NixoraTrade
DRAFT

This document is a draft and is not yet in force. It has not been reviewed by a lawyer and does not create a binding agreement. Amber boxes below are internal notes marking decisions still open. Published here for review only — please do not rely on it.

Nixora Systems Inc. · United States

Privacy Policy

Applies to NixoraTrade. See also Terms of Use, Privacy, Risk Disclosure.


Controller: Nixora Systems, Inc., a Delaware corporation Postal address: Nixora Systems, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States Privacy and data requests: admin@nixorasys.com Support: support@nixorasys.com Nevada opt-out requests: admin@nixorasys.com — see §15 Provided at: www.nixoratrade.com (API host hook.nixoratrade.com)

Effective date: [set to the publication date] Last updated: [same as effective date on first publication]


1. The most important thing: this product is local-first

Most of what you create in NixoraTrade never reaches our servers.

Stored only in your browser (IndexedDB database MarketStructureDB), on your own device:

We do not receive this data, we do not hold a copy, and we cannot read it, produce it, or restore it.

The trade-off: if you clear your browser's site data, switch browser or device, or lose the device, this data is gone and we cannot recover it. Export your own backups.

1.1 Exception: optional cloud backup (off by default)

The product includes an optional cloud backup feature. It is off by default and does nothing unless BOTH of the following are true: (a) we have enabled the feature for your account, and (b) you choose to back up to the cloud (or turn on automatic backup on a device you use).

When you use it, the data listed above — including screenshots and file attachments — is uploaded to and stored in our object storage (Cloudflare R2), under a prefix private to your account, encrypted at rest, and subject to a per-account storage quota (currently 5 GB). We retain your last 10 backup versions; older objects no longer referenced by any retained version are automatically removed. We do not read the contents of your backups except as needed to operate the service (for example, computing your storage usage).

You stay in control: you can delete every cloud copy at any time from inside the application ("cloud purge"), and closing your account automatically deletes all of it. If the feature is not enabled for your account, everything above in this section remains true without exception — and using cloud backup also softens the trade-off above: a cleared browser or lost device is then recoverable from your cloud backup.

2. What our servers do hold

Our server is a Cloudflare Worker backed by a Cloudflare D1 database. It holds the following.

2.1 Account record

Required to have an account: username, email address, and password — the password is stored as a hash, never as the password itself. Alongside these we keep your account's role and status, session and token metadata, and timestamps.

Account details we require. First name, last name, account name, billing email address, phone number, your country of residence, and — if that country is the United States — the US state where you live. We ask for these so we can identify your account and reach you about it, send billing documents to the address you choose, and — for the state — apply the right notification rules to you if there is ever a data incident. They are required: you can correct any of them at any time, but you cannot leave them empty. Accounts created before 31 August 2026 may not have all of them on file yet; those accounts keep working, and we ask for the missing ones on the profile screen.

Settings you can fill in: display name, time zone, date format, and a profile picture. These are optional.

Date of birth — required. We ask for your date of birth when you create an account and we keep it. We use it to work out your age and confirm you are 18 or older, which our Terms require; the age itself is calculated when needed and is never stored. A date of birth that shows you are 18 or older also records the date on which that was confirmed. We also use it, with the trading questionnaire below, to understand who the product is for and what to build next. We do not sell it, and we do not share it. Accounts created before 31 August 2026 may not have one on file.

Personal details you may choose to give. Gender and income range. These are optional — the product does not require them and does not withhold anything if you leave them blank. We do not sell them, and we do not share them.

Trading questionnaire. If you answer it, your responses to a fixed set of questions about your trading experience (years trading, instruments, style, frequency, and similar). We use these to understand who the product is for and what to build. They are stored under their own key so they can be identified and removed separately from the rest of your account.

Where you live. A self-declared country, and a US state or territory when that country is the United States. This is not an address and we do not verify it. We hold it for two reasons: the country tells us which privacy rules apply to you at all, and — for US residents — if there is ever a data incident, notification rules follow your state and we cannot follow them without knowing which state that is. We record the state only for US residents; for everyone else no state is stored.

