Privacy Policy
Version 0.4 · Effective 29 September 2026. This policy explains what information [Legal Entity Name] (“PenguinAlgos”, “we”, “us”) collects about you when you use penguinalgos.com and the PenguinAlgos platform, why we collect it, who we share it with, how long we keep it, how we protect it, and the choices you have. It forms part of our Terms of Service.
Contents
- 1. Who we are and what this policy covers
- 2. Information we collect
- 3. Cookies
- 4. How we use information
- 5. Who we share information with
- 6. What other users can see
- 7. How long we keep information
- 8. How we protect information
- 9. Your choices
- 10. Your privacy rights under state law
- 11. Do Not Track and Global Privacy Control signals
- 12. Children
- 13. Where information is held, and users outside the United States
- 14. Changes to this policy
- 15. How to contact us
1. Who we are and what this policy covers
PenguinAlgos is a software platform that transmits trading signals to brokerage accounts that belong to its users. It is operated by [Legal Entity Name] from the United States, and is offered to users located in the United States.
This policy covers the website at penguinalgos.com, the signed-in platform, the endpoints that receive strategy signals, and the emails and in-platform notices we send. It does not cover your broker or proprietary-trading firm, TradingView, Stripe, or any other service you use alongside ours. Each has its own privacy policy, and what they do with your information is governed by it, not by this one.
When you create an account you accept this policy alongside the Terms of Service. If the Terms and this policy say different things about how we handle information, this policy governs.
2. Information we collect
Information you give us
- Account details. Your email address and a password. We store the password only as a one-way hash (Argon2); we cannot read it, and neither can anyone who obtains a copy of our database.
- Broker connections. The login for each brokerage or prop-firm account you connect — a username and password, or an API key or similar credential, depending on the broker — together with the account identifiers the broker returns, and any display name you give the account. Credentials are stored encrypted (section 8).
- Configuration. Which strategies you have switched on, for which accounts, at what contract size; pauses and halts; your portfolios, watchlists and settings such as your cross-hedging preference; and the copy-trading groups you lead or follow.
- Strategies you build or publish. Their names, descriptions and images, the TradingView trade list you upload for a track record, the alerts you configure to send signals, and whether you have made the strategy visible to others.
- Preferences. Your theme and timezone.
- Correspondence. What you send us when you ask for support, and our replies.
Information collected automatically
- IP address. Recorded when you create an account, as part of the record that you accepted the Terms and this policy; used to rate-limit sign-ups and login attempts; and written to server logs with the page requested, the time and the result. Our logs carry no tracking identifiers.
- Sign-in records. When you last logged in, a hash of each active session token and its expiry, the count of recent failed login attempts, and any lockout.
- Activity records. An audit log of actions taken on your account — sign-up, login, a strategy switched on or off, an account connected, paused or disconnected, a setting changed — each with a timestamp; and the in-platform notifications we have sent you.
- Browser security reports. If a page tries to load something our security policy forbids, your browser sends us a short technical report naming the page and the blocked resource.
Information from your broker
Once you connect an account, we retrieve from the broker what the platform needs to trade it and to keep the picture straight: the account's identifiers and status (for example whether the firm shows it active), its balance, its open positions, and the orders and fills placed through it. The platform continually compares what it believes the account holds with what the broker reports, so this information is fetched throughout the time an account is connected.
Information from strategy signals
Strategy signals arrive as webhook alerts from a charting service such as TradingView, or — for copy trading — from changes in a leader account's positions. A signal names the strategy, the instrument, the action and the time. It identifies you only through the webhook token issued to your account; it carries no other personal information.
Payment information
If you buy a subscription, payment is handled by Stripe. We create a customer record at Stripe holding your email address and your internal user number. Stripe collects your card details directly on its own pages and never passes them to us; we receive your Stripe customer identifier, the status and renewal dates of your subscription, and whether a payment succeeded. Stripe's handling of your card and identity information is governed by Stripe's privacy policy.
