NYTHOSX
Pricing Sign in

Privacy Policy

Last updated: 2026 · Aligned with RA 10173
This document is a template for a real product. Before launching to paying customers, have a qualified lawyer in your jurisdiction review and adapt it to Philippine law (RA 10173 for privacy) and any other jurisdiction you serve.

This policy describes what data NythosX collects, why, and your rights. We aim to collect the minimum necessary to run the service.

1. What we collect

  • Account data — email, display name, hashed password, tier, and timestamps.
  • Configuration — the instruments, targets, and alert preferences you set.
  • Positions — trades you log, including amounts, prices, and notes.
  • Usage logs — sign-in events, admin actions, alert firings, and API key usage. Stored in our audit table.
  • Session data — IP address and user-agent for each session, used to detect compromise.
  • Payment data — handled entirely by Stripe. We never see card numbers.

2. What we do NOT collect

  • Exchange API keys.
  • Bank account details.
  • Identity documents.
  • Location data beyond IP-derived country.

3. How we use it

  • Deliver alerts you configured.
  • Show your portfolio and analytics.
  • Prevent fraud and abuse.
  • Bill subscriptions and send service emails.
  • Improve the product through aggregated, anonymised usage statistics.

4. Sharing

We share data only with:

  • Cloudflare — hosting and D1 database.
  • Resend — transactional email delivery.
  • Stripe — payment processing.

We do not sell your data to third parties or ad networks.

5. Retention

Account data is retained while your account is active. Audit logs are retained for 90 days. On account deletion, we purge your configuration, positions, API keys, and sessions from production within 30 days. A hashed record of deletion is kept for compliance.

6. Your rights (RA 10173 / GDPR)

  • Access — export all your data from Account → Sessions & data.
  • Rectification — edit your profile from Account → Profile.
  • Erasure — delete your account at any time. See retention above.
  • Portability — same as access; export is machine-readable JSON.
  • Objection — email privacy@nythosx.com.

7. Security

Passwords are hashed with PBKDF2-SHA-256 at 100,000 iterations. Sessions are stored as SHA-256 hashes. API keys are hashed at rest and shown only once. All traffic is served over HTTPS.

8. Cookies

We use one cookie, nx_session, to keep you signed in. It is HttpOnly, Secure, and SameSite=Lax. We do not use tracking cookies or third-party analytics cookies.

9. Children

NythosX is not for anyone under 18. We do not knowingly collect data from minors.

10. Contact

Data Protection Officer: privacy@nythosx.com.

Terms · Privacy · Disclaimer · Refunds · Home