1. Scope of This Policy
This Privacy Policy explains what information Loop Trading LLC ("LoopTrading", "we") collects when you use the LoopTrading website and application (the "Service"), how we use and share it, how long we keep it, and the choices you have. It is effective as of the "Last updated" date shown above.
LoopTrading is operated in the United States. Privacy questions and requests go to [email protected].
2. Short Version
We collect the information needed to provide automated trading software: account information, encrypted exchange API credentials, exchange account and trading data, bot configurations, billing records, support messages, security logs, and optional analytics. We do not sell your personal data. We do not share your trading activity, balances, API credentials, or bot configurations for advertising.
3. Information We Collect
3.1 Account and identity information
- Email address, name, profile image, and account identifiers;
- Hashed password if you use email and password sign-in;
- OAuth profile data, such as Google email, name, and profile image, if you sign in with Google;
- Sign-up allowlist status, acknowledgement version, acceptance timestamps, and account settings.
3.2 Authentication and security information
- Login events, failed login events, IP address, approximate device/browser information, and user agent;
- Rate-limit records, session data, security alerts, and operational audit logs;
- Bug reports, screenshots, page URLs, and diagnostic data you choose to submit.
3.3 Exchange integration information
- Exchange name, account label, and public API key identifier;
- API secrets encrypted at rest using a key stored separately from the database;
- Account balances, order status, fills, fees, symbols, and trade history fetched from connected exchanges;
- Exchange errors, rejected orders, rate-limit events, and reconciliation data needed to keep bots accurate.
3.4 Bot, trading, and performance information
- Bot names, symbols, strategy choices, offsets, order sizes, capital caps, safety settings, and runtime state;
- Orders placed through the Service and their results, including fill price, quantity, fees, realized P&L, cycle count, and status;
- Price candles, sandbox runs, backtest inputs, analytics views, and billing calculations;
- Optional leaderboard opt-in data, such as pseudonymous performance metrics (a hashed handle, strategy, exchange, realized return percentage, and cycle count).
3.5 Billing and payment information
- Billing plan, trial status, subscription status, payment-method-on-file status, and billing cycle dates;
- Stripe customer, checkout, subscription, invoice, setup intent, and payment identifiers;
- Legacy performance-fee calculation records from the discontinued profit-share plan, including billing windows, net realized profit, fee amount, carry-forward amounts, and charge status.
Payment cards are processed by Stripe. We do not store full card numbers, CVV codes, or complete card credentials.
3.6 Communications and support
- Emails, support requests, bug reports, feedback, waitlist entries, notification preferences, and unsubscribe records;
- Transactional email delivery metadata, such as whether a message was sent or failed.
3.7 Cookies, analytics, and device data
- Essential cookies and local storage used for login, security, preferences, and consent choices;
- Google Analytics page-view and navigation data when analytics is enabled and you grant analytics consent;
- Sentry error diagnostics when enabled, scrubbed of credentials before they leave the application. We do not record session replays;
- Server logs such as request paths, response codes, timestamps, IP addresses, and error traces;
- Request metadata seen by our content delivery network and web application firewall (Cloudflare), such as your IP address, user agent, and requested URL, used to route traffic and block abuse;
4. Sources of Information
We collect information from:
- You, when you create an account, configure bots, connect exchanges, choose settings, contact support, or submit feedback;
- Your connected exchanges, when you authorize us to read balances, orders, fills, fees, and market data through API keys;
- Stripe, Google, Resend, Sentry, hosting providers, and other service providers used to operate the Service;
- Your browser or device through cookies, local storage, headers, logs, and consent preferences.
5. How We Use Information
- Operate the Service. Authenticate users, run bots, process exchange API instructions, reconcile state, display dashboards, and send notifications.
- Protect users and the platform. Detect fraud, abuse, unauthorized access, suspicious activity, and technical failures.
- Process billing. Manage trials, subscriptions, legacy performance-fee settlement from the discontinued plan, invoices, payment method setup, and billing support.
- Improve the product. Debug errors, monitor uptime, plan capacity, evaluate feature quality, and understand aggregate usage.
- Communicate with you. Send transactional messages, security notices, product updates, support replies, billing notices, and optional summaries.
- Comply with law. Respond to lawful requests, enforce terms, maintain tax/accounting records, and protect legal rights.
6. How We Share Information
We share information only as needed to provide, secure, bill, support, and improve the Service, or when required by law. Current provider categories include:
- Hosting and infrastructure: Railway, Neon/Postgres, Upstash/Redis, and related infrastructure providers;
- Authentication: Google OAuth if you choose Google sign-in;
- Payments: Stripe for checkout, subscriptions, invoices, setup intents, and payment-method handling;
- Email: Resend or other transactional email providers;
- Error monitoring: Sentry for error diagnostics when enabled (no session replay);
- Analytics: Google Analytics 4 when enabled and allowed by consent settings;
- AI model provider: Anthropic, PBC, which generates the text for the in-app assistant, configuration helper, error explainer, and digests from the inputs described in section 9. Under Anthropic's commercial API terms, our inputs and outputs are not used to train Anthropic's models and are retained by Anthropic only for a limited period for abuse monitoring;
- Content delivery and web application firewall: Cloudflare, which sits in front of our servers and processes IP addresses and request metadata to route traffic and block abuse;
- Exchanges: Binance.US, Coinbase, or Kraken — whichever you connect. Additional exchanges (such as Binance global where legally available) may be supported later and will be listed here before they launch;
- Professional advisers: lawyers, accountants, auditors, insurance providers, or compliance advisers under appropriate confidentiality expectations;
- Legal and safety recipients: courts, regulators, law enforcement, or counterparties when required or appropriate to protect rights, safety, security, or legal compliance.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. If that changes, this policy and the app must be updated with any required opt-out mechanisms before the change occurs.
