Privacy Policy

This page explains what data we collect, why we need it and what you can do with it.

Revised on July 25, 2026Version 1.0Terms of Use

1. Who processes your data

The data controller is the owner of the Finzli service (finzli.com). Full operator details will be added to this section once a legal entity is registered.

For any questions about data processing, as well as for access, correction or deletion requests, contact our support team on Telegram. We aim to respond within a reasonable time, usually within 30 days.

2. What data we collect

We collect only the data required for the service to function. Below is a complete list by category.

  • Registration data: email address, password stored as an irreversible hash, name and username, profile image. The password itself is never stored: neither the site administration nor support can see or recover it, it can only be set anew. When you sign in with Google we receive your Google account identifier, email address and profile image; no password is created at all in that case.
  • Profile settings: time zone, interface language, appearance, notification and privacy preferences, your list of favourite coins and widgets.
  • Telegram data: your Telegram chat identifier and username, if you have connected the notification bot.
  • Technical data: IP address, country and region derived from it, internet provider, device type, a technical device identifier and a set of device signals, dates and times of visits, and actions within the interface.
  • Subscription and payment data: the selected plan, its validity period, the history of cryptocurrency payments (network, amount, transfer address, transaction identifier), promo codes used, and a wallet address if you take part in the affiliate programme and receive payouts.
  • Trading Journal data: exchange API keys in encrypted form, the imported history of your trades, your deposit size and its changes, and the resulting statistics. This data is stored on our servers until you delete the connection or your account.
  • Content you publish: posts, comments, signals, images, clubs and membership requests, direct messages, and reports about other users’ content.

3. Why we process data

  • To provide access to the service: create your account, authenticate you, and present the interface in your language and time zone.
  • To deliver the subscription you paid for: unlock the plan, extend or close it, apply promo codes, and calculate and pay affiliate rewards.
  • To run the features you have enabled: on-site and Telegram notifications, trade import into the Journal, participation in the League, and community publishing.
  • To protect subscriptions and free offers from abuse: the service allows one active session per account and grants a trial once per user, so we compare the device identifier and its technical signals, the IP address and the login region.
  • To keep the platform in order: review reports, hide violating content, and restrict access in cases of abuse.
  • To improve the service: analyse load, errors and which sections are used. Aggregated, non-identifying statistics are sufficient for this.

5. Exchange API keys

The Trading Journal works through your exchange API keys. These are the most sensitive data you entrust to us, so we describe how they are handled separately.

  • Keys are used solely to read your trade history and current balance. The service does not place orders, does not open or close positions, and does not transfer or withdraw funds.
  • When you add a key we verify it with the exchange and recommend granting read-only permissions. Do not grant trading or withdrawal rights: the service does not need them.
  • The key and secret are stored encrypted in our database and are not displayed in the interface after saving.
  • You can delete a connection at any time in the Journal section. Once deleted, the key is erased from our database. We also recommend revoking the key on the exchange side.

6. AI-generated analysis

Some texts in the service are generated automatically by language models. These include Pulse AI analyses, signal explanations, and news headlines and summaries. Such texts are marked in the interface and, by their nature, may contain inaccuracies.

We use third-party language model providers for this generation. They receive market data only: the instrument ticker, prices, volumes, order-book and liquidation metrics. Your personal data, trade history and the contents of your direct messages are never sent to language models.

7. External services

We do not sell your data, do not share it for third-party advertising, and do not disclose it to anyone for their own purposes. The service does not run in a vacuum: some data is processed on the infrastructure of providers it cannot operate without, while other data we receive from outside at your request. Below are all such points of contact.

  • Hosting provider: your data is stored on its servers because the service runs there. The provider does not use it for its own purposes.
  • Google: when you sign in with a Google account we receive your identifier, email address and profile image from Google. We also run Google Analytics, which receives anonymised visit data: the page, the referring source, the country and the device type. Your name, email, journal contents and exchange keys are never sent there.
  • Exchanges: if you connected the Journal, requests are made with your own key and we receive your trade history and balance from there.
  • Telegram: if you connected the bot, your notification texts are sent to Telegram, otherwise they cannot be delivered.
  • Language models: only market data is sent to them, as described above. These requests contain no personal data.
  • Blockchain networks: when you pay, the transfer and its amount are visible in the public network by the nature of the network itself, not because we disclose anything.

