Back to AlphaGoat
ALPHAGOAT / LEGAL
Terms of usePrivacy policy

AlphaGoat Privacy Policy

Effective Date: [EFFECTIVE DATE]
Last Updated: [EFFECTIVE DATE]

This Privacy Policy explains how [LEGAL ENTITY NAME], registration number (EDRPOU) [EDRPOU], with its registered office at [REGISTERED ADDRESS] (“AlphaGoat”, “we”, “us”, or “our”), collects, uses, stores, shares, and protects personal information when you use AlphaGoat.

This Policy applies to the AlphaGoat website, trading terminal, mobile applications, APIs, signal-processing functionality, and related services (collectively, the “Service”).

1. Data Controller

For purposes of applicable data-protection laws, the controller responsible for personal data processed in connection with the Service is:

[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Registration number (EDRPOU): [EDRPOU]
Email: [email protected]

Depending on where you live, applicable privacy laws may provide additional rights described below.

2. Information We Collect

The information we process depends on the functionality you use.

2.1 Account and Identity Information

We may process:

  • email address;
  • display name;
  • profile information;
  • internal user identifiers;
  • account creation and status information;
  • authentication-provider identifiers.

If you sign in through a third-party authentication provider, such as Google, Apple, X, Facebook, or Discord, we may receive information made available by that provider according to your settings and the authorization flow.

We do not receive your password for those third-party services.

2.2 Authentication and Security Information

We may process:

  • session identifiers;
  • login timestamps;
  • authentication events;
  • IP addresses;
  • device and browser information;
  • security-related activity;
  • two-factor authentication configuration and verification state;
  • information used to identify suspicious or unauthorized access.

2.3 Connected Exchange Information

When you connect a supported third-party cryptocurrency exchange, we may process information required to provide the integration, including:

  • exchange name;
  • account identifiers;
  • API credentials;
  • API permission information;
  • connection status;
  • account balances;
  • open positions;
  • orders;
  • executed trades;
  • trading history;
  • realized and unrealized profit and loss information;
  • margin and leverage information;
  • funding-related information;
  • other account information returned by the relevant exchange API.

AlphaGoat uses this information to provide trading-terminal functionality and account synchronization.

2.4 API Credentials

Where required to connect an exchange, AlphaGoat may process exchange API keys, API secrets, passphrases, or equivalent authentication information.

These credentials are sensitive information and are handled using security controls designed for their sensitivity.

AlphaGoat does not require withdrawal permissions to provide ordinary trading functionality.

You should not provide AlphaGoat with exchange API credentials that permit withdrawals unless AlphaGoat explicitly introduces a feature requiring such permission and separately informs you.

AlphaGoat will never ask you to submit:

  • wallet seed phrases;
  • wallet recovery phrases;
  • blockchain private keys;
  • exchange passwords;
  • authentication codes intended for another service.

2.5 Trading and Terminal Information

We may process information generated when you use the Service, including:

  • trading instructions;
  • order parameters;
  • position information;
  • entry prices;
  • stop-loss settings;
  • soft stop-loss settings;
  • take-profit settings;
  • DCA settings;
  • leverage;
  • margin configuration;
  • risk settings;
  • timeframes;
  • order and position status;
  • trading-related user preferences;
  • other terminal configuration.

This information is processed to provide the functionality you request.

2.6 Signal Parsing Information

When you use AlphaGoat's signal-parsing functionality, we may process:

  • text submitted for parsing;
  • parsed output;
  • identified symbols;
  • trading direction;
  • entry information;
  • stop-loss information;
  • take-profit information;
  • DCA information;
  • risk information;
  • timeframe information;
  • parser status;
  • model and processing diagnostics;
  • error information;
  • timestamps;
  • identifiers associated with the requesting account.

Signal-parsing information may be reviewed by authorized AlphaGoat personnel where reasonably necessary to investigate parsing failures, security incidents, or product-quality issues.

Do not include passwords, exchange API keys, wallet private keys, authentication codes, or other unnecessary confidential information in signal text.

2.7 Usage and Technical Information

We may automatically collect:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • application version;
  • pages or screens viewed;
  • feature usage;
  • timestamps;
  • request and response metadata;
  • performance information;
  • crash information;
  • diagnostic logs;
  • security events.

We use this information to operate, secure, troubleshoot, and improve AlphaGoat.

2.8 Communications and Support

If you contact us, we may process:

  • your email address;
  • the contents of your message;
  • attachments you intentionally provide;
  • support history;
  • information necessary to investigate and resolve your request.

2.9 Payment and Subscription Information

If AlphaGoat offers paid subscriptions, we may process information related to:

  • subscription plan;
  • subscription status;
  • billing period;
  • transaction identifiers;
  • payment status;
  • invoices or receipts;
  • limited payment-related metadata.

