How we protect your data and your keys — stated plainly, with no hedging.
All your data is stored on Supabase (PostgreSQL) infrastructure with encryption at rest and TLS 1.3 for everything in transit. Access is enforced by row-level security (RLS) — your account is the only one that can read its own rows, enforced at the database level.
Broker keys (Binance, MT4/MT5) are encrypted with AES-256 before storage — never stored as plain text. We always request read-only scope: your keys cannot withdraw funds, execute trades automatically, or change any setting on your broker account. You can delete a connection anytime from the Connections page, which permanently removes the stored key immediately.
When you request AI analysis (AURA, morning brief, trade reports), we send only the minimum data needed to generate the response to our inference provider (Groq — Llama models). Your API keys or password are never included in any prompt. Under Groq's commercial API usage policy, data sent through the API is not used to train their general models.
Paid subscriptions run through NOWPayments in USDT (TRC20) — a non-custodial payment flow: funds go directly to our wallet without your wallet address or private keys ever passing through our servers.
We don't sell your personal data to any third party. We never grant an API key auto-execution permission without your explicit request. We don't store your broker passwords — only encrypted, read-only API keys.
For fuller detail on data collection and use, see our Privacy Policy.
Have a specific security question? Email us at support@coretrader-ai.com.