Privacy Policy
Last updated: April 2026
This Privacy Policy describes how the Talos platform ("Platform", "we", "us") collects, uses, and protects your information.
1. Information We Collect
1.1 Account Information
- Email address (used for authentication and account recovery)
- Display name (chosen by you, can be a pseudonym)
- Preferred language
1.2 Trading Data
- Exchange API keys (encrypted at rest, used solely for trade execution)
- Trading activity (pairs, positions, profits/losses) generated through the Platform
- Bot configuration preferences
1.3 Financial Data
- Deposit and withdrawal history
- Token balances and fee records
- Referral commissions
1.4 Technical Data
- IP address (used for rate limiting and security)
- Browser type and device information
- Session data and authentication tokens
1.5 Blockchain Data
- Cryptocurrency wallet addresses generated by the Platform
- Transaction hashes for deposits and withdrawals
2. How We Use Your Information
We use your information to:
- Provide and operate the Platform
- Execute trades on your behalf via exchange APIs
- Process deposits, conversions, and withdrawal requests
- Calculate and deduct applicable fees
- Track referral commissions
- Send in-app notifications (account activity, alerts, system updates)
- Maintain security (rate limiting, fraud detection, access logging)
- Improve the Platform (aggregated, anonymized analytics)
3. How We Protect Your Information
- API keys are encrypted using AES-256-GCM and decrypted only in memory during trade execution. They are never stored in plaintext.
- Security PINs are hashed using bcrypt and cannot be recovered — only reset.
- Authentication uses industry-standard JWT tokens with short expiration.
- Rate limiting is enforced on all endpoints to prevent abuse.
- Database access is restricted by row-level security — users can only access their own data.
- Administrative access is restricted to authorized personnel with audit logging.
4. Information Sharing
We do not:
- Sell, rent, or trade your personal information to third parties.
- Share your data with advertisers or marketing platforms.
- Provide your information to other users (except your public display name and referral alias).
We may share information:
- With supported exchanges, strictly limited to API calls necessary for trade execution.
- With blockchain networks, as required for deposit/withdrawal transactions (wallet addresses and transaction data are inherently public on-chain).
- If required by law, regulation, or legal process.
- To protect the rights, safety, or property of the Platform, its users, or the public.
5. Data Retention
- Account data is retained for as long as your account is active.
- Trading history and financial records are retained for compliance purposes even after account deletion.
- Upon account deletion request, personal identifiers (email, display name) are removed or anonymized. Financial records are retained in anonymized form.
- Encrypted API keys are permanently deleted upon account deletion or key removal.
6. Your Rights
You have the right to:
- Access your personal data through the Platform's interface.
- Correct your display name, language preference, and other profile information.
- Delete your account and associated personal data (subject to retention requirements in Section 5).
- Export your trading data through available Platform features.
- Withdraw consent by discontinuing use of the Platform and requesting account deletion.
To exercise these rights, contact us through the Platform's support channels.
7. Cookies & Local Storage
- The Platform uses browser local storage and cookies for authentication tokens and language preferences.
- No third-party tracking cookies are used.
- No advertising or analytics cookies are used.
8. Third-Party Services
The Platform interacts with:
- Cryptocurrency exchanges (for trade execution via API)
- Blockchain networks (for deposit/withdrawal processing)
- Authentication providers (for secure login)
These services have their own privacy policies. We encourage you to review them.
9. Children's Privacy
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect information from minors.
10. International Users
The Platform may be accessed from multiple jurisdictions. By using the Platform, you consent to the transfer and processing of your information in the jurisdiction where the Platform operates.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on the Platform with an updated date. Continued use after changes constitutes acceptance.
12. Contact
For questions about this Privacy Policy, contact us through the Platform's support channels.
By using Talos, you acknowledge that you have read and understood this Privacy Policy.