Privacy Policy

Last Updated: May 7, 2026

Effective Date: May 7, 2026

This Privacy Policy is published in English, which is the authoritative version. Site navigation and menus are available in all supported languages.

1

Introduction

This Privacy Policy explains how Algonney collects, uses, discloses, stores, and protects personal information when you use the Platform. It also explains your privacy choices and rights.

Where required by law, we ask for your consent separately, such as for non-essential cookies, marketing communications, or other optional processing. Otherwise, we process personal information based on the legal bases described in this Policy.

This Policy applies to the Algonney platform, website, mobile applications, APIs, WebSocket services, and related services (collectively, the “Platform”).

2

Who We Are / Data Controller

The data controller responsible for your personal information is:

Algonney Technologies

Registered address: Beirut, Lebanon

Country: Lebanon

Privacy contact: privacy@algonney.com

Support contact: support@algonney.com

Legal notices: legal@algonney.com

If you are in the European Economic Area or the United Kingdom and have questions about your rights under GDPR or UK GDPR, you may contact us at privacy@algonney.com.

3

Scope of This Policy

This Policy covers all personal information processed by Algonney in connection with the Platform, including account data, trading data, wallet and payment data, exchange data, support communications, device and session data, cookies, and analytics.

The Platform may contain links to third-party services (such as exchanges, payment providers, or analytics tools). This Policy does not apply to those third parties. We encourage you to review their privacy policies.

4

Information We Collect

We collect information that you provide directly, information generated when you use the Platform, and information from third-party services you connect to your account.

4.1 Account Data

When you create an account, we collect:

  • Email address
  • Username and display name
  • Hashed password
  • Two-factor authentication settings and authenticator status
  • Account preferences and language settings
  • Account creation date and status

4.2 Authentication, Session, and Device Data

When you log in or use the Platform, we may collect:

  • Login timestamps, methods, and outcomes
  • Session tokens and refresh tokens
  • Device identifiers and device fingerprint
  • IP address and approximate geolocation (country, region, city)
  • Browser type, version, and language
  • Operating system and platform
  • PIN login status and mobile device identifiers
  • Push notification tokens
  • Device trust status and security event history
  • Failed login attempts and CAPTCHA results

If you sign in using Google or another third-party login provider, we may receive your email address, name, profile identifier, profile image, authentication tokens, and verification status, depending on your settings and the provider.

4.3 Exchange API Credentials and Exchange Data

When you connect an exchange, we may collect and store exchange API credentials such as API key, API secret, passphrase (where required), permissions, exchange name, account type, and connection status. We encrypt API credentials at rest and use them only to provide connected exchange features.

You should not grant withdrawal permissions to API keys used with Algonney. You may revoke API key access at any time by disconnecting your exchange.

Exchange data we may process includes:

  • Exchange name, account type, and API permissions
  • Balances, assets, and margin information
  • Positions, leverage settings, and margin mode
  • Order history, open orders, fills, and trades
  • Fees, funding rates, and trading rules
  • Market data, symbols, and exchange rules needed for execution
  • Connection status, API errors, and reconciliation results

4.4 Trading, Bot, Strategy, Backtest, and Market Data

  • Bot configurations, parameters, and status
  • Trading strategy configurations, signals, and execution events
  • Custom strategy code, indicators, templates, scripts, and sandbox data
  • Compilation results, errors, and sandbox telemetry
  • Order requests, order status, and execution records
  • Trade ledger records, freeze/unfreeze status, and review notes
  • Backtest parameters, results, performance outputs, and diagnostics
  • Position sizing, stop-loss, take-profit, and trailing stop settings
  • PnL records, performance metrics, and analytics

4.5 Wallet, Deposit, Withdrawal, and Blockchain Data

If you use wallet, deposit, withdrawal, or payment features, we may collect and process:

  • Wallet balances and wallet activity
  • Deposit and withdrawal requests
  • Blockchain addresses, chains/networks, transaction hashes, memo/tag fields
  • Assets, amounts, timestamps, confirmations, and network status
  • Invoice records, payment status, checkout events, and webhook events
  • Verification results, refund records, and chargeback records
  • Reconciliation records and correction workflows
  • Withdrawal review status, approval/rejection records, risk flags
  • Support communications related to payments

For connected exchange accounts, your funds remain on the exchange. We process exchange API keys, account metadata, balances, positions, open orders, and trade history so the Platform can display account information and operate configured trading tools.

If you use Algonney wallet, deposit, withdrawal, token, credit, or payment features, we process the separate wallet and payment data described in this section.

