Privacy policy
We collect as little as the Service needs to work, and we do not sell or share it for advertising.
What we store
- Account. Your email address, a salted password hash (never the password), creation and last-login times, your referral code and who referred you.
- Sessions. A hashed session token, the IP address and browser string of each login, so you can see and revoke sessions.
- Billing. Invoices with plan, period, amounts in USD and the BTCPay invoice identifier. We never see a card number because there is none. Bitcoin transactions are public by nature; we do not link your wallet to anything beyond the invoice.
- Usage. Your watchlist, positions, alert preferences, settings and the signals you marked as taken. Market data itself is shared and not personal.
- Exchange keys. Encrypted with a key derived from a password only you know. We cannot read them. They are used solely to talk to your exchange.
- Logs. Server logs with IP addresses, kept for up to 30 days for security and debugging.
What we do not do
- No third-party analytics, advertising pixels or tracking scripts on this site or in the app.
- No selling, renting or sharing of personal data.
- No email beyond transactional messages (password resets, invoice status, important service notices).
Cookies
Two first-party cookies: cs_session (login, 30 days) and cs_ref (which referral link brought you here, 30 days). Nothing else.
Third parties
Market data is fetched by our server from public exchange endpoints; your browser does not talk to them. Payments go through our own BTCPay Server instance. Telegram alerts, if you enable them, use your own bot token and go to Telegram's servers.
Your rights
You can export or delete your account by writing to support@patternxradar.com. Deletion removes your account and usage data; invoice records are kept as long as accounting law requires. If you are in the EU/EEA or UK you also have the rights of access, rectification, portability and complaint to your supervisory authority.
Security
Passwords are hashed with scrypt, sessions are HttpOnly cookies, forms are CSRF-protected, and login attempts are throttled. Report any issue to the support address above.