Privacy Policy
Last Updated: May 7, 2026
Effective Date: May 7, 2026
This Privacy Policy is published in English, which is the authoritative version. Site navigation and menus are available in all supported languages.
Table of Contents
Introduction
This Privacy Policy explains how Algonney collects, uses, discloses, stores, and protects personal information when you use the Platform. It also explains your privacy choices and rights.
Where required by law, we ask for your consent separately, such as for non-essential cookies, marketing communications, or other optional processing. Otherwise, we process personal information based on the legal bases described in this Policy.
This Policy applies to the Algonney platform, website, mobile applications, APIs, WebSocket services, and related services (collectively, the “Platform”).
Who We Are / Data Controller
The data controller responsible for your personal information is:
Algonney Technologies
Registered address: Beirut, Lebanon
Country: Lebanon
Privacy contact: privacy@algonney.com
Support contact: support@algonney.com
Legal notices: legal@algonney.com
If you are in the European Economic Area or the United Kingdom and have questions about your rights under GDPR or UK GDPR, you may contact us at privacy@algonney.com.
Scope of This Policy
This Policy covers all personal information processed by Algonney in connection with the Platform, including account data, trading data, wallet and payment data, exchange data, support communications, device and session data, cookies, and analytics.
The Platform may contain links to third-party services (such as exchanges, payment providers, or analytics tools). This Policy does not apply to those third parties. We encourage you to review their privacy policies.
Information We Collect
We collect information that you provide directly, information generated when you use the Platform, and information from third-party services you connect to your account.
4.1 Account Data
When you create an account, we collect:
- Email address
- Username and display name
- Hashed password
- Two-factor authentication settings and authenticator status
- Account preferences and language settings
- Account creation date and status
4.2 Authentication, Session, and Device Data
When you log in or use the Platform, we may collect:
- Login timestamps, methods, and outcomes
- Session tokens and refresh tokens
- Device identifiers and device fingerprint
- IP address and approximate geolocation (country, region, city)
- Browser type, version, and language
- Operating system and platform
- PIN login status and mobile device identifiers
- Push notification tokens
- Device trust status and security event history
- Failed login attempts and CAPTCHA results
If you sign in using Google or another third-party login provider, we may receive your email address, name, profile identifier, profile image, authentication tokens, and verification status, depending on your settings and the provider.
4.3 Exchange API Credentials and Exchange Data
When you connect an exchange, we may collect and store exchange API credentials such as API key, API secret, passphrase (where required), permissions, exchange name, account type, and connection status. We encrypt API credentials at rest and use them only to provide connected exchange features.
You should not grant withdrawal permissions to API keys used with Algonney. You may revoke API key access at any time by disconnecting your exchange.
Exchange data we may process includes:
- Exchange name, account type, and API permissions
- Balances, assets, and margin information
- Positions, leverage settings, and margin mode
- Order history, open orders, fills, and trades
- Fees, funding rates, and trading rules
- Market data, symbols, and exchange rules needed for execution
- Connection status, API errors, and reconciliation results
4.4 Trading, Bot, Strategy, Backtest, and Market Data
- Bot configurations, parameters, and status
- Trading strategy configurations, signals, and execution events
- Custom strategy code, indicators, templates, scripts, and sandbox data
- Compilation results, errors, and sandbox telemetry
- Order requests, order status, and execution records
- Trade ledger records, freeze/unfreeze status, and review notes
- Backtest parameters, results, performance outputs, and diagnostics
- Position sizing, stop-loss, take-profit, and trailing stop settings
- PnL records, performance metrics, and analytics
4.5 Wallet, Deposit, Withdrawal, and Blockchain Data
If you use wallet, deposit, withdrawal, or payment features, we may collect and process:
- Wallet balances and wallet activity
- Deposit and withdrawal requests
- Blockchain addresses, chains/networks, transaction hashes, memo/tag fields
- Assets, amounts, timestamps, confirmations, and network status
- Invoice records, payment status, checkout events, and webhook events
- Verification results, refund records, and chargeback records
- Reconciliation records and correction workflows
- Withdrawal review status, approval/rejection records, risk flags
- Support communications related to payments
For connected exchange accounts, your funds remain on the exchange. We process exchange API keys, account metadata, balances, positions, open orders, and trade history so the Platform can display account information and operate configured trading tools.
If you use Algonney wallet, deposit, withdrawal, token, credit, or payment features, we process the separate wallet and payment data described in this section.
