| Category | Examples | Why |
|---|---|---|
| Pilot access requests | Email, consent record and version, signup source, locale, submission time, and technical anti-abuse data | To record your request, prevent duplicate or abusive submissions, and contact you about the pilot you asked to join |
| Account | Email, handle, authentication identifiers (via Supabase) | Sign-in, account management |
| Exchange connections | API keys you paste (stored encrypted at rest), connection settings, risk caps | To operate the tooling you configure |
| Trading & journal data | Positions, orders, fills, journal entries, playbooks, rules, guardrail settings | Analytics, journaling, rule enforcement, audit trail |
| Chat & AI usage | Messages to the copilot, tool receipts, approvals | To provide AI features and keep an audit record of live-risk approvals |
| Technical | Logs, IP address, device/browser info, localStorage preferences | Security, rate limiting, debugging |
We do not sell personal data. We do not use your private trading data to trade against you. We do not hold or move your funds. Exchange API keys are stored encrypted; provision them without withdrawal permission.
We process data to perform our contract with you (operating the service), for legitimate interests (security, abuse prevention, improving the service), and with your consent where required (e.g. contacting you about a requested pilot, or live-execution terms acceptance, which we log with version and evidence). A pilot-access request is not an account and does not enroll you in unrelated marketing. You may withdraw contact consent at any time. Anonymized, aggregated statistics derived from service operation may be published as research; published records never identify you without your consent (public profiles and published edges are opt-in surfaces under your handle).
The service runs on Operator-managed infrastructure plus third-party processors (authentication, hosting/CDN, AI model providers, payment processing if/when billing launches). The current list is maintained at /xonic/legal/subprocessors.html. Chat content sent to AI features is processed by the listed model providers to generate responses.
Pilot-access requests are retained while we assess and operate the pilot, or until you withdraw consent or ask us to delete the request, subject to security records we must retain. Account and trading data are retained while your account is active. You may request export or deletion of your account data at any time; deletion covers personal data including terms-acceptance records where law permits, subject to records we must keep (e.g. security logs, records evidencing consent to live execution) for as long as legally necessary. Revoking an exchange key takes effect immediately; we recommend also deleting the key on the exchange.
Depending on your jurisdiction (e.g. GDPR, PDPA), you may have rights to access, correct, export, restrict, or delete your personal data, and to complain to a supervisory authority. Contact us at the address below; we will respond within the legally required period.
Credentials are encrypted at rest; live-risk actions require explicit confirmations that are logged; access to production systems is restricted to the Operator. No system is perfectly secure: if a breach affecting your personal data occurs, we will notify you as required by applicable law. Report vulnerabilities to the contact address.
The app uses localStorage and essential cookies for authentication, preferences, and risk-disclosure acknowledgements. No third-party advertising trackers are used.
The service is not directed at anyone under 18, and we do not knowingly process their data.
This policy is versioned by date; material changes will be announced in-app. Data controller: X3 Lab (operating entity details will be added upon incorporation). Contact: [email protected]
候补试用申请(邮箱、同意记录与版本、申请来源、语言、提交时间及防滥用技术数据);账户信息(邮箱、用户名、经 Supabase 的认证标识);交易所连接(您粘贴的 API 密钥,静态加密存储;连接设置与风险上限);交易与日志数据(仓位、订单、成交、日志、交易手册、规则、护栏设置);聊天与 AI 使用记录(发给助手的消息、工具收据、审批记录);技术数据(日志、IP 地址、设备/浏览器信息、localStorage 偏好)。用途分别为:记录并处理您主动申请的试用、避免重复或滥用申请、就该试用与您联系、登录与账户管理、运行您配置的工具、分析/日志/规则执行/审计、提供 AI 功能并保留实盘审批的审计记录、安全与限流与调试。
我们不出售个人数据;不利用您的私人交易数据与您对赌;不持有或转移您的资金。交易所 API 密钥加密存储;请使用无提币权限的密钥。
我们基于履行与您的合同(运营服务)、正当利益(安全、防滥用、改进服务)以及必要时的同意(如就您申请的试用与您联系,或实盘条款接受,含版本与证据记录)处理数据。候补试用申请不等同于创建账户,也不会将您加入无关营销;您可随时撤回联系同意。经匿名化、聚合的统计可能作为研究发布;未经您同意,公开记录不会识别您本人(公开主页与发布的策略是您以用户名主动选择的公开面)。
服务运行在运营方管理的基础设施及第三方处理方之上(认证、托管/CDN、AI 模型提供方、未来如开通计费则含支付处理方)。最新清单见 /xonic/legal/subprocessors.html。发送至 AI 功能的聊天内容由所列模型提供方处理以生成回复。
候补试用申请会在我们评估及运营试用期间保留;如您撤回同意或要求删除,我们将删除申请,但依法须保留的安全记录除外。账户与交易数据在账户有效期内保留。您可随时申请导出或删除账户数据;在法律允许范围内,删除涵盖个人数据(含条款接受记录),但法律要求保留的记录(如安全日志、实盘同意证据)将按法定期限保留。撤销交易所密钥立即生效;建议同时在交易所侧删除该密钥。
视您所在司法辖区(如 GDPR、PDPA),您可能享有访问、更正、导出、限制或删除个人数据的权利,以及向监管机构投诉的权利。请通过下方联系方式提出,我们将在法定期限内回复。
凭据静态加密;实盘风险操作须经明确确认并留痕;生产系统访问仅限运营方。没有绝对安全的系统:如发生影响您个人数据的泄露,我们将按适用法律通知您。漏洞请报告至联系方式。
应用使用 localStorage 与必要 Cookie 用于认证、偏好与风险披露确认。不使用第三方广告追踪器。
本服务不面向 18 周岁以下人士,我们不会有意处理其数据。
本政策按日期标注版本;重大变更将在应用内公告。数据控制者:X3 Lab(实体注册后将补充详情)。联系方式:[email protected]