Privacy · effective 22 August 2026
Privacy policy
Chart Lab can be used worldwide without a verified identity account. We store only what is needed for the app to work. We do not store money or identity documents.
1. Stored on your device
The browser stores the login session in an HttpOnly cookie and may store a display name, last selected coin, pinned study list, analysis ticks, and a short viewed-coin trail in localStorage. A partner referral cookie (if you arrived with ?ref=) remembers the referring partner for a limited window so a later paid plan can be attributed.
Google Analytics
We use Google Analytics to see how the site is used (pages opened, country/city at a coarse level, device type, and traffic source). Google may set its own cookies. We do not send your Chart Lab password or chart images to Google Analytics. This is not used to run investment ads.
2. Stored on the server
- Username, email, hashed password, and display name
- Session token until it expires or you sign out
- Chart-analysis logs: typed context, file type, file size, and the analysis text. we do not intend to keep the image file permanently
- Email is used to verify the account, reset a forgotten password, send a membership receipt after a Kasikorn transfer or a card, and send security notices. Not for ads
- Membership period and free-read count on the account. That is a software right, not a crypto balance
- Incoming transfers to Chart Lab’s receive wallet: amount, asset, and transaction id. We do not take your seed phrase, exchange keys, or broker APIs
- Pinned study list: up to 12 coin ids when you sign in
- Recently viewed coins: coin id, page (home / market / analyzer), and last-seen time. We keep the latest 24
There is no KYC, no address, no national ID, and we do not take broker API keys.
3. Uploaded chart images
When you tap Analyze chart, the image is sent to Anthropic’s Claude vision model to summarize what is in the picture. Do not upload images that contain personal data you do not want processed.
4. Third-party market data
Rankings, prices, logos, and charts come from public services such as CoinGecko, CoinMarketCap, Binance, and TradingView. Those calls are market data, not your bank-account data.
5. We do not sell data
We do not sell user lists and we do not use in-app data to target third-party ads.
6. Users in every country
This policy applies to users everywhere as educational software. If your local law limits market-watch tools, you decide whether to use the app.
7. Data inventory addendum · 25 September 2026
This addendum lists personal data the current codebase actually handles. It does not claim a deletion deadline, anonymization program, or encryption property that the code does not implement. A self-serve account erasure control was not found. How to request access or deletion: owner input required.
- Account: username, email, password hash, display name, and an optional Solana wallet address used only to sign a sign-in message.
- Session: an HttpOnly cookie, SameSite=Lax, and Secure on HTTPS. The cookie lasts until it expires or you sign out. A specific retention period beyond that session lifetime is not stated here.
- On the device: display name, last coin, pinned study list, and a partner referral marker may sit in localStorage.
- Chart analysis: typed context, file type, file size, and analysis text may be logged. Do not upload images that contain personal data you do not want processed. Images are sent to Anthropic when you run chart analysis. This policy does not claim the image file is deleted on a fixed schedule.
- Membership: plan status and free-analysis count. That is a software right, not a crypto balance.
- Payments: amount, asset, and transaction id for a software-fee transfer, plus receipt email metadata. Card charges, when enabled, go through Stripe. Chart Lab does not receive your card number in this app.
- Partner: referral code, application details, payout details you submit, and a hash of the signup IP. Commission records relate to membership fees, not investment returns.
- Futures research: if an exchange API key is connected, the key and secret are stored encrypted with AES-256-GCM. They are not returned to the browser. Ordinary chart membership does not ask for them. Seed phrases and private keys are not requested.
- Google Analytics may load when a measurement id is configured (pages, coarse location, device, source). A separate analytics consent banner was not verified in this audit. Analytics consent is therefore owner input required, and it is not described as bundled into membership.
- Server logs may include IP addresses and request paths for security and operations. They must not include exchange secrets.
- Recipients that can process data: the operator, Anthropic (chart images), Google (analytics, when enabled), Stripe (card, when enabled), public market-data sources, and the Solana network for a software-fee transfer. Some of these are outside Thailand. A cross-border transfer agreement is owner input required.
- Purposes: provide the software, keep the session, prevent abuse, attribute a partner referral to a membership fee, and send verification or receipt mail. Not for selling user lists.
- Contact for privacy requests: owner input required.
Continue to the terms of use and the risk disclosure.
Continue to the terms of use