# KLinePic Privacy Policy

Effective date: August 17, 2026

Version: 2.0

## 1. Scope

This policy explains how KLinePic, a digital trade-journal and chart-visualization service operated by an independent software developer, handles personal data.

## 2. Data we process

- **Uploaded trade data:** trade identifiers, symbols, execution times, prices, quantities, fees, and notes contained in files you submit.
- **Market data and settings:** requested symbols, market sources, chart settings, language, theme, and similar preferences.
- **Account data:** email address, hashed login and account tokens, current plan, redemption history, monthly usage, and support requests.
- **Agent API data:** API-key hash and prefix, permissions, limits, IP allowlist, request identifiers, status codes, timing, usage, and error summaries. A complete API key is shown only when it is created.
- **Billing records:** Creem customer, order, product, and subscription identifiers; plan, billing status, currency, amount, and relevant event timestamps. KLinePic does not receive or store full payment-card details.
- **Operational data:** security, error, delivery, webhook, and administrator audit records needed to operate and protect the service.

## 3. How data is used

We use data to provide charts and account features, prevent duplicate charges, enforce quotas, deliver login links, handle billing and support, investigate faults or abuse, and comply with legal obligations. Uploaded trade records are not used to train AI models.

## 4. Service providers and data sources

KLinePic shares only the data needed for the requested service with relevant providers:

- **Creem** acts as merchant of record and handles checkout, payment, tax, invoices, refunds, and subscription management.
- **Email, hosting, and storage providers** deliver login messages and operate the service.
- **Market-data providers** such as Tushare, AkShare-backed public sources, Binance, or Yahoo receive the market-data request needed to fetch candles.

These providers process data under their own terms and privacy policies. KLinePic does not sell personal data.

## 5. Storage and retention

Browser preferences and an account token may be stored in local storage. Server-side SaaS data is transmitted over HTTPS and stored only as needed for the service, security, billing, support, and legal obligations. Batch images are normally temporary and may be removed after the published retention period; backups may retain deleted records for a limited backup cycle.

Self-hosted deployments store their own data under the deployer's control. KLinePic cannot delete data held solely in someone else's self-hosted installation.

## 6. Your choices and rights

You may use basic features without creating a paid account, avoid uploading personal identifiers, revoke Agent API keys, cancel a paid subscription through the Creem Customer Portal, and request access, correction, export, or deletion of account data where applicable. Some billing, fraud-prevention, audit, or legal records may need to be retained.

## 7. Security

KLinePic uses access controls, token hashing, limited API-key display, and transport encryption. No internet service can guarantee absolute security, so keep tokens and API keys private and report suspected compromise promptly.

## 8. Children

KLinePic is not directed to children and is not intended for anyone who cannot lawfully enter into these terms in their jurisdiction.

## 9. Changes

Material changes will be published on this page with a new effective date.

## 10. Contact

Email `support@klinepic.com`. We normally respond within 3 business days.
