Privacy Policy
Last updated: September 10, 2026
Our default is minimum data. This page tells you what that actually means in practice, in plain language — not in legalese written to protect us at your expense.
What we collect
Normal mode (email or Google sign-in)
- Your email address
- A salted hash of your IP address (for session security only — we never store the raw IP)
- Your display name, if you sign in with Google
- The exchange trading data you connect via API keys or wallet addresses
Private mode (12-word recovery phrase)
- Only the public cryptographic key derived from your phrase
- No email, no IP address, no session-linked personal identifiers
- The exchange trading data you connect
What we do with it
- Show it back to you. All computed metrics, tags, charts, and reports are yours to see in the app.
- Sync more trades. We periodically fetch new trades from the exchanges you’ve connected, using the read-only credentials you provided.
- Send you emails you asked for (sign-in links, invite codes, receipts, service notices). We use Resend as our email provider — they see the email address but not the content of your trades.
- Charge you if you subscribe. Payment is processed by Stripe or Atlos. We never see your card details.
What we do NOT do
- We do not sell your data to anyone. Ever.
- We do not share it with third parties for advertising, profiling, or analytics.
- We do not run third-party tracking scripts (no Google Analytics, no Facebook Pixel, no Mixpanel, no Segment).
- We do not log your IP address in private mode.
- We do not have access to your exchange trading funds. The API keys and wallet addresses you provide are read-only.
Where it lives
Your data is stored in a PostgreSQL database on servers in Germany (Hetzner Falkenstein). The database is encrypted at rest and only accessible over SSH by a small number of authorized operators.
How long we keep it
- Active accounts: as long as your account exists.
- Deleted accounts: all your data is permanently removed within 30 days of the deletion request. Backups containing your data expire and are overwritten within 60 days.
- Sign-in logs: rotated after 90 days.
Your rights (GDPR)
If you’re in the European Economic Area, you have the right to:
- Access your data (available directly in the app; a full JSON export can be requested at support@11xlab.trade)
- Correct inaccurate personal data
- Delete your account and all associated data
- Object to processing for reasons that we don’t currently do anyway (marketing, profiling)
- Complain to your local Data Protection Authority (in Slovenia, that’s the Information Commissioner — ip-rs.si)
Private-mode users have effectively already exercised the “minimize personal data” principle by design — we don’t have your email or IP to begin with.
Cookies
We use one cookie: a session token that keeps you signed in. It expires when you sign out or after 30 days of inactivity, whichever comes first.
We do not use third-party cookies, analytics cookies, or advertising cookies. No cookie consent banner is legally required because we only use functionally-necessary cookies.
Children
11xLab is not intended for anyone under 18. If we learn we’ve collected data from a child, we will delete it and any associated account.
Payment processors
- Stripe (card payments) processes your name, email, and card details directly — we only receive a customer ID and a payment status. Stripe’s privacy policy
- Atlos (crypto payments) processes your wallet address and amount — we receive an invoice ID and a payment status. Atlos’s privacy policy
- Resend (transactional email) processes the recipient’s email address and the message body of sign-in links and receipts. Resend’s privacy policy
Changes to this policy
We’ll email registered users (or notify in-app for private-mode users) before making material changes.
Contact
Data protection questions: support@11xlab.trade · General support: support@11xlab.trade · Or use our contact page.