TradingIA Privacy Policy

What data we store when you connect your exchange, what it is used for, how long it lasts, and what the key you give us can never do.

Read the nine sections Notices
The policy in three lines
We collect
Only what is needed to open the account and execute your orders: email, login credentials, and the exchange API key.
We do not collect
Private wallet keys or withdrawal permissions. TradingIA does not custody funds.
We do not sell
Your data is not shared with advertisers, data brokers, or other users.
document.meta
  1. // record for the document you are reading
  2. document: "privacy-policy"
  3. version: "2026-03"
  4. scope: "tradingia.ai + platform"
  5. controller: "TradingIA"
  6. sections: 9
  7. contact: "[email protected]"
  8. replaces: "previous versions"

This policy covers API connections with

Krakenspot and futures Binancespot and futures OKXspot and futures tradingia.aiaccount and dashboard

What this policy governs

291
Market signals
Technical, on-chain, macro, sentiment, and institutional flow
4 min
Decision cycle
Before each buy and each sell
9
Traded assets
BTC, ETH, SOL, AAVE, LINK, NEAR, ARB, BNB and AVAX
3
Connected exchanges
Kraken, Binance and OKX · futures only on BTC, ETH and SOL
  • Your accountEmail, login credentials, and the preferences with which you configure the platform.
  • The API keyIt is stored encrypted and requested without withdrawal permissions: it is used to read and trade, not to move funds.
  • The trading activity generated by the engineLimit orders, the stop registered on the exchange, and the defenses activated in your account.
  • Technical access dataIP address, browser, and session logs, required for account security.
  • What is excludedYour funds. They never leave the exchange, so there is no custody data to protect.
Notices
data_inventory
  1. account: ["email", "password_hash", "preferences"]
  2. connection: ["api_key", "encrypted_api_secret",
  3. "exchange"]
  4. trading: ["limit_orders", "stops", "assets",
  5. "risk_parameters"]
  6. technical: ["ip", "browser", "access_log"]
  7. support: ["messages", "history"]
  8. never: ["wallet_private_key",
  9. "withdrawal_permission", "custody"]
01

Introduction

TradingIA is the controller of the personal data it collects through tradingia.ai and the associated trading platform.

This document explains what information is collected when you open an account and connect your exchange, for what purpose it is used, how long it is retained, and what control you retain over it. It is written so you can verify it, not just accept it.

It applies to the website, the platform, and the API connection with Kraken, Binance and OKX. It does not cover those exchanges' own policies, which govern the account data you maintain with them and which you should review separately.

Last updated: March 2026. When the policy changes in a material way, notice is given in the platform and by email before the new version takes effect; the date always indicates which version you are reading. [email protected]

02

Information we collect

Five categories, no more. Each exists because without it the service cannot be provided.

Account data
Email address, password stored as a cryptographic hash, and the preferences with which you configure the platform.
Connection credentials
The API key and its secret from the exchange you choose. They are requested with read and trading permissions; never with withdrawal permission.
Trading data
Orders issued, assets, destination exchange, risk parameters, and the log of defenses activated in your account: Stop-Hunt Detector, Proactive Wick Buys, and Grid Auto-Reposition.
Technical data
IP address, browser type, language, and access and incident logs.
Communications
The messages you send to support and the history of that conversation.

No private wallet keys are collected, nor any permission that authorizes moving funds out of your exchange. The engine needs to know what to trade and within what limits; it does not need to know where your money is.

03

How we use your information

Execute trading operations
The engine evaluates 291 market signals —technical, on-chain, macro, sentiment, and institutional flow— in a decision cycle of 4 minutes. Your credentials are used to issue those orders, always limit, and to register the stop on the exchange.
Protect the position
The same data feeds the three defenses: the Stop-Hunt Detector, which compares BTC, ETH and SOL to detect coordinated manipulation in 60 seconds; Proactive Wick Buys, with limit buys prepared at −1.5 %, −2.5 %, and −3.5 %; and Grid Auto-Reposition, which recenters the range when it deviates by more than 5 %.
Maintain your account
Give you access, handle support, and send you service notices about the connection or platform status.
Security and abuse prevention
Detect unauthorized access, limit automated attempts, and keep traces that allow an incident to be reconstructed.
Legal obligations
Meet accounting and tax duties, and respond to requests from competent authorities.

Your data is not used to create advertising profiles and is not sold. Your trading activity is processed to execute it and so you can review it; never as the basis for a profitability promise, which TradingIA does not make.

