Security & Privacy
This is a simplified explanation of our security and privacy practices. For complete details, please refer to our:
Keeping Your Info Safe
Your security and privacy are very important to us. Here's how we protect your information:
Exchange API Keys (How we keep them safe)
When you connect your exchange, you give us API keys. We protect them:
- Read-Only Only: We ONLY ask for keys that can READ your trades. We tell you NOT to give keys that can trade or withdraw money. This is the most important step. (See Connecting Guides)
- Encrypted Storage: We scrambled (encrypt) your API keys before saving them. No one can read them directly from our database.
- Secure Connection: All info sent between your browser, us, and the exchange is encrypted (HTTPS).
- Delete Keys: When you remove an exchange connection in Alara, we permanently delete its keys.
- You Control Keys: You can always delete the API key on your exchange's website too. This fully removes our access.
Trading Data (How we use it)
We look at your trade history (what, when, how much) to find patterns.
- Just For You: We use your trade data ONLY to give YOU insights on your dashboard or through AI tools you connect. We DO NOT sell it or share it with others for marketing.
- AI Tools: If you use AI tools (like Cursor), small bits of summarized data might be sent to the AI to answer your questions (like "Did I FOMO trade?").
- Anonymous Stats: We might use combined, anonymous data (that can't be linked to you) to improve our features.
- Data Deletion: We keep your data while your account is active. If you delete an exchange or your account, we delete the related data (usually within 90 days).
For complete details about how we handle your data, please see our Privacy Policy.
Your Alara Account
We also protect your main account:
- Password Hashing: We don't store your password directly. We store a scrambled (hashed) version that can't be easily reversed.
- Secure Login: We use standard secure methods for login and keeping you logged in.
- 2FA (Coming Soon): We plan to add Two-Factor Authentication (like codes from an app) for extra security. Use 2FA on your exchange accounts too!