SigCopier

Privacy Policy

Last updated: July 9, 2026

1. Introduction

This Privacy Policy describes how SigCopier(“Company,” “we,” “us,” or “our”) collects, uses, and protects your personal information when you use the SigCopier platform and related services (the “Service”). By using the Service, you consent to the practices described in this policy.

2. Information We Collect

We collect information in the following categories:

2.1 Account Information

  • Email address (used for authentication and communication)
  • Password (hashed and stored securely via Supabase Auth)
  • Subscription plan and billing status

2.2 Broker Account Credentials

  • Broker server address
  • Trading account number
  • Trading account password

These credentials are required to connect your MetaTrader 4/5 broker account for automated trade execution. See Section 5 for how we protect this data.

2.3 Telegram Connection Data

  • Telegram session tokens (encrypted, used to listen for signals)
  • Channel names and IDs you subscribe to for signal ingestion

2.4 Trading Activity Data

  • Parsed trading signals (symbol, side, entry, stop loss, take profit)
  • Trade execution records (lots, open/close prices, P&L)
  • Risk settings and configuration preferences

2.5 Technical Data

  • Browser type and version
  • IP address and approximate location
  • Device information and operating system
  • Usage patterns and feature interactions

3. How We Use Your Information

We use your information to:

  • Authenticate your identity and manage your account
  • Connect to your broker account and execute trades on your behalf
  • Parse signals from your Telegram channels
  • Display your trading dashboard, journal, and analytics
  • Enforce risk management rules you have configured
  • Process subscription payments and manage billing
  • Send service-related communications (account alerts, billing notices)
  • Improve the Service, diagnose technical issues, and prevent fraud

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Data Sharing

We share your data only with the following categories of third parties, strictly as needed to operate the Service:

  • Supabase— database hosting and authentication (your account data, trading records, and encrypted credentials are stored on Supabase’s infrastructure)
  • MetaApi — broker connectivity (your broker credentials are transmitted to MetaApi to establish and maintain your MT4/MT5 connection)
  • Anthropic (Claude AI) — signal parsing (raw signal text from Telegram is sent to Claude for AI-powered parsing; no personal identifiers are included)
  • Payment processor — billing (your payment details are processed directly by our payment gateway and are never stored on our servers)
  • Hosting providers — infrastructure (Vercel for the web application, Railway for background worker processes)

We may also disclose information if required by law, regulation, legal process, or governmental request.

5. Broker Credential Security

We understand the sensitivity of your broker account credentials. The following measures are in place:

  • Credentials are encrypted at rest and in transit using industry-standard encryption
  • Credentials are used solely for the purpose of connecting your broker account via MetaApi
  • We do not store broker credentials in plain text at any point
  • Your broker will see the IP address of our cloud execution server, not your personal device IP
  • Upon account deletion or disconnection, broker credentials are removed from our systems within 30 days

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • SSL/TLS encryption for all data in transit
  • Row-level security (RLS) ensuring each user can only access their own data
  • Hashed passwords — we never store or have access to your plain-text password
  • Service role separation — the web application uses restricted access; only the background worker uses elevated privileges
  • Regular security reviews and dependency updates

While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

7. Cookies

We use essential cookies to maintain your authenticated session and remember your preferences. We do not use third-party advertising or tracking cookies. You can disable cookies in your browser settings, but this may prevent you from using the Service.

8. Data Retention

  • Account data: Retained for the duration of your active subscription plus 90 days after cancellation
  • Trading records: Retained for as long as your account is active; available for export upon request
  • Broker credentials: Deleted within 30 days of account closure or broker disconnection
  • Telegram session data: Deleted upon disconnection or account closure
  • Logs: System and error logs are retained for up to 90 days for debugging and fraud prevention

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (“right to be forgotten”)
  • Export your data in a portable format
  • Withdraw consent for data processing
  • Object to automated decision-making

To exercise any of these rights, contact us at admin@sigcopier.com. We will respond within 30 days.

10. Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify affected users via email within 7 business days of discovering the breach. We will also notify relevant regulatory authorities as required by applicable law.

11. Email Communications (CAN-SPAM Compliance)

We comply with the CAN-SPAM Act. Our emails will:

  • Not use false or misleading subjects or sender information
  • Identify the message as an advertisement when applicable
  • Include our contact information
  • Provide a clear unsubscribe mechanism

Unsubscribe requests are honored within 10 business days. Note that transactional emails (password resets, billing confirmations, security alerts) cannot be unsubscribed from.

12. Children’s Privacy

The Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected data from a child under 18, we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification at least 14 days before taking effect. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

14. Contact

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at admin@sigcopier.com.