Privacy Policy

What we collect, why, and your rights.

VERSION 2026-06-01 · DRAFT — HAVE LEGAL COUNSEL REVIEW

STOIC — Privacy Policy

Version: 2026-06-01 Last Updated: June 1, 2026

This Privacy Policy explains what data STOIC ("we", "us") collects when you use the STOIC trading platform (the "Service"), why we collect it, and the rights you have over it.


1. Data We Collect

  • Account data — email address, display name, hashed password (bcrypt —
  • we can never read your password), acceptance timestamps for the Terms of Use, and your subscription/entitlement state.

  • Security data — login timestamps, IP-derived rate-limit counters,
  • two-factor enrollment state (TOTP secrets are stored encrypted and never displayed again), security audit trail entries, and one-time sign-in codes (stored only as salted hashes, deleted on use or expiry).

  • Trading data — the MT5 account numbers and broker server names you
  • register, balance/equity snapshots and open-position data reported by the STOIC Expert Advisor ("EA") you install, trade history your EA syncs, and the bot configurations you create.

  • Billing data — your subscription plan, payment amounts and Stripe
  • Checkout session identifiers. We never see or store your card number — payment details are handled entirely by Stripe.

  • Support data — tickets and messages you submit through the in-app
  • support system.

2. What We Never Collect

  • Your MT5 investor or master passwords. The EA runs inside your own
  • terminal; STOIC authenticates it with a per-account bridge token.

  • Your card or bank details (Stripe processes payments).
  • Data from your device beyond what is needed to render the app.

3. How We Use Your Data

  • To operate the Service: generate signals, route trades to your EA, enforce
  • risk guardrails, and show you your own performance analytics.

  • To secure your account: rate limiting, anomaly detection, two-factor and
  • email verification, session revocation.

  • To bill you and to honor refunds/disputes via Stripe.
  • To send transactional email (activation, password reset, sign-in codes,
  • renewal reminders, support replies). We do not send marketing email without a separate opt-in.

  • To improve the bot's decision quality using your own trade outcomes.
  • Model training is scoped per user — your trading data is not used to train models served to other users.

4. Legal Bases (GDPR)

Where the GDPR applies, we process data under: performance of a contract (operating your account), legitimate interest (security, fraud prevention), legal obligation (billing records), and consent (optional notifications).

5. Sharing

We share data only with processors required to run the Service: Stripe (payments), Resend (transactional email), our hosting provider (encrypted infrastructure), and — only if you connect them — Telegram (notifications you enable). We never sell personal data.

6. Retention

  • Account and trading data: kept while your account is active.
  • Billing ledger entries: retained as required for accounting.
  • Sign-in codes: minutes (deleted on use/expiry). Sessions: revoked server-side
  • on logout and rotate automatically.

  • On verified account-deletion requests we delete or irreversibly anonymize
  • personal data within 30 days, except records we must keep by law.

7. Your Rights

Depending on your jurisdiction you may request: access to your data, a portable copy, correction, deletion, restriction of processing, or objection to processing. Submit requests through the in-app Support page (category "Account") — we verify the request against your authenticated session.

8. Security

Passwords are bcrypt-hashed and screened against known breach corpora; sessions live in httpOnly cookies with CSRF protection and server-side revocation; live-sensitive actions require step-up MFA; EA artifacts are integrity-signed. No system is perfectly secure — report suspected issues via Support immediately.

9. International Transfers

Infrastructure may be located outside your country. Where required, we rely on appropriate safeguards (e.g. standard contractual clauses of our processors).

10. Children

The Service is not directed at anyone under 18. We do not knowingly collect data from minors.

11. Changes

We will update the version stamp above and notify you in-app of material changes. Continued use after the effective date constitutes acceptance.

12. Contact

Privacy requests: open a Support ticket (category "Account") or email the address on the Status page footer.

© 2026 STOIC AI Technologies. All rights reserved.