4.6 Payment, Billing, Subscription, Token, and Invoice Data

  • Subscription plan, billing cycle, and billing status
  • Payment transactions and billing records
  • Token balances, token purchases, token grants, and token usage
  • Promo codes, vouchers, and discounts
  • Plan tier, entitlements, limits, and quota usage
  • API request counts, bot counts, WebSocket connection counts, storage, and compute usage
  • Invoices and checkout events

Payment processing is handled by third-party providers. Algonney does not store full credit card numbers, only transaction records necessary for support and compliance.

4.7 Referral, Affiliate, Campaign, Mission, and Reward Data

If you participate in referral, affiliate, mission, campaign, reward, voucher, promo, or partner features, we may process:

  • Referral codes and attribution links
  • Campaign IDs and referred users
  • Eligibility events and mission milestones
  • Reward status, review decisions, and settlement records
  • Fraud flags and payout records
  • Related analytics and attribution data

4.8 Tournament and Leaderboard Data

If you join tournaments or competitions, we may process:

  • Registrations, eligibility, and entries
  • Rankings and leaderboard data
  • PnL/performance data and scoring events
  • Reward status, disqualification, and review data
  • Public display names or profile information shown on leaderboards

4.9 Support and Communications Data

When you contact us, we may collect:

  • Support tickets, messages, and attachments
  • Screenshots, logs, and troubleshooting information
  • Account identifiers and related communications
  • Email metadata and notification preferences
  • Notification delivery tokens, delivery status, opens/clicks where applicable
  • Quiet hours and notification content
  • Phone numbers where provided, and webhook URLs

4.10 Security, Fraud, Compliance, Sanctions, and KYC Data

For security, fraud prevention, and compliance, we may collect and process:

  • Login attempts, device fingerprints, and API usage patterns
  • IP addresses and approximate geolocation
  • CAPTCHA results and bot-prevention signals
  • Failed authentication attempts and suspicious activity flags
  • Fraud scoring, risk flags, and abuse signals
  • Sanctions/PEP screening results and AML screening data
  • Identity verification data (legal name, date of birth, address, government ID, selfie/liveness, proof of address, source of funds, verification status) where required
  • Wallet address screening and blockchain transaction screening

We may use CAPTCHA or bot-prevention providers. These providers may process IP address, device/browser information, interaction data, and challenge results according to their own privacy notices.

4.11 Cookies, Analytics, and Tracking Data

We use essential, functional, and analytics cookies and similar technologies. Analytics data may be aggregated, pseudonymized, or de-identified where possible, but some analytics identifiers may still be considered personal information under applicable law. For details, see our Cookie Policy.

4.12 AI-Assisted Feature Data

Some Platform features may use AI systems or third-party model providers to generate, classify, summarize, analyze, or assist with content. Depending on the feature, we may process prompts, outputs, strategy text, support content, diagnostics, metadata, and usage logs. We do not use AI output as financial advice, and users should not submit sensitive information unless necessary for the feature.

We do not send API keys, secrets, passwords, payment credentials, or full wallet/private data to AI/LLM providers.

4.13 Logs, Monitoring, WebSocket, and Infrastructure Data

  • Application logs, access logs, error logs, and security logs
  • WebSocket connection events, room subscriptions, and stream identifiers
  • Authentication tokens for real-time connections, connection status, and timestamps
  • Message delivery status, reconnect attempts, and related logs
  • Infrastructure metrics, traces, and monitoring data
  • Session tokens, rate-limit counters, fraud counters, and cache keys
  • Event streams and message queue data
5

Sources of Information

We may receive information from:

  • Connected exchanges (Binance, Bybit, OKX)
  • Payment providers and Algonney Pay
  • Blockchain networks and blockchain analytics providers
  • OAuth/login providers such as Google
  • CAPTCHA and fraud-prevention providers
  • Analytics and infrastructure providers
  • Referral/affiliate partners
  • Support, email, webhook, and notification providers
  • Public sources where needed for compliance, sanctions, fraud, or abuse review
6

How We Use Information

We use information to:

  • Provide, operate, and maintain the Platform
  • Execute trading strategies, manage automated bots, and process orders
  • Operate wallet, deposit, withdrawal, and payment features
  • Process payments, manage subscriptions, tokens, billing, and invoices
  • Provide backtesting, strategy creation, and custom code execution
  • Operate tournaments, leaderboards, and competitions
  • Manage referrals, affiliates, missions, campaigns, and rewards
  • Send account, trading, wallet, security, billing, tournament, referral, and system notifications
  • Detect and prevent fraud, abuse, unauthorized access, and security incidents
  • Screen for sanctions, AML, and compliance obligations
  • Provide customer support and investigate issues
  • Improve Platform performance, user experience, and features
  • Conduct analytics and research
  • Comply with legal obligations and legal process
7

