Draft. This summary reflects current product data flows. Before a capital-facing public launch it must be reviewed by counsel (GDPR/CCPA/fintech). The engineering brief is docs/legal/privacy-policy.md in the repository.
DrawExec processes account data, chart drawing metadata, exchange API credentials (encrypted at rest with AES-256-GCM), TradingView session cookies you authorize, audit/hash-chain logs, and optional coach insights that may be generated via third-party LLM providers (e.g. DeepSeek / Anthropic) when you use Coach features.
What we collect
- Account email, display name, and consent / verification records
- TradingView session tokens or Terminal-drawn geometry you authorize
- Encrypted exchange API keys and bot execution logs
- MCP / API access keys you mint for Claude, Cursor, or custom clients
- Coach prompts/context when you request insights (may leave our servers to LLM vendors)
Security posture
Multi-tenant isolation is enforced in application queries (customer_id filters). Secrets are not stored in plaintext. Hash-chained execution logs support tamper-evident history (Patent B). We do not sell personal data.
Your controls
Revoke exchange access, pause trading via the kill switch, delete drawings, or request account deletion from Settings. Email [email protected] for access / export / deletion requests (hash-chain retention may limit hard erasure of some audit records — counsel to finalize).
Also see Terms of Service · System status