Privacy Policy
In force since 6 September 2026 · Last updated: 6 September 2026
This policy describes which data CryptoTrader - TradingView Organizer — the Chrome extension that adds a sidebar to TradingView Web — collects, why it collects it, who it is shared with and how you exercise your rights.
The most important point: your exchange API keys never leave your computer. They are encrypted with 256-bit AES-GCM using a master key marked as non-extractable, kept in the extension's own private storage. Neither CryptoTrader, nor our server, nor any third party receives those keys. Orders go from your browser straight to the API of the exchange where you registered the key.
1. Who is the controller
The party responsible (controller) is the developer of CryptoTrader, who can be contacted at cryptotrader.trade@gmail.com. This is also the channel for any request regarding personal data.
2. Data we collect
The extension only works on tradingview.com pages. Outside them it is
not loaded and collects nothing. Every data transmission goes to our server at
https://st.cryptotrader.trade.
| Data | How it is obtained | When it is sent | Purpose |
|---|---|---|---|
| E-mail and nickname | Sign-up form in the Account tab | On sign-up and when changing your details | Create and identify your account; send the validation link, the password set/reset link and the account change link |
| TradingView username | Read from the settings page of your own TradingView account, already authenticated in your browser | On sign-up, when checking the account status, on login, on password reset and when requesting a change of details | It is the account's identity in the extension: it links the registration to your TradingView user and appears as the author of the analyses you publish |
| Password | Defined by you through the link sent to your e-mail | On login and when setting/changing the password | Authenticate you. We store only the hash (scrypt), never the password |
| Language selected in TradingView | Browser environment | On sign-up and when changing your details | Send e-mails and display the interface in your language |
| Feedback message, with the symbol on screen, the extension version, the language and the browser's user agent | Form in the Send feedback tab | Only when you click Send | Handle and diagnose the reported problem, bug or suggestion |
| Shared analyses: chart drawings and studies, symbol and the text of the comments | From your chart, when you use the sharing feature | Only when you publish an analysis or comment on one | Allow someone else to reproduce your analysis through the generated code |
| Installed version of the extension | From the package itself | On every call to the server (X-TVA-Version header) |
Compatibility and mandatory update notices |
| Daily usage record: your username and the date | Generated on the server | Automatically, on each day you use the extension while signed in | Active user count. It does not record what you did, nor which symbols, orders or amounts |
2.1. Data we do not collect
- Exchange API keys and secrets — they stay encrypted on your device only, as described above.
- Your balances, positions, orders and results — they are read straight from the exchange by your browser and displayed in the sidebar. They do not go through our server.
- Your TradingView plan and the remaining days — they are read and displayed locally only, in the Account tab. They are not sent to the server.
- Your browsing history — the extension does not watch or record
visited pages; it is only loaded on
tradingview.com. - Your IP address is not stored in a database. It is used only in memory, at the moment of the request, to limit abuse (rate limit), and discarded right after.
- We do not use tracking cookies, advertising, third-party analytics or fingerprinting. The only existing cookie is the session cookie of our server's account page — technical and strictly necessary.
3. Legal basis
- Performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b)) — sign-up, authentication, operation of the tabs, sharing of analyses and sending the transactional e-mails. Without that data the extension does not work.
- Legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)) — security (abuse limiting), active user count and diagnosis of the feedback received. You may object at any time through the contact e-mail.
- Consent (LGPD art. 7, I; GDPR art. 6(1)(a)) — accepting this policy and the Terms of Use at sign-up, and the publication of each shared analysis, which only happens through an action of yours.
4. Who we share it with
We do not sell, rent or assign personal data. We use two processors, exclusively to provide the service:
- Supabase — the database holding the registration, the sessions, the feedback and the shared analyses. Access is made only by our server, with a service key; the tables have Row Level Security enabled and no public access policies.
- Brevo — sending the transactional e-mails (e-mail validation, password set and reset, change of details). It receives the destination address and the content of the message.
The application server runs on our own VPS at Contabo. We may disclose data if legally required to do so by a competent authority.
International transfer: these providers may process data outside Brazil. The transfer takes place based on the contractual clauses and safeguards offered by each of them, in accordance with the LGPD (art. 33) and the GDPR (Ch. V).
5. How long we keep it
- Registration (e-mail, nickname, TradingView user, password hash, language) — for as long as your account exists. It is deleted when you request the deletion.
- Login sessions — they expire within 90 days and are swept automatically from the database. Logging out invalidates the session immediately.
- E-mail login codes — they expire in about 15 minutes and are also swept automatically.
- Feedback — kept while useful for the support and diagnosis history; it can be deleted at your request.
- Shared analyses and comments — they remain available until you delete them through the extension itself, or until the account is deleted.
- Daily usage record — kept for the active user metric.
6. Your rights
Under the LGPD (art. 18) and the GDPR (arts. 15 to 22), you may request: confirmation of the processing and access to your data; correction of incomplete or outdated data; anonymization, blocking or erasure; portability; information about the sharing; withdrawal of consent; and objection to processing based on legitimate interest.
6.1. How to change your data
Nickname, e-mail and password are changed by you: in the Account tab, click Change account details. We send a link to the registered e-mail — possession of the e-mail is what authorizes the change.
6.2. How to request account deletion
The extension does not have a self-deletion button yet. Send an e-mail to cryptotrader.trade@gmail.com from the registered address, asking for the deletion and including your TradingView username. We answer within 15 days, deleting the registration, the sessions and the published analyses.
To erase what is on your device — including the encrypted API keys — just remove the extension from the browser; or, before that, delete each exchange account through the Exchanges tab.
7. Security
- All traffic is HTTPS-only, with a fixed list of allowed destinations. The authorization header is sent only to our own server.
- Exchange API keys: AES-GCM 256 with a non-extractable master key, in the extension's private storage.
- Session token kept out of reach of web pages, in the extension's private area;
on the account page, in an
HttpOnlycookie. - Password stored only as a scrypt hash.
- The extension runs no remote code: no
eval, no CDN scripts, no code downloads. Everything that runs comes inside the package published on the Chrome Web Store.
No system is 100% secure. We recommend creating the API keys without withdrawal permission and revoking them on the exchange if you stop using the extension.
8. Minors
CryptoTrader is not intended for people under 18 and we do not knowingly collect data from children and teenagers. If we identify a registration in that condition, it will be deleted.
9. Limited use of data (Chrome Web Store)
The use of the information received by CryptoTrader complies with the Chrome Web Store's Limited Use policy. In particular:
- the data is used only to provide and improve the user-facing features described in this policy;
- we do not transfer data to third parties, except to the processors listed in section 4, where necessary to provide the service, by legal requirement, or in a security investigation;
- we do not use or transfer data for advertising, marketing, data brokerage or creditworthiness assessment;
- we do not allow humans to read user data, except with express consent (for example, when analysing feedback you sent), by legal requirement, for security, or when the data is aggregated and anonymized.
10. Changes to this policy
We may update this document. The last-updated date at the top always indicates the version in force. Relevant changes will be communicated by e-mail or inside the extension itself before they take effect.
11. Contact
Questions, access or deletion requests, or any privacy matter: cryptotrader.trade@gmail.com. You may also complain to the ANPD (Brazil's National Data Protection Authority) or to the data protection authority of your country.