Privacy Policy
This policy explains what personal data Daepak collects, why, on what legal basis, who else sees it and what you can do about it. It is written to meet the EU/UK General Data Protection Regulation (GDPR) and Korea's Personal Information Protection Act (PIPA). A Korean-language policy is published at daepak.com/privacy.html; where the two differ in wording, they are intended to mean the same thing.
1. Who is responsible
The data controller is Individual Entrepreneur ARHIKAD (BIN 640128450428), represented by Elena Ivanyutina, 142 Lunacharskogo St., Shchuchinsk, Akmola Region 021700, Kazakhstan ("Daepak", "we"). For anything in this policy, including any request about your data, write to privacy@daepak.com. We answer within 30 days, and tell you sooner if a request needs longer.
2. What we collect, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address, password hash, plan | Your account and access to the service | Performance of a contract, Art. 6(1)(b) |
| Social login identifier (Google, Kakao, Naver) and the email that provider returns | Signing you in without a separate password | Contract, Art. 6(1)(b) |
| Your questions to the AI analyst, chat history, attached images | Answering you, and keeping the conversation so you can return to it | Contract, Art. 6(1)(b) |
| Watchlist, positions and trade journal you enter, saved notes, agent memory | Features you asked for; these exist only because you created them | Contract, Art. 6(1)(b) |
| API keys, request counts, credit usage | Metering, quotas and abuse prevention | Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f) |
| Payment records: plan, amount, date, Paddle transaction id | Giving you the plan you paid for and handling refunds | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Server logs: IP address, user agent, requested page, time | Running and securing the service, diagnosing faults | Legitimate interests, Art. 6(1)(f) |
| Analytics cookies and identifiers (Google Analytics; Naver Analytics on Korean pages; Meta pixel) | Understanding which pages work | Your consent, Art. 6(1)(a) — nothing loads until you accept |
| Support emails you send us | Answering you | Contract and legitimate interests |
We do not collect special categories of data (health, beliefs, biometrics), and we ask you not to put such data into chats. We do not buy personal data from anyone.
3. What we do not do
We do not sell personal data. We do not use your chats, positions or journal to train AI models, and our model providers are engaged under terms that exclude training on our traffic. We do not profile you for advertising.
4. Who else processes your data
- Paddle.com Market Ltd (United Kingdom) — our Merchant of Record. Paddle takes payment details directly; card numbers never reach our servers. Paddle is a separate controller for the tax and invoicing part of the transaction.
- AI model providers reached through OpenRouter (Ireland/USA) — the text of your question and the relevant market data are sent to the model that answers it. Providers change as we test them; the current list is available on request.
- Google Ireland Ltd — Google Analytics 4, only after you accept analytics cookies.
- Naver Corp. (Korea) — Naver Analytics, only on Korean-language pages and only after you accept analytics cookies.
- Meta Platforms Ireland Ltd — advertising pixel, only after you accept.
- Our hosting provider — servers in Japan; the database and application run there.
- Telegram — our own operational alerts (for example "a new user registered"). Email addresses in these alerts are masked.
5. Where your data is stored, and transfers
Our servers are in Japan, and we are established in Kazakhstan. Neither country is covered by an EU adequacy decision, and some of the providers above are in the United States. Where a provider processes data on our behalf, we rely on the European Commission's Standard Contractual Clauses as included in that provider's data processing terms. You can ask us for details of the safeguards that apply to a specific provider.
6. How long we keep things
- Account, chats, watchlist, positions, notes, memory — until you delete your account or ask us to delete them. Deletion is immediate and irreversible.
- Collected news and social posts (not personal data about you) — original text is cleared after 30 days once a summary exists; search vectors are mirrored for 48 hours.
- Visit records used for analytics — 90 days, then deleted.
- Payment and usage rows — kept as statistics after account deletion with the link to you removed, so that they are no longer personal data.
- Server logs — rotated by size, typically within weeks.
7. Automated processing
Daepak produces scores, alerts and AI answers automatically. These describe markets, not you: we make no automated decision that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Art. 22. Nothing the service outputs is investment advice, and no automated system decides your access, pricing or eligibility.
8. Your rights
If the GDPR applies to you, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out. Under PIPA you have equivalent rights of access, correction, deletion and suspension of processing.
Two of these you can exercise yourself, immediately, without writing to anyone: in the app open Profile → Your data and use Download my data (a machine-readable JSON export) or Delete my account (immediate erasure). For anything else write to privacy@daepak.com.
You can withdraw cookie consent at any time through the "Cookie settings" link in the footer.
If you are in the EEA or the UK and believe we have handled your data wrongly, you may lodge a complaint with the data protection authority of the country where you live or work. In Korea you may contact the Personal Information Protection Commission (privacy.go.kr, or call 182 from within Korea).
9. Cookies
Strictly necessary cookies keep you signed in and remember your cookie choice; these are set without consent because the service cannot work without them. Analytics and advertising cookies are set only after you accept them. Refusing is one click and costs you nothing in the product.
10. Security
Traffic is encrypted in transit (HTTPS). Passwords are stored only as salted hashes; API keys are stored only as hashes and shown to you once. Accounts are isolated from one another and the AI analyst can only reach the data of the account asking. Access to production is limited to the operator.
11. Children
Daepak is not intended for children. We do not knowingly create accounts for anyone under 16 (under 14 in Korea). If you believe a child has registered, write to us and we will delete the account.
12. Changes
If we change this policy in a way that matters, we will say so on the site before the change takes effect and update the date at the top.