Privacy Policy
In short: we collect what Levr needs to run your trades and nothing to sell. Exchange keys are sealed so the web app can't read them back, we never hold your payment details, and you can ask for your data or its deletion at any time.
1. Controller
[Company name], [Country], is responsible for your personal data. Contact: [support email].
2. What we collect and why
- Account data: email, password (stored only as a hash), two-factor secret (encrypted). To let you sign in securely.
- Exchange connections: account addresses and API keys, sealed when you paste them; balances and positions read from the exchange. To size and manage your trades.
- Trading data: signals you paste or forward (text and images), the trades Levr opens, their events and results. To run trades, show your journal and send alerts.
- Discord: if you connect it, your Discord user ID and username, the messages you send to the Levr bot and your alert webhook. To read forwarded signals and deliver alerts.
- Billing: plan, the paid-until date and the payment reference from NOWPayments (amount, currency and status). We never see your wallet's keys.
- Security logs: IP address and browser of sign-ins and requests, kept for a short time. To prevent abuse and protect accounts.
The legal bases are the contract with you (running the service), our legitimate interest (security, fraud prevention, improving Levr) and legal obligations (tax and accounting records).
3. Who processes data for us
- Hosting and network providers that run the application and the website.
- NOWPayments, which processes crypto payments.
- A crypto payment processor, if you pay in crypto.
- An AI service provider that reads screenshots and unusual signal formats and writes trade reviews. It receives only the signal content or trade data needed for that request, not your keys or password.
- Discord, if you connect it.
- Exchanges you connect, which receive your orders.
Some providers are outside the EU/EEA. Where they are, transfers rely on adequacy decisions or standard contractual clauses.
4. How long we keep it
- Account and trading data: while your account is open, then deleted within 30 days of closing it.
- API keys: deleted as soon as you disconnect the account.
- Billing records: as long as tax law requires.
- Security logs: up to 90 days.
5. Your rights
You can ask to access, correct, export or delete your data, and to restrict or object to processing, by writing to [support email]. You can also complain to your data protection authority.
6. Cookies
The app uses one essential cookie to keep you signed in. The website doesn't use advertising or tracking cookies.
7. Security
Exchange keys are encrypted with a public key the web application can't decrypt; only the trading engine opens them, in memory, to sign orders. Two-factor authentication is required for every account. No system is perfectly secure; we'll tell you without undue delay if a breach affects your data.
8. Changes
We'll update this page when our practices change and tell you of material changes by email or in the app.