Privacy Policy

How we collect, use, and protect your personal data

Version 1.0Last updated: 15 April 2026Operator: Clavon Solutions sp. z o.o., Warsaw, Poland

1. Who we are

Clavon Solutions sp. z o.o. ("Clavon", "we", "us") is the data controller for personal data processed by QARI. Registered office: Warsaw, Poland. Contact: privacy@qari.trade.

2. What personal data we collect

We collect only what is necessary to operate the Service:

  • Account data: email address, hashed password (managed by Supabase Auth), display name (optional), account creation date.
  • Settings: your trading parameters (capital allocation, max positions, stop-loss percent, etc.) and feature preferences.
  • Exchange API key: encrypted at rest with AES-256-GCM. Decrypted in memory only at the moment of use. Never logged. Never returned to any client.
  • Trade history: open and closed positions, entry/exit prices, P&L, R-multiples, decision metadata.
  • Subscription & billing: tier, status, payment method, provider customer IDs (Stripe / Flutterwave). We do not store full card details - those live with the payment provider.
  • Operational logs: timestamps and IP addresses for security and debugging, retained for 30 days.

3. Why we process your data

We process personal data for the following purposes:

  • To provide the Service (account, trading, settings, history).
  • To process payments and manage subscriptions.
  • To enforce our Terms of Service and prevent abuse.
  • To send service-related communications (account verification, security alerts, billing).
  • To comply with legal obligations (tax, anti-money laundering).

4. Legal bases for processing (GDPR Art. 6)

  • Contract performance - providing the Service you signed up for.
  • Legal obligation - tax, AML, regulatory reporting.
  • Legitimate interest - security, fraud prevention, system improvement (anonymised analytics).
  • Consent - for the optional collective ML training data contribution and for non-essential cookies.

5. Collective ML training data

With your explicit opt-in, we use anonymised feature vectors and outcome labels (win/loss, R-multiple) to train a shared machine learning model. The training set excludes user identifiers, account balances, capital amounts, prices, exchange order IDs, and any data that could re-identify you. You can opt in or out at any time via Settings → Data & Privacy. Opting out does not affect the analysis you receive from the current model.

6. Cookies and local storage

We use the minimum browser storage required for the platform to function:

  • Essential (required, no consent needed): the Supabase authentication session token, stored in browser localStorage by the Supabase JS client. Without this, you cannot stay signed in. Cleared on sign-out.
  • Preferences: cookie consent choice. Stored in localStorage.
  • Optional analytics: if you accept analytics cookies, we may set Google Analytics cookies for aggregate usage statistics. None set if you decline. None set today as analytics is not currently enabled.

We do not use third-party advertising trackers. We do not sell or share data with advertisers.

7. Who we share data with

  • Supabase (Frankfurt, EU) - authentication and database hosting. Data Processing Agreement in place.
  • DigitalOcean (Frankfurt, EU) - application hosting.
  • Bybit - only your encrypted API key is used to interact with your exchange account. We never share your QARI account details with Bybit.
  • Stripe / Flutterwave - payment processing. They receive only what is needed for payment.
  • Telegram - only if you connect a chat ID for alerts.

We do not sell personal data. We disclose data to authorities only when legally compelled (court order, valid law-enforcement request).

8. International transfers

Personal data is primarily processed within the European Economic Area (Frankfurt). Where data is transferred outside the EEA (e.g. to Bybit or Stripe), we rely on Standard Contractual Clauses or equivalent safeguards.

9. Retention

  • Account data: for the duration of your account + 30 days after deletion.
  • Trade history: 7 years (tax / regulatory requirement).
  • Encrypted API key: until you disconnect the exchange or delete your account.
  • Operational logs: 30 days.
  • Anonymised collective ML data: indefinitely (cannot identify you).

10. Your rights (GDPR / NDPR)

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time (for processing based on consent).
  • Lodge a complaint with your national data-protection authority.

Send requests to privacy@qari.trade. We respond within 30 days.

11. Security

We implement industry-standard security measures: AES-256-GCM encryption for sensitive data at rest, TLS for data in transit, Row-Level Security on the database, principle of least privilege for staff access, audit logging of admin actions. No system is 100% secure; we cannot guarantee absolute security.

12. Children

QARI is not directed at persons under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@qari.trade and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced via email and in the dashboard.

14. Contact

Privacy questions and rights requests: privacy@qari.trade.