Legal document
Privacy Policy
Effective: September 2, 2026
1. The data controller
- Company name: [To be filled in]
- Registered address: [To be filled in]
- E-mail: [To be filled in]
- Registration number (if relevant, e.g. NAIH): [To be filled in]
2. Data processed
The Service processes the following data about the User:
- The email address given at registration and (for password registration) a password stored encrypted.
- When signing in with a Google account, the email address and profile name provided by Google.
- The User's own content created within the Service: saved chart layouts, chart drawings, watchlist.
- For a paid subscription, the subscription ID and billing status managed by Stripe — the Provider never sees or stores card details.
- Basic technical log data (e.g. login timestamps) needed to operate the service securely.
3. Purpose and legal basis of processing
- Creating an account and identifying the User — performance of a contract (GDPR Art. 6(1)(b)).
- Billing the subscription fee — performance of a contract, and a legal obligation (invoicing).
- Storing the User's own content (drawings, layouts, watchlist) — performance of a contract.
- Operating the service securely and preventing abuse — legitimate interest (GDPR Art. 6(1)(f)).
4. Data retention period
The Provider processes account-linked data for as long as the account exists, until deleted by the User. Billing and payment data must be retained for the period required by accounting and tax law (typically 8 years), regardless of account deletion.
5. Data processors the data is shared with
The Service uses the following third parties, acting as independent controllers or as processors:
- Supabase, Inc. — storage and authentication of user accounts, and operation of the database (saved layouts, drawings, watchlist).
- Stripe, Inc. — subscription management and payment processing; card details are handled exclusively by Stripe.
- Vercel Inc. — the Service's cloud hosting provider.
- Binance — source of publicly available, anonymous market price data; the Service does not send any personal data about the User to Binance.
6. Cookies and local storage
The Service uses strictly necessary session cookies set by Supabase Auth to keep you signed in. The Service does not currently use any third-party marketing or tracking cookies.
7. User rights
Under the GDPR, the User may request:
- access to their data,
- correction of their data,
- deletion of their data (by deleting the account, subject to the legal retention obligation noted in section 4),
- restriction of, or objection to, processing,
- data portability (receiving their own content — drawings, layouts — in a machine-readable format).
The User may seek redress from the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, naih.hu) or the competent court.
8. Data security
The Provider stores passwords encrypted, applies row-level access control (Row Level Security) to the database — so a User can only access their own data in the Supabase database — and all communication with the Service takes place over an encrypted (HTTPS) channel.
9. Contact
For questions about data processing, or to exercise the rights above, the User may contact the Provider at the contact details given in section 1.