Privacy Policy
EdgeFlow — versión 2.0 · September 25, 2026
Descargado el 05-10-2026

# Privacy Policy

> **Courtesy translation.** The binding text is the Spanish version. If the two
> differ, the [Spanish version](/legal/privacy) prevails.

This policy explains what personal data we process, for what purpose, on what legal basis, who we share it with and what you can do about it. It is written against Chilean Law 21,719 on the protection of personal data and is compatible with the European General Data Protection Regulation.

## 1. Data controller

EdgeFlow es un servicio prestado por <strong>Leonardo Reyna</strong>, con residencia en Santiago, Chile, en calidad de titular de un emprendimiento personal. Contacto: legal@edgeflow.app. La identificación tributaria y el domicilio del responsable se entregan a cualquier usuario o titular de datos que los solicite, por correo a legal@edgeflow.app o desde <a href="/legal/responsable" rel="noopener">tu cuenta → Legal</a>. Para los efectos de la legislación aplicable, Leonardo Reyna es el proveedor del servicio y el responsable del tratamiento de los datos.

Contact for personal-data matters: legal@edgeflow.app.

## 2. What data we process and why

| Category | What it includes | Purpose | Legal basis |
| --- | --- | --- | --- |
| Account | Your email address, the date you confirmed the account, and if you sign in with Google, the identifier Google gives us. If you set a password, we store only its hash (bcrypt), never the password. | Create the account, identify you, let you in, communicate with you. | Performance of the contract. |
| Session and security | Session and email sign-in tokens, with the address they were sent to; IP address and browser user agent; an audit log of sensitive actions (who granted or revoked a plan, and why), including the email of whoever did it. | Keep the session open, limit sign-in attempts, detect abuse, and be able to reconstruct what happened in the event of a complaint. | Performance of the contract and legitimate interest in the security of the service. |
| Acceptance of legal documents | Which document you accepted, in which version, when, in what context, your **truncated** IP address (only the first three groups are stored, for example 200.1.2.0) and part of your user agent. | Being able to demonstrate your consent, as the law requires. | Legal obligation and performance of the contract. |
| Exchange credentials | The API key and its secret (and the passphrase, where the exchange uses one), **encrypted with AES-256-GCM**. They are never shown back or sent to the browser. | Read the state of your exchange account and send the orders you instruct. Nothing else. | Performance of the contract. |
| Trading data | Orders you sent, positions, fills, realised results, fees, funding, closed-trade history, transfers between your exchange wallets, bots and their events, risk rules. | Show you your trading and your results, compute your PnL, apply your risk rules, and protect open positions. | Performance of the contract. |
| Settings | Visible indicators and their configuration, workspaces, favourite assets, preferred timeframe and chart type, theme, time zone, price and indicator alerts. | So the platform looks and behaves the way you left it. | Performance of the contract. |
| AI assistant | The text of your messages and any files you attach, together with market context and, when the answer requires it, account data (positions, balances, PnL). Also: whatever you ask it to remember (a short piece of text associated with your account), your own provider key if you loaded one (encrypted), and a monthly counter of messages and tokens. | Answer your queries, keep the thread of the conversation, apply your plan's quota. | Performance of the contract. For the assistant's memory, your consent. |
| Payments | Plan and period purchased, network, destination address, amount, status, date and the on-chain transaction identifier. **Never card details**, because we do not charge cards. | Identify your payment, activate the plan, handle complaints and refunds. | Performance of the contract and legal accounting and tax obligations. |
| Notifications | For browser notifications: the delivery endpoint your browser assigns, its encryption keys and your user agent. For email: your address. | Send you the notices you asked to receive. | Consent, which you can withdraw by turning notifications off. |
| Waiting list | If you signed up before your account existed: your email and what you trade. | Let you know when there is room. | Consent. |
| Technical usage | Server logs with the path, response code, timestamps and, in production logs, your internal user identifier. | Operate, diagnose errors and size the infrastructure. | Legitimate interest in keeping the service running. |

We do not process sensitive data and we do not ask you for any. We do not carry out profiling with legal effects or automated decisions that significantly affect you.

## 3. Who we share data with

We do not sell personal data, we do not hand it to third parties for their own marketing and we do not advertise with it. We share it only with those who provide a service necessary for the platform to work, and only with what that service needs.

| Recipient | Purpose | What they receive |
| --- | --- | --- |
| Fly.io (Estados Unidos) | Host the application and the database. | Everything the application stores, on their infrastructure. |
| Twilio SendGrid (Estados Unidos) | Send the service's emails: sign-in link, confirmations, plan notices. | Your email address and the content of the message. |
| Exchanges: Binance, Bybit, OKX | Read your account and send your orders. | Your own credentials and the orders and queries you originate. Each exchange processes that data as its own controller, under its own policy. |
| AI model providers: Google (Gemini), OpenAI, Anthropic, Groq | Generate the assistant's answers. Which one is involved depends on the configured agent; if you use your own key, it is the provider you chose. | The text of your query, any files you attach, the market context and whatever account data the query requires. Before sending, we automatically filter out anything that looks like a key or a secret. |
| Google | Sign in with your Google account, if you choose that route. | Your email and your Google account identifier. |
| Your browser's notification service (Mozilla, Google or Apple, depending on the browser you use) | Deliver push notifications. | The delivery endpoint that same service generated and the encrypted message. |

**News providers.** When the news-context feature is on, we query external sources (Finnhub, GDELT, public RSS feeds and the SEC's EDGAR database). Those queries are about instruments and keywords: **we send them no personal data of yours**.

