We take your privacy seriously. This policy explains what data we collect, how we use it, and the controls you have over it.
Information We Collect
Account information: email address, display name, and encrypted password when you create an account.
Exchange API keys: encrypted read and trade-only API keys you provide to connect your exchange accounts. We reject keys with withdrawal permission enabled.
Signal channel data: Telegram channel links, channel names, and the signal messages we parse from them.
Trading data: order fills, balances, trade history, and portfolio state generated by signal execution.
Usage data: page views, feature interactions, and error logs to improve the platform.
Payment data: when you subscribe to a paid plan, payment card details are processed and stored by Stripe — we never see or store your full card number.
How We Use Your Information
To operate the AI TRED AGENT platform — process signals, execute trades, display your portfolio, and generate reports.
To communicate with you — account notifications, billing receipts, service updates, and support responses.
To improve our service — analyze usage patterns, fix bugs, and develop new features.
To prevent abuse — detect unauthorized access, fraudulent activity, and violations of our Terms of Service.
API Key Security
All exchange API keys are encrypted at rest using AES-256-GCM with a unique per-key initialization vector and derivation salt.
Keys are decrypted only in memory at the moment of trade execution and are never written to logs, error traces, or analytics.
We validate every key upon submission and reject any key that has withdrawal permission, futures trading, or margin trading enabled.
You can revoke, rotate, or delete your API keys from the exchange settings panel at any time. Revoked keys are purged from our database within 24 hours.
We recommend enabling IP allowlisting on your exchange API keys to restrict access to our server IPs.
Third-Party Services
Stripe: payment processing for subscriptions. Stripe's privacy policy governs how they handle your payment data.
Exchanges (Binance, Bybit, etc.): trade execution happens on the exchanges you connect. Each exchange independently processes your trades and may collect transaction data under their own privacy policies.
Cloud hosting: your data is stored on encrypted servers provided by our cloud infrastructure provider (AWS / Hetzner).
Analytics: we use privacy-respecting analytics to understand feature usage. No personally identifiable information is sent to analytics providers.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
Data Retention
Account data: retained for as long as your account is active. You may request account deletion at any time.
Trading data: trade history and portfolio snapshots are retained for the duration of your subscription plus 90 days.
Signal messages: raw signal messages are retained for 30 days for debugging purposes, then permanently deleted.
Backup data: encrypted backups are retained for 90 days and then securely purged.
After account deletion, personally identifiable information is erased within 30 days. Anonymized aggregate data may be retained for analytics.
Your Rights (GDPR)
If you are a resident of the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
Right to access: request a copy of the personal data we hold about you.
Right to rectification: request correction of inaccurate or incomplete data.
Right to erasure ('right to be forgotten'): request deletion of your personal data. We will comply within 30 days.
Right to data portability: request a machine-readable export of your data.
Right to object: object to processing of your personal data for certain purposes, including direct marketing.
To exercise any of these rights, email privacy@aitredagent.com from your registered email address.
Your Rights (CCPA / CPRA)
If you are a resident of California, USA, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:
Right to know: request disclosure of the categories and specific pieces of personal information we collect, use, and disclose.
Right to delete: request deletion of your personal information, subject to certain exceptions.
Right to opt-out of sale: we do not sell personal information. There is no sale to opt out of.
Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA rights.
To make a request, email privacy@aitredagent.com. We will verify your identity and respond within 45 days.
Cookies & Analytics
We use essential cookies required for authentication and session management. These cannot be disabled without affecting platform functionality.
We use a privacy-respecting analytics service to collect anonymized page view and feature usage data. No IP addresses are stored in long-term analytics.
We do not use third-party advertising cookies, cross-site tracking cookies, or fingerprinting techniques.
You can manage cookie preferences through your browser settings. Disabling essential cookies will prevent the platform from functioning correctly.
Security
All data transmitted between your browser and our servers is encrypted in transit using TLS 1.3.
All data at rest is encrypted using AES-256 standards.
Access to production systems is restricted to a small set of authorized personnel with multi-factor authentication.
We conduct regular security audits and penetration testing. Bug bounty reports are welcome at security@aitredagent.com.
We maintain SOC 2-type controls and perform annual third-party security assessments.
Contact
Data Protection Officer: privacy@aitredagent.com
Security: security@aitredagent.com
Support: support@aitredagent.com
Postal address: AI TRED AGENT, Attn: Privacy, 100 Crypto Street, Suite 200, San Francisco, CA 94105, USA
We will acknowledge your privacy request within 5 business days and respond substantively within 30 days.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and through an in-app notification at least 14 days before they take effect.
Your continued use of the platform after the effective date constitutes acceptance of the updated policy.