Kolosseum.pro
Email: support@kolosseum.pro
This policy explains what personal data Kolosseum Journal processes, why, where, for how long, and which rights you have under the General Data Protection Regulation (GDPR).
We do not process payment data, and we do not collect data from your device beyond what your browser sends with each request.
Database, authentication and file storage are provided by Supabase Inc. and hosted in Frankfurt, Germany (EU). The application is hosted by Vercel Inc. in Frankfurt, Germany (EU). Both act as processors under data processing agreements including the EU standard contractual clauses for any support access from outside the EU.
Trade data is retrieved directly from your exchange (currently BloFin) over encrypted connections using your read-only key. The exchange's own privacy policy applies to your account there.
Personal data is not sold, rented or shared with advertisers. Recipients are limited to the processors named above and, where required, the email delivery provider configured for transactional emails. We disclose data to authorities only where legally obliged.
Account, profile, exchange and journal data are kept for as long as your account exists. When you delete your account in the settings, all database rows and stored files linked to it are deleted immediately and permanently; backups of the database expire within 30 days. Server logs are retained for a short period, typically up to 30 days, for security purposes.
You have the right to access your data (Art. 15 GDPR), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent you may withdraw it at any time with effect for the future. Most of this you can do yourself in the settings: change email, handle, image and preferences, disconnect exchanges, delete your account. For anything else write to support@kolosseum.pro. You also have the right to lodge a complaint with a data protection supervisory authority.
The Service uses only strictly necessary cookies: the session cookie that keeps you signed in (set by the authentication provider) and a cookie that remembers your chosen language. There are no advertising, tracking or analytics cookies and no third-party trackers.
All connections use TLS. Passwords are stored only as salted hashes. Exchange secrets are encrypted at rest and are never returned to the browser. Database access is restricted per user through row-level security so that one account can never read another's rows. Access to production systems is limited to the operator.
The Service is intended for adults. We do not knowingly process data of persons under 18; if you believe a minor has created an account, contact us and we will delete it.
We may update this policy, for example when we add features or change processors. The current version with its date is always available at kolosseum.pro/privacy. Material changes will be communicated in the app or by email.
Kolosseum.pro · support@kolosseum.pro