STOIC — Privacy Policy
Version: 2026-06-01 Last Updated: June 1, 2026
This Privacy Policy explains what data STOIC ("we", "us") collects when you use the STOIC trading platform (the "Service"), why we collect it, and the rights you have over it.
1. Data We Collect
- Account data — email address, display name, hashed password (bcrypt —
- Security data — login timestamps, IP-derived rate-limit counters,
- Trading data — the MT5 account numbers and broker server names you
- Billing data — your subscription plan, payment amounts and Stripe
- Support data — tickets and messages you submit through the in-app
we can never read your password), acceptance timestamps for the Terms of Use, and your subscription/entitlement state.
two-factor enrollment state (TOTP secrets are stored encrypted and never displayed again), security audit trail entries, and one-time sign-in codes (stored only as salted hashes, deleted on use or expiry).
register, balance/equity snapshots and open-position data reported by the STOIC Expert Advisor ("EA") you install, trade history your EA syncs, and the bot configurations you create.
Checkout session identifiers. We never see or store your card number — payment details are handled entirely by Stripe.
support system.
2. What We Never Collect
- Your MT5 investor or master passwords. The EA runs inside your own
- Your card or bank details (Stripe processes payments).
- Data from your device beyond what is needed to render the app.
terminal; STOIC authenticates it with a per-account bridge token.
3. How We Use Your Data
- To operate the Service: generate signals, route trades to your EA, enforce
- To secure your account: rate limiting, anomaly detection, two-factor and
- To bill you and to honor refunds/disputes via Stripe.
- To send transactional email (activation, password reset, sign-in codes,
- To improve the bot's decision quality using your own trade outcomes.
risk guardrails, and show you your own performance analytics.
email verification, session revocation.
renewal reminders, support replies). We do not send marketing email without a separate opt-in.
Model training is scoped per user — your trading data is not used to train models served to other users.
4. Legal Bases (GDPR)
Where the GDPR applies, we process data under: performance of a contract (operating your account), legitimate interest (security, fraud prevention), legal obligation (billing records), and consent (optional notifications).
5. Sharing
We share data only with processors required to run the Service: Stripe (payments), Resend (transactional email), our hosting provider (encrypted infrastructure), and — only if you connect them — Telegram (notifications you enable). We never sell personal data.
6. Retention
- Account and trading data: kept while your account is active.
- Billing ledger entries: retained as required for accounting.
- Sign-in codes: minutes (deleted on use/expiry). Sessions: revoked server-side
- On verified account-deletion requests we delete or irreversibly anonymize
on logout and rotate automatically.
personal data within 30 days, except records we must keep by law.
7. Your Rights
Depending on your jurisdiction you may request: access to your data, a portable copy, correction, deletion, restriction of processing, or objection to processing. Submit requests through the in-app Support page (category "Account") — we verify the request against your authenticated session.
8. Security
Passwords are bcrypt-hashed and screened against known breach corpora; sessions live in httpOnly cookies with CSRF protection and server-side revocation; live-sensitive actions require step-up MFA; EA artifacts are integrity-signed. No system is perfectly secure — report suspected issues via Support immediately.
9. International Transfers
Infrastructure may be located outside your country. Where required, we rely on appropriate safeguards (e.g. standard contractual clauses of our processors).
10. Children
The Service is not directed at anyone under 18. We do not knowingly collect data from minors.
11. Changes
We will update the version stamp above and notify you in-app of material changes. Continued use after the effective date constitutes acceptance.
12. Contact
Privacy requests: open a Support ticket (category "Account") or email the address on the Status page footer.