Draft. OPERATOR and COUNTRY and EMAIL still needs to be filled in in services/legal.py. Until then this page is not indexed and is not in the sitemap.
Legal
Privacy Policy
What we hold about you, why we hold it, and how to get it back or have it deleted. No advertising trackers, no data sold, no profiles built for anyone else.
Last updated 20 September 2026
Who holds your data
the operator of Crypto War Room decides what is collected here and why. For any question about your data, or to exercise any of the rights below, write to the contact address published at /contact.
What we collect
When you make an account
A username, a display name, and either a password or a Google sign-in. Passwords are never stored — what is stored is a scrypt hash with a per-account salt, which cannot be turned back into your password. If you sign in with Google, we receive your email address, your name and your Google account identifier, and nothing else from your Google account.
While you use the room
The messages you post in chat and the images you upload, the signals you are shown, and which lessons you have marked complete. Session tokens are stored in your browser so you stay signed in.
If you connect an exchange
Your API key and secret, encrypted at rest with a key that is not in the database. They are only ever decrypted to place an order you asked for, are never returned to any caller, and are refused outright if they carry withdrawal permission.
Automatically
Ordinary server logs: IP address, browser user agent, the pages requested and when. Failed login attempts are recorded so an account can be locked after repeated failures.
We do not run advertising trackers, we do not sell data, and we do not build profiles of you for anyone else.
Why we are allowed to hold it
- To provide what you paid for — your account, the room, the signals. This is performance of our contract with you.
- To keep the service safe — login throttling, logs, abuse handling. This is our legitimate interest in a service that is not overrun.
- To meet legal obligations — payment and tax records.
Who else sees it
- Google, if you choose Google sign-in, under Google's own privacy policy.
- Our hosting provider, which runs the server your data sits on.
- The payment provider, when you pay. Card details go to them, never to us, and we never see or store them.
- Other members, for anything you deliberately post in chat.
Market data, news and research providers receive coin names and search terms, never anything that identifies you.
How long we keep it
Account data lives as long as your account does. Ask us to delete it and we will, except where we must keep payment records for tax purposes. Backups are kept for 30 days on a rolling basis, so deleted data can persist in a backup for up to a month before it ages out.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Write to the contact address published at /contact and we will answer within 30 days. If you are in the UK or EU you also have the right to complain to your data protection regulator.
Security
The site is served over HTTPS. Passwords are scrypt-hashed, exchange keys are encrypted with a secret held outside the database, logins are locked out after repeated failures, and members' uploads are served through links that expire rather than public URLs.
No service can promise it will never be breached. If one happens and it puts you at risk, we will tell you.
Children
This service is not for anyone under 18, and we do not knowingly collect their data.
Changes
If this policy changes, the date below changes with it, and material changes are announced in the room.