Draft – pending legal review. This page describes how XcalpAI works so that a lawyer can finalise it. Items in [brackets] must be completed. Remove this notice only after legal sign-off.

Privacy Policy

Last updated: [DATE OF LEGAL SIGN-OFF]

1. Controller

[COMPANY LEGAL NAME], [REGISTERED ADDRESS], is responsible for your personal data. Contact: privacy@xcalpai.com [CONFIRM ADDRESS]. [DATA PROTECTION OFFICER / EU-UK REPRESENTATIVE IF REQUIRED].

2. What we collect and why

DataWhyLegal basis [CONFIRM]
Name, email, password (stored only as a salted hash), optional phone and Telegram chat idYour account, sign-in, notificationsContract
Broker login number, server and account labelConnecting and copying to your trading accountContract
Your broker passwordPassed once to MetaApi to connect your account; we do not store itContract
Trades, balance, equity, deposits and withdrawals of connected accountsYour dashboard, risk limits, performance-fee calculationContract
Subscription, invoices, payment status (card data is held by Paddle, not us)Billing and tax recordsContract / legal obligation
Two-factor secret, Telegram bot token (stored encrypted)Account security and alerts you configureContract
IP address, request logs, security audit logsSecurity, fraud and abuse prevention, rate limitingLegitimate interest
Partner/agency application detailsAssessing partnership requestsSteps before a contract

3. Who we share it with

We do not sell personal data. [LIST INTERNATIONAL TRANSFER SAFEGUARDS, e.g. standard contractual clauses.]

4. Cookies

We use one essential, HttpOnly session cookie to keep you signed in, and your browser's local storage for display preferences. We do not use advertising or tracking cookies. [UPDATE IF ANALYTICS ARE ADDED.]

5. How long we keep it

6. Your rights

You can download all of your data (Profile → "Download my data") and delete your account and personal data yourself (Profile → "Delete my account"). You may also ask us to correct, restrict or object to processing, and complain to your data-protection authority [NAME OF AUTHORITY].

7. Security

Passwords are hashed with Argon2, sessions use HttpOnly cookies, two-factor authentication is available, stored secrets are encrypted, and access to the admin console requires an authenticator code. No system is perfectly secure; we will notify you of a breach as the law requires.