Privacy Policy

Last updated: July 17, 2026

1. Introduction

Tradingale (“we,” “our,” or “us”), operated by Asterio 37, a company registered in France with its registered office at 231 rue Saint-Honoré, 75001 Paris, operates the website tradingale.com and provides descriptive financial data, including the Martingale Score, the Startingale metric, and dimensionless model parameters, on cryptocurrencies and US-listed equities, delivered through our web application, REST API, and MCP server (the “Service”). Tradingale never places orders, holds funds, or gives advice. This Privacy Policy outlines our commitment to protecting your privacy and personal data in compliance with the General Data Protection Regulation (GDPR) and French data protection laws.

This Privacy Policy is available in English and French. The French version is the legally governing version; in the event of any discrepancy between the language versions, the French version prevails.

2. Information Collection

2.1 Personal Data

  • Email address and contact information
  • Full name and billing information
  • API tokens for REST API and MCP access (we store a cryptographic hash of each token only, never the token itself)
  • API and MCP usage metrics (call counters used to enforce plan quotas)
  • Journal snapshots you choose to save (ticker, the amounts you enter, and a timestamp)
  • IP address, device information, and browser type

2.2 Non-Personal Data

We may also collect non-identifiable data, such as aggregated usage statistics, which helps us improve our Service.

3. API Tokens and Legacy Exchange Credentials

API tokens: when you generate a token to access the Service through the REST API or the MCP server, we store only a cryptographic hash of that token, never the token itself. The full token is displayed once at creation and cannot be retrieved from our systems afterwards. If you lose a token, you can revoke it and generate a new one from your account settings.

Usage metrics: we record API and MCP call counters associated with your account. These metrics are used solely to enforce the quotas of your plan, to keep billing accurate, and to detect abuse of the Service.

Legacy exchange credentials: the Service no longer collects exchange API keys and no longer connects to any exchange account on behalf of users. Exchange API keys provided under earlier versions of the Service, where they still exist, remain stored encrypted, are no longer used by the Service, and are retained only until you delete them from your account settings, which you can do at any time.

Important: Tradingale never places orders, holds funds, or gives advice. We do not collect trading API keys from our customers, and we do not transmit orders to any exchange on behalf of third parties.

4. How We Use Your Information

We use your information for the following purposes, each with its legal basis under the GDPR:

  • To provide and maintain our Service: delivering data through the web application, REST API, and MCP server, managing your account and subscription, saving your journal snapshots, and enforcing plan quotas (legal basis: performance of the contract)
  • To communicate updates and respond to inquiries (legal basis: performance of the contract and our legitimate interest)
  • To secure the Service and to detect and prevent fraudulent, abusive, or malicious activity, including rate limiting and anti-abuse monitoring of API and MCP usage (legal basis: our legitimate interest)
  • To improve our Service using aggregated usage statistics (legal basis: our legitimate interest)
  • To comply with applicable legal obligations, such as accounting and tax requirements (legal basis: legal obligation)

5. Cookies and Tracking Technologies

We use cookies and similar technologies in two categories:

Strictly Necessary (Always Active)

Required for authentication, security, and core functionality. These cannot be disabled because the Service would not function without them.

  • Auth0 session cookies
  • CSRF tokens and other security tokens
  • Session management

Performance & Analytics (Optional)

Used to measure platform performance and aggregate usage. We rely on Vercel Analytics, which uses privacy-preserving, cookie-less measurement by default. It is loaded only after you consent.

  • Vercel Analytics (platform performance monitoring)

Marketing (Optional)

Used for personalized advertising and conversion tracking. Loaded only after you consent, and you can opt out at any time.

  • Retargeting pixels (Meta, Google, TikTok)
  • Conversion tracking
  • Ad optimization

You can manage your cookie preferences at any time through the cookie settings in the footer. Declining optional categories does not affect your access to the Service.

6. Data Sharing and Third Parties

We do not sell or rent your personal data. However, we may share your data with third parties in the following circumstances:

  • Service Providers: For hosting, analytics, and payment processing.
  • Legal Requirements: To comply with legal obligations or respond to lawful requests.
  • Business Transfers: In case of a merger, acquisition, or asset sale.

7. Data Security

We implement state-of-the-art security measures to protect your data:

  • End-to-end encryption for sensitive data
  • Multi-factor authentication
  • Regular security audits and monitoring
  • Secure API endpoints with rate limiting
  • Automated threat detection systems

Users are responsible for keeping their API tokens confidential. Because we store only a hash of each token, we cannot recover a lost token; you can revoke a token and generate a new one from your account settings at any time.

8. Your Rights

Under GDPR, you have the following rights:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Request data erasure
  • Restrict or object to data processing
  • Data portability to another service
  • Lodge a complaint with a supervisory authority

8b. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.

Categories of personal information we collect

  • Identifiers (email, IP address, account ID)
  • Commercial information (subscription tier, saved journal snapshots)
  • Internet or network activity (login events, Service usage, API and MCP call metrics)
  • Device and browser information
  • Inferences drawn from the above (e.g. aggregated usage statistics)

Your rights

  • Right to know what personal information we collect, use, and disclose
  • Right to delete your personal information (subject to narrow legal exceptions)
  • Right to correct inaccurate personal information
  • Right to limit the use of sensitive personal information
  • Right to opt out of sale or sharing of personal information for cross-context behavioral advertising
  • Right to non-discrimination for exercising any of the above

We do not sell your personal information for money. If you decline marketing cookies, we do not “share” your information for cross-context behavioral advertising within the meaning of the CPRA. You can change this choice at any time via Cookie Settings in the site footer, which also acts as our Global Privacy Control (GPC) signal handler.

To exercise any CCPA/CPRA right, email support@tradingale.com. We will verify your request against the email on your account and respond within 45 days. You may also designate an authorized agent to submit a request on your behalf.

9. Support Conversations Data Retention

When you interact with our AI support assistant (Martin), we collect your messages, our responses, and account context to provide support and improve our services.

Support conversations are automatically deleted according to the following schedule:

  • Resolved conversations: Deleted 30 days after resolution
  • Inactive conversations: Deleted after 90 days of no activity

10. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy at any time. Changes will be communicated via email or posted on this page. Please review it periodically.

11. Contact Information

For any privacy-related queries or concerns, contact our Data Protection Officer:

Email: support@tradingale.com

12. Data Processing Location

As a French company, all data processing occurs in compliance with GDPR requirements. Any data processing by our authentication (Auth0) and payment (Stripe) providers is governed by our data processing agreements with them and their respective privacy policies.