Privacy policy
Last updated: 30 September 2026
In short: we keep what is needed to run your account and the tools you use, nothing for advertising, and we never sell data. You can download everything or delete your account yourself from Account & privacy.
1. Who is responsible
The data controller is , , operator of Trigger Terminal (the "Service"). Contact for anything about your data: .
2. What we keep, why, and on what legal basis
- Account: username, a salted password hash, your email if you add one, two-factor settings, plan, sign-up date and the invite you used. — To provide the Service you signed up for (GDPR art. 6(1)(b), contract).
- What you set up in the Service: exchange and broker connections with read-only API keys, bots, DCA settings, alerts, watchlists, Telegram/Discord connections, Pine scripts, saved charts and drawings, paper trades, journal notes, AI settings (including an AI key if you add one). — Contract.
- Logs of what the Service did for you: signals received, orders the bots sent, alert and notification history. — Contract, and our legitimate interest in being able to explain what happened (art. 6(1)(f)).
- Payments: if you subscribe, Stripe collects your card and billing details. We only keep the Stripe customer and subscription ids, the plan, the renewal date and the status. — Contract and our legal obligation to keep accounting records (art. 6(1)(c)).
- Security: your IP address is used in memory to slow down password guessing and abuse; it is not stored with your account. — Legitimate interest in keeping accounts safe.
- Phone / browser notifications: if you turn them on, the address your browser gives for push messages and a device name like "Chrome on Android". — Your request (contract).
We do not sell your data, use it for advertising or build profiles about you. We do not use automated decisions that have legal or similar effects on you.
3. Who else receives data
- Hosting: the Service runs .
- Stripe (payments, if you subscribe) — Stripe Payments Europe Ltd., Ireland, which may transfer data to Stripe, Inc. in the USA under the EU–US Data Privacy Framework and Standard Contractual Clauses.
- Our email provider, only to deliver the emails you ask for (email check, password reset, lost authenticator, payment messages).
- Push services of your browser (Google, Mozilla, Apple or Microsoft) carry the notification text to your device when you turn notifications on.
- Services you connect yourself — your exchanges and brokers, trigger.trade, Telegram, Discord, your webhook addresses and your AI provider (Anthropic or OpenAI with your own key). They get only what the feature needs and process it under their own privacy policies.
- Authorities, only when French or EU law obliges us to.
4. How long we keep it
- Account and everything in it: while your account exists. When you delete your account (or we close it), it is deleted from the live system straight away and from backups within 14 days, when they rotate.
- Invoices and payment records: 10 years, as French accounting law requires (Code de commerce, art. L123-22) — kept by Stripe.
- Email links (check, reset, recovery): until used, 30 minutes or 24 hours at most.
5. Your rights
You can at any time: see and download your data (Account & privacy → Download my data), correct it, delete your account (Account & privacy → Delete my account), object to processing based on legitimate interest, restrict processing, and take your data elsewhere (portability). For anything else, or if you can't sign in, write to ; we answer within one month. You can also give instructions about your data after your death (French law, art. 85 Loi Informatique et Libertés).
If you think we don't respect your rights you can complain to the CNIL (cnil.fr) or to the data-protection authority of your EU country.
6. Security
Passwords are stored only as salted scrypt hashes. Sign-in can be protected with an authenticator app. The website accepts read-only exchange keys only; keys that can trade stay in the Chrome extension on your own computer. Data files are readable only by the Service. Backups are made every night.
7. Cookies and browser storage
We set one cookie, tt_s, which keeps you signed in (strictly necessary, so no consent is needed). Your browser's local storage keeps display preferences like chart layout, favourites and whether you closed a notice; they stay on your device. No advertising, analytics or tracking cookies, and no third-party scripts that track you.
8. Changes
If we change this policy in a way that matters, we tell signed-in members in the Service before it applies.