Legal document

Privacy Policy

Effective: September 2, 2026

Operator details to fill in: this document is a template — before going live, fill in the Data Controller's real company details in section 1, and have a lawyer confirm it fully covers your obligations under the GDPR and Hungary's Privacy Act (e.g. NAIH registration, whether a data protection officer is required).

1. The data controller

  • Company name: [To be filled in]
  • Registered address: [To be filled in]
  • E-mail: [To be filled in]
  • Registration number (if relevant, e.g. NAIH): [To be filled in]

2. Data processed

The Service processes the following data about the User:

  • The email address given at registration and (for password registration) a password stored encrypted.
  • When signing in with a Google account, the email address and profile name provided by Google.
  • The User's own content created within the Service: saved chart layouts, chart drawings, watchlist.
  • For a paid subscription, the subscription ID and billing status managed by Stripe — the Provider never sees or stores card details.
  • Basic technical log data (e.g. login timestamps) needed to operate the service securely.

3. Purpose and legal basis of processing

  • Creating an account and identifying the User — performance of a contract (GDPR Art. 6(1)(b)).
  • Billing the subscription fee — performance of a contract, and a legal obligation (invoicing).
  • Storing the User's own content (drawings, layouts, watchlist) — performance of a contract.
  • Operating the service securely and preventing abuse — legitimate interest (GDPR Art. 6(1)(f)).

4. Data retention period

The Provider processes account-linked data for as long as the account exists, until deleted by the User. Billing and payment data must be retained for the period required by accounting and tax law (typically 8 years), regardless of account deletion.

5. Data processors the data is shared with

The Service uses the following third parties, acting as independent controllers or as processors:

  • Supabase, Inc. — storage and authentication of user accounts, and operation of the database (saved layouts, drawings, watchlist).
  • Stripe, Inc. — subscription management and payment processing; card details are handled exclusively by Stripe.
  • Vercel Inc. — the Service's cloud hosting provider.
  • Binance — source of publicly available, anonymous market price data; the Service does not send any personal data about the User to Binance.

6. Cookies and local storage

The Service uses strictly necessary session cookies set by Supabase Auth to keep you signed in. The Service does not currently use any third-party marketing or tracking cookies.

7. User rights

Under the GDPR, the User may request:

  • access to their data,
  • correction of their data,
  • deletion of their data (by deleting the account, subject to the legal retention obligation noted in section 4),
  • restriction of, or objection to, processing,
  • data portability (receiving their own content — drawings, layouts — in a machine-readable format).

The User may seek redress from the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, naih.hu) or the competent court.

8. Data security

The Provider stores passwords encrypted, applies row-level access control (Row Level Security) to the database — so a User can only access their own data in the Supabase database — and all communication with the Service takes place over an encrypted (HTTPS) channel.

9. Contact

For questions about data processing, or to exercise the rights above, the User may contact the Provider at the contact details given in section 1.