Internal note · COUNSELcapturing the country tells us WHICH regime applies — it does not by itself satisfy any non-US regime. This Set A document is written for US users only; a user who selects an EEA or UK country is not covered by GDPR/UK-GDPR compliance simply because the country was recorded (lawful basis, DSAR handling, retention limits and transfer mechanism are all still outstanding — see Set B). Advise on whether non-US signups should be accepted at all before that work exists.

Consent and compliance records. Whether you opted in to marketing email and when you opted in or out; which version of the Terms you accepted and when; and the time you confirmed you are 18 or over. These exist so that we can prove what you agreed to, and so that you can hold us to it.

An email change in progress. If you ask to change your email address we hold the new address and a one-time token until you confirm it, or for 30 minutes, whichever comes first.

2.2 Broker connection and trading data

2.3 Alerts and webhook payloads

The raw payload posted to your personal webhook URL, plus request metadata.

2.4 Optional cloud-synced items

A small number of features sync deliberately — for example watchlists and certain chart objects. These are the exceptions to §1, not the rule.

2.5 Logs

Request and error logs, including IP address, user agent, timestamps and endpoint, retained for security and troubleshooting.

2.6 What we do not collect

Internal note · VERIFYtrue today because no payment processing exists in the codebase. When Stripe or another processor is added, this section must be rewritten — card data will be handled by the processor and must be named.

2.7 Where the information comes from

Source What we get
You Everything in §2.1 — your account details, settings, the optional personal details and questionnaire if you fill them in, support messages, and anything you type into the assistant
Your own MetaTrader terminal, via the EA you installed Account login number, Broker server name, balance, equity, free margin, currency, open positions and pending orders, and the outcome of each Command
TradingView, when it posts to your webhook URL The alert payload you configured it to send
Your browser, automatically IP address, user agent, timestamps, pages requested

We do not buy personal information, and we do not obtain it from data brokers or from any third party other than those listed above.

3. Broker credentials — we do not hold any

This section is deliberately specific, because "we protect your credentials" usually means a company holds them carefully. We do not hold them at all.

Never received at all — your Broker credentials. We do not have them. Your MetaTrader account number, password and investor password never leave your computer. Your EA runs on your machine and logs in to your Broker locally.

We hold no Broker credential of any kind, for any Broker, and we have no technical means of accessing your Broker account.

Hashed at rest (one-way — the server can recognise a value but cannot read it): your account password, and the machine and execution tokens your EA presents to us.

Encrypted at rest (reversible):

Internal note · VERIFYwith no server-side broker integration, confirm whether any reversibly-encrypted secret remains in the database. If none does, delete this line — do not keep a category that no longer has anything in it. Internal note · VERIFYre-confirm each classification against the current worker crypto helpers before publication.

4. Broker integrations — what flows where

4.1 MetaTrader 4 / 5 — our only Broker integration

Your EA connects outbound to our server, authenticates with a machine token, polls for Commands, and reports telemetry and results. We never connect to your Broker. We receive only what the EA reports (§2.2).

4.2 TradingView (inbound)

TradingView posts your alert to your personal webhook URL. We store the payload (§2.3). The only credential protecting that endpoint is the secrecy of your webhook URL.

4.3 Telegram, Discord, email (outbound, optional)

If you configure them, our server posts trade content to the destination you chose. Once sent, that content is governed by that platform's own policy, not ours.

5. The AI assistant

Internal note · VERIFYproduction models — the code path uses `@cf/zai-org/glm-4.7-flash`, plus `@cf/meta/llama-3.1-8b-instruct-fast` for rephrase and strategy drafting. Internal note · COUNSELCloudflare's Workers AI terms determine whether inputs may be used for model improvement. Read them; do not assume.

6. Email

Transactional email — activation, password reset, notices — is sent through Resend. Resend receives your email address and the message content.

7. Cookies, browser storage, tracking signals, and third-party requests

Covered fully in the Cookie & Local Storage Notice. In summary:

7.1 Third parties that may collect information about you over time and across sites

Some resources in our pages are served by other companies. When your browser loads them, that company receives your IP address, your browser and device information, and the page you were on — and it can potentially do so across other websites you visit that use the same resources.

