DEDrawExec

Privacy Policy

Draft for legal review · Operator: DrawExec, LLC · Product: drawexec.com

Draft. This summary reflects current product data flows. Before a capital-facing public launch it must be reviewed by counsel (GDPR/CCPA/fintech). The engineering brief is docs/legal/privacy-policy.md in the repository.

DrawExec processes account data, chart drawing metadata, exchange API credentials (encrypted at rest with AES-256-GCM), TradingView session cookies you authorize, audit/hash-chain logs, and optional coach insights that may be generated via third-party LLM providers (e.g. DeepSeek / Anthropic) when you use Coach features.

What we collect

  • Account email, display name, and consent / verification records
  • TradingView session tokens or Terminal-drawn geometry you authorize
  • Encrypted exchange API keys and bot execution logs
  • MCP / API access keys you mint for Claude, Cursor, or custom clients
  • Coach prompts/context when you request insights (may leave our servers to LLM vendors)

Security posture

Multi-tenant isolation is enforced in application queries (customer_id filters). Secrets are not stored in plaintext. Hash-chained execution logs support tamper-evident history (Patent B). We do not sell personal data.

Your controls

Revoke exchange access, pause trading via the kill switch, delete drawings, or request account deletion from Settings. Email [email protected] for access / export / deletion requests (hash-chain retention may limit hard erasure of some audit records — counsel to finalize).

Also see Terms of Service · System status