BTC Cycle CockpitBTC Cycle Cockpit

Privacy Policy

Effective: October 7, 2026

Privacy · Web · iOS · iPadOS · Android
This Privacy Policy applies to BTC Cycle Cockpit on the website and in the mobile apps for iOS, iPadOS and Android. It provides the information required by Articles 13 and 14 GDPR about the categories and sources of personal data, purposes, legal bases, recipients, international transfers, retention and your rights. Storage of, and access to, information on an end device is additionally governed by applicable ePrivacy rules, including the German TDDDG where applicable.

Important: research model, not investment advice

BTC Cycle Cockpit is a general analytical, informational and research tool. Terms such as stage, model state, confirmation, risk, support, resistance or reference band describe only a methodological classification of market and research data. They are neither a guarantee of future results nor investment, financial, tax or legal advice, asset management, or a personal recommendation or solicitation to acquire, hold or dispose of Bitcoin or another crypto-asset. Outputs are not based on your finances, knowledge, objectives, loss-bearing capacity or portfolio. BTC Cycle Cockpit does not execute transactions, receive or transmit orders, custody customer funds or crypto-assets, or broker financial instruments or crypto-asset services. You remain solely responsible for your decisions.

Read the full Risk & Methodology notice →

Controller

Chingo LabsChingo Labs

Inhaber: Tobias Leluschko

c/o IP-Management #11513

Ludwig-Erhard-Straße 18

20459 Hamburg

Deutschland

contact@chingolabs.com

Scope and data minimisation

We process only data needed to provide the service, authentication, access rights, security, billing, support and technical product improvement. BTC Cycle Cockpit does not access your contacts, photos, microphone, camera or precise location, does not create a personal financial or portfolio profile, and does not use advertising SDKs. Where a function can be provided without personal data, no additional identification is required.

Sources of personal data

We receive personal data directly from you when you register, sign in, edit a profile, subscribe, send feedback or request support. Other data arise technically when you use the service, particularly session, security, log and usage data. Authentication providers, payment providers and app stores transmit the information needed for identity, payment and entitlement. Market, macro, technical and on-chain data come from public or licensed sources and are not linked to your account unless an account-specific feature expressly states otherwise.

Accounts, sign-in and entitlements

When you register or sign in, we process in particular your email address, internal user ID, optional display name, provider and identity references, authentication and session information, MFA metadata where applicable, and your assigned Free/Pro entitlement. Passwords are handled by Supabase Auth and are not stored by BTC Cycle Cockpit in plain text. If you expressly choose GitHub sign-in or account linking, the identity and account information required for that process is exchanged between GitHub, Supabase and BTC Cycle Cockpit. The legal basis is Article 6(1)(b) GDPR, supplemented by Article 6(1)(f) GDPR for security and abuse prevention.

Local settings, cookies and device storage

The web app uses only technically necessary cookies and comparable storage. The HttpOnly cookies bcc_sb_access, bcc_sb_refresh and bcc_sb_expires maintain sign-in; the refresh and expiry cookies last no longer than 30 days and the access token only until it expires. Language and theme settings may be stored for up to one year; short-lived OAuth/PKCE, entitlement and generation hints secure sign-in, access and consistent delivery. Local Storage and Session Storage hold language, appearance, session and navigation state and limited cockpit/history caches. Mobile apps use operating-system protected storage for required sign-in information, notably iOS Keychain or Android Keystore/encrypted preferences. Where German law applies, these accesses are strictly necessary for the service expressly requested and rely on Section 25(2) no. 2 TDDDG. Non-essential technologies would be used only after valid consent. There are no advertising cookies and no cross-site or cross-app tracking.

Usage and feature analytics

For signed-in accounts, we record limited, self-hosted usage statistics: internal user ID, random session ID, start and last activity, cockpit section, active duration, page views and daily section counts. The purposes are reliability, capacity planning, troubleshooting, abuse prevention and product improvement. The legal basis is Article 6(1)(f) GDPR and our legitimate interest in secure, reliable and needs-oriented operation. We do not use screen recording, advertising profiles or device fingerprinting, and the data are not used for personalised advertising or cross-provider tracking. You may object on grounds relating to your particular situation.

Knowledge check, learning progress and daily poll

For the knowledge check, we store against your account the answered question or learning item, difficulty, whether the answer was correct, the answer time, and completed daily rounds. This prevents unnecessary repetition of correctly solved content, allows incorrectly solved content to be offered again, continues your learning progress, and enforces the daily question limit after a reload. After the daily round, you may voluntarily take part in a short market poll. To prevent duplicate votes, the server derives a secret pseudonymous verification value from the internal user ID; the poll table stores neither your email address, user ID nor IP address. Only aggregated votes are displayed. Public comments, chat posts and public user profiles are currently not active. The legal bases are Article 6(1)(b) GDPR for the requested learning function and Article 6(1)(f) GDPR for a reliable poll protected against duplicate votes.

Contact, feedback and diagnostics

If you send feedback or a support request, we process the selected category and area, message content, optional email address, locale, Free/Pro status, relevant page, data status, app version, case reference, time received and the technically transmitted user agent. Processing is used to handle the request and, where needed, investigate errors; the legal basis is Article 6(1)(b) or (f) GDPR depending on the request. Do not submit passwords, payment details or authentication tokens.

Subscriptions and payments

Where offered, web subscriptions are processed through Stripe. Stripe handles payment, billing, authentication and fraud-prevention data required for the transaction. BTC Cycle Cockpit stores the user, customer, subscription, product, event, status and term references needed to perform the contract and control access, but not full card details. App subscriptions are handled through Apple In-App Purchase/StoreKit or Google Play Billing; BTC Cycle Cockpit receives only the product, transaction and status information needed to verify and assign entitlement. The legal bases are Article 6(1)(b) GDPR and, for statutory records, Article 6(1)(c) GDPR.

