Legal
Privacy Policy
- Effective
- 31 August 2026
- Last updated
- 31 August 2026
This policy describes AI Trading Terminal as it is actually built. Where a section says something is not collected, that reflects the current implementation — not an intention. It applies to the website at www.aitradingterminal.in and to the AI Trading Terminal Android application.
Introduction
This Privacy Policy explains what information AI Trading Terminal collects, why it collects it, how long it is kept, and what choices you have. It is written plainly and describes the service that exists today.
AI Trading Terminal is a market-analysis service. It reads public market data, produces analysis of it, and shows that analysis to you. It is not a broker, an exchange, or a trading venue.
By using the website or the Android app, you agree to this policy. If you do not agree with it, please do not use the service.
Who operates AI Trading Terminal
AI Trading Terminal is operated by Nilesh Mandloi as an independent software developer and operator. AI Trading Terminal provides market analysis, trading intelligence, educational information, and related software services.
For privacy, support, or data-related inquiries, users may contact us using the contact information provided in this Privacy Policy.
In this policy, “we”, “us” and “our” mean the operator described above.
Information we collect
We collect as little as the service can function on. In summary:
- Account and authentication information — a single opaque account identifier from your Google sign-in. See section 4.
- Device and technical information — standard web-server request records, and a browser identification string stored alongside a notification registration. See section 5.
- Notification registration data — only if you turn notifications on. See section 8.
- Preferences stored on your own device — which never reach us. See section 9.
We do not ask for or collect your name, email address, postal address, phone number, date of birth, payment details, or any government identification. There is no contact form, newsletter, comment system or profile page in the service, and no field anywhere that accepts a password.
Account and authentication information
Signing in uses Google Sign-In through Firebase Authentication, a Google service. The flow works like this:
- Google authenticates you and issues a short-lived identity token to the app.
- Our server verifies that token with Google and reads one value from it: your Firebase user ID — an opaque identifier for your account on this service.
- Every other claim in that token — including your email address, display name, profile photo and sign-in provider — is discarded at that point, and is never stored or logged.
- Our server then creates its own session and sets a session cookie in your browser or app.
What a session record contains on our server, in full:
- your Firebase user ID;
- a SHA-256 hash of the session token — never the token itself, so the token cannot be recovered from our storage;
- the time the session was created;
- the time it was last used.
Your interaction with Google during sign-in is governed by Google’s own privacy policy. We never see or receive your Google password, and there is no password field anywhere in this service.
Device and technical information
- Server request logs. Like any web server, ours records a standard entry for each request: the IP address it came from, the date and time, the URL requested, the response status and size, the referring page, and the browser or app identification string. These records exist so the service can be operated, secured and debugged.
- Notification diagnostics. If you enable notifications, we store the browser or app identification string next to the registration so an operator can recognise a stale entry. It is never parsed, and never matched against anything else.
- Android network state. The app checks whether a usable network connection is present, so it can retry a failed request by itself instead of waiting for you. That check happens on the device; the result is not transmitted or stored, and it gives no access to your traffic, browsing history or location.
The Android app requests three permissions and no others: internet access, network-state access, and permission to post notifications — which is asked for only when you turn notifications on, never at launch. It does not request or use access to your location, camera, microphone, contacts, call logs, SMS, files or photos, and it collects no advertising or device identifier.
App usage, diagnostics and analytics
We do not use any analytics or product-measurement service. The website and the Android app contain no Google Analytics, no Google Tag Manager, no Firebase Analytics, no Firebase Crashlytics, and no third-party analytics, attribution, crash-reporting, session-replay, heat-map or advertising SDK of any kind.
We do not build behavioural profiles, we do not track you across other websites or apps, and we do not use advertising identifiers. No usage event, screen view, click or session recording is sent anywhere.
Our server writes ordinary application logs so that faults can be diagnosed. Those logs are automatically scrubbed before they are written: session cookies, authorization headers, and any field named like a password, API key, secret or token are replaced with a redaction marker.
Market and trading data
Three different things are often confused under “financial data”. This section separates them.
