None
We have never sold personal data
No advertising or data brokers
Sign out of CryptoPilot on this device? Your theme and layout preferences are kept.
Version 3.6 · effective 1 Aug 2026 · 12 sections
None
We have never sold personal data
No advertising or data brokers
AES-256
At rest · TLS 1.3 in transit
API keys sealed in an HSM
30 days
After closure, then deleted
Except records the law requires us to keep
30 days
Maximum, for any privacy request
Exports usually complete same day
What we hold, why we hold it, and what you can do about it
Your trading history says a great deal about you, and we treat it accordingly. This policy explains in plain terms what we collect, the reason for each piece, who else ever sees it, how long it survives and the controls you hold over it. It applies to the dashboard, the mobile apps and our APIs.
CryptoPilot Technologies Pte. Ltd., 12 Marina Boulevard, Singapore 018982, is the data controller for the personal data described here. Where we process data on behalf of an institutional client, that client is the controller and we act as processor under a separate agreement.
This policy sits alongside our Terms of Service, which govern your use of the platform generally.
We collect only what a feature actually needs. Data falls into four groups:
Each purpose below is tied to a specific lawful basis under GDPR and equivalent laws. We do not repurpose data beyond what is listed without telling you first.
| Purpose | Data used | Legal basis | Retention |
|---|---|---|---|
| Run your account | Account, technical | Contract | Life of account + 30 days |
| Execute and track trades | Trading, account | Contract | 7 years |
| Generate AI signals | Trading, market data | Contract | Life of account |
| Verify identity (KYC) | Verification | Legal obligation | 5 years after closure |
| Prevent fraud and abuse | Technical, trading | Legitimate interest | 2 years |
| Improve the product | Technical, aggregated usage | Legitimate interest | 14 months |
| Marketing emails | Email, preferences | Consent | Until you withdraw it |
Where we rely on legitimate interest we have weighed it against your rights and can share that assessment on request. Where we rely on consent, you can withdraw it at any time without affecting anything done beforehand.
Exchange API keys are the most sensitive data we hold, and they are handled apart from everything else. Keys are encrypted with AES-256 under a key held in a hardware security module, are never written to logs, and are never visible in plaintext to our staff — including support.
Our signal models are trained on market data — prices, volumes, order books, on-chain activity and public news. They are not trained on your individual trading history, and your positions are never used to train a model that serves another user.
Your own data is used at inference time to personalise what you see: your portfolio shapes your risk assessment, and your holdings decide which signals reach you. That processing happens for your account and stays within it.
We may compute aggregate, de-identified statistics — for instance, the share of users holding an asset — and publish them. These cannot be traced back to an individual, and no single user's activity is identifiable in the output.
We do not sell personal data, and we have never done so. We share it only in these circumstances:
A current list of sub-processors is available on request and is updated whenever one changes.
We operate from Singapore with infrastructure in Singapore, Frankfurt and Virginia. EU and UK data is stored in Frankfurt by default and is transferred outside that region only where necessary to operate the service.
Such transfers rely on the European Commission's Standard Contractual Clauses, the UK Addendum, and a transfer impact assessment for each destination. Copies are available from our Data Protection Officer.
Retention periods are set out per purpose in section 3. Broadly: account data goes 30 days after closure, trade records are held seven years, verification documents five years, and analytics 14 months.
The 30-day window after closure exists so an account closed by mistake — or by someone who should not have had access — can be restored. After it passes, deletion is permanent and cannot be reversed. Backups containing deleted data expire within 35 days.
Where the law obliges us to keep a record, we retain that record alone and delete everything else.
No system is perfectly secure. If a breach affects your personal data and poses a real risk to you, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, and tell you what happened and what to do.
Depending on where you live you have some or all of the following rights. We honour them for every user regardless of jurisdiction, and we never charge for exercising one.
Most of these are self-service in Settings → Privacy. For the rest, email privacy@cryptopilot.example — we respond within 30 days and will tell you promptly if a request genuinely needs longer. You may also complain to your local supervisory authority.
We use three categories of cookie:
We run no third-party advertising or cross-site tracking cookies, and we honour Global Privacy Control signals automatically. Preferences can be changed at any time in Settings.
When this policy changes materially — a new purpose, a new category of recipient, a longer retention period — we give at least 30 days' notice by email and in-app before it takes effect. Clarifications and typographical fixes take effect on posting.
Data Protection Officer · CryptoPilot Technologies Pte. Ltd. · 12 Marina Boulevard, Singapore 018982 · privacy@cryptopilot.example
EU representative: CryptoPilot Europe B.V., Herengracht 420, 1017 BZ Amsterdam, Netherlands. UK representative: CryptoPilot UK Ltd., 30 Finsbury Square, London EC2A 1AG.
For product questions rather than privacy ones, the Help Center and FAQ are faster.
Last reviewed 18 Jul 2026 by CryptoPilot Legal