Privacy Policy

Last Updated: 1 April 2026
Effective Date: 1 April 2026
Version: 1.0


1. Introduction

This Privacy Policy describes how Numen ("the Service", "we", "us", "our"), operated by Numen Labs Ltd ("Numen Labs Ltd"), collects, uses, stores, and protects your personal information when you use our trade journaling and analytics platform.

We are committed to protecting your privacy and handling your data responsibly. By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Data Controller

The data controller responsible for your personal data is:

Numen Labs Ltd
39 Rosaville Road, London SW6 7BN
Email: privacy@numenlabs.xyz

3. Information We Collect

3.1 Information You Provide

DataPurpose
Email addressAccount creation, authentication, communications
Username / display nameProfile identification
PasswordAuthentication (stored as a salted hash, never in plain text)
Exchange API keys and secretsSyncing trade data from your exchange accounts (encrypted at rest)
Journal entries, notes, and tagsProviding the journaling feature
Uploaded images and mediaTrade chart screenshots and journal attachments
Trading rules and setupsProviding the rules/setup tracking feature
Feedback submissionsImproving the Service

3.2 Information Collected from Exchanges

When you connect an exchange account, we retrieve the following data via the exchange's API:

DataPurpose
Trade historyDisplaying trades, calculating PnL and analytics
Open positionsPosition management and risk display
Account balancesPortfolio overview and risk calculations
Asset/symbol informationTrade categorisation and analytics

This data is associated with your Numen account and stored in our database.

3.3 Information Collected Automatically

DataPurposeCollected By
IP addressSecurity, rate limiting, abuse preventionServer infrastructure
Browser type, OS, device infoError diagnostics, compatibilitySentry
Pages visited, features used, session durationProduct improvement, understanding usage patternsPostHog
Error logs and stack tracesDebugging and fixing issuesSentry
Performance metricsMonitoring service reliabilityAWS CloudWatch

3.4 Information from Third-Party Authentication

If you sign in using Discord OAuth, we receive:

DataPurpose
Discord user IDAccount linking
Email address (from Discord)Account creation and communication
Username (from Discord)Profile display

We do not access your Discord messages, servers, or other Discord data.

3.5 Payment Information

Payment processing is handled entirely by Stripe. We do not store your credit card number, bank account details, or other payment credentials. From Stripe, we receive:

DataPurpose
Subscription statusFeature access control
Billing emailPayment receipts
Payment history (amounts, dates, status)Subscription management
Last four digits of card (via Stripe dashboard)Customer support identification

4. How We Use Your Information

We use your information for the following purposes:

PurposeLegal Basis (GDPR)
Providing and operating the ServicePerformance of contract
Syncing and displaying your trade dataPerformance of contract
Processing payments and managing subscriptionsPerformance of contract
Sending transactional emails (password resets, billing)Performance of contract
Monitoring and fixing errorsLegitimate interest
Analysing usage to improve the productLegitimate interest
Ensuring platform security and preventing abuseLegitimate interest
Sending product updates and feature announcementsLegitimate interest (with opt-out)
Sending marketing emailsConsent (opt-in)
Complying with legal obligationsLegal obligation

We do not:

  • Sell your personal data to third parties.
  • Share your trade data or journal entries with other users (unless you explicitly use a sharing feature).
  • Use your data for advertising or ad targeting.
  • Access your exchange accounts for any purpose other than retrieving data for display.

5. Third-Party Service Providers

We use the following third-party services to operate the Platform. Each processes data on our behalf under data processing agreements:

ProviderPurposeData ProcessedLocation
SupabaseDatabase hosting, authenticationAll user and trade data (encrypted)AWS infrastructure
Amazon Web Services (AWS)Backend processing (Lambda, API Gateway, Secrets Manager)Trade data, encrypted credentials, request logsEU (eu-west-2)
VercelFrontend hostingRequest logs, IP addressesGlobal CDN
StripePayment processingBilling info, email, subscription dataUnited States
SentryError monitoringError context, user ID (anonymised), browser infoUnited States
PostHogProduct analyticsUsage events, device info, session dataEU
DiscordOAuth authenticationDiscord user ID, email, usernameUnited States

