Last updated: 2026-05-11 · This document is legally binding when you use the Platform.
Privacy Policy — ExodusTradeAI
Last updated: May 2026
1. Data We Collect
Account Information
- Email address
- Encrypted password (hashed, never stored in plain text)
- Subscription tier
- IP address (for security audit)
- Browser/device information
Trading Data
- Exchange API keys (encrypted at rest, decrypted in-memory only when executing orders)
- Trade history, positions, orders
- Wallet balances (read-only)
Usage Data
- Pages viewed, features used
- Click events (for product improvement)
- Performance metrics
Derived Data
- AI training: aggregated/anonymized signal outcomes
- Edge analysis: aggregated symbol performance (no personal trade attribution in published stats)
2. How We Use Your Data
- Service delivery: Execute your trades, generate signals, manage your account.
- Security: Detect fraud, prevent unauthorized access, audit logs.
- Product improvement: AI model training (paper + live trade outcomes), feature development.
- Communication: Service updates, security alerts, account notifications.
- Compliance: Legal and regulatory obligations.
3. Data Sharing
We do not sell your personal data. We share data only:
- With service providers (hosting, email, analytics) under strict contracts.
- When required by law (court orders, regulatory requests).
- With your explicit consent.
4. Data Security
- Encryption at rest: AES-256 for sensitive data (API keys, passwords).
- Encryption in transit: TLS 1.3 for all connections.
- Access controls: Role-based access, audit logs.
- No withdrawal permission: Exchange API keys stored have read-only + trade permissions, NEVER withdrawal.
5. Data Retention
- Account data: as long as your account exists, plus 90 days after deletion.
- Trade history: retained for 7 years (regulatory).
- Audit logs: retained for 1 year.
6. Your Rights (GDPR, CCPA)
You have the right to:
- Access: Request a copy of your data (Settings → Export Data).
- Correct: Update inaccurate data.
- Delete: Request account deletion (Settings → Delete Account).
- Portability: Export your trade history in CSV format.
- Object: Opt out of marketing emails.
- Restrict processing: Request limited processing.
7. Cookies
We use essential cookies for authentication and preferences. We do NOT use third-party tracking cookies.
8. Third-Party Services
We use:
- Cloud hosting: [Provider TBD]
- Email: [SMTP Provider TBD]
- Payment: Stripe (for subscription billing)
- Exchange APIs: Binance, Gate.io, Coinbase, Kraken, Bybit (you authorize)
9. Children's Privacy
The Platform is not intended for users under 18. We do not knowingly collect data from minors.
10. International Transfers
Your data may be processed outside your country. We ensure adequate safeguards (SCC, equivalent protections).
11. Changes to This Policy
Material changes will be notified via email or in-app notice.
12. Contact
Privacy questions: privacy@exodustrade.ai
Data Protection Officer: [DPO contact TBD]