Note: this policy is a good-faith description of MarketEngine AI's actual data practices, drafted directly from how the platform is built. It is not a substitute for review by a qualified attorney, particularly given the platform handles financial and cryptocurrency data — independent legal review is strongly recommended before relying on this as a complete or final policy.

1. Information We Collect

Account information. When you sign up, we collect your email address and name. Your password is never stored by us directly — authentication is handled by Amazon Cognito, an AWS identity service.

Wallet and trading data. If you use the Wallet, Earn, or Exchange features, we store your deposit addresses (one per supported blockchain), balances, and the history of your deposits, withdrawals, stakes, and exchanges. Private keys associated with platform-generated addresses are encrypted at rest and are never transmitted or displayed in plain text.

IP address and device information. For account security, we log the IP address and a general device/browser descriptor (e.g. "Chrome on Windows") associated with signup, login, and money-moving actions (withdrawals, exchanges, stakes). This is used to detect signs of unauthorized account access — such as activity from multiple distinct locations or devices — and is visible to platform administrators for security review. We do not currently resolve IP addresses to a geographic location.

Usage and analytics data. We collect basic, aggregated analytics about page views, referring pages, device type, and browser, used to understand overall platform usage. This data is not tied to individual user accounts in a way that's exposed outside internal reporting.

Trading activity. If you use paper trading or connect a live broker, we record the positions, trades, and signals associated with your account in order to display your trading history and performance.

2. How We Use Information

  • To create and maintain your account, and authenticate you when you log in
  • To process deposits, withdrawals, stakes, and exchanges you request
  • To detect and prevent unauthorized access or fraudulent activity
  • To send you account-related and security email (see Section 6 — we do not send marketing email)
  • To provide customer support when you contact us
  • To understand aggregate platform usage and improve the product

3. Third-Party Services We Use

Certain functions of the platform are provided by third-party services, each of which processes a limited slice of the data described above to do their specific job:

  • Amazon Web Services (AWS) — hosts the platform's infrastructure, database, and authentication (Amazon Cognito), and sends account-related email (Amazon SES)
  • Kraken — provides the live market price feed used to display current prices; no personal account data is shared with Kraken as part of this
  • SimpleSwap — executes the underlying asset conversion when you request an Exchange, after admin review
  • Tradovate — if you connect a live broker account, order execution is routed through Tradovate's own systems under your own broker credentials

4. Data Security

Platform-generated wallet private keys are encrypted at rest. Withdrawals require two-factor authentication, with a lockout after repeated failed codes. Passwords must meet a minimum complexity standard enforced by Amazon Cognito. Administrative access to user accounts and financial data is restricted to designated platform administrators.

5. Data Retention

We retain account and transaction data for as long as your account is active, and as needed to comply with legal, accounting, or security obligations after account closure. Activity logs used for security purposes (Section 1) are retained separately from transaction history and may be kept for a limited period after an account is closed for fraud-review purposes.

6. Your Choices and Rights

You can request access to, correction of, or deletion of your personal data by contacting us at the address below. Account deletion permanently removes your authentication record; associated financial history may be retained separately where required for legal or accounting reasons. We do not send marketing or promotional email — the only email you'll receive from us is a one-time welcome message and account security notices (such as password reset or verification codes), which cannot be individually unsubscribed from since they relate directly to account security and access, not marketing.

7. Cookies and Local Storage

The platform uses browser local storage to keep you signed in between visits and to remember basic display preferences. We do not use third-party advertising trackers or sell browsing data to advertisers.

8. Children's Privacy

MarketEngine AI is not directed at, and is not intended for use by, anyone under the age of 18. We do not knowingly collect information from minors.

9. Changes to This Policy

We may update this policy as the platform evolves. Material changes will be reflected by updating the "Last updated" date at the top of this page.

10. Contact Us

Questions about this policy or your data can be sent to support@marketflowengine.com.