Data Retention Notice
Version 1.1.0
| Data | Where | Retention |
|---|---|---|
| Account email and authentication | Supabase Auth | Until you delete your account |
| Webhook secret and auth token | Checked against keyed HMAC-SHA-256 hashes (Cloudflare KV and Supabase). An AES-256-GCM encrypted copy is kept so you can view your TradingView link again | Until rotated or the account is deleted |
| Broker API credentials | AES-256-GCM ciphertext in Supabase. The decryption key exists only in isolated Cloudflare environment secrets | Until you delete the broker profile |
| Execution logs (status, error code, broker, ticker, side, bot, timing) | Supabase execution_logs, stored by month |
Shown in full for 90 days, then kept in an access-limited archive for 3 years so you can look up past activity, then permanently deleted by dropping whole months. You can ask for your logs to be deleted earlier |
| Replay-protection fingerprints (hash of alert id and timestamp) | Cloudflare Durable Object and KV | 60 seconds |
| Legal acceptance records (version, text hash, time, IP, user agent) | Supabase | Kept for the life of the account plus [RETENTION PERIOD], as evidence of consent |
| Billing records | Paddle, our merchant of record | Under Paddle's retention policy and the tax law that applies to it |
Raw webhook bodies and order payloads are never written to persistent storage.