Payment information may be processed directly by a payment provider or app-store operator.

AlphaGoat does not necessarily receive or store your complete payment-card number.

3. How We Obtain Information

We obtain personal information:

  • directly from you;
  • automatically through your use of AlphaGoat;
  • from connected exchanges at your instruction;
  • from authentication providers;
  • from payment providers;
  • from devices and browsers;
  • from service providers that support operation of AlphaGoat.

4. Why We Process Information

We process personal information where necessary to:

Provide the Service

This includes:

  • creating and maintaining your account;
  • authenticating you;
  • connecting exchange accounts;
  • synchronizing balances and positions;
  • retrieving market and account information;
  • submitting authorized trading instructions;
  • operating soft stop-loss and other trading-management functionality;
  • parsing signals;
  • providing customer support.

Protect the Service

We process information to:

  • prevent unauthorized access;
  • detect abuse;
  • investigate security incidents;
  • protect accounts and infrastructure;
  • enforce our Terms of Service.

Maintain and Improve AlphaGoat

We may use operational and diagnostic information to:

  • identify defects;
  • investigate parser failures;
  • improve reliability;
  • monitor infrastructure;
  • understand feature performance.

Comply With Legal Obligations

We may process or retain information where necessary to comply with:

  • applicable law;
  • valid governmental requests;
  • court orders;
  • tax or accounting requirements;
  • legal claims;
  • sanctions requirements.

5. Legal Bases for Processing

Where the GDPR, UK GDPR, or another law requiring a legal basis applies, we generally rely on the following bases.

Performance of a Contract

We process information necessary to provide AlphaGoat and perform our obligations under the Terms of Service.

Examples include account data, exchange connectivity information, trading information, and signal-parsing requests.

Legitimate Interests

We may process information where necessary for legitimate interests such as:

  • protecting AlphaGoat;
  • preventing fraud and abuse;
  • maintaining security;
  • diagnosing technical issues;
  • improving reliability;
  • protecting legal rights.

We consider the impact on users when relying on legitimate interests.

Consent

Where required by law, we rely on consent for specific processing activities, including certain cookies, analytics, or marketing activities.

You may withdraw consent where processing is based on consent.

Legal Obligations

We may process information when necessary to comply with applicable laws or valid legal requirements.

6. Signal Parsing and OpenAI

AlphaGoat uses artificial-intelligence technology to provide signal-parsing functionality.

When you request signal parsing, the text you submit and information reasonably necessary to perform the request may be transmitted to OpenAI through its API services.

OpenAI processes this information as a technology service provider subject to the applicable contractual terms and data-processing configuration.

AlphaGoat does not intentionally submit your exchange API credentials, account passwords, or authentication secrets to OpenAI as part of signal parsing.

You should not include such information in signal text.

OpenAI API inputs and outputs are not used to train OpenAI models by default unless the applicable account explicitly opts into such use.

Retention by OpenAI may depend on the API, configuration, applicable contractual arrangements, and available data-retention controls.

AlphaGoat may independently retain signal-parsing history as described below.

7. Signal History Retention

AlphaGoat currently retains signal-parsing history for up to 30 days by default for operational diagnostics, troubleshooting, and product-quality purposes.

Signal history may include the submitted text, parsed result, processing status, diagnostics, and an association with the requesting AlphaGoat account.

If an AlphaGoat account is deleted before the end of this retention period, identifying references may be removed or dissociated while retained signal text and processing results may remain until the applicable retention period expires.

Retention may be shorter where operationally possible or longer where required by law, security needs, dispute resolution, or preservation obligations.

8. Sharing of Information

AlphaGoat does not sell your personal information.

We may disclose information to the following categories of recipients where necessary.

Infrastructure and Hosting Providers

Providers used to host or operate AlphaGoat infrastructure, databases, networking, backups, and related systems.

Artificial Intelligence Providers

Providers such as OpenAI where necessary to provide signal-parsing functionality.

Authentication Providers

Where you choose to use them, this may include services such as:

  • Apple;
  • Google;
  • X;
  • Facebook;
  • Discord.

Cryptocurrency Exchanges

Information and trading instructions are transmitted to exchanges that you choose to connect.

Payment Providers and App Stores

Where paid subscriptions are offered, payment information may be processed by payment processors, Apple, Google, or other relevant billing providers.

Security, Monitoring, and Technical Providers

We may use third parties to help operate, secure, diagnose, monitor, or maintain the Service.

Professional Advisers

Information may be disclosed where reasonably necessary to lawyers, accountants, auditors, insurers, or other professional advisers.

Authorities and Legal Recipients

We may disclose information where reasonably necessary to:

  • comply with law;
  • respond to legally valid requests;
  • enforce our agreements;
  • investigate fraud or abuse;
  • protect AlphaGoat, users, or third parties.