Legal Bases for Processing

Where required by applicable law (such as GDPR), we rely on the following legal bases to process your personal information:

PurposeData UsedLegal Basis
Account creation/loginEmail, username, password hash, device/session dataContract performance; security legitimate interest
Trading automationExchange API keys, balances, positions, orders, strategy configsContract performance
Wallet/deposits/withdrawalsWallet records, addresses, transaction hashes, payment records, verification dataContract performance; legal obligation; fraud prevention
Fraud/securityIP, device fingerprint, failed login attempts, CAPTCHA, abuse signalsLegitimate interest; legal obligation
MarketingEmail, preferences, campaign attributionConsent or legitimate interest where allowed
AnalyticsUsage events, device/browser data, cookiesConsent where required; legitimate interest for essential analytics
Legal/complianceAccount, payment, wallet, audit logs, fraud recordsLegal obligation; legitimate interest
TournamentsRegistrations, rankings, performance, leaderboard dataContract performance; legitimate interest
Referrals/rewardsReferral codes, eligibility, reward status, payout recordsContract performance; legitimate interest
AI-assisted featuresPrompts, outputs, diagnostics, usage logsLegitimate interest; consent where required
SupportTickets, messages, logs, communicationsContract performance; legitimate interest
KYC/identity verificationLegal name, ID, selfie, proof of address, screening resultsLegal obligation; legitimate interest
8

How We Share Information

We do not sell personal information for money.

We do not use personal information for cross-context behavioral advertising.

We may share information with:

  • Connected exchanges to operate trading features
  • Payment providers to process payments, deposits, and withdrawals
  • Service providers who assist with hosting, email delivery, analytics, fraud prevention, CAPTCHA, notifications, and AI features
  • Blockchain networks when you make deposits or withdrawals
  • Law enforcement, regulators, or other parties when required by law, legal process, or to protect rights, safety, or property
  • Other users in limited contexts, such as tournament leaderboards, public bot/template listings, referral pages, or marketplace content
9

Subprocessors and Third-Party Services

We use the following third-party service providers ("subprocessors") to help operate the Platform. This list may change as our providers change; the current list is maintained here, and you may request the latest version at privacy@algonney.com.

SubprocessorPurposeData Categories
CloudflareCDN, edge security/WAF, and Turnstile bot & CAPTCHA protectionIP address, device and browser data, challenge results
Google (Google Analytics)Consent-based usage analyticsUsage and cookie data, approximate location
Google (Sign-In / OAuth)Optional third-party loginEmail, name, profile identifier, authentication tokens
Google (Gmail API)Transactional and notification email deliveryEmail address, message content
SentryApplication error and performance monitoringDiagnostic/error data, IP, device, page context
TelegramOptional notification delivery (if you connect Telegram)Telegram identifier, message content
Binance, Bybit, OKXConnected trading and account data via your API keysExchange account, order, position, and balance data
Blockchain networks & Algonney Pay gatewayDeposit and withdrawal processingWallet addresses, transaction hashes, amounts, network status
Cloud infrastructure & database hosting providersPlatform hosting, compute, and data storageApplication data, logs, account/trading/wallet/support data

Where personal data is transferred internationally, we use appropriate safeguards such as contractual protections, standard contractual clauses, or other lawful transfer mechanisms.

10

Cookies and Similar Technologies

We use essential cookies required for the Platform to function, as well as functional and analytics cookies that help us improve your experience. Where required by law, we will request consent before using non-essential cookies or similar technologies. You may change your cookie preferences through our cookie settings interface and should not rely only on browser settings.

For a detailed cookie table (cookie name, provider, purpose, category, duration, and consent mechanism), see our Cookie Policy.

11

International Data Transfers

Algonney is based in Lebanon and uses service providers, infrastructure, exchanges, payment providers, analytics providers, communication providers, and AI providers that may process data in Lebanon, the United States, the European Economic Area, the United Kingdom, and other countries.

Where required, we use appropriate safeguards such as contractual protections, standard contractual clauses, transfer risk assessments, or other lawful transfer mechanisms.

12

Data Retention

We retain personal information according to the following general guidelines:

Data CategoryTypical Retention
Account profileAccount life + defined post-closure period
Exchange API credentialsUntil disconnected/deleted, then removed from active systems promptly
Trading/order/position recordsAccount life + legal/compliance/dispute period
Wallet/deposit/withdrawal/payment recordsLegal, tax, AML, fraud, chargeback, accounting retention period
Security logs/session logsDefined security period, longer if investigation required
Fraud/abuse/audit recordsDefined compliance/security period
Support ticketsDefined support/legal period
Marketing preferencesUntil opt-out plus suppression list retention
BackupsRetained for backup cycle, then overwritten
Anonymized/aggregated analyticsMay be retained indefinitely if no longer personal data

Data may remain in backups, immutable logs, disaster recovery systems, and audit records until those systems expire or are overwritten according to our retention schedules.

