Privacy Policy

Last Updated: January 14, 2026

1. Introduction

Welcome to AralForex GPT ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational platform and services.

By using AralForex GPT, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

We are committed to protecting your privacy and ensuring the security of your personal information. This policy describes our practices regarding data collection, use, and protection.

2. Information We Collect

We collect information that you provide directly to us and information that is automatically collected when you use our services:

Account Information

  • Email address (required for account creation)
  • Password (encrypted and hashed)
  • Display name (optional)
  • Account creation date and last login information

Profile & Subscription Data

  • Subscription plan (Free, Starter, Pro, or Elite)
  • Account role (user or admin)
  • Subscription status and billing information
  • Payment method information (processed securely by third-party payment processors)

Usage Data

  • Trade journal entries and trading data you input
  • Chat conversations and messages with our AI assistant
  • Trade ideas you generate or save
  • Feature usage statistics (e.g., number of chat messages, trade ideas generated)
  • Analytics and performance metrics

Technical Information

  • IP address and location data (approximate)
  • Browser type and version
  • Device information (type, operating system)
  • Pages visited and time spent on pages
  • Referral sources and search terms
  • Error logs and crash reports

Authentication Data

  • OAuth provider information (if using Google OAuth)
  • Session tokens and authentication cookies
  • Login history and security events

3. How We Use Your Information

We use the information we collect for the following purposes:

Service Provision

  • Create and manage your account
  • Provide access to platform features (Dashboard, Chat, Journal, Trade Ideas, Risk Calculator)
  • Process subscriptions and manage billing
  • Deliver AI-powered educational content and responses
  • Store and organize your trade journal data

Communication

  • Send account-related notifications (welcome emails, password resets)
  • Respond to your support requests and inquiries
  • Send important service updates and policy changes
  • Provide customer support and technical assistance

Improvement & Analytics

  • Analyze usage patterns to improve our services
  • Develop new features and functionality
  • Monitor platform performance and identify issues
  • Conduct research and analytics (aggregated and anonymized)

Security & Compliance

  • Protect against fraud, abuse, and security threats
  • Enforce our Terms & Conditions
  • Comply with legal obligations and respond to legal requests
  • Detect and prevent unauthorized access

Personalization

  • Customize your experience based on your preferences
  • Provide relevant educational content and recommendations
  • Remember your settings and preferences

4. Data Sharing & Disclosure

We do not sell your personal information. We may share your information only in the following circumstances:

Service Providers

We share data with trusted third-party service providers who assist us in operating our platform:

  • Supabase: Cloud database and authentication services
  • Stripe/PayRex: Payment processing and subscription management
  • OpenAI: AI model services for chat and trade idea generation
  • Hosting Providers: Cloud infrastructure and hosting services

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

Legal Requirements

We may disclose your information if required by law or in response to:

  • Court orders, subpoenas, or legal processes
  • Government requests or regulatory inquiries
  • Enforcement of our Terms & Conditions
  • Protection of our rights, property, or safety

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control.

With Your Consent

We may share your information with your explicit consent or at your direction.

5. Data Storage & Security

Storage Location: Your data is stored on secure servers provided by Supabase and other cloud service providers. Data may be stored in various geographic locations, including outside your country of residence.

Security Measures: We implement industry-standard security measures to protect your information:

  • Encryption in transit (SSL/TLS) and at rest
  • Secure password hashing (never stored in plain text)
  • Row-level security policies in our database
  • Regular security audits and monitoring
  • Access controls and authentication requirements
  • Secure API endpoints and data transmission

Limitations: While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we continuously work to improve our security measures.

Your Responsibility: You are responsible for maintaining the confidentiality of your account credentials. Please use a strong, unique password and do not share your account with others.

6. Payment Processing

When you subscribe to a paid plan, your payment information is processed by third-party payment processors (Stripe or PayRex). We do not store your full credit card details on our servers.

Payment Data Collected:

  • Payment method type (credit card, etc.)
  • Billing address and contact information
  • Transaction history and subscription status
  • Payment processor customer ID (for subscription management)

Payment Processor Privacy: Payment processors have their own privacy policies governing the collection and use of your payment information. We encourage you to review their privacy policies:

We only receive confirmation of successful payments and subscription status updates. We do not have access to your full payment card numbers or CVV codes.

7. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience and analyze platform usage:

Essential Cookies

Required for the platform to function properly. These include authentication cookies that keep you logged in and session management cookies.

Analytics Cookies

Help us understand how users interact with our platform. This data is aggregated and anonymized.

Preference Cookies

Remember your settings and preferences (e.g., theme, language) to personalize your experience.

Managing Cookies: You can control cookies through your browser settings. However, disabling essential cookies may affect platform functionality. Most browsers allow you to:

  • View and delete cookies
  • Block cookies from specific sites
  • Block all cookies
  • Receive notifications when cookies are set

Do Not Track: We do not currently respond to "Do Not Track" signals, but we respect your privacy preferences through our cookie controls.

8. Your Rights & Choices

You have the following rights regarding your personal information:

Access & Portability

You can access and download your personal data, including trade journal entries, chat history, and account information, through your account settings or by contacting support.

Correction

You can update your account information, including email, display name, and preferences, through your account settings.

Deletion

You can request deletion of your account and associated data by contacting support. We will delete your data within 30 days, except where we are required to retain it for legal or operational purposes.

Opt-Out

You can opt out of marketing communications by unsubscribing from emails or adjusting your notification preferences in account settings. Account-related communications cannot be opted out of.

Data Portability

You can export your data in a machine-readable format. Contact support to request a data export.

Account Cancellation

You can cancel your subscription at any time through your account settings. Cancellation does not automatically delete your account or data.

To exercise these rights, please contact us at support@aralforex.com. We will respond to your request within 30 days.

9. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy:

  • Account Data: Retained while your account is active and for a reasonable period after account deletion for legal and operational purposes (typically 30-90 days)
  • Trade Journal Data: Retained until you delete your account or individual entries
  • Chat History: Retained until you delete conversations or your account
  • Payment Records: Retained as required by law (typically 7 years for tax and accounting purposes)
  • Analytics Data: Aggregated and anonymized data may be retained indefinitely for research and improvement purposes

When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution).

10. Third-Party Services

Our platform integrates with third-party services that have their own privacy policies. We encourage you to review their privacy practices:

Supabase

Provides database and authentication services. Privacy Policy: https://supabase.com/privacy

OpenAI

Provides AI model services for chat and content generation. Privacy Policy: https://openai.com/privacy

Stripe/PayRex

Processes payments and manages subscriptions. Privacy Policy: https://stripe.com/privacy

We are not responsible for the privacy practices of third-party services. Your interactions with these services are governed by their respective privacy policies.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.

By using our services, you consent to the transfer of your information to these countries. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy, including:

  • Using standard contractual clauses approved by data protection authorities
  • Ensuring service providers comply with applicable data protection laws
  • Implementing security measures regardless of data location

If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under GDPR. Please contact us to exercise these rights.

12. Children's Privacy

AralForex GPT is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will delete such information upon verification.

If we become aware that we have collected personal information from a child under 18 without parental consent, we will take steps to delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated Privacy Policy on this page with a new "Last Updated" date
  • Sending an email notification to your registered email address (for significant changes)
  • Displaying a notice on the platform

Your continued use of AralForex GPT after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you should stop using the platform and delete your account.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: support@aralforex.com

Support Hours: We typically respond within 24-48 hours during business days.

For data access requests, account deletion requests, or privacy-related inquiries, please use the contact information above or visit our Help & Support page.

We are committed to addressing your privacy concerns and will respond to your inquiries promptly.