Privacy

Our privacy principles.

Short version: we handle as little of your data as possible, your API keys never leave your machine, and we don't share anything with third parties.

1. What we collect

To run the service we collect: your email address, an encrypted password hash, and minimal product telemetry (page views, errors). If you enable Telegram or email alerts you provide those identifiers directly. Nothing else is collected by default.

2. What we do NOT collect

We do not store your exchange API keys on our servers. The desktop app encrypts them client-side with AES-256-GCM and keeps them on your disk. The web app encrypts per-user in the browser and only the ciphertext ever reaches our database — we can't decrypt it without your user-specific key.

3. Trading data

Your trade history is stored so you can review it across devices. It is never sold, never shared, and never used to train any model. You can export all of it as CSV or delete it from the settings page at any time.

4. Third-party subprocessors

We use AWS for hosting and infrastructure, and (optionally, if you enable it) Telegram and your own SMTP provider for alerts. That's it. No ad networks, no analytics SaaS trackers, no data brokers.

5. Your rights

You can request a full export or deletion of your account by emailing us. We will respond within 30 days. Account deletion purges every row associated with your user ID.

6. Contact

Privacy questions: privacy@cryptoroute.io. This policy was last updated on April 18, 2026.

Placeholder document — a formal legal review is in progress. The principles above reflect how the product is actually built today.