Third party What it is used for When it loads
Google Fonts No longer loaded. The typefaces are served from our own servers Never
unpkg No longer loaded. The charting library is served from our own page; the preconnect that used to fire on every visit has been removed Never
TradingView Not loaded. No TradingView chart or widget is embedded in the product Never
YouTube (youtube.com) A link to a tutorial video — an ordinary link, not an embed. Nothing reaches YouTube unless you click it Only if you click

As of today this table is empty in practice: no third-party request is made from any of our pages. See the Cookie & Local Storage Notice §5 for the same inventory kept in one place.

We do not control what these companies do with that information, and their own privacy policies apply, not ours. We receive nothing from them about you.

Economic-calendar data is fetched by our server, not by your browser — that provider never sees your IP address.

Internal note · OWNERthree of the four entries above can be removed outright — self-host the fonts, self-host or bundle the charting library instead of preconnecting to unpkg, and gate the TradingView and YouTube embeds behind click-to-load. Each one removed is one fewer disclosure, one fewer company seeing your users, and one fewer thing to keep accurate.

7.2 Do Not Track and Global Privacy Control

Some browsers can send a "Do Not Track" (DNT) signal, or a Global Privacy Control (GPC) signal, asking sites not to track you. There is no common industry standard for how a site must respond to DNT.

We do not currently respond to Do Not Track or Global Privacy Control signals.

We tell you this plainly because California law requires us to disclose our response, whatever it is. In practice the signals would change little here: we do not sell or share personal information, we run no advertising trackers of our own, and we do not track you across other websites. The third-party resources in §7.1 are the only cross-site exposure, and the way to remove that is to remove them, not to send a signal.

Internal note · COUNSELseveral state privacy laws treat GPC as a valid opt-out of sale/sharing **once those laws apply to us**. They do not today, and we neither sell nor share. Revisit the moment either fact changes — and if we ever begin honouring GPC, this section must be corrected the same day.

8. Retention and deletion — what the code actually does

Stated honestly, including where it falls short.

Data How long we keep it
Account record While your account is open. Deleted the moment you close it
Broker connections and settings While the connection exists — deleted when you disconnect it, and on closure
Broker order records Completed orders are removed automatically after 400 days. All of them go on closure
Order history, notification history and notification events 90 days
Alerts and webhook payloads ⚠️ No automatic time limit yet — kept until you delete them, or until you close your account
Commands and signals ⚠️ No automatic time limit yet — kept until you clear them, or until you close your account
Chart objects ⚠️ No automatic time limit yet — kept until you close your account
Cloud backups, if you use them (§1.1) Your most recent 10 versions. All purged on closure
Failed sign-in records (security log — the username or email tried, the reason, and the IP address) 30 days, then deleted automatically. Not removed by account closure — see §8.1
An email change in progress Until you confirm it, or 30 minutes, whichever is sooner
Logs Per platform defaults
AI conversations Not stored at all
Your local data (§1) Entirely under your control
Internal note · OWNER/COUNSEL: the three rows marked ⚠️ have no automatic time limit. Proposal for approval — alerts and webhook payloads 12 months, commands and signals 12 months, chart objects for the life of the account. Everything else in this table is enforced in code today.

8.1 Closing your account

You can close your account yourself, from Profile → Privacy & Data → Close account. It asks for your password and for you to type the word CLOSE, because closure is irreversible. An administrator can also close an account.

Closing your account erases what our servers hold about you, with the two narrow exceptions named below. In a single transaction we delete your account record, your alerts and webhook payloads, your commands and signals, your connections, your broker order records and order history, your notification history and events, your chart objects, your strategies with their versions and deployments, your shared trades, and any broker fast-track vote you submitted. We then destroy your execution mailbox and purge your cloud backups (§1.1).

Two things survive closure, and you should know about both.

  1. A closure marker. A record that an account with a particular internal identifier was closed, and when. It holds no personal information — no name, no email, no content, nothing you wrote — and it exists so a closed account cannot be silently recreated or resurrected.

