Privacy Policy
Last updated 6 August 2026
Signalvexa collects the minimum needed to run an account and produce analyses. There is no advertising, no analytics, no tracking pixels, and nothing is sold or shared for marketing.
1. What we collect
- Your email address. Used to create the account, verify ownership, and reset a password. Nothing else.
- A password hash. Passwords are hashed with scrypt and a per-account random salt. The plaintext is never written to disk and cannot be recovered.
- Verification codes. Stored only as an HMAC-SHA256 hash, valid for ten minutes, single-use, and deleted once used or expired.
- Your analyses. The prompts you send and the reports produced, so a session has history. These contain market data and your chosen asset and timeframe.
- Timestamps. Account creation and last-seen, used for session handling.
We do not collect your name, address, phone number, date of birth, payment details, IP-based location, device fingerprint, or any financial account information.
2. What we do not do
- No advertising, ad networks, or marketing profiles.
- No analytics or product-telemetry services.
- No third-party trackers, pixels, or session recording.
- No selling, renting, or sharing of personal data.
- No automated decisions with legal or similarly significant effects. Signalvexa produces market analysis; it does not evaluate you.
3. Where it is stored
Account and analysis data are stored in a PostgreSQL database belonging to this instance, in the region its operator chose. There is no replication to third-party analytics platforms and no sharing between deployments.
Whoever operates the instance controls that database and its backups, and is the data controller for it.
4. Who else sees data
Signalvexa calls a small number of external services. Only the last of these ever receives anything about you.
- Binance public market API — prices, candles and the tradeable coin list. Requests contain no user data.
- CoinGecko — coin names, market caps and total-market figures. Requests contain no user data.
- Public news RSS feeds (CoinDesk, Cointelegraph, Decrypt) — headlines only. Requests contain no user data.
- Anthropic — optional. If the operator supplies an API key, the finished analysis is sent to Claude to write the narrative. It contains market figures and the asset name, not your identity.
- An email provider — receives your email address in order to deliver verification codes. This is the only third party that receives personal data.
5. How long it is kept
Account records persist until the account is deleted. Verification codes are removed on use or expiry. Analysis history persists until deleted. Market data caches are held in memory for minutes to hours and are not personal data.
6. Your rights
Depending on where you live you may have the right to access, correct, export, delete, or restrict processing of your data, and to withdraw consent. Because this instance is self-hosted, exercise those rights with whoever operates it — they hold the database.
Consent recorded through the banner can be withdrawn at any time by clearing site data in your browser, which removes the stored record and makes the banner reappear.
7. Children
Signalvexa is not directed at anyone under 18 and should not be used by them.
8. Changes
Material changes bump the consent version, which retires every previous acceptance and shows the consent banner again so you can review the current terms.
This document has not been reviewed by a lawyer
It accurately describes what the Signalvexa software does today, and is written to be a useful starting point — but it is not legal advice and has not been checked against GDPR, UK GDPR, CCPA or any other regime. Have counsel review it before relying on it in production or collecting data from real users.