Privacy Policy
This Privacy Policy explains what the independently developed IOST Terminal project ("we", "us") collects, why we collect it, and the choices you have. We do not sell your data. Passwords are hashed and saved exchange credentials, if enrollment is separately enabled, are encrypted.
1. What we collect
- Account data: email address, a hashed password (bcrypt — plaintext passwords are never stored or logged), and optional two-factor authentication (2FA) configuration.
- Trading data: paper-trading positions, journal entries, autopilot configuration, and simulated actions. While live trading is off, the Service does not place real-money orders. An account that is separately admitted for live trading stores its own venue credential, encrypted, and uses it only to place and cancel that account's own orders.
- Optional exchange connection: if enabled and you consent, your Kraken API key and secret are sent to our server for read-only verification. The server uses the API key and a secret-derived signature to contact Kraken; it does not send your secret as a request field. We inspect permissions and balance access. Raw provider responses and balance amounts are not stored or shown by this flow. A separate confirmation is required to save the encrypted credential.
- Session data: a session cookie (
iost.sid, httpOnly, SameSite=Lax, Secure when served over HTTPS) so you stay signed in. We do not use third-party advertising cookies or tracking cookies. - Technical logs: brief server-side audit entries (timestamp, method, path, API key label or "anon") used to detect abuse. No request bodies are logged.
2. How we use data
To operate and secure the Service: authenticating you, running your paper account, generating simulated actions and AI analyses from market data, and preventing abuse. Market data and AI outputs shown in the Service are derived from public third-party feeds, not from your personal data.
3. What we do NOT do
- We do not sell, rent, or trade your personal data.
- We do not use your data for advertising or ad targeting.
- We do not place real-money orders for any account that has not been admitted for live trading, and we never grant agents credential-management access.
4. Data sharing
We share data only with service providers strictly necessary to run the Service (hosting), and only where required by law or to protect the rights and safety of the Service and its users. A list of processors and their purposes is available on request.
If you explicitly verify a Kraken connection, Kraken receives authenticated API requests from our infrastructure and processes them under its own policies. Your IOST account password is not sent to Kraken. Public market lookup sends only market identifiers, not your entered order quantities or account credentials.
5. Security practices
- Passwords are hashed with bcrypt; plaintext passwords are never stored.
- 2FA (TOTP) is supported and recommended for your account.
- All traffic is served over HTTPS with HSTS; security headers (CSP, nosniff, X-Frame-Options, Referrer-Policy, Permissions-Policy) are set on every response.
- Sessions expire after 4 hours of inactivity.
- Access to production infrastructure is limited to authorized operators.
- Saved exchange credentials use account-bound application encryption. The running application can decrypt them for permitted verification; this is not end-to-end encryption or independent vault certification.
- Credential saving, disconnect and storage upgrades require fresh account authentication, including configured 2FA. This authentication does not authorize trading.
6. Retention and deletion
If you select the optional held-funds check, we query extended Kraken balances and show only a positive, zero, negative or unavailable USD cash indication, excluding borrowed credit. Balance amounts are not returned or saved. This indication does not establish order affordability, fees or eligibility.
If you select the optional BTC/USD fee check, we query Kraken's account fee schedule. Only maker/taker percentages or an unavailable result are returned; trading volume and tier thresholds are not returned or retained. The draft cash + fees check also compares the draft total with reported cash after holds and used credit, returning an indication without a balance amount. Neither check establishes a final execution fee, full affordability or eligibility. IOST Terminal's platform fee is currently $0.
Account and paper-trading data are kept while your account is active. You may request deletion of your account and associated data at any time via iostcallister@hotmail.com; we will delete or anonymize the data within 30 days, except where law requires retention (for example, security records required for fraud prevention).
Unsaved credential candidates are encrypted in process memory and expire after two minutes. A timer removes the expired candidate when the event loop runs; expiry also prevents saving. JavaScript memory cannot be guaranteed to be immediately zeroized. No unsaved candidate is intentionally written to disk.
Disconnect removes the active saved exchange credential from IOST. It does not revoke the key at Kraken or cancel any exchange orders. Encrypted historical backups may retain a credential after disconnect; there is no automatic backup-erasure guarantee. Revoke retired keys at Kraken. A documented backup retention and deletion schedule, including off-host copies and recovery testing, must be finalized before customer credential onboarding is enabled. Contact us about a deletion request that includes backups.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise them, contact iostcallister@hotmail.com.
8. Changes to this policy
We will post any changes here with a revised effective date. Material changes will be announced in the Service.
9. Contact
Privacy questions: iostcallister@hotmail.com.