  2. Failed sign-in records, for up to 30 days. Whenever a sign-in attempt is rejected we log the username or email address that was tried, the reason it failed, and the IP address it came from. These are security records, kept so we can detect attacks on accounts. They are deleted automatically after 30 days, and account closure does not remove them early.

Internal note · COUNSELconfirm that a short-retention security log sits within legitimate interests and outside the scope of an erasure request. If it does not, login_rejections must be added to USER_DATA_TABLES and this paragraph deleted. Flagged because §8.1 previously said closure erases everything — it does not, and an overstatement here is the exact FTC §5 exposure this policy is written to avoid.

Work stored in your own browser (§1) is not touched by closure. It is on your device, not ours, so we cannot reach it. Clear your browser data yourself if you want it gone.

If you are the only administrator, you must promote another administrator before you can close your own account.

9. How we use information

We do not make automated decisions with legal or similarly significant effects about you. The automated trading you configure is your automation, executed on your instruction.

10. Who we share with

We do not sell your personal information.

11. Security

We use commercially reasonable administrative, technical and organisational measures, including transport encryption, password hashing, encryption at rest for Broker tokens, scoped per-user data access, rate limiting, and token revocation.

No system is perfectly secure. You are responsible for your password, your device, and the secrecy of your webhook URL and execution tokens.

We will notify you of a security incident affecting your data as required by applicable law.

12. Your rights and choices

How we verify a request. Before we act on a request about your data we will confirm you are who you say you are — normally by requiring the request to come from, or be confirmed at, the email address registered on the account. For a deletion request we will ask you to confirm a second time, because deletion cannot be undone. We will not ask you for a copy of an ID document. If we cannot verify you, we will tell you why rather than act.

How long we take. We aim to respond within 45 days. If we need longer we will tell you within that period and explain why.

No charge, and no penalty. Exercising a right is free, and we will not degrade your service, change your price, or treat you differently for having exercised one.

13. California residents (CCPA / CPRA)

If you are a California resident you may request: the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients; deletion; correction; and to opt out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising. We will not discriminate against you for exercising a right.

To make a request, email admin@nixorasys.com or write to us at the postal address above. An authorised agent may act for you. We will verify your identity before acting.

"Shine the Light" (Cal. Civ. Code § 1798.83): we do not share personal information with third parties for their own direct-marketing purposes.

14. Other US state privacy laws

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah and Texas) may have rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale or profiling. We do not conduct targeted advertising, sale, or profiling. To exercise a right, or to appeal a refused request, contact us at the address above.

15. Nevada residents

Nevada law lets a consumer direct a website operator not to sell their covered information.

We do not sell covered information, and we have never sold it.

Nevada law nonetheless requires us to publish a designated address for such requests, so here it is:

Designated request address: admin@nixorasys.com

We will respond to a verified request within 60 days. Nevada law allows us a further 30 days where reasonably necessary, and we will tell you if we need it.

16. Geographic scope

The Service is offered only in the United States and is not offered to residents of the European Economic Area or the United Kingdom. This policy therefore does not contain GDPR provisions.

Our infrastructure is operated by Cloudflare and data may be processed in the United States and other countries where Cloudflare operates.

Internal note · COUNSELthis exclusion must be operationally real, not merely stated — see the Terms §26. Today no jurisdiction check is performed at signup.

17. Children

The Service is not directed to anyone under 18, and we do not knowingly collect information from children under 18.

Internal note · VERIFYsignup performs no age check today.

If you believe a child has provided us information, contact us and we will delete it.

18. Changes to this policy

We will post any updated policy with a new "Last updated" date, and give notice in the application or by email where appropriate. Continued use after the effective date is acceptance.

19. Contact

Questions, requests, or complaints about privacy:

Privacy and data requests: admin@nixorasys.com Support and general enquiries: support@nixorasys.com Post: Nixora Systems, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States Telephone: +1 302 207 9414

If you are not satisfied with our response, you may contact the consumer-protection authority in your state. California residents: see §13.