4.6 Payment, Billing, Subscription, Token, and Invoice Data
- Subscription plan, billing cycle, and billing status
- Payment transactions and billing records
- Token balances, token purchases, token grants, and token usage
- Promo codes, vouchers, and discounts
- Plan tier, entitlements, limits, and quota usage
- API request counts, bot counts, WebSocket connection counts, storage, and compute usage
- Invoices and checkout events
Payment processing is handled by third-party providers. Algonney does not store full credit card numbers, only transaction records necessary for support and compliance.
4.7 Referral, Affiliate, Campaign, Mission, and Reward Data
If you participate in referral, affiliate, mission, campaign, reward, voucher, promo, or partner features, we may process:
- Referral codes and attribution links
- Campaign IDs and referred users
- Eligibility events and mission milestones
- Reward status, review decisions, and settlement records
- Fraud flags and payout records
- Related analytics and attribution data
4.8 Tournament and Leaderboard Data
If you join tournaments or competitions, we may process:
- Registrations, eligibility, and entries
- Rankings and leaderboard data
- PnL/performance data and scoring events
- Reward status, disqualification, and review data
- Public display names or profile information shown on leaderboards
4.9 Support and Communications Data
When you contact us, we may collect:
- Support tickets, messages, and attachments
- Screenshots, logs, and troubleshooting information
- Account identifiers and related communications
- Email metadata and notification preferences
- Notification delivery tokens, delivery status, opens/clicks where applicable
- Quiet hours and notification content
- Phone numbers where provided, and webhook URLs
4.10 Security, Fraud, Compliance, Sanctions, and KYC Data
For security, fraud prevention, and compliance, we may collect and process:
- Login attempts, device fingerprints, and API usage patterns
- IP addresses and approximate geolocation
- CAPTCHA results and bot-prevention signals
- Failed authentication attempts and suspicious activity flags
- Fraud scoring, risk flags, and abuse signals
- Sanctions/PEP screening results and AML screening data
- Identity verification data (legal name, date of birth, address, government ID, selfie/liveness, proof of address, source of funds, verification status) where required
- Wallet address screening and blockchain transaction screening
We may use CAPTCHA or bot-prevention providers. These providers may process IP address, device/browser information, interaction data, and challenge results according to their own privacy notices.
4.11 Cookies, Analytics, and Tracking Data
We use essential, functional, and analytics cookies and similar technologies. Analytics data may be aggregated, pseudonymized, or de-identified where possible, but some analytics identifiers may still be considered personal information under applicable law. For details, see our Cookie Policy.
4.12 AI-Assisted Feature Data
Some Platform features may use AI systems or third-party model providers to generate, classify, summarize, analyze, or assist with content. Depending on the feature, we may process prompts, outputs, strategy text, support content, diagnostics, metadata, and usage logs. We do not use AI output as financial advice, and users should not submit sensitive information unless necessary for the feature.
We do not send API keys, secrets, passwords, payment credentials, or full wallet/private data to AI/LLM providers.
4.13 Logs, Monitoring, WebSocket, and Infrastructure Data
- Application logs, access logs, error logs, and security logs
- WebSocket connection events, room subscriptions, and stream identifiers
- Authentication tokens for real-time connections, connection status, and timestamps
- Message delivery status, reconnect attempts, and related logs
- Infrastructure metrics, traces, and monitoring data
- Session tokens, rate-limit counters, fraud counters, and cache keys
- Event streams and message queue data
Sources of Information
We may receive information from:
- Connected exchanges (Binance, Bybit, OKX)
- Payment providers and Algonney Pay
- Blockchain networks and blockchain analytics providers
- OAuth/login providers such as Google
- CAPTCHA and fraud-prevention providers
- Analytics and infrastructure providers
- Referral/affiliate partners
- Support, email, webhook, and notification providers
- Public sources where needed for compliance, sanctions, fraud, or abuse review
How We Use Information
We use information to:
- Provide, operate, and maintain the Platform
- Execute trading strategies, manage automated bots, and process orders
- Operate wallet, deposit, withdrawal, and payment features
- Process payments, manage subscriptions, tokens, billing, and invoices
- Provide backtesting, strategy creation, and custom code execution
- Operate tournaments, leaderboards, and competitions
- Manage referrals, affiliates, missions, campaigns, and rewards
- Send account, trading, wallet, security, billing, tournament, referral, and system notifications
- Detect and prevent fraud, abuse, unauthorized access, and security incidents
- Screen for sanctions, AML, and compliance obligations
- Provide customer support and investigate issues
- Improve Platform performance, user experience, and features
- Conduct analytics and research
- Comply with legal obligations and legal process
Legal Bases for Processing
Where required by applicable law (such as GDPR), we rely on the following legal bases to process your personal information:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation/login | Email, username, password hash, device/session data | Contract performance; security legitimate interest |
| Trading automation | Exchange API keys, balances, positions, orders, strategy configs | Contract performance |
| Wallet/deposits/withdrawals | Wallet records, addresses, transaction hashes, payment records, verification data | Contract performance; legal obligation; fraud prevention |
| Fraud/security | IP, device fingerprint, failed login attempts, CAPTCHA, abuse signals | Legitimate interest; legal obligation |
| Marketing | Email, preferences, campaign attribution | Consent or legitimate interest where allowed |
| Analytics | Usage events, device/browser data, cookies | Consent where required; legitimate interest for essential analytics |
| Legal/compliance | Account, payment, wallet, audit logs, fraud records | Legal obligation; legitimate interest |
| Tournaments | Registrations, rankings, performance, leaderboard data | Contract performance; legitimate interest |
| Referrals/rewards | Referral codes, eligibility, reward status, payout records | Contract performance; legitimate interest |
| AI-assisted features | Prompts, outputs, diagnostics, usage logs | Legitimate interest; consent where required |
| Support | Tickets, messages, logs, communications | Contract performance; legitimate interest |
| KYC/identity verification | Legal name, ID, selfie, proof of address, screening results | Legal obligation; legitimate interest |
How We Share Information
We do not sell personal information for money.