04

Data security

Encryption and access control are the predictable part. The part you can verify yourself is this: the key you give us cannot withdraw money.

In transit and at rest
All traffic is encrypted with TLS. API secrets are stored encrypted and separated from the rest of the account data.
Restricted access
Only the execution system decrypts them, at the moment an order is issued. No team member sees them in plaintext.
Traceability
Each access to the systems is logged, with periodic review of those logs.
Sessions
Automatic logout due to inactivity and notification when access from a new device is detected.
connection_permissions
  1. {
  2. "exchange": "kraken | binance | okx",
  3. "read": true, // balances and positions
  4. "trade": true, // limit orders and stops
  5. "withdraw": false // cannot move funds
  6. }

Verify it outside this pageIn Kraken, Binance or OKX, the key management screen shows the permissions granted to each one. The withdrawal permission must appear disabled. If you ever see it enabled, revoke that key and generate another one: TradingIA does not need it to operate.

05

Data sharing and third parties

Your exchange
Kraken, Binance or OKX receives the orders that the engine issues on your behalf and the conditions of each one. This is the only transmission essential to the service.
Infrastructure providers
Hosting, transactional email, and technical monitoring. They act as processors, under contract and only to provide the service.
Legal obligations
Competent authorities, when there is a valid request that requires it.

Data is not sold, not transferred to advertisers or data brokers, and your trading activity is not shared with other platform users.

What your exchange sees

  • api_key
  • limit_order
  • registered_stop
  • pair and volume

What TradingIA sees

  • balances and positions
  • orders_issued
  • risk_parameters
  • no withdrawal access
06

Cookies and tracking

Necessary cookies
They keep your session signed in, protect the login form, and remember the language. Without them, it is not possible to access the platform.
Usage measurement
Aggregated statistics on which screens are used and where navigation fails. They are processed without identifying the person behind each visit.
What is not used
There are no advertising cookies, no third-party pixels for profiling, and no resale of browsing behavior.

You can block or delete cookies from your browser settings. If you block the necessary ones, the session will no longer remain open and you will need to sign in on each visit; the connection with your exchange is not affected.

07

Data retention

Each data item has a written retention period. When it expires, it is deleted or anonymized.

Account data
As long as the account remains active.
API credentials
They are removed from the systems as soon as you disconnect the exchange or close the account. This is the shortest-lived data of all.
Order log
Five years, so you have your history available and due to applicable accounting and tax obligations.
Technical logs
Twelve months, a period that allows a security incident to be investigated without accumulating more than necessary.
Support
Twenty-four months from the last response.

After an account is closed, a thirty-day buffer is maintained in case you want to recover it. After that period, the data is deleted or anonymized, except for data that a legal obligation requires retaining.

08

Your rights

Access
Obtain a copy of the data that TradingIA processes about you, including your trading history.
Rectification
Correct any inaccurate or incomplete data in your account.
Erasure
Request deletion of your data when it is no longer necessary, with the legal exceptions in section 07.
Restriction and objection
Request that specific processing be suspended or object to it for reasons related to your situation.
Portability
Receive your data in a structured, commonly used format so you can take it to another service.
Withdraw consent
Revoke it at any time, without affecting the lawfulness of prior processing.

There is one right you can exercise without asking anyone for permission: revoke the API key from your exchange. As soon as you do, the platform immediately stops being able to operate in your account.

09

International transfers

The exchanges the platform connects to and some infrastructure providers operate outside the European Economic Area.

With what guarantee
Standard contractual clauses approved by the European Commission, or an adequacy decision when one exists for the destination country.
With what technical protection
Encryption in transit and at rest, and minimization: only the data that the specific operation needs is transferred.
What crosses the border
The order that reaches your exchange travels identified by the API key, not by your name. The exchange already knows you; it does not need TradingIA to tell it.

You can request information about the safeguards applied to a specific transfer by writing to [email protected].

Exercise your rights

A single address, a written deadline, and a complaint channel that does not depend on us.

Channel

[email protected], writing from the email address with which you opened the account.

Deadline

Response within a maximum of thirty calendar days from verification of your identity.

What to indicate

The right you are exercising and, if it affects your trading activity, the connected exchange and the period.

Supervisory authority

If the response does not satisfy you, you can file a complaint with your country's data protection authority.

Read it before connecting your API. Verify it afterward.

Notices