When you connect an exchange, your API keys are used to communicate directly with that exchange's API:

ExchangeData RetrievedNote
HyperLiquidTrades, positions, balancesAPI keys encrypted at rest and in transit
BitunixTrades, positions, balancesAPI keys encrypted at rest and in transit
BitgetTrades, positions, balancesAPI keys encrypted at rest and in transit

6. Data Security

We implement the following security measures to protect your data:

  • Encryption at rest: Exchange API keys and secrets are encrypted using industry-standard encryption before storage.
  • Encryption in transit: All data is transmitted over TLS/SSL encrypted connections.
  • Row-Level Security (RLS): Database access policies ensure users can only access their own data.
  • JWT authentication: All API requests are authenticated using JSON Web Tokens validated against Supabase Auth.
  • Rate limiting: API endpoints are rate-limited to prevent abuse.
  • Access controls: Internal access to production systems follows the principle of least privilege.
  • Secret management: Sensitive configuration is stored in AWS Secrets Manager, not in code or environment variables.

While we take extensive measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

7. Data Retention

Data TypeRetention Period
Account data (email, profile)Duration of account + 30 days after deletion
Trade data and analyticsDuration of account + 30 days after deletion
Journal entries and mediaDuration of account + 30 days after deletion
Exchange API keysDuration of connection; deleted immediately upon disconnection or account deletion
Payment recordsAs required by tax and accounting laws (typically 7 years)
Error logs (Sentry)90 days
Analytics data (PostHog)1 year
Server/access logs30 days

When you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law.

8. Your Rights

8.1 Rights Under GDPR (European Economic Area)

If you are located in the EEA, you have the following rights:

  • Right of access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing (Art. 18): Request that we limit how we use your data.
  • Right to data portability (Art. 20): Request your data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interest, including profiling.
  • Right to withdraw consent (Art. 7): Withdraw consent at any time where processing is based on consent.
  • Right to lodge a complaint: You may lodge a complaint with your local data protection supervisory authority.

8.2 Rights Under CCPA (California)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose.
  • Delete your personal information.
  • Opt-out of the sale of personal information. Note: We do not sell your personal information.
  • Non-discrimination for exercising your privacy rights.

8.3 Exercising Your Rights

To exercise any of these rights, contact us at privacy@numenlabs.xyz. We will respond to your request within 30 days (or within the timeframe required by applicable law). We may ask you to verify your identity before processing your request.

You can also export your trade data and journal entries directly from the Platform at any time.

9. Cookies and Tracking

9.1 Essential Cookies

We use essential cookies that are necessary for the Service to function, including:

  • Authentication cookies: To keep you signed in.
  • Session cookies: To maintain your session state.
  • Preference cookies: To remember your settings (theme, column layout, etc.).

These cookies cannot be disabled without breaking the Service.

9.2 Analytics Cookies

With your consent, we use analytics cookies to understand how the Service is used:

  • PostHog: Collects anonymised usage data to help us improve the product.

You can opt out of analytics cookies at any time through the cookie preferences in the Platform or by contacting us.

9.3 Third-Party Cookies

  • Stripe: May set cookies for fraud prevention during payment processing.
  • Sentry: May set cookies for error tracking sessions.

9.4 Managing Cookies

You can manage cookies through your browser settings. Note that disabling essential cookies will prevent the Service from functioning properly.

10. International Data Transfers

Your data may be processed in countries outside your country of residence, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Data processing agreements with all subprocessors.
  • Compliance with applicable data protection frameworks.

11. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you believe a child under 18 has provided us with personal data, please contact us at privacy@numenlabs.xyz.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you via email or a prominent in-app notification at least 30 days before the changes take effect.

The "Last Updated" date at the top of this policy indicates when the latest revision was made. Your continued use of the Service after changes take effect constitutes your acceptance of the revised policy.

13. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us at:

  • Email: privacy@numenlabs.xyz
  • Website: https://numenapp.xyz

If you are in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.


This Privacy Policy was last updated on 1 April 2026.