(a) Market data is not personal data
The service analyses public market data about financial instruments: candles, prices and derived indicators for cryptocurrency perpetual futures obtained from Binance’s public market endpoints, together with a public market-sentiment index and a public economic-events calendar. This data describes markets, not you. Our server requests it directly; your browser and your phone play no part in those requests, and no information about you is sent to those sources.
The list of instruments the service analyses is a single shared configuration for the deployment. It is not a per-user watchlist, and it does not record who added a symbol.
(b) Personal data
The only personal data we hold is what sections 4, 5 and 8 describe.
(c) Broker and exchange credentials, and your trading activity
These are not handled at all, in any form. AI Trading Terminal is an analysis service. It does not connect to your exchange or broker account. It does not ask for, receive, store, transmit or use exchange API keys, API secrets, exchange passwords, wallet keys or seed phrases. It does not place, modify or cancel orders, does not move funds, and has no access to your balances, positions, order history, profit and loss, or portfolio.
This is a property of the implementation rather than a policy choice: the code contains no credential field, no request-signing path, and no order-placement route that could do any of these things.
The service produces market analysis for information purposes. It does not execute trades on your behalf, and it does not provide personalised investment advice.
Notifications
Notifications are off until you turn them on, and they are entirely optional. The service works without them.
- On the web, enabling them creates a Web Push subscription in your browser. We store the endpoint address your browser issues, the two public values your browser generates so a message can be encrypted for it, the browser identification string, and the time of registration.
- In the Android app, enabling them registers a Firebase Cloud Messaging token for that install. We store the token, the platform, which alert categories that device asked for, the app identification string, and the time of registration.
These registrations identify a device, not an account. They are not linked to your Firebase user ID, or to any other personal information we hold.
We also keep a short internal record of which market events have already been announced, so the same event is not sent twice. It contains a symbol, an event identifier, the analysis outcome and a delivery status — no user or device identifier — and it is deleted after 7 days.
You can turn notifications off at any time from the settings panel on the web or in the app. Doing so deletes that device’s registration from our server immediately. You can also revoke the permission in your browser settings or in Android system settings.
Delivery is carried out by Google (Firebase Cloud Messaging) for the Android app, or by your browser vendor’s push service for the website. The message payload is encrypted for your device.
How information is used
We use the information described above only to:
- sign you in, and keep you signed in;
- determine what your account is permitted to do;
- deliver the notifications you explicitly asked for;
- operate, maintain and secure the service, including detecting, investigating and preventing faults, abuse and unauthorised access;
- comply with applicable legal obligations.
We do not use your information for advertising, for profiling, for automated decision-making about you, or to train machine-learning models. The analysis this service produces is derived from public market data, not from your personal information.
Third-party service providers
These providers process data on our behalf, or as part of a feature you use:
- Google — Firebase Authentication
- Verifies your Google sign-in. Your Google credentials go to Google directly and never pass through our server; we receive only a token, from which we keep the account identifier.
- Google — Firebase Cloud Messaging
- Delivers notifications to the Android app. Receives the device’s registration token and the encrypted message.
- Your browser vendor’s push service
- Delivers web notifications — for example Google, Mozilla or Apple, depending on your browser. Receives the push endpoint and the encrypted message.
- TradingView
- Renders the price chart inside your browser. Receives your IP address and standard browser information, as any embedded content does.
- Hosting provider
- Runs the website, the application server and its storage on a virtual private server, and therefore holds everything the service stores.
These market-data sources receive no information about you: Binance (public market data), the public market-sentiment index, and the public economic-events calendar. Our server calls them for market data only; your browser and phone are not involved, and nothing identifying you is included in those requests.
Data storage and security
Measures actually in place today:
- all traffic is served over HTTPS, with HTTP Strict Transport Security and standard hardening response headers;
- the session cookie is HttpOnly, Secure and host-scoped, so it cannot be read by scripts or set by another subdomain;
- session tokens are 256-bit random values, and only a SHA-256 hash is ever written to disk — the token itself cannot be recovered from our storage;
- the application API is not exposed directly to the internet — it is reachable only through the web server — and the internal API documentation is not published publicly;
- application logs redact session cookies, authorization headers and secret-shaped fields before they are written;
- on Android the session token is held in encrypted storage backed by the Android Keystore, and system backup is disabled for the app;
- the number of simultaneous sessions per account is capped, and the oldest is discarded beyond that cap.