**Telegram.** We use Telegram only for internal team notices, to a channel of our own. We do not send you alerts over Telegram and we do not send it any personal data of yours.

We may also disclose data when a law or a decision of a competent authority obliges us to, and in that case we will tell you unless the order itself prohibits it.

## 4. International transfers

The infrastructure hosting the application and several of the providers in section 3 are outside Chile, including in the United States and the European Union. That means your data is transferred and processed outside the country.

Those transfers rely on being **necessary to perform the contract** you have with us — we cannot provide the service without hosting it somewhere, nor answer you with an AI model without sending it your query — and, where applicable, on contractual clauses with the provider imposing confidentiality and security obligations equivalent to ours.

If you do not want your queries leaving for an AI provider, do not use the assistant: the rest of the platform works the same.

## 5. How long we keep data

As a rule, we keep data **for as long as your account exists**, because it is what makes the service work. There is no automatic deletion by age: if you want something deleted sooner, ask and we delete it.

Exceptions and specifics, with what actually happens today:

- **Assistant conversations.** They are not stored in the database. They live in server memory, are limited to the most recent messages and are discarded within a few hours or when the server restarts. The same goes for any files you attach.
- **Assistant memory.** It is short text and is kept until you delete it. You can delete it at any time.
- **Session tokens.** They expire on their own: session tokens after 60 days, email sign-in links after 15 minutes.
- **Record of acceptance of legal documents.** Kept for as long as the account exists and deleted with it. It is the proof of your consent: while you are a user we do not delete it on request, because without it we cannot evidence that you accepted.
- **Audit log.** It survives the closing of the account, because its whole purpose is being able to reconstruct who did what. Today it keeps the email of the person who performed the action.
- **When you close your account** the following are deleted: your API keys, your AI key, the assistant's memory, your settings, your workspaces, your alerts, your bots, your risk rules, your notification subscriptions, your usage counters and your PnL data. Some historical trading records are **unlinked from your account** instead of being deleted.
- **Payment records are kept, unlinked from you.** Tax and accounting law requires us to keep proof of payments received for several years. When you close your account, your USDT invoices survive with the amount, network, transaction hash and date, but the link to your account is severed: there is no longer anyone to attribute them to.

## 6. Security

Connections travel over HTTPS. Exchange API keys and AI provider keys are stored encrypted with AES-256-GCM and are never returned to the browser. Passwords, where they exist, are stored as a bcrypt hash. Database access is restricted and administrative actions are logged.

Before sending your text to an AI provider, we automatically filter out anything shaped like a key, secret or certificate.

No system is infallible. If a breach occurs that affects your data and could cause you harm, we will inform you and the authority within the deadlines the law requires.

**Something that depends on you:** signing in to EdgeFlow is done with a link sent to your email or with your Google account. Whoever has access to your inbox can get into your account. Protect your email with two-step verification.

## 7. Your rights

You have the right to **access** your data, to **rectify** it if it is wrong, to request its **erasure**, to **object** to certain processing, to **request restriction** of processing and to **portability** of the data you gave us, in a structured, commonly used format.

To exercise them, write to legal@edgeflow.app from the address you registered with, or from one where you can evidence your identity. **We answer within 30 calendar days.** We do not charge for this, unless the requests are manifestly unfounded or repetitive.

Some things you can do yourself, without writing to us: delete your exchange keys, delete your AI key, delete the assistant's memory, download your data, turn notifications off and close your account.

If you believe we are not respecting your rights, you can complain to Chile's **Personal Data Protection Agency**. If you reside in the European Union or the United Kingdom, to your country's supervisory authority.

## 8. Cookies

We use **only strictly necessary cookies**: the one that keeps your session open, the "keep me signed in" one if you tick it, and cross-site request forgery protection. We also store interface preferences, such as the theme, in your browser's local storage.

**We use no advertising, cross-site tracking or third-party analytics cookies.** That is why you will not see a cookie banner: necessary cookies do not require consent. If we ever add third-party analytics, we will ask you first and you will be able to refuse.

## 9. Minors

EdgeFlow is not directed at people under 18 and we do not knowingly collect data from minors. If we detect a minor's account, we close it and delete the data. If you are a parent or guardian and believe we hold a minor's data, write to us at legal@edgeflow.app.

## 10. Changes to this policy

If we change this policy materially, we will tell you at least 15 days in advance by email and with a notice inside the platform, and the version you accepted will be recorded. Earlier versions are in the [version history](/legal/changelog).

## 11. Contact

legal@edgeflow.app — Leonardo Reyna, Santiago, Chile.

If you need the operator's tax identification or address — for example for a formal complaint or to exercise your rights before the authority — we provide them to whoever asks: write to legal@edgeflow.app or request them from your account under [Legal](/legal/responsable). We do not publish them here because the operator is a natural person.
