FORECANDLEOPEN CONSOLE

Legal

Privacy Policy

Forecandle is a market data product, not an advertising product. We collect what running the service requires and close to nothing else: an email address, what you create in the app, and payment metadata that Stripe hands back to us. There are no advertising trackers, no tracking cookies and no third-party profiling on this site.

LAST UPDATED 24 July 2026

1. Who is responsible

Controller
The Forecandle team, operating the service from Cyprus. A small team rather than a company with a dedicated privacy department; the people who build the product answer these emails.
Data protection officer
Not appointed. Our processing does not meet the Art. 37(1) GDPR criteria: it is not carried out by a public authority, our core activities are not large-scale regular and systematic monitoring, and we do not process special-category data at scale. That changes if the scale of processing does.

2. What we collect

Account data. Your email address; a display name if you set one; a password hash (Argon2id) if you signed up with email rather than Google; your plan; whether the address is verified; and the account creation date. Signing in with Google gives us your verified email address from the Google ID token — nothing else, and we do not receive your Google password.

Billing data. Stripe handles the payment. We store your Stripe customer id, subscription status and renewal date. We never receive your full card number. Stripe holds the payment details and its own privacy terms apply to them.

What you create in the product. Manual positions, alert rules and their delivery history, in-app notifications, messages you send to the AI desk, browser push subscriptions, API keys (stored as a SHA-256 hash plus a short display prefix — the full key is shown once, at creation), per-day usage counters for quota enforcement, and preferences such as your watchlist, console layout and digest frequency.

Technical data. Your IP address is used transiently for rate limiting and abuse prevention (held in Redis for short windows, typically a minute) and appears in ordinary server logs. Requests to the public API are counted per key per day.

3. What we do not do

  • No advertising, no ad networks, no retargeting pixels, no social-media trackers.
  • No tracking cookies. The app keeps your session token and a couple of UI preferences in your browser's local storage, which never leaves your device except as the Authorization header on requests to our own API. Stripe's own checkout pages set cookies under Stripe's control.
  • We do not sell, rent or share personal data with anyone for their own marketing.
  • We do not build behavioural profiles of you, and there is no automated decision-making with legal effect: the signals engine reads markets, not people. It produces the same output for every account.
  • We never publish your positions, chat messages or watchlist.

4. Why we are allowed to (Art. 6 GDPR)

  • Performance of a contract, Art. 6(1)(b): running your account, delivering paid features, taking payment, sending transactional email such as verification, password reset and receipts.
  • Legitimate interests, Art. 6(1)(f): keeping the service up and un-abused (rate limiting, logs, quota counters), and privacy-preserving product analytics that let us see which surfaces are used at all.
  • Consent, Art. 6(1)(a): browser push notifications, which only exist after you grant the browser permission, and which you can withdraw at any time.
  • Legal obligation, Art. 6(1)(c): keeping invoices and accounting records for the statutory period.

5. Who else processes your data

We use a small number of processors, each for one job. Contracts under Art. 28 GDPR are in place or are being put in place.

Stripe
Payments and subscription management. Receives your email address and payment details directly.
Resend
Transactional email and the optional digest. Receives your email address and the message.
Google
Sign-in with Google (Identity Services). Only if you use that button.
OpenRouter / Anthropic
The language models behind the AI desk, triage, signal reasoning and briefings. See section 6.
ElevenLabs
Text-to-speech for the daily briefing. Receives briefing scripts we generate, not your data.
Hosting
The servers and database that run Forecandle. The provider and the data-centre region are not yet named on this page; ask by email and we will tell you.

6. AI features

When you use the AI desk or request an analysis, the text of your message and the market context needed to answer it are sent to our model provider (OpenRouter, which routes to the model host; Anthropic is the fallback). We send what the feature needs and no account identifiers beyond what is inside the conversation itself.

7. Email and notifications

Transactional email — address verification, password reset, billing events — is part of the service and cannot be switched off while you have an account. The daily or weekly digest is optional: it is set to daily by default, only ever goes to a verified address, carries an unsubscribe link in every message, and can be turned off in your preferences at any time. Browser push notifications require your explicit permission and stop the moment you revoke it or remove the subscription.

8. Analytics

We run a self-hosted Umami instance for aggregate usage statistics. It is cookieless, it does not fingerprint, and it collects no personal data: page paths, referrer, coarse country, device type, plus a short list of product events (for example: a pricing page was viewed, a checkout was started, a gate was hit, a referral link was clicked). Event properties are restricted by design to non-identifying values such as a symbol, a plan interval or a surface name — never an email address, never a token, never an order size. The whole thing is switched off entirely unless a website id is configured at build time. The event catalogue is public in docs/ANALYTICS.md.

9. How long we keep it

  • Account data: while your account exists, then deleted on request or when the account is closed.
  • Invoices and accounting records: for the statutory retention period under Cypriot tax and accounting law. We cannot delete these on request, because keeping them is a legal obligation rather than a choice.
  • Chat messages, positions, alerts and notifications: until you delete them or the account.
  • Rate-limit records: minutes. Server logs: short-lived operational retention.
  • Platform market data (news events, candles, metrics, odds, signals) is not personal data and follows its own retention rules — the modelled liquidation heatmap history is pruned after 48 hours, unscored raw events are pruned after roughly a day, and the signals ledger is permanent by design: entries are never deleted, including the losing ones.

10. Your rights

Under the GDPR you can ask us for access to your data (Art. 15), correction (Art. 16), deletion (Art. 17), restriction (Art. 18), portability (Art. 20), and you can object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you can withdraw it at any time without affecting what was lawful before. Write to the email address in section 1 — we answer within one month, usually far sooner, and we do not charge for it.

You also have the right to complain to a data protection supervisory authority. Under Art. 77 GDPR you may complain to the authority where you live, where you work, or where you believe the infringement happened — you do not need our permission or our involvement to do it.

Because we are established in Cyprus, our lead supervisory authority is the Office of the Commissioner for Personal Data Protection (Cyprus). You are not required to go through them: if an authority in your own country is easier for you to deal with, that is your right and it does not weaken your complaint.

11. International transfers

Some processors in section 5 are based in the United States or process data there. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply to a specific transfer.

12. Security

Traffic is encrypted in transit. Passwords are hashed with Argon2id; API keys are stored only as hashes. Sessions are signed 30-day tokens held in your browser's local storage — signing out clears the token from that browser, but it is not yet revoked server-side, so if you think a token or key has been exposed, revoke the key and tell us so we can rotate what needs rotating. Security reports are welcome and taken seriously: see Contact.

13. Children

Forecandle is not intended for anyone under 18, we do not knowingly collect data from children, and we delete any such account we become aware of.

14. Changes

If what we collect or who processes it changes, this page changes with it and the date at the top moves. Material changes affecting account holders are announced by email.