copytrades.ailive demo

Legal

Privacy Policy

Effective [date] · Last updated [date]

The short version — the text below is what binds, not this

Sign-in is a passkey, not a password, and your biometric never leaves your device. We hold no private keys at all. The whole cookie jar is two strictly functional cookies, demo accounts delete themselves, and there are no ads, analytics trackers, or data sales.

01Who we are

This policy describes how [Entity] (“we”, the operator of CopyTrades) handles information when you use the terminal at copytrades.ai, the public demo, and their APIs (the “Service”). Privacy questions and requests: [privacy email].

02What we collect

Passkey credentials (WebAuthn). When you create an account we store a credential identifier, the public key, a signature counter, and — where your browser provides one — a device label such as “MacBook Touch ID”. We never receive your fingerprint, face, or device PIN; that verification happens on your device and only its result, a signature, reaches us.

Account profile. An optional display handle, your timezone, your risk preference, and the version of the Terms of Service you accepted.

Wallets you watch or copy. The public blockchain addresses you add, the copy rules you configure, and the simulated positions and ledger entries that result. The on-chain activity of the traders the terminal indexes is public data by design.

Cookies. Exactly two, both strictly necessary to operate the Service:

  • ct_session — keeps you signed in. HttpOnly, Secure in production, SameSite=Lax, expires within 24 hours.
  • ct_demo — identifies a demo session. Signed so it cannot be forged; expires with the demo.

There are no advertising cookies, no analytics cookies, and no cross-site trackers. If that ever changes, this page changes first.

Technical and usage data. Standard server logs (IP address, user agent, timestamps, requested paths). To enforce rate limits and abuse budgets we process IP addresses; the demo’s per-address budget stores a keyed hash of the address rather than the address itself. Error reports are wired through Sentry with payload scrubbing configured; on a deployment with no Sentry DSN set, error reporting is off entirely.

03What we do not collect

  • Private keys or seed phrases. The Service holds no user private keys of any kind in its current mode — there is nothing to type them into, and nowhere they would be stored.
  • Email addresses. Sign-up is passkey-only today; there is no email field. Email sign-in is specified for a later milestone — if it ships, this policy will say so before the field appears.
  • Biometric data. Passkey verification happens on your device; we only ever see public keys and signatures.
  • Precise location. We do not resolve or store your location today. A country field exists in the account record for future eligibility checks; if it is switched on, this section and the Terms will name it.
  • Payment card or bank data. The Service is free and simulated; there is nothing to pay with.

04Demo and ephemeral accounts

Opening the demo creates a temporary account with a paper vault and simulated activity. Demo accounts are marked ephemeral at creation, expire 24 hours later, and are deleted by an automated job that runs nightly. The demo cookie identifies that session and is useless without it.

05How we use information

  • To operate the Service: your session, your watchlist, your copy rules, your ledger.
  • To keep the simulation honest: computing and labelling simulated fills.
  • To secure the Service: rate limits, abuse budgets, audit logs.
  • To comply with law and enforce the Terms.

We do not sell personal information, do not share it for advertising, and do not profile you for anyone else.

06Third parties that process data for us

  • Railway — hosting, database, and cache (United States region). Server logs and the database live there.
  • Sentry — error reporting, with scrubbing configured; inactive on any deployment without a DSN.

Planned and not yet live: Helius (Solana data), Telegram (an optional notifications bot), and an email transport (if email sign-in ships). None receives data today.

Public blockchains are not a processor of ours: watched addresses and their activity are public by design. In the Service’s current mode nothing we do writes anything on-chain.

07Retention

  • Sessions: expire within 24 hours.
  • Demo accounts: deleted on expiry, nightly at the latest.
  • Account data: kept while the account is active; when you delete your account the profile is removed, with residual copies in backups and logs purged on their own cycle [retention windows].

08Your rights

You can access, correct, export, or delete your account information from the Service’s settings or by writing to [privacy email]. Deleting your account removes your profile, credentials, and configuration; it cannot alter public blockchain data, which no one controls. Depending on where you live, statute may give you additional rights (access, portability, erasure, objection, non-discrimination); we honour that standard set for everyone as a matter of policy. You may also lodge a complaint with your local data-protection authority.

09Security

Passkey-only authentication, scoped database roles with row-level security, signed short-lived session cookies, and no user key material on our systems at all. No method is perfect; if a breach ever affects your data we will notify you as the law requires.

10International processing

The Service is hosted in the United States. By using it you understand that your information is processed there, under the protections described in this policy.

11Children

The Service is not directed at anyone under 18, and we do not knowingly collect their information. If you believe a minor has created an account, write to [privacy email].

12Changes to this policy

If this policy changes, the new version is posted on this page with a new date, and for material changes we will make reasonable efforts to give notice in the product before the change takes effect.

13Contact

Privacy questions and requests: [privacy email]. Postal correspondence: [Entity], [registered address].