Privacy notice
Draft: a lawyer has to review this text and the operator's details must be filled in before the public launch.
Effective from 4 October 2026 (draft)
1. Controller
Controller: [operator's name, address, e-mail – to be filled in].
2. What we process
Account: username, display name, a one-way fingerprint of the password (scrypt), plan, creation and last sign-in time.
Synced settings: workspaces, watchlists, alerts, lab cells, community nickname and its key, VX AI personal notes – only while you are signed in.
Community: the posts, team messages and notes you publish, with your nickname. API tokens and sessions: only their fingerprints.
Technical data: the IP address for overload limits, in memory only and briefly; anonymous VX AI usage statistics (question words, not the full text).
3. Purpose and legal basis
The account and the sync are necessary to provide the service (GDPR Art. 6(1)(b) – performance of a contract). Security limits and logs rely on legitimate interest (Art. 6(1)(f)).
4. Retention
Account data is kept until the account is deleted; sessions live at most 30 days. Community posts stay until their author deletes them.
5. Recipients
Hosting provider: [to be filled in]. External data sources (prices, statistics) receive no personal data – the browser talks only to our server.
Exception: when you start a live broadcast, the player loads from YouTube's privacy mode (youtube-nocookie.com); until then YouTube receives nothing.
6. Cookies and local storage
We use a single cookie: the sign-in session (necessary, httpOnly). Your settings live in your browser's local storage. No tracking, advertising or analytics cookies.
7. Your rights
Access and portability: My account → Download my data. Erasure: My account → Delete account. Rectification, objection, restriction: write to the controller.
You may lodge a complaint with the Hungarian data protection authority (NAIH).
8. Security
Passwords, licence keys, sessions and API tokens are stored only as one-way fingerprints; in production the connection is encrypted (HTTPS) and the session cookie cannot be read by JavaScript.