We do not use personal information for cross-context behavioral advertising.
We may share information with:
- Connected exchanges to operate trading features
- Payment providers to process payments, deposits, and withdrawals
- Service providers who assist with hosting, email delivery, analytics, fraud prevention, CAPTCHA, notifications, and AI features
- Blockchain networks when you make deposits or withdrawals
- Law enforcement, regulators, or other parties when required by law, legal process, or to protect rights, safety, or property
- Other users in limited contexts, such as tournament leaderboards, public bot/template listings, referral pages, or marketplace content
Subprocessors and Third-Party Services
We use the following third-party service providers ("subprocessors") to help operate the Platform. This list may change as our providers change; the current list is maintained here, and you may request the latest version at privacy@algonney.com.
| Subprocessor | Purpose | Data Categories |
|---|---|---|
| Cloudflare | CDN, edge security/WAF, and Turnstile bot & CAPTCHA protection | IP address, device and browser data, challenge results |
| Google (Google Analytics) | Consent-based usage analytics | Usage and cookie data, approximate location |
| Google (Sign-In / OAuth) | Optional third-party login | Email, name, profile identifier, authentication tokens |
| Google (Gmail API) | Transactional and notification email delivery | Email address, message content |
| Sentry | Application error and performance monitoring | Diagnostic/error data, IP, device, page context |
| Telegram | Optional notification delivery (if you connect Telegram) | Telegram identifier, message content |
| Binance, Bybit, OKX | Connected trading and account data via your API keys | Exchange account, order, position, and balance data |
| Blockchain networks & Algonney Pay gateway | Deposit and withdrawal processing | Wallet addresses, transaction hashes, amounts, network status |
| Cloud infrastructure & database hosting providers | Platform hosting, compute, and data storage | Application data, logs, account/trading/wallet/support data |
Where personal data is transferred internationally, we use appropriate safeguards such as contractual protections, standard contractual clauses, or other lawful transfer mechanisms.
Cookies and Similar Technologies
We use essential cookies required for the Platform to function, as well as functional and analytics cookies that help us improve your experience. Where required by law, we will request consent before using non-essential cookies or similar technologies. You may change your cookie preferences through our cookie settings interface and should not rely only on browser settings.
For a detailed cookie table (cookie name, provider, purpose, category, duration, and consent mechanism), see our Cookie Policy.
International Data Transfers
Algonney is based in Lebanon and uses service providers, infrastructure, exchanges, payment providers, analytics providers, communication providers, and AI providers that may process data in Lebanon, the United States, the European Economic Area, the United Kingdom, and other countries.
Where required, we use appropriate safeguards such as contractual protections, standard contractual clauses, transfer risk assessments, or other lawful transfer mechanisms.
Data Retention
We retain personal information according to the following general guidelines:
| Data Category | Typical Retention |
|---|---|
| Account profile | Account life + defined post-closure period |
| Exchange API credentials | Until disconnected/deleted, then removed from active systems promptly |
| Trading/order/position records | Account life + legal/compliance/dispute period |
| Wallet/deposit/withdrawal/payment records | Legal, tax, AML, fraud, chargeback, accounting retention period |
| Security logs/session logs | Defined security period, longer if investigation required |
| Fraud/abuse/audit records | Defined compliance/security period |
| Support tickets | Defined support/legal period |
| Marketing preferences | Until opt-out plus suppression list retention |
| Backups | Retained for backup cycle, then overwritten |
| Anonymized/aggregated analytics | May be retained indefinitely if no longer personal data |
Data may remain in backups, immutable logs, disaster recovery systems, and audit records until those systems expire or are overwritten according to our retention schedules.
