// privacy policy
Privacy Policy
Current statusNexlot is in construction and testing. There are no public sign-ups, nothing is for sale, no fee is charged, and no bot trades real money — execution runs against exchange testnets only. This document describes that state and will be re-issued under a new version before any of it changes.
This explains what Nexlot stores about you, why we are allowed to, who else touches it, and how to get it back or have it destroyed. It is written under Articles 13 and 14 of the GDPR.
1Who is responsible for your data
The controller within the meaning of Art. 4(7) GDPR is the private individual operating Nexlot from Germany. Postal details are being finalised and will be published in the Impressum; until then, reach the controller at support@nexlots.com, and we will supply the postal address on request.
We have not appointed a Data Protection Officer. We are not required to — we carry out neither large-scale systematic monitoring nor large-scale processing of special category data under Art. 37(1) GDPR. Data protection questions go to support@nexlots.com and reach the controller directly.
2What we process, and why we may
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Waitlist email address | To email you once when there is something to open | Art. 6(1)(a) — your consent, given by ticking the box on the form | Until you unsubscribe or ask for deletion, or 24 months after the last contact |
| Which product page you signed up from | To see which pages actually convert | Art. 6(1)(f) — our legitimate interest in knowing what works | With the waitlist entry |
| Account: email, password hash, username | To create and run your account | Art. 6(1)(b) — necessary to perform the contract | For the life of the account, then 30 days |
| Session and refresh tokens | To keep you logged in and to let us revoke a stolen session | Art. 6(1)(b) and Art. 6(1)(f) — performance, and account security | Until expiry or revocation |
| Journal entries, trades, notes, strategies, backtests | They are the product — this is the content you create | Art. 6(1)(b) — necessary to perform the contract | Until you delete them or close your account |
| Encrypted exchange and broker credentials | To place the orders your strategy produces, when you connect a key | Art. 6(1)(b) — necessary to perform the contract | Until you disconnect the integration, then deleted immediately |
| Text you submit for AI review | To generate the journal review or strategy analysis you asked for | Art. 6(1)(b) — necessary to perform the contract, and only when you request it | Not retained by us beyond producing the result |
| Legal acceptance log: which document version, when, and the IP used | To prove which terms you agreed to, if that is ever disputed | Art. 6(1)(c) and Art. 6(1)(f) — evidence of contract formation | Three years after the account closes |
| Server logs | To keep the service running and to investigate abuse | Art. 6(1)(f) — our legitimate interest in a working, non-abused service | Short-lived, deleted on rotation |
We do not sell your data. We do not share it for advertising. We do not build profiles of you, and we run no automated decision-making with legal effect under Art. 22 GDPR.
3What we deliberately do not store
Some of this is worth stating explicitly, because it is unusual and it is verifiable in how the system is built:
- Your password is never stored. Only a bcrypt hash, which cannot be reversed into your password.
- MetaTrader 5 credentials are never stored at all. Your login and investor password are passed once to MetaAPI to provision the connection. We keep only the non-secret account identifier they return.
- Exchange API secrets are encrypted with AES-256-GCM before they touch the database. Plaintext secrets are never written to disk.
- We never hold your funds and never have withdrawal rights over your exchange account.
4Who else processes your data
The services below process data on our behalf or receive data because you asked us to connect to them. Where a service sits outside the EEA, the basis for the transfer is named.
| Service | Purpose | Data | Location | Transfer basis |
|---|---|---|---|---|
| Railway | Application hosting, Postgres database, file volume | Everything stored: account, journal, strategies, encrypted broker credentials | EU region (Amsterdam); company is US-based | Standard Contractual Clauses (Art. 46(2)(c)) |
| Brevo (Sendinblue) | Transactional email — verification, password reset, waitlist | Email address | France (EU) | No transfer — processing inside the EEA |
| OpenRouter | AI journal review and strategy analysis | Journal note text and strategy definitions you submit for review | United States | Standard Contractual Clauses (Art. 46(2)(c)) |
| MetaAPI | MetaTrader 5 terminal connection | The account identifier MetaAPI issues. Your MT5 login and password are never stored by Nexlot | United States | Standard Contractual Clauses (Art. 46(2)(c)) |
| SnapTrade | Stock broker account linking | An encrypted user secret. Your broker password is never seen by Nexlot | Canada | Adequacy decision (Art. 45) — Canada, commercial organisations |
| Binance | Market data, and order execution when you connect keys | The API keys you supply, and the orders placed with them | Outside the EEA; varies by entity | Art. 49(1)(b) — necessary to perform the contract you asked for |
| Bybit | Order execution when you connect keys | The API keys you supply, and the orders placed with them | Outside the EEA; varies by entity | Art. 49(1)(b) — necessary to perform the contract you asked for |
| Financial Modeling Prep | Company fundamentals | None — the server requests public data and no user identifier is sent | United States | No personal data transferred |
| ForexFactory / faireconomy.media | Economic calendar | None — public feed fetched by the server | United States | No personal data transferred |
| News sources (CoinDesk, Cointelegraph, Decrypt, CNBC, Dow Jones, Yahoo Finance, FXStreet) | Market headlines | None — public RSS fetched by the server | Various | No personal data transferred |
Transfers to countries without an adequacy decision carry a real residual risk: local authorities there may have access powers that EU law would not permit. Contractual safeguards reduce that risk but do not remove it, and you should know that before connecting an integration.
5Cookies and browser storage
This website sets no tracking cookies and runs no third-party analytics. The Cookies and Storage page lists the single item of browser storage we do use and why it needs no consent.
6Your rights
Under the GDPR you can require us to act, and we will, free of charge:
- Art. 15 — access. A copy of everything we hold about you.
- Art. 16 — rectification. Correction of anything wrong.
- Art. 17 — erasure. Deletion, where we have no overriding obligation to keep it.
- Art. 18 — restriction. We keep it but stop using it.
- Art. 20 — portability. Your data in a machine-readable format.
- Art. 21 — objection. You can object to any processing we base on legitimate interest, and we then have to justify it or stop.
- Art. 7(3) — withdraw consent. Where processing rests on your consent, you can withdraw it at any time. That does not affect what we did lawfully before you withdrew it.
Write to support@nexlots.com. We answer within one month, as Art. 12(3) requires. We will not make you explain why.
7Complaining about us
You can lodge a complaint with a data protection supervisory authority — either the authority for the German federal state Nexlot is operated from, or the one where you live or work (Art. 77 GDPR). You do not need our permission and you do not need to raise it with us first, though we would rather you did so we can fix it.
8If there is a breach
If personal data is breached in a way that is likely to result in a risk to your rights, we report it to the supervisory authority within 72 hours (Art. 33), and where the risk to you is high we tell you directly and without undue delay (Art. 34). We will tell you what happened and what to do about it, not just that “an incident occurred”.
9Changes to this policy
When this policy changes materially — a new sub-processor, a new purpose, a new legal basis — we publish it under a new version number and tell account holders. Adding a service that touches your data without listing it here would make this policy wrong, so the list above is updated in the same change that adds the service.
Questions about this document go to support@nexlots.com. This page is written in English; it is not legal advice, and it does not limit any right you have under German or EU law that cannot be limited by agreement.