Legal

Privacy Policy

Last updated: September 10, 2026

Our default is minimum data. This page tells you what that actually means in practice, in plain language — not in legalese written to protect us at your expense.

What we collect

Normal mode (email or Google sign-in)

  • Your email address
  • A salted hash of your IP address (for session security only — we never store the raw IP)
  • Your display name, if you sign in with Google
  • The exchange trading data you connect via API keys or wallet addresses

Private mode (12-word recovery phrase)

  • Only the public cryptographic key derived from your phrase
  • No email, no IP address, no session-linked personal identifiers
  • The exchange trading data you connect

What we do with it

  • Show it back to you. All computed metrics, tags, charts, and reports are yours to see in the app.
  • Sync more trades. We periodically fetch new trades from the exchanges you’ve connected, using the read-only credentials you provided.
  • Send you emails you asked for (sign-in links, invite codes, receipts, service notices). We use Resend as our email provider — they see the email address but not the content of your trades.
  • Charge you if you subscribe. Payment is processed by Stripe or Atlos. We never see your card details.

What we do NOT do

  • We do not sell your data to anyone. Ever.
  • We do not share it with third parties for advertising, profiling, or analytics.
  • We do not run third-party tracking scripts (no Google Analytics, no Facebook Pixel, no Mixpanel, no Segment).
  • We do not log your IP address in private mode.
  • We do not have access to your exchange trading funds. The API keys and wallet addresses you provide are read-only.

Where it lives

Your data is stored in a PostgreSQL database on servers in Germany (Hetzner Falkenstein). The database is encrypted at rest and only accessible over SSH by a small number of authorized operators.

How long we keep it

  • Active accounts: as long as your account exists.
  • Deleted accounts: all your data is permanently removed within 30 days of the deletion request. Backups containing your data expire and are overwritten within 60 days.
  • Sign-in logs: rotated after 90 days.

Your rights (GDPR)

If you’re in the European Economic Area, you have the right to:

  • Access your data (available directly in the app; a full JSON export can be requested at support@11xlab.trade)
  • Correct inaccurate personal data
  • Delete your account and all associated data
  • Object to processing for reasons that we don’t currently do anyway (marketing, profiling)
  • Complain to your local Data Protection Authority (in Slovenia, that’s the Information Commissioner — ip-rs.si)

Private-mode users have effectively already exercised the “minimize personal data” principle by design — we don’t have your email or IP to begin with.

Cookies

We use one cookie: a session token that keeps you signed in. It expires when you sign out or after 30 days of inactivity, whichever comes first.

We do not use third-party cookies, analytics cookies, or advertising cookies. No cookie consent banner is legally required because we only use functionally-necessary cookies.

Children

11xLab is not intended for anyone under 18. If we learn we’ve collected data from a child, we will delete it and any associated account.

Payment processors

  • Stripe (card payments) processes your name, email, and card details directly — we only receive a customer ID and a payment status. Stripe’s privacy policy
  • Atlos (crypto payments) processes your wallet address and amount — we receive an invoice ID and a payment status. Atlos’s privacy policy
  • Resend (transactional email) processes the recipient’s email address and the message body of sign-in links and receipts. Resend’s privacy policy

Changes to this policy

We’ll email registered users (or notify in-app for private-mode users) before making material changes.

Contact

Data protection questions: support@11xlab.trade  ·  General support: support@11xlab.trade  ·  Or use our contact page.