3. Cookies
We set a small number of cookies, all of them our own and none of them for advertising or analytics:
| Cookie | What it does | Lasts |
|---|---|---|
pa_session | Keeps you signed in. Marked HttpOnly, so scripts on the page cannot read it. | 30 days, or until you log out |
pa_csrf | Protects the forms you submit against cross-site request forgery. | 1 year |
pa_theme | Remembers light or dark mode. | 1 year |
pa_tz, pa_tz_pin | Your timezone, detected from your browser or chosen in Settings, so that times are shown in it. | 1 year |
Our pages load no third-party scripts, fonts, pixels or embedded content, so visiting them discloses your visit to nobody but us. You can block or delete cookies in your browser; if you block them, you will not be able to stay signed in.
4. How we use information
We use the information described above to:
- Run the service — authenticate you, connect to your broker with the credentials you gave us, transmit the orders your configuration calls for, reconcile positions, and show you your accounts, positions and trade history.
- Keep accounts secure — rate-limit sign-ups and logins, lock an account after repeated failed attempts, detect and investigate misuse, and warn you of suspicious activity such as a sign-up attempted with your email address.
- Support you — answer your questions and diagnose problems, which often means reading your account's activity and trade records.
- Bill you — for any subscription you buy, through Stripe.
- Send service communications — verification and password-reset codes, security notices, notices of changes to the Terms or this policy and, where you have strategies enabled, a summary of their activity; and in-platform notifications about your own account, such as a rejected order or a halt.
- Publish what you choose to publish — a strategy you list on the Marketplace, with its performance record (section 6).
- Operate and improve the platform — using aggregate figures such as counts of sign-ups, logins, signals and trades. Our internal operating reports are built from counts and strategy names, never from identities.
- Meet legal obligations and resolve disputes — including keeping the record of what was traded in your name.
We do not use your information to build advertising profiles, and we do not send marketing email without your consent. Where we ask for consent to something new, you can withdraw it at any time.
6. What other users can see
By default, nothing. Your email address, your broker accounts, their balances, positions and trade history, and your configuration are private to you and to us.
If you publish a strategy on the Marketplace, every signed-in user can see its name, description and images, and its performance record, built from the signals it has sent and from any trade list you uploaded. It is listed under the strategy's own name; we do not show your email address with it. Withdrawing a strategy removes it from the Marketplace, but not from the notes of people who already saw it.
If you share a copy-trading group, the people who follow it see the trader name you chose and the positions mirrored into their accounts as signals. They never see your account identifiers, your balance or your broker login. As the leader, you see the email address of each user who asks to follow you, so that you can approve or decline them.
If you follow a copy-trading group, its leader sees your email address, that you follow, and the standing of your request. The leader does not see your balance or your broker login.
7. How long we keep information
- Your account and its configuration: for as long as the account exists. Deactivating an account ends its sessions and stops its trading; the account record is kept, marked inactive.
- Broker credentials: for as long as an account that uses them is connected. When you disconnect the last account connected through a broker login, the stored login is erased; the broker username stays with the disconnected account's record, so its history still says which login it traded under. A login you verify but never connect an account to is erased automatically after one day.
- Signals, orders, fills, positions and the audit log: kept after an account is disconnected and after your account is closed. They are the record of what was done in your name; we may need them to meet legal obligations, to resolve a dispute, and to keep published track records honest.
- The record of your acceptance of the Terms and of this policy, with the version, the time and your IP address: kept indefinitely, as evidence of the agreement.
- Sessions: 30 days, or until you log out or reset your password. One-time verification and reset codes expire minutes after they are sent.
- Server logs: [log retention period].
- Backups: we take a daily backup of the database and keep each for 30 days. Information deleted from the live system persists in backups until they age out.
- Stripe's records of your customer account and payments are kept by Stripe under its own policy.
8. How we protect information
Every connection to the service is encrypted in transit. Passwords are stored only as salted Argon2 hashes. Broker credentials are encrypted at rest with authenticated encryption, under a key that is held outside the database, and are decrypted only when the trading process connects to your broker; they are never written to logs. Session cookies are HttpOnly and SameSite; forms carry anti-forgery tokens; pages are served under a content security policy; sign-ups and logins are rate-limited, and repeated failed logins lock the account. Access to the production system is limited to named operators using key-based authentication.
