Privacy Policy
Last updated: May 25, 2026
1. Data Controller
EdgeFlow (the “Service”) is an independently operated software project based in Dubai, United Arab Emirates. Lemon Squeezy (Lemon Squeezy LLC, a Delaware company) acts as the Merchant of Record for all subscription transactions and is responsible for collecting payments, charging applicable VAT and sales tax, issuing invoices, and processing payment-related disputes per Lemon Squeezy's terms.
2. Data We Collect
- Account data: email, name, hashed password, OAuth provider ID (Google).
- Trade data: trades you log (instrument, prices, sizes, timestamps, tags, notes).
- Journal data: text entries, emotion tags, lessons.
- AI data: prompts and responses generated by your use of the AI Coach.
- Billing data: processed by LemonSqueezy; we store only subscription status and customer ID, never card numbers.
- Telemetry: browser, IP, page paths, error logs. Retained 90 days then anonymized.
3. Legal Bases (GDPR Art. 6)
Contract performance (delivering the Service), legitimate interest (security, fraud prevention, product analytics), consent (marketing emails), legal obligation (tax, regulatory).
4. How We Use Data
To operate the Service, generate behavioral analytics, provide AI coaching, send transactional emails, prevent fraud, and comply with law.
5. AI Processing
Your trades and journal entries may be sent to third-party AI providers (e.g., Anthropic, OpenAI) under data-processing terms that prohibit training on your content.
6. Sharing
We do NOT sell personal data. We share with: (a) sub-processors strictly necessary (hosting, AI providers, email, payments) under DPAs, (b) law enforcement under valid legal request, (c) acquirers in the event of a business sale (with notice).
7. Retention
Account data for the life of the account + 90 days post-deletion. Trade and journal data deleted immediately on account deletion request (Settings → Danger Zone). Billing records retained 7 years for tax compliance.
8. Your Rights (GDPR / UAE PDPL / CCPA where applicable)
Access, rectification, erasure, portability, restriction, objection, and withdrawal of consent. Exercise rights by emailing davidmosbusiness@gmail.com or using the in-app data export and delete tools.
9. Transfers
Data may be processed outside your country (including the United States and the European Union) under Standard Contractual Clauses where required.
10. Security
TLS in transit, encryption at rest, scoped database access, audit logs. No system is 100% secure.
11. Children
Not for users under 18.
12. Cookies
See Cookie Policy.
13. Changes
Material changes notified by email or in-app 14 days before effective date.
14. Contact
EdgeFlow · davidmosbusiness@gmail.com