No system can be made completely secure. We cannot guarantee that information transmitted over the internet, or held on any system, will never be accessed by an unauthorised party, and nothing in this policy should be read as such a guarantee. If we become aware of a breach affecting your personal information, we will act in accordance with applicable law.
Data retention
We keep information only as long as it has a purpose.
- Session record
- Your account identifier, the session token hash and the two timestamps. Deleted 30 days after last use, or 90 days after creation, whichever comes first. Also removed when the per-account session cap discards it.
- Notification registration
- Kept until you turn notifications off, or until the push service reports that the registration is no longer valid — at which point it is removed automatically.
- Notification de-duplication record
- Contains no user or device identifier. Deleted after 7 days.
- Web server request logs
- Retained for a limited period under the server’s standard log rotation, then deleted.
- Market data
- Operational data about financial instruments. Contains no personal information.
Data deletion and account deletion
You can do all of the following yourself, at any time:
- Turn notifications off in Settings — this deletes that device’s registration from our server immediately.
- Sign out — this ends the app’s use of the session on that device. In the Android app, signing out also clears what that device had stored: your selected symbol, the local record of analysis readings, and the alert state behind it.
- Clear your browser’s site data, or clear the app’s storage in Android settings — this removes locally stored preferences and cached screens.
Because the service holds so little, there is currently no self-service “delete account” button. To have your server-side records deleted — your session records, and any notification registrations associated with your devices — email tradewithtrendofficial@gmail.com from the address associated with your Google sign-in, with the subject Data deletion request. We will confirm and act on the request within 30 days.
The full account-deletion process — what is deleted, what may be retained, and the timeline we commit to — is set out on the account deletion page, which also carries a request form. It is the same address and the same 30-day commitment, written out in full.
One limitation, stated plainly: signing out on a device does not by itself revoke the session record held on the server. That record expires on the schedule in section 14, or can be deleted sooner on request.
Deleting your data here does not delete your Google Account. Your Google Account is managed by Google, at myaccount.google.com.
User rights and choices
Depending on where you live, you may have the right to request:
- access to the personal information we hold about you;
- correction of information that is inaccurate;
- deletion of your personal information;
- restriction of, or objection to, certain processing;
- a copy of your information in a portable form;
- withdrawal of a consent you gave — for example, by turning notifications off;
- to lodge a complaint with your local data protection authority.
To exercise any of these, email tradewithtrendofficial@gmail.com. We may need to verify that the request comes from you. There is no charge, and we will not treat you differently for making a request.
Choices you always have, without contacting anyone: not signing in; not enabling notifications; revoking notification permission in your browser or device settings; clearing locally stored data; and blocking third-party content, which will stop the embedded chart from loading.
Children’s privacy
The service provides financial market analysis and is intended for adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 18 years of age.
If you believe a child has provided us with personal information, contact us at tradewithtrendofficial@gmail.com and we will delete it.
International data processing
The service runs on a virtual private server hosted in India — Google Cloud, the asia-south1 (Mumbai) region. If you access the service from another country, the information described in this policy is processed in India.
The providers listed in section 12 — Google in particular — operate globally, and may process data in other countries under their own privacy policies and transfer mechanisms.
Changes to this Privacy Policy
We may update this policy as the service changes. The Last updated date at the top of this page always reflects the version currently in force.
If a change materially affects how we handle your information, we will make it prominent — for example, with a notice in the app before it takes effect. Continuing to use the service after an update means you accept the revised policy.
A revision may also change the contact details in section 20. Please use the address published on this page rather than one kept from an earlier version.
Contact information
For privacy questions, data deletion requests, or anything else about this policy:
- Operator
- Nilesh Mandloi, independent software developer and operator
- Website
- www.aitradingterminal.in
This is the single address for all of it: privacy questions, support requests, data deletion requests, and requests to exercise the rights in section 16. We aim to respond within 30 days.
These contact details may change. If they do, the new details will be published in a future revision of this policy and the Last updated date above will change with them.