8. Where data is stored

The service’s servers are located in the European Union, where common European data protection rules apply. If our infrastructure changes, we will update this section.

The external services listed in the previous section run on their own infrastructure and under their own rules, including outside the EU. We aim to keep any interaction with them limited to the minimum information required, but we are not responsible for their internal processes.

9. Automated decisions

Some decisions are made by the service without human involvement: ending a previous session when you sign in from another device, refusing a repeat trial period, automatic restrictions when abuse indicators appear, and algorithmic selection of publications for the community feed.

These decisions do not concern your funds and create no legal consequences for you beyond access to the service. If you believe the automation got it wrong, contact support: a human will review your case and lift the restriction if the error is confirmed. We do not disclose how our protective mechanisms work or what triggers them, as that would make them easier to circumvent.

10. What other users can see

Some data you publish yourself and it is public by definition: your username, profile image, your posts, comments and signals, and club membership. Your email address and last-seen time are shown only if you enable them in privacy settings.

Two features deserve special attention. Joining the League makes your relative statistics (percentage return, win rate, number of trades, average leverage) visible in the public leaderboard. The public journal opens the sections you select via a link, and if you enable deposit display, others will also see absolute amounts. Both features are optional and can be turned off in settings.

11. Cookies and browser storage

We use cookies and browser storage to run the site: the authentication session, your chosen language, interface and chart settings, and a technical device identifier used to protect subscriptions. We do not use cookies for advertising and do not open them to ad networks.

Since 25 August 2026 we additionally use Google Analytics cookies: they show which sections people use and where visitors come from. For visitors from the European Union, the European Economic Area and the United Kingdom this counter does not load at all until you press Accept in the consent bar. You can withdraw or change your decision at any time: the Cookies link in the site footer reopens the same bar, and declining turns the counter off in any country.

If you clear your browser storage, the interface will reset to its defaults and you will need to sign in again.

12. How long we keep data

  • Account and profile data are kept for as long as the account exists.
  • Imported trade history is kept indefinitely until you delete the connection or your account.
  • Session records and technical logs are kept for a limited period needed for security and diagnostics.
  • Payment records are kept for a limited period needed to confirm payments and resolve disputes.
  • After deletion, data disappears from the live database immediately but remains in backups for a limited period until they are rotated on schedule. Data is not restored from backups except during full disaster recovery.

13. Your rights

You manage your data yourself in your profile: change your details, disconnect Telegram, remove an exchange connection, close the public journal, leave the League.

You can also delete your account entirely right there, with no requests and no waiting. Deletion is irreversible: your profile, exchange connections, imported trade history and your content are erased together with the account. Any active subscriptions end with no right of restoration, payment for the unused period is not refunded, and collectible coins and received gifts are lost.

If you need a copy of your data or have questions about how it is processed, contact support.

14. Security

The connection to the site is encrypted. Passwords are stored as irreversible hashes and remain inaccessible to the site administration even with full database access; exchange API keys are stored encrypted. Server access is restricted and administrative actions are logged. No system can rule out incidents entirely, so enable two-factor authentication on your exchange and avoid reusing passwords across services.

If an incident occurs that could harm users, we will announce it on the website and, where necessary, notify affected users through available channels, and advise what to do: change your password, revoke exchange keys, review active sessions.

15. Age restriction

The service is intended for persons aged 18 and over. We do not knowingly collect data from minors. If we learn that an account was created by a minor, it will be deleted.

16. Changes to this policy

We may update this document when the service or legal requirements change. The date of the latest revision is shown at the top of the page. We will announce material changes on the website.

Any questions about this document? Write to support and we will sort it out.

Contact support
Privacy Policy - Finzli