No system is perfectly secure. If you believe your account has been compromised, tell us at once at support@penguinalgos.com. If we learn of a breach that affects your personal information, we will notify you, and any authority we are required to notify, in the manner and within the time the law requires.
9. Your choices
- See and change your information. Your accounts, strategies, configuration, notifications and preferences are all shown in the platform and can be changed there. Your trade records are shown on each account's page.
- Disconnect a broker account. On the account page, turn every strategy off, then use Disconnect. Disconnecting the last account on a broker login erases the stored login (section 7).
- Sign out everywhere. Changing your password through the reset flow revokes every session.
- Close your account. Yourself, under Settings → Close your account, or ask us at support@penguinalgos.com. Closing ends your subscriptions, disconnects your broker accounts (which erases their stored logins) and signs you out everywhere; section 7 explains what is kept and why. Strategies have to be switched off first, so open positions finish the normal way (section 9 of the Terms).
- Email. Service emails — codes, security notices, notices of changes to the Terms or this policy — are part of having an account and cannot be switched off while it is open. We do not send marketing email unless you ask for it, and any such email will carry an unsubscribe link.
- Cookies. See section 3.
10. Your privacy rights under state law
Depending on where you live, state law may give you the right to know what personal information we hold about you and to receive a copy of it, to correct it, to delete it, to opt out of its sale or of its sharing for targeted advertising, and not to be treated differently for exercising those rights. Laws of this kind include the California Consumer Privacy Act as amended by the California Privacy Rights Act, and similar statutes in other states. Several apply only to businesses above a size threshold; we will honour requests from any user regardless.
We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding twelve months, so there is no sale or sharing to opt out of. We do not use or disclose sensitive personal information for any purpose other than providing the service you asked for.
For California residents: the categories of personal information we have collected in the preceding twelve months, their sources and our uses of them are set out in sections 2, 4 and 5. In the statute's terms they are identifiers (email address, IP address, internal account identifiers), account credentials, commercial information (subscriptions and trades), financial account information received from your broker (balances, positions, orders and fills), internet activity on our service (server logs, the audit log), and the content you submit. We disclose them for the business purposes in section 5 only.
To make a request, email support@penguinalgos.com from the address on your account, or tell us how to verify that the account is yours. An authorised agent may make a request for you with written permission we can verify. We will respond within 45 days, extending once by a further 45 days where necessary and telling you why. We may decline part of a deletion request where the law lets us keep the information — in particular the trade, order and audit records and the record of your acceptance of the Terms, described in section 7 — and we will tell you what we kept and why. If we deny a request, you may ask us to reconsider by replying to our response.
California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing. Nevada: we do not sell covered information, and there is nothing to opt out of.
11. Do Not Track and Global Privacy Control signals
We do not track you across other websites, and we do not sell or share your information, so there is nothing for a Global Privacy Control signal to switch off: we treat every visitor as though the signal were set. We do not change how the service behaves in response to a browser’s Do Not Track header, because there is no tracking to stop.
12. Children
The service is for adults. You must be at least 18 to create an account, and we do not knowingly collect information from anyone under 18. If you believe a child has given us information, tell us at support@penguinalgos.com and we will delete it.
13. Where information is held, and users outside the United States
We store and process information in the United States. The service is offered to users in the United States and is not directed at residents of the European Economic Area, the United Kingdom or any other jurisdiction outside the United States. If you nonetheless use it from elsewhere, you do so on your own initiative, and your information will be transferred to and held in the United States, whose privacy laws may differ from those where you live.
14. Changes to this policy
We may update this policy. The version and effective date at the top change when we do, and earlier versions are available from us on request. Where a change would materially expand what we collect, how we use it or who we share it with, we will tell you by email and in the platform at least 30 days before it takes effect. For other changes we will post the updated policy, and continuing to use the service after the effective date means the new version applies to you. If you do not agree to a change, close your account before it takes effect.
15. How to contact us
Questions, requests and complaints about privacy: support@penguinalgos.com. Written notices: [Legal Entity Name], [notice address].
Create an account · Log in · Home · Terms of Service · Privacy Policy · support@penguinalgos.com