13

Security

We use encryption in transit (HTTPS/TLS) and at rest where appropriate, credential encryption for exchange API keys, password hashing, two-factor authentication, access controls, logging, monitoring, and other technical and organizational measures designed to protect personal information.

Trading, wallet, payment, API credential, and security data are treated as sensitive operational data. Access is restricted to authorized systems and personnel with a business, security, support, compliance, or legal need.

Internal access may be controlled through role-based access controls, multi-factor authentication, audit logs, approval workflows, breakglass controls, and least-privilege permissions. Administrative actions, including impersonation, breakglass access, approvals, rejections, edits, exports, and reviews, may be logged in audit records.

No system is completely secure. We regularly review and improve our security practices.

Security Incidents

If we become aware of a personal data breach, we will investigate and take appropriate steps to contain, remediate, and notify affected users or authorities where required by law.

14

Automated Processing, Fraud Detection, and Profiling

We may use automated systems to detect fraud, abuse, suspicious login activity, rate-limit violations, prohibited activity, payment risk, withdrawal risk, reward abuse, bot behavior, or security threats. These systems may result in additional verification, CAPTCHA challenges, delays, warnings, feature limits, blocked actions, manual review, suspension, or termination.

We may compare, reconcile, correct, restate, or update trading, wallet, payment, balance, order, position, reward, and analytics records based on exchange data, blockchain data, payment provider data, internal ledgers, support requests, or administrative review.

Where required by law, you may request human review or appeal certain decisions. If your account, withdrawal, reward, payment, or feature access is restricted because of automated or manual risk review, you may contact support to request review, unless prohibited by law or security requirements.

15

Your Privacy Rights and Choices

Depending on your location, you may have rights to:

  • Access your personal information
  • Correct inaccurate information
  • Delete your information
  • Object to or restrict processing
  • Withdraw consent where applicable
  • Data portability
  • Opt out of marketing communications
  • Opt out of sale/share or targeted advertising where applicable
  • Limit use/disclosure of sensitive personal information where applicable
  • Appeal certain decisions where applicable
  • Lodge a complaint with a supervisory authority

To exercise your rights: contact privacy@algonney.com.

We may verify your identity before responding. We will respond within the timeframe required by applicable law.

Account Deletion and Data Export

You may request account deletion or data export through the Platform or by contacting support@algonney.com. If you request deletion, we will delete or de-identify personal information that is no longer needed, subject to legal, compliance, tax, accounting, fraud-prevention, security, dispute-resolution, backup, and legitimate business retention requirements.

Data exports may exclude information that would compromise security, reveal another person's data, disclose trade secrets, reveal fraud/risk logic, violate law, or interfere with investigations.

Marketing Communications

Where permitted, we may send product updates, promotions, referral or campaign messages, and educational content. You can opt out of marketing emails using the unsubscribe link or account settings. Transactional, security, billing, trading, wallet, and account messages may still be sent where necessary.

16

Public or Shared Information

Some features may display information to other users or the public, such as display name, username, avatar, tournament ranking, leaderboard results, public bot or template listings, referral campaign pages, or strategy marketplace content.

If you create, publish, sell, share, review, or use templates, bots, indicators, or strategies in the marketplace, we may process creator identity, listing data, usage metrics, purchases, reviews, moderation status, takedown records, version history, and related analytics.

Do not submit information you do not want shared through those features.

17

Sensitive Data

Depending on the feature and jurisdiction, some information we process may be considered sensitive, such as identity verification data, financial account information, precise location (if collected), security credentials, biometric/liveness verification data, or fraud/risk signals. We use sensitive data only for permitted purposes such as security, compliance, identity verification, fraud prevention, payment processing, and providing requested services.

18

Children

The Platform is not intended for individuals under 18. We do not knowingly collect personal information from minors. If we learn that a minor has provided personal information, we may delete it and close the account.

19

Changes to This Policy

We may update this policy periodically. If we make material changes, we will provide notice through the Platform, email, or another appropriate method. Where required by law, we will request consent before applying changes to processing that require consent.

The “Last Updated” date at the top of this page indicates when this Policy was last revised.

20

Contact Us

Privacy requests: privacy@algonney.com

Support: support@algonney.com

Legal notices: legal@algonney.com

Your privacy is our priority. Thank you for trusting Algonney.

This document is published in English. If it is translated into another language, the English version controls unless applicable law requires otherwise.