Legal

Privacy Policy

Last updated: June 1, 2026

1. Information we collect

We collect information you provide directly (email, name on registration), usage data (API calls, backtest history, webhook signals) and technical information (IP address, browser type, access logs). We do NOT collect or store exchange login credentials (exchange API keys are encrypted to AES-256 standard).

2. How we use information

Information is used to: provide and improve Backpulse services; account authentication and security; send service-related notifications (no marketing spam without your consent); aggregated analytics to improve the user experience.

3. Information sharing

We do not sell your personal information. Information may be shared with: third-party service providers (Lemon Squeezy for billing, MongoDB Atlas for database) under appropriate data processing agreements; law enforcement when required by valid legal process.

4. Data security

We apply industry-standard security: HTTPS/TLS for all connections; AES-256 encryption for exchange API keys; HMAC-SHA256 authentication for webhooks; bcrypt for passwords. However, no system is completely secure.

5. Cookies and tracking

We use session cookies necessary for authentication. We do not use advertising tracking cookies. You can disable cookies in your browser but some features may not work.

6. Your rights

You have the right to: access your personal data; request correction or deletion; export your backtest data and signal history; cancel your account at any time. To exercise these rights, contact: info.backpulse@gmail.com.

7. Data retention

Account data is retained while the account is active. When you delete your account, personal data will be removed within 30 days. Anonymised aggregated data may be retained longer for service improvement purposes.

8. Contact

If you have questions about this privacy policy, contact: info.backpulse@gmail.com or via the Contact page. We respond within 72 hours.