Privacy Policy
1. Who is responsible for your data
The Service is operated by Fēlikss Zariņš, trading as ElquoAI (Private individual (fiziska persona)), based in Krūzes iela 2, LV-1046, Riga, Latvia.
- Contact: admin@elquoai.com
If you have a question about your data, email admin@elquoai.com.
2. What we collect, why, and on what legal basis
| What | Why | Lawful basis |
|---|---|---|
| Email address, password (hashed), username | To create and secure your account | Performance of our contract with you |
| Sign-in records: IP address, approximate city and country, device | To detect unauthorised access and abuse | Our legitimate interest in keeping accounts secure |
| Your settings, strategies, scans, trades and backtests | To operate the Service you asked for | Performance of our contract |
| Exchange API keys, encrypted | To read your balance and place the orders you authorise | Performance of our contract |
| Support conversations with the in-app assistant | So you can read them back and so we can help you | Performance of our contract, and our legitimate interest in support |
| Payment records: Stripe customer id, card brand and last four digits | To take payment and meet tax obligations | Contract, and our legal obligation to keep accounting records |
| Information you give us before signing up (email, and any goals or capital range you enter) | To answer you and to understand who the product is for | Your consent |
We never see your card number. It goes from your browser to Stripe and never touches our servers.
3. Who else receives your data
We do not sell your data and we never will. These are the processors and services that necessarily receive some of it in order for the Service to work:
- AI providers — Anthropic, OpenAI, Google and DeepSeek, depending on which model is in use. Ordinary trading analysis sends market data and your own strategy settings, and carries no name, email or account identifier. The in-app assistant is the exception: your chat messages are sent verbatim, so please do not paste secrets into it.
- Stripe — payments and subscriptions.
- Telegram — if you link a chat, your alerts are delivered through it.
- Google — as our outbound email provider, for verification codes and reports.
- ipapi.co — receives your IP address when you sign in, to turn it into an approximate city for the security log.
- Your exchange — Binance, Bybit, OKX or Hyperliquid, whichever you connect. They receive the signed requests we make on your behalf.
- Fly.io — hosts the web application and therefore handles the traffic between you and it.
Some of these are outside the EEA. Where that is so, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
There is no analytics, advertising, or error-tracking software in this product. No Google Analytics, no Sentry, no advertising pixels, no session recording. Nothing profiles you across the web.
4. Automated decision-making
The Service uses models to grade trade setups. If you switch on automatic execution, that grading can result in orders being placed on your exchange account without a person reviewing each one — that is the feature you are buying. It has no legal effect on you and does not determine access to credit, employment or services. You can switch automation off at any time, use approval mode so that every trade requires your confirmation, or revoke your API keys at the exchange.
5. Support conversations
Messages you exchange with the assistant inside the cockpit are saved to your account, so that you can read your own history back and so that a person can see the context if you ask us for help.
- What is kept: the text of the conversation and the time each message was sent.
- Who can read it: you, and ElquoAI operations staff. It is never sold, shared with third parties, or used to train a model — though the message is sent to our AI provider to generate the reply, as with any chat feature.
- Your control: the History tab in the assistant panel shows your full transcript and can delete all of it permanently.
- Please do not paste secrets: the assistant never needs your API keys, your password or your recovery details, and will not ask for them.
6. How long we keep things
| What | How long |
|---|---|
| Your account and its settings | Until you delete it |
| Sign-in records | 12 months |
| Support conversations | 2 years, or until you delete them |
| Scans and trading history | 3 years |
| AI usage records | 90 days |
| Pre-signup enquiries | 12 months |
| Payment and invoice records | 5 years, because tax law requires it |
7. Deleting your account
You can close your account from Settings → Account & Privacy. It takes effect immediately: you are signed out everywhere, the bot stops, and any subscription is cancelled the same moment.
Your data is then permanently erased 30 days later. We email you a link that restores the account if you change your mind before that date. After it, the data is gone and cannot be recovered.
Two things deliberately survive, and only these:
- Payment and invoice records, for 5 years, because accounting law requires us to keep them.
- A record that the deletion happened — when it ran and what it covered. It does not contain your name or your email; it exists so we can prove we did what we said.
We also keep anonymous counts of trading outcomes — how many wins and losses occurred on a given market and direction. These carry no identifier of any kind and cannot be traced back to a person, which is why they are not personal data and are not erased.
8. Your rights
Under the GDPR you have the right to:
- See your data.Settings → Account & Privacy → Download my data gives you everything we hold, immediately and free.
- Correct it, from Settings, or by emailing us.
- Delete it, as described in section 7.
- Take it elsewhere — the export is machine-readable JSON.
- Object to, or ask us to restrict, processing we do on the basis of legitimate interest.
- Withdraw consent where consent is the basis, without affecting what was done before.
- Complain to a supervisory authority. In Latvia that is Datu valsts inspekcija. You can also complain to the authority where you live.
We answer requests within one month. If you exercise a right we do not need to be asked twice — deletion and export are self-service, so you never have to wait for us at all.
9. Security
Exchange API keys and other secrets are encrypted with AES-256-GCM before they are stored, and the master key is held separately from the database. They are decrypted only in memory, only for the moment a request needs them, and are never logged, exported or included in your data download. Passwords are stored using PBKDF2-HMAC- SHA256, which is designed to be slow to attack. Sessions are signed, and signing out ends them everywhere.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk we will tell the supervisory authority within 72 hours and tell you without undue delay.
10. Cookies
We use only what is needed to keep you signed in. There are no tracking, advertising or third-party cookies. See the Cookie Policy for the detail.
11. Children
The Service is not for anyone under 18 and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.
12. Changes to this policy
Every version carries a version number and an effective date, shown at the top of this page. If we make a change that materially affects you, we will tell you rather than quietly republishing.
