Privacy Policy

Last updated 5 August 2026

ChartRaven is operated by Giovanni Macciocu ("ChartRaven", "we", "us"), Cami Els Terrers 38, 46591 Albalat Dels Tarongers, Valencia, Spain. We are the data controller responsible for the personal data described below.

This policy explains what personal data we collect when you use the ChartRaven website and application, why we collect it, and what rights you have over it.

1. Data we collect

Account data

Authentication is handled by Auth0. When you sign in we receive and store a persistent user identifier, and we read your email address from your access token to identify your account. We never receive or store your password — Auth0, or your chosen identity provider, holds those credentials.

Billing data

Subscription payments are processed by Stripe. We store only a Stripe customer identifier, a subscription identifier, your plan, your subscription status, and the current billing period end date. We never receive or store your card number. Card details are entered directly into Stripe's systems and are governed by Stripe's privacy policy.

Application data

Data you create by using the product, stored against your account identifier:

  • Watchlists — the symbols you follow.
  • Workspaces and chart configuration — layouts, intervals, indicators, and timezone.
  • AI provider keys — if you supply your own API key for an AI provider, it is encrypted at rest before being stored.

Contact data

If you write to us through the contact form, we process the name, email address, and message you provide in order to answer you. The form is protected by an anti-spam check that runs entirely on our own servers — no third-party captcha service is involved, and no data about your visit is sent to one.

Technical data

Our servers and infrastructure produce operational logs (request metadata, timestamps, error traces) used to keep the service running and to diagnose faults.

2. How we use your data

  • To authenticate you and give you access to the features in your plan.
  • To take payment and manage your subscription.
  • To store and restore your charts, watchlists, and preferences between sessions.
  • To generate the AI analysis you request.
  • To operate, secure, monitor, and debug the service.

We do not sell your personal data, and we do not use it for third-party advertising.

3. Legal bases

Where the GDPR applies, we rely on:

  • Performance of a contract — account, billing, and application data, all of which are necessary to provide the service you subscribed to.
  • Legitimate interests — operational logging, security, and fraud prevention.
  • Legal obligation — retention of billing and tax records.

4. Service providers

We share data with the following processors, only as needed to run the service:

ProviderPurposeData involved
Auth0 (Okta)AuthenticationIdentifier, email, credentials
StripePayments and billingEmail, payment details, subscription
DigitalOceanHosting and databaseAll stored application data
Anthropic / OpenAIAI analysisThe chart context you submit for analysis
Twelve DataMarket dataNone — symbol requests only
Grafana CloudLogs and metricsTechnical and operational data

5. International transfers

Some providers above process data outside the European Economic Area. Where that happens, transfers are covered by the safeguards those providers offer, such as the European Commission's Standard Contractual Clauses.

6. Cookies and local storage

We use cookies and browser storage that are necessary for the service to function: keeping you signed in, and remembering your interface preferences such as theme and chart layout. We do not use advertising or cross-site tracking cookies.

7. Retention

Account and application data are kept while your account is active. When you delete your account, your watchlists, workspaces, and chart configuration are deleted immediately, and your authentication record is removed at the same time. There is no grace period and the deletion cannot be undone.

The subscription record held in our own database — the payment-processor identifiers, your plan, and your billing period — is deleted in the same operation, so no billing data about you remains on our systems.

Stripe, our payment processor, keeps its own separate record: a customer account and the invoices it issued, both of which carry the email address associated with your payments. Stripe states that it retains transaction data for 10 years from the transaction date, under the accounting, tax, and financial-reporting obligations that apply to Stripe. That record is our account of the payments we received, so we retain it for the same period and do not delete it when an account is closed.

If you want that record erased, ask us through the contact form and we will pass the request to Stripe. It can only be acted on to the extent the retention period above, and Stripe's own legal duties, allow.

8. Your rights

Subject to local law, you may request access to your data, correction of it, deletion of it, a portable copy of it, or restriction of how we process it. You may also object to processing based on legitimate interests, and lodge a complaint with your data protection authority.

9. Security

Data is transmitted over TLS and stored on managed infrastructure with access restricted to the people who operate the service. Sensitive values such as your AI provider keys are encrypted at rest. No system is perfectly secure, and we cannot guarantee absolute security.

10. Children

ChartRaven is not directed at anyone under 18, and we do not knowingly collect their data.

11. Changes

We may update this policy. Material changes will be reflected in the "last updated" date above, and where required we will notify you directly.

12. Contact

For any privacy question or to exercise the rights in §8, use our contact form. You do not need an account or an active subscription to reach us, so the form remains available to you after your account has been deleted. You can also write to Giovanni Macciocu, Cami Els Terrers 38, 46591 Albalat Dels Tarongers, Valencia, Spain.