Privacy Policy

CryptoPro is operated by VibeSoft Studio, KVK 42136303 (info@vibesoftstudio.com) - see the Terms of Service for who operates this service. This policy covers CryptoPro Suite, Charts, Trader and Training, which share one account and one database. It explains what we store, why, and what you can do about it.

What we store

Your account: username, a hashed password (never the password itself), and - only if you switch it on - a two-factor secret. You may add a notification email; it is stored but nothing sends email yet. What you create: watchlists, chart layouts and drawings, settings, your chosen theme and language, course progress and quiz results, and Trader's trading journal and paper-trading state. Broker keys: if you connect Alpaca, your API credentials are encrypted before they are stored. Trader places paper orders only. We do not collect payment card details, and we do not ask for special-category data.

Why, and on what legal basis

To provide the account and the features you asked for (performance of a contract), and to keep the account secure - sessions, optional two-factor, and write limits on credential changes (legitimate interest). We do not profile you, we do not make automated decisions about you, and we do not use your data to train anything.

Cookies and local storage

One cookie. cpc_session is set only when you sign in. It is HttpOnly, SameSite=Lax, Secure in production, and valid for 30 days or until you sign out. It identifies your session and nothing else - and the same cookie is shared across every CryptoPro Suite app (Charts, Trader, Training), so signing in once signs you in everywhere. Local storage keeps your own preferences on your device - theme, language, last open tab, watchlists, and in Trader the API keys you entered. No analytics, no advertising, no tracking pixels, no social media embeds and no third-party cookies. Fonts and chart libraries are served from our own servers, so opening a page does not tell anyone else that you were here.

Who else processes it

Hosting: Vercel. Database: Supabase. Both process data on our instructions only. If you connect Alpaca, requests go to Alpaca using your own keys. Nothing is sold, rented, or shared for advertising.

How long we keep it

For as long as your account exists. Deleting your account (Account → Danger zone) ends every session immediately and blocks sign-in across the whole suite; the data is then permanently erased after 30 days. Sign-in sessions expire after 30 days on their own.

Your rights

You can ask for access, correction, erasure, restriction, objection, or a portable copy of your data - and you can delete your account yourself at any time, without asking us. Write to info@vibesoftstudio.com for anything else. You also have the right to complain to your national data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens).

Changes

If this policy changes, the date above changes with it. Material changes will be announced in the app.