Privacy Policy

Last updated: August 28, 2026

1. Introduction

This Privacy Policy describes how SignalCopier Pro ("we", "us", or "our") collects, uses, protects, and deletes information when you use the trading automation service.

2. Data We Collect

  • Account information: Email address, hashed password, authentication status, billing identifiers, and optional Telegram identifiers.
  • Trading automation data: Connected account metadata, monitored source configuration, signal records, intended execution data, broker execution identifiers, reconciliation results, and performance metrics.
  • Credential and session data: Encrypted Telegram session strings, broker tokens, bridge credentials, service keys, and related metadata needed to operate the service.
  • Security and support data: Login attempts, 2FA events, audit logs, security events, support actions, device/IP metadata, error logs, and operational alerts.
  • Billing data: Subscription status, provider customer IDs, checkout events, invoices or transaction references provided by payment processors, and plan entitlement history.

3. How We Use Your Data

  • Monitor configured sources and execute, pause, reconcile, or alert on trades according to your settings
  • Provide trade history, discrepancy visibility, source health, and performance analytics
  • Maintain and improve our services
  • Send critical service notifications, including trade failures, source outages, security alerts, and billing status changes
  • Prevent abuse, enforce plan limits, investigate incidents, and protect other users
  • Comply with legal obligations

4. Optional External AI Processing

External AI processing is optional and disabled unless both the deployment and the account owner enable it. When enabled, we may send a minimized copy of an ambiguous trading message to one of the processors identified in your Data settings. Common contact identifiers are redacted before transfer, providers are restricted by deployment policy, and the result is checked against the original message before it can influence trading logic.

You can withdraw consent at any time from Dashboard Settings under Data. New messages then use local deterministic parsing only. Provider contracts, approved processing regions, retention limits, and incident-response controls remain public-launch gates.

5. Data Security

We use layered security controls that match the current product architecture:

  • Clerk-managed authentication and MFA, with hashed storage for application service-key secrets
  • Envelope-style encryption for reusable Telegram, broker, and bridge credentials on active write paths
  • 2FA support and step-up checks for sensitive account, privacy, and admin actions
  • Tenant-scoped data access controls, audit logs, security events, and admin approval workflows
  • Log and error-report scrubbing for sensitive payload fields before operational use
  • HTTPS/TLS should be enforced in production deployments

A managed KMS or equivalent no-operator-access secret boundary is still a production launch gate and should not be assumed until that deployment control is active.

6. Data Retention

  • Active account and configuration data is retained while your account remains active.
  • Raw Telegram message payloads are retained only for bounded operational windows where possible, then scrubbed or summarized.
  • Trading, billing, audit, and security records may be retained longer where needed for reconciliation, fraud prevention, tax, legal, or incident-response purposes.
  • Deleted-account personal data is scheduled for deletion or de-identified, subject to legal, security, billing, backup, and abuse-prevention exceptions.
  • Encrypted backups can retain deleted data until the backup expires under the documented backup-retention schedule.

7. Your Rights

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your data where applicable
  • Portability: Export your data in a machine-readable format
  • Objection: Object to certain processing of your data
  • Restriction: Request limited processing of your data

To exercise these rights, visit Dashboard Settings - Data or contact us at privacy@example.com.

8. Third-Party Services

We integrate with:

  • Telegram: Source monitoring and service notifications, subject to Telegram platform rules and privacy terms.
  • MetaTrader, brokers, and MetaApi: Trading account connectivity, execution, account state, and broker reconciliation.
  • Stripe and Paddle: Checkout, subscription status, invoices, refunds, disputes, and billing reconciliation.
  • Email, logging, and monitoring providers: Transactional email, error reporting, security monitoring, and incident response.
  • Configured AI processors: Optional processing of redacted ambiguous signal text only after explicit account consent and deployment approval.

9. Contact Us

For privacy-related inquiries, contact privacy@example.com.