7. Sensitive and Financial Information
Exchange API credentials, exchange account data, balances, trading history, billing records, and financial account-related information can be sensitive. We use this information to provide the Service, secure accounts, process billing, comply with law, and support users. We do not use this information for advertising.
8. Cookies and Consent
Essential cookies and local storage support login, security, preferences, theme settings, and consent choices. Analytics cookies are optional. When Google Analytics is enabled, the app defaults analytics consent to denied until you accept analytics cookies in the banner. You can decline analytics without losing access to core Service features. Analytics data is pseudonymous, not anonymous: Google Analytics sets a persistent client identifier cookie and processes your IP address to infer approximate location.
Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a decline of optional analytics cookies and do not show you the consent banner. You can change that choice later by clearing the site's stored data.
9. AI Features and Automated Processing
We incorporate certain interactive artificial intelligence features into the Service ("AI Technology"), such as the in-app assistant, configuration helper, error explainer, and periodic digests. When you use these features, the text you type and limited context about your account's bot configuration (such as strategy settings, symbols, recent bot activity, and, for the assistant, the bot's current position and profit or loss) are transmitted to our AI model provider, Anthropic, PBC, to generate the response. We do not send your password, API secrets, or payment card details to the AI provider. AI output is generated by a third-party model, can be wrong or incomplete, and is not investment, legal, accounting, or tax advice. Our AI features are designed to explain and to translate your instructions into proposed settings — they do not make trading decisions, execute trades, or change a bot until you apply a proposal yourself.
Avoid typing personal data you do not want processed into AI features. Inputs you make that contain personal data may be subject to automated processing by the AI provider. If you believe your personal data has been processed in this manner, contact us at [email protected] and we will attempt to assist you with the protection of your data rights.
10. Data Retention
We keep information for as long as reasonably needed to provide the Service, maintain security, meet legal and tax obligations, resolve disputes, and enforce agreements. Current expected retention includes:
- Account data: for the life of the account, then deleted or anonymized after account closure unless retention is legally or operationally required;
- Encrypted API secrets: deleted when you remove the exchange key or close the connected account, subject to backup and operational limits;
- Trading, billing, and invoice records: retained as needed for accounting, tax, dispute, fraud-prevention, and audit purposes;
- Authentication and security events (sign-ins, failed sign-ins, IP address, user agent, MFA and key changes): up to 12 months;
- Operational audit and warning events about bots and orders: up to 24 months, because they document what the software did with your exchange account;
- In-app notifications: up to 6 months;
- Resolved bug reports and their attachments: up to 12 months after resolution;
- Opt-out records (an email address and the reason it must not be contacted) are retained after account deletion so your choice keeps being honoured;
- Hosting request logs and error diagnostics: about 30 days at our hosting and monitoring providers, unless needed longer for security, debugging, legal, or abuse-prevention reasons;
- Backups: retained on provider backup cycles and deleted according to normal backup rotation;
- Aggregated or anonymized data: may be retained indefinitely if it no longer identifies you.
11. Security
We use administrative, technical, and operational safeguards designed for the sensitivity of the information we handle. Current safeguards include TLS in transit, encrypted API secrets at rest, bcrypt password hashing, same-origin checks on mutating routes, rate limiting, logging, limited access to production systems, and monitoring for operational failures.
Our security practices and the limits of what we claim are described on the Security & reliability page. Security researchers can find our disclosure contact in /.well-known/security.txt.
12. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to certain processing, withdraw consent, opt out of sale or sharing, limit use of sensitive personal information, or appeal a privacy request decision.
To make a request, contact [email protected]. If that mailbox is unavailable, write to [email protected]. We may need to verify your identity before fulfilling certain requests. Some data may be retained where needed for security, legal, tax, billing, dispute, or operational reasons.
We will not discriminate against you for exercising privacy rights. The in-app export (Settings → Export) contains your filled orders and Convert trades as a CSV; account details, exchange-key metadata, security events, and billing records are provided on request to the address above. Deleting your account requires stopping your bots and closing or taking over any open positions first, because we cannot leave orders running on your exchange without an account to manage them. Deletion of account or exchange data ends the Service for that account.
13. State Privacy Notices
For U.S. state privacy-law review, the categories of personal information collected include identifiers; account credentials; commercial and billing information; internet, device, and network activity; geolocation inferred from IP address; financial and trading information; support communications; and inferences or analytics derived from use of the Service. We use and disclose these categories for the purposes described in this policy.
We do not currently sell personal information or share it for cross-context behavioral advertising. We do not knowingly collect personal information from anyone under 18.
14. International Users
The Service is operated from the United States. If you access it from outside the United States, your information may be processed in the United States and other locations where our service providers operate. Do not use the Service if doing so would violate laws applicable to you.
15. Children
LoopTrading is not directed to children or anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can address it.
16. Changes to This Policy
We may update this Privacy Policy as the Service evolves or service providers change. When a change is material, we will email the address on your account at least 14 days before it takes effect and, where appropriate, ask you to acknowledge it in the app. Other changes take effect when posted with a new "Last updated" date.
17. Contact
Privacy questions can be sent to [email protected]. If that mailbox is unavailable, write to [email protected].
Changes in this version
Version dated September 28, 2026: replaced the status paragraphs in sections 1, 7, and 11 with a plain scope statement; named Anthropic (AI model provider) and Cloudflare (CDN and firewall) in sections 3.7, 6, and 9; stated that session replay is not used; described Global Privacy Control handling in section 8; replaced the "about 30 days" log retention line with the real retention buckets in section 10; described the export contents and the deletion prerequisite in section 12; added the 14-day notice commitment to section 16.