Privacy Policy
1. Who we are
Dojiq ("we", "us") provides software for automating trading on your own brokerage and exchange accounts. This policy explains what personal data we process and why.
2. What we collect
- Account data: your username, display name, and a securely hashed password.
- Access requests: the email address and any note you submit to request an invite.
- Connected-account credentials: the API keys you provide for brokers and exchanges, stored encrypted at rest (Fernet) and never in plain text.
- Trading and usage data: your strategy selections, paper and live trading activity, positions, orders, and portfolio history generated within the Service.
- Technical data: session information, IP address, and request logs used for security and to operate the Service.
- Billing data: if you subscribe, payment is handled by our payment processor; we receive subscription status and identifiers, not your full card details.
3. How we use it
- To operate the Service: run strategies, place orders on your connected accounts, and show your dashboards.
- To secure the Service: authentication, abuse and brute-force protection, and audit logging.
- To manage invites, accounts, and subscriptions.
- To communicate with you about access, your account, and important changes.
4. How API keys are protected
Your brokerage and exchange API keys are encrypted at rest with a Fernet key and decrypted only in memory when needed to place or manage orders. We recommend trade-only keys with withdrawals disabled, so that even in the unlikely event of exposure, funds cannot be withdrawn.
5. Third parties we share with
- Brokers and exchanges (for example Alpaca and Bitvavo) to execute and reconcile your trades.
- Market-data and news providers to power prices, indicators, and sentiment.
- Our payment processor to handle subscriptions.
We do not sell your personal data.
6. Data retention
We keep account and trading data while your account is active and as needed to operate the Service, meet legal obligations, and resolve disputes. Security logs such as login attempts are kept for a limited period and then purged. You can request deletion of your account data as described below.
7. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the address published on the Service. You can disconnect a brokerage or exchange account at any time, which removes its stored keys from active use.
8. Cookies and sessions
We use a signed session cookie to keep you logged in. It is essential for the Service to function. We do not use it for advertising.
9. Security
We use encryption for credentials at rest, hashed passwords, signed sessions, and brute-force protection. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data.
10. Changes and contact
We may update this policy from time to time and will communicate material changes through the Service or by email. For privacy questions or requests, contact us at the address published on the Service.