Corporate Transactions

If AlphaGoat is involved in a merger, acquisition, financing, restructuring, asset sale, or similar transaction, personal information may be transferred subject to appropriate confidentiality and legal safeguards.

9. International Data Transfers

AlphaGoat and its service providers may process information in countries other than the country in which you live.

This may include processing outside Ukraine and, where applicable, outside the European Economic Area.

Where required by applicable law, we use appropriate safeguards for international transfers, which may include contractual safeguards, adequacy mechanisms, or other legally recognized transfer mechanisms.

10. How Long We Keep Information

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected.

Retention depends on the type of information and may include:

  • account information: generally while your account remains active and for a limited period afterward where required for security, legal, accounting, or dispute purposes;
  • exchange connection information: while necessary to maintain the connection or until the credentials are removed or revoked, subject to limited security or audit records;
  • signal-parsing history: generally up to 30 days by default;
  • security logs: for a period reasonably necessary to investigate abuse, incidents, and unauthorized activity;
  • support communications: as reasonably necessary to provide support and maintain relevant records;
  • billing records: for the period required by tax, accounting, and other applicable laws.

Data may remain temporarily in encrypted backups until those backups are rotated or deleted under ordinary backup schedules.

We may retain information for longer where reasonably necessary to establish, exercise, or defend legal claims or where required by law.

11. Security

We use administrative, organizational, and technical measures designed to protect information against:

  • unauthorized access;
  • disclosure;
  • alteration;
  • destruction;
  • loss;
  • misuse.

Security measures may include encryption, access controls, authentication controls, infrastructure isolation, monitoring, credential protection, and restricted administrative access.

However, no internet-connected system can be guaranteed to be completely secure.

You are responsible for protecting your own AlphaGoat account, connected exchange accounts, devices, authentication methods, and API permissions.

12. Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • request access to your personal information;
  • request correction of inaccurate information;
  • request deletion;
  • request restriction of processing;
  • object to certain processing;
  • request a portable copy of certain information;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with an applicable data-protection authority.

These rights may be subject to legal exceptions and verification requirements.

To exercise a privacy right, contact:

[email protected]

We may need to verify your identity before completing a request.

Do not send passwords, API keys, authentication codes, or wallet credentials when making a privacy request.

13. Account Deletion

You may request deletion of your AlphaGoat account through available account-deletion functionality or by contacting [email protected].

Deleting an AlphaGoat account does not automatically delete an account maintained independently by a third-party exchange or authentication provider.

When your AlphaGoat account is deleted, we will delete, anonymize, or dissociate personal information that is no longer reasonably necessary, subject to:

  • legal retention obligations;
  • security records;
  • fraud prevention;
  • dispute resolution;
  • accounting requirements;
  • backup cycles;
  • other lawful retention requirements.

Exchange API credentials associated with a deleted account will no longer be used by AlphaGoat for ongoing account connectivity.

For additional security, you may also revoke AlphaGoat's API credentials directly through your connected exchange.

14. Cookies and Similar Technologies

The AlphaGoat website and web application may use cookies, local storage, or similar technologies necessary for:

  • authentication;
  • session management;
  • security;
  • preferences;
  • functionality.

Where non-essential analytics, advertising, or tracking technologies are introduced and consent is legally required, AlphaGoat will request appropriate consent.

15. Third-Party Links and Services

AlphaGoat may contain links to or integrate with third-party services.

This Privacy Policy does not govern the independent processing performed by:

  • cryptocurrency exchanges;
  • authentication providers;
  • payment providers;
  • third-party websites;
  • other independent services.

You should review the privacy policies of those services.

16. Children's Privacy

AlphaGoat is not intended for persons under the age of 18.

We do not knowingly provide the Service to children under 18.

If we become aware that personal information has been collected from a person who is not eligible to use the Service, we may delete the relevant information and account.

17. Automated Processing

AlphaGoat uses automated systems to provide technical functionality, including signal parsing and trading workflow tools.

The signal parser converts user-submitted text into structured information.

It does not determine whether a trade is suitable for you and is not intended to make legal, credit, employment, insurance, or similarly regulated decisions about you.

You remain responsible for deciding whether to use parsed trading information.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to AlphaGoat;
  • new functionality;
  • changes to service providers;
  • legal requirements;
  • security or operational changes.

The latest version will be published with an updated “Last Updated” date.

Where required by law or where changes materially affect your privacy rights, we will provide additional notice.

19. Contact

For questions, privacy requests, or concerns regarding this Privacy Policy, contact:

[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Registration number (EDRPOU): [EDRPOU]
Email: [email protected]

BalanceEntry formAdjust riskPositionHistoryExchangesTry demoTerms of usePrivacy policy
Made with ❤️ in Ukraine 🇺🇦© 2026 AlphaGoat. All rights reserved.