Security
We use encryption in transit (HTTPS/TLS) and at rest where appropriate, credential encryption for exchange API keys, password hashing, two-factor authentication, access controls, logging, monitoring, and other technical and organizational measures designed to protect personal information.
Trading, wallet, payment, API credential, and security data are treated as sensitive operational data. Access is restricted to authorized systems and personnel with a business, security, support, compliance, or legal need.
Internal access may be controlled through role-based access controls, multi-factor authentication, audit logs, approval workflows, breakglass controls, and least-privilege permissions. Administrative actions, including impersonation, breakglass access, approvals, rejections, edits, exports, and reviews, may be logged in audit records.
No system is completely secure. We regularly review and improve our security practices.
Security Incidents
If we become aware of a personal data breach, we will investigate and take appropriate steps to contain, remediate, and notify affected users or authorities where required by law.
Automated Processing, Fraud Detection, and Profiling
We may use automated systems to detect fraud, abuse, suspicious login activity, rate-limit violations, prohibited activity, payment risk, withdrawal risk, reward abuse, bot behavior, or security threats. These systems may result in additional verification, CAPTCHA challenges, delays, warnings, feature limits, blocked actions, manual review, suspension, or termination.
We may compare, reconcile, correct, restate, or update trading, wallet, payment, balance, order, position, reward, and analytics records based on exchange data, blockchain data, payment provider data, internal ledgers, support requests, or administrative review.
Where required by law, you may request human review or appeal certain decisions. If your account, withdrawal, reward, payment, or feature access is restricted because of automated or manual risk review, you may contact support to request review, unless prohibited by law or security requirements.
Your Privacy Rights and Choices
Depending on your location, you may have rights to:
- Access your personal information
- Correct inaccurate information
- Delete your information
- Object to or restrict processing
- Withdraw consent where applicable
- Data portability
- Opt out of marketing communications
- Opt out of sale/share or targeted advertising where applicable
- Limit use/disclosure of sensitive personal information where applicable
- Appeal certain decisions where applicable
- Lodge a complaint with a supervisory authority
To exercise your rights: contact privacy@algonney.com.
We may verify your identity before responding. We will respond within the timeframe required by applicable law.
Account Deletion and Data Export
You may request account deletion or data export through the Platform or by contacting support@algonney.com. If you request deletion, we will delete or de-identify personal information that is no longer needed, subject to legal, compliance, tax, accounting, fraud-prevention, security, dispute-resolution, backup, and legitimate business retention requirements.
Data exports may exclude information that would compromise security, reveal another person's data, disclose trade secrets, reveal fraud/risk logic, violate law, or interfere with investigations.
Marketing Communications
Where permitted, we may send product updates, promotions, referral or campaign messages, and educational content. You can opt out of marketing emails using the unsubscribe link or account settings. Transactional, security, billing, trading, wallet, and account messages may still be sent where necessary.
Public or Shared Information
Some features may display information to other users or the public, such as display name, username, avatar, tournament ranking, leaderboard results, public bot or template listings, referral campaign pages, or strategy marketplace content.
If you create, publish, sell, share, review, or use templates, bots, indicators, or strategies in the marketplace, we may process creator identity, listing data, usage metrics, purchases, reviews, moderation status, takedown records, version history, and related analytics.
Do not submit information you do not want shared through those features.
Sensitive Data
Depending on the feature and jurisdiction, some information we process may be considered sensitive, such as identity verification data, financial account information, precise location (if collected), security credentials, biometric/liveness verification data, or fraud/risk signals. We use sensitive data only for permitted purposes such as security, compliance, identity verification, fraud prevention, payment processing, and providing requested services.
Children
The Platform is not intended for individuals under 18. We do not knowingly collect personal information from minors. If we learn that a minor has provided personal information, we may delete it and close the account.
Changes to This Policy
We may update this policy periodically. If we make material changes, we will provide notice through the Platform, email, or another appropriate method. Where required by law, we will request consent before applying changes to processing that require consent.
The “Last Updated” date at the top of this page indicates when this Policy was last revised.
Contact Us
Privacy requests: privacy@algonney.com
Support: support@algonney.com
Legal notices: legal@algonney.com
Your privacy is our priority. Thank you for trusting Algonney.