its users. A list of processors and their purposes is available on request.
5. Security practices
- Passwords are hashed with bcrypt; exchange API secrets are encrypted at rest.
- 2FA (TOTP) is supported and recommended for your account.
- All traffic is served over HTTPS with HSTS; security headers (CSP, nosniff, X-Frame-Options, Referrer-Policy, Permissions-Policy) are set on every response.
- Sessions expire after 4 hours of inactivity.
- Access to production infrastructure is limited to authorized operators.
6. Retention and deletion
Account and trading data are kept while your account is active. You may request deletion of your account and associated data at any time via [privacy@example.com]; we will delete or anonymize the data within [30] days, except where law requires retention (e.g. audit records required for fraud prevention).
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise them, contact [privacy@example.com].
8. Changes to this policy
We will post any changes here with a revised effective date. Material changes will be announced in the Service.
9. Contact
Privacy questions: [privacy@example.com].