Skip to content

Privacy notice

Draft: a lawyer has to review this text and the operator's details must be filled in before the public launch.

Effective from 4 October 2026 (draft)

1. Controller

Controller: [operator's name, address, e-mail – to be filled in].

2. What we process

Account: username, display name, a one-way fingerprint of the password (scrypt), plan, creation and last sign-in time.

Synced settings: workspaces, watchlists, alerts, lab cells, community nickname and its key, VX AI personal notes – only while you are signed in.

Community: the posts, team messages and notes you publish, with your nickname. API tokens and sessions: only their fingerprints.

Technical data: the IP address for overload limits, in memory only and briefly; anonymous VX AI usage statistics (question words, not the full text).

3. Purpose and legal basis

The account and the sync are necessary to provide the service (GDPR Art. 6(1)(b) – performance of a contract). Security limits and logs rely on legitimate interest (Art. 6(1)(f)).

4. Retention

Account data is kept until the account is deleted; sessions live at most 30 days. Community posts stay until their author deletes them.

5. Recipients

Hosting provider: [to be filled in]. External data sources (prices, statistics) receive no personal data – the browser talks only to our server.

Exception: when you start a live broadcast, the player loads from YouTube's privacy mode (youtube-nocookie.com); until then YouTube receives nothing.

6. Cookies and local storage

We use a single cookie: the sign-in session (necessary, httpOnly). Your settings live in your browser's local storage. No tracking, advertising or analytics cookies.

7. Your rights

Access and portability: My account → Download my data. Erasure: My account → Delete account. Rectification, objection, restriction: write to the controller.

You may lodge a complaint with the Hungarian data protection authority (NAIH).

8. Security

Passwords, licence keys, sessions and API tokens are stored only as one-way fingerprints; in production the connection is encrypted (HTTPS) and the session cookie cannot be read by JavaScript.