Privacy Policy
Last updated 2026-07-28
This policy explains what information Signal Lab collects, why, where it is stored, who it is shared with, and what rights you have over your own data. Our principle is simple: collect only what running the service genuinely requires, and store nothing we can avoid storing.
1.What we collect
Account data: your email address; when signing in with Google, also the account identifier and email-verification status Google returns. Passwords are stored as an irreversible hash — we cannot read your original password.
MT5 connection data: the login number, broker server name, account name, currency, balance, equity, leverage and symbol suffix reported by the bridge app, plus its online heartbeat time.
Trading records: the place / close / modify instructions you send through the platform and their receipts; and the real closing-deal records for platform-opened positions reported by the bridge (time, symbol, side, volume, fill price, P&L).
Usage statistics: page-view counts and dwell time (aggregated per page-and-hour, containing no user identity), plus a per-day dedup marker for "this user opened this page on this day" (day granularity only — no timestamp, no duration).
Technical data: your push subscription endpoint (when notifications are on), the bridge app's version, and request IP addresses (used only for rate limiting and failed-login lockout, never for profiling).
2.What we don't collect
We never obtain — and technically cannot obtain — your MT5 trading account password. The bridge app reads terminals you have already logged into on your own computer.
We never touch or custody any of your funds.
We do not collect identity documents, bank card numbers or postal addresses. Crypto payments are handled by NOWPayments; we retain only the payment id, amount, currency and status.
We do not sell your personal data, nor trade it for any third party's marketing resources. Your browser's local storage holds only your login token and interface preferences (language, chart settings, selected tab).
3.Why we collect it
To run the Service: showing signals, routing instructions to the correct MT5 account, computing your personal win rate and discipline score.
Security and abuse prevention: rate limiting, blocking credential stuffing, spotting anomalous activity, enforcing tier permissions.
Billing: confirming subscription status and expiry.
Product improvement: understanding which pages get used and for how long. This data is deliberately split so that we can answer "how many people opened the chart page on Tuesday" but cannot answer "when did this person look, and for how long".
4.Where your data lives
The database is hosted on Supabase (PostgreSQL, Singapore region). The backend runs on a cloud server; the frontend is hosted and delivered by Vercel.
All traffic between clients and servers is encrypted in transit over HTTPS/WSS.
Because the Service is distributed across the regions above, your data may be transferred outside your own country and stored and processed there. By using the Service you acknowledge and agree to this.
5.Who we share it with
We do not sell your personal data and do not trade it with anyone for marketing.
To operate, necessary data reaches these providers: Google (only if you use Google sign-in, to verify your identity), NOWPayments (payment processing), browser vendors' push services such as Google / Apple / Mozilla (only when notifications are on, to deliver them), and the cloud and database providers named above.
Advertising measurement: this site loads the Meta Pixel (Facebook advertising pixel). It stores cookies such as `_fbp` in your browser and reports which pages of this site you visited back to Meta, so we can measure ad performance and show retargeted ads. It cannot read your MT5 account, positions, trade history or payment details. You can limit this tracking through your browser's cookie settings, an ad blocker, or the Ad Preferences section of your Meta account.
We may disclose information where legally required, or where necessary to protect the Service and its users' legitimate interests.
6.How long we keep it
Account and trading records are kept for as long as your account exists. Unbinding an MT5 account does not delete its historical fills — they simply stop counting toward your statistics, and re-binding restores the view.
Per-day page-visit dedup markers are pruned automatically after roughly 100 days.
1-minute candles are kept for 30 days by default; other timeframes are kept long-term (this is market data and contains no personal identity).
After you close your account we delete or anonymise your personal data within a reasonable period, except where the law requires retention.
7.Your rights
You have the right to ask what personal data we hold about you, to have inaccurate information corrected, and to have your account and associated data deleted.
At any time you can turn notifications off on the account page, reset your API token on the Connect MT5 page, and review every trading record on the orders page.
To exercise any of these rights, get in touch with us. To protect your account we may need to verify your identity first.
8.Minors
The Service is not intended for anyone under 18. If we learn that we have unknowingly collected a minor's information, we will delete it promptly.
9.Changes to this policy
When this policy is updated we change the "Last updated" date on this page. Updates that substantively change how data is used will also be flagged in the app.