Privacy Policy
Last updated August 20, 2026
Draft. The operator’s details are not filled in yet — the highlighted places are pending. Until they are, this page is not offered to search engines.
What Sonarcast stores about you, why, who processes it on our behalf and how to have it deleted. Short version: an account needs an email and little else, and we do not sell anything to anyone.
1. Who is responsible
The controller of your personal data is [TO FILL: legal name of the operator], [TO FILL: registered address], [TO FILL: country of registration and governing law]. Privacy requests go to support@sonarcast.app.
2. What we store
An account holds only what the service needs to work:
- your email address and whether it has been confirmed;
- a bcrypt hash of your password — never the password itself. Accounts created through Google or Telegram have no password at all, only the provider identifier they signed in with;
- optionally a display name and avatar, if your sign-in provider supplied them;
- your Telegram user and chat identifier, if you connect Telegram for notifications;
- your plan, trial and subscription dates, and the payment records behind them;
- your settings: interface language, theme, coin-card layout, the coins you put "in work" and your notification preferences;
- per active session: the IP address and browser user-agent it was opened from, plus a hash of the refresh token — this is what lets you see and revoke your sessions.
3. What we do not do
We do not sell or rent personal data, and we do not run advertising on the site.
Our own visit statistics are collected anonymously, without cookies and without personal data: which page was opened, where you came from and how long you stayed. Nothing is stored in your browser, so it always runs and needs no consent.
The only cookies set are the ones the service needs to function: sign-in, session and security, plus your chosen interface language.
With your consent, visits are also counted by Yandex Metrica — the service sets its own cookies. Without consent it does not load; you can withdraw through the "Cookie" button in the footer.
4. Why we process it
To give you access to the account and the plan you paid for; to send the notices you asked for (Guardian alerts, setup alerts, reports) and the ones the service must send (email confirmation, password reset, subscription expiry); to take payment; to keep accounts secure; and to keep the service working.
5. Processors we use
These providers process data on our behalf, each for a single purpose:
- CryptoCloud — payment in USDT. Receives what is needed to issue and confirm an invoice; we never see or store your wallet keys.
- Resend — delivery of service email. Receives your email address and the message.
- Telegram — delivery of notifications, if you connect it. Receives your chat identifier and the message text.
- Google — sign-in, if you use it. We receive the account identifier and email address you consent to share.
- Anthropic (and, as a fallback, OpenRouter) — generation of the narrative text. Receives the market facts our own engine has already computed; account identifiers are not part of that context. Chat messages you type yourself are sent as you wrote them.
- Market data providers (Binance, Bybit, OKX, CoinGlass, CoinGecko) receive no personal data at all — we request public market data from them, not anything about you.
6. How long we keep it
Account data is kept while the account exists. Sessions expire on their own and are removed. Payment records are kept for as long as accounting and tax rules in [TO FILL: country of registration and governing law] require, even after an account is deleted.
Ask us to delete your account and we delete the account and its settings; what remains is only what the law requires us to retain.
7. Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete the account, or object to a particular use. Write to support@sonarcast.app from the address the account uses and we will answer within 30 days.
Notification settings, connected channels and active sessions can also be changed by you at any time in the account settings.
8. Security
Passwords are stored only as bcrypt hashes. Access tokens are short-lived and refresh tokens are stored hashed, so a database copy does not hand over live sessions. Traffic runs over HTTPS.
No system is perfectly secure. If a breach ever affects your data, we will tell affected account holders by email.
9. Changes
When this policy changes, the date at the top of the page changes with it. Material changes are announced to account holders by email.