Privacy Policy
Last updated: September 8, 2026
1. Information We Collect
We process information used to operate your Decoded account, trade replication sessions and Security Strategy configurations. This includes:
- Account Credentials: Email address and username when registering.
- Exchange API Keys: API keys, secret keys, and passphrases for connected exchanges (e.g. Binance, Bybit, OKX).
- Trading and operational data: Configured accounts, symbols, sizing rules, order and position information, timestamps, status and error diagnostics used to operate and troubleshoot the services.
2. How We Use Your Information
These data support the services you configure and the operation of your account:
- Trade replication and protection: Sending follower orders and managing Binance TP/SL under your session and strategy settings.
- Position reconciliation: Comparing available order and position information to detect differences and determine configured follow-up actions. Reconciliation does not guarantee identical positions or execution across accounts.
- Platform Troubleshooting: Debugging rate limit issues, connection dropouts, or execution errors.
3. Exchange Credentials
Saved exchange credentials are managed through HashiCorp Vault, and execution services receive access through time-limited wrapped credentials. Keep withdrawal permissions disabled on every connected key and enable only the market permissions your configuration needs. Read the API credential security guidance for access and revocation steps.
4. Data Sharing and Third Parties
Decoded does not sell, lease, or rent your personal information or trading history. Connected exchanges receive the API authentication and trading requests needed for your configuration. Services used for sign-in, hosting and credential storage also process information as part of operating Decoded.
5. Cookies and Tracking
Browser storage and cookies can support sign-in and interface preferences. Your browser lets you review and clear this storage; doing so can sign you out or reset saved preferences. Clearing browser data does not remove server-side account records or exchange orders.
6. Access, Deletion and Credential Revocation
To request access, export or deletion of your account information, contact support@decodedtrading.com. Removing an exchange connection deletes its saved credential record as part of that operation. This does not promise immediate deletion from every running service or backup, and it does not revoke the key on the exchange. Revoke the exchange key to end its authority, and review any open orders or positions separately.