Market, macro and on-chain data

BTC Cycle Cockpit obtains market, macro, technical, institutional and on-chain information from external data sources. These data are used for display, calculation, quality assurance and calibration of research models. Provider requests are generally made server-side. Data providers ordinarily receive no user ID, email address, payment details or personal financial information; technically unavoidable server connection data may arise at the relevant provider.

Hosting and delivery by Vercel

The website, web app, APIs and parts of mobile backend communication are delivered through Vercel. This may involve IP address, date and time, requested URL and route, referrer where transmitted, HTTP status, request ID, device/browser information, user agent, error and security events, and technically required headers. The purposes are delivery, operation, troubleshooting, scaling and attack prevention. The legal bases are Article 6(1)(b) and (f) GDPR; the legitimate interest is secure and available delivery.

Authentication and database through Supabase

Supabase is used for authentication, sessions, profiles, entitlements and the server-side database. The connected project is hosted in the EU West region (Ireland). Depending on use, data include email address, user and identity ID, password hash within the authentication service, session and refresh tokens, MFA and OAuth metadata, profile, entitlement and subscription references, account-specific snapshots, and usage and security data. Depending on a table’s purpose, access is restricted through server-side keys, database roles, permissions and Row Level Security. The legal bases are Article 6(1)(b) and (f) GDPR.

Email delivery through Resend

Resend may be used for feedback, support, security alerts and account-deletion confirmations. The processing includes sender and recipient address, subject, message content, delivery status, and technically required delivery and log data. The legal basis is Article 6(1)(b) or (f) GDPR depending on the message. Security and delivery logs are retained only as long as needed for delivery, abuse prevention, troubleshooting or legal defence.

Apple App Store, TestFlight and Google Play

When you install the app, use TestFlight, make an in-app purchase or subscribe, Apple or Google processes data under its own responsibility, particularly store account, device, diagnostic, transaction and payment information. BTC Cycle Cockpit receives only information needed for distribution, troubleshooting, and entitlement verification and assignment. The relevant store provider’s privacy notice additionally applies to that independent processing.

Service providers and recipients

Recipients are limited to authorised internal personnel and providers required for the relevant function: Vercel, Supabase, Stripe, Resend, Apple, Google and, where GitHub sign-in is expressly selected, GitHub. Authorities, courts or other bodies receive data only where legally required or needed to establish, exercise or defend legal claims. Data are not disclosed for third-party advertising. Where a provider acts as processor, an Article 28 GDPR agreement is used; independent controllers process data under their own privacy notices.

Purposes and legal bases

Article 6(1)(b) GDPR applies to accounts, sign-in, entitlements, requested functions, subscriptions, payments and contract-related support. Article 6(1)(c) GDPR applies to statutory retention, evidence and disclosure duties. Article 6(1)(f) GDPR applies to secure operation, logging, attack and abuse prevention, troubleshooting, limited usage statistics and product improvement, taking account of data minimisation, access controls and your right to object. Article 6(1)(a) GDPR applies only where consent is requested for optional processing; consent may be withdrawn at any time for the future.

Requirement to provide data

An email address and authentication data are contractually required for registration, sign-in and account functions. Without them, an account cannot be provided; publicly accessible research functions remain available without an account where offered. Optional feedback details are voluntary, while message content is required to handle a request. Payment data is required only for a paid subscription.

No automated individual decisions

We do not make decisions based solely on automated processing within the meaning of Article 22 GDPR that produce legal effects concerning you or similarly significantly affect you. The research models analyse market data and do not make decisions about individuals.

Processing outside the EU/EEA

The Supabase database project is hosted in Ireland. Vercel, Supabase, Stripe, Resend, Apple, Google or GitHub may nevertheless use affiliates or subprocessors outside the EU/EEA. International transfers take place only on the basis of an adequacy decision, appropriate safeguards such as EU Standard Contractual Clauses, or another statutory exception. Information about safeguards used in a specific case and a reference source may be requested through the contact address.

Server logs, security and abuse prevention

For secure and reliable operation we process technically necessary log data, particularly IP address or network identifier, timestamp, route, HTTP status, request ID, user agent, error, authentication, rate-limit and security information. Security events may be emailed to a designated recipient for attack detection. The legal basis is Article 6(1)(f) GDPR. The data are not used for advertising or personal market profiles.

No advertising and no sale of personal data

BTC Cycle Cockpit does not sell or rent personal data. Personal data is not shared with advertising networks and we do not track users across third-party apps and websites for advertising or profiling. If these practices were ever to change, this policy would be updated before such processing and any legally required consent would be obtained.

Retention

The account profile, authentication identity and entitlement data are generally retained until account deletion or termination of the user relationship. Detailed quiz answers, completed quiz rounds and pseudonymous daily poll responses are automatically deleted after 120 days; compact learning-progress and question statistics remain until account deletion so that difficulty progression and repetition logic continue to work. User-linked usage sessions are automatically deleted after 30 days, daily account-linked usage aggregates after 365 days, and expired rate-limit records no later than one day after expiry. Feedback and support data are deleted once the matter is complete and no retention is needed for follow-up, abuse prevention or legal defence. Payment, invoice, contract and evidence data remain only for statutory periods. Hosting, authentication, delivery and security logs follow necessity and the contractually defined periods of the providers; a specific security or legal matter may require longer purpose-limited retention.

Withdrawal, account deletion and deletion requests

A readily accessible account-deletion option is available in account settings. It deletes the Supabase authentication identity and linked profiles, entitlements, personal startup state, account-linked daily/swing snapshots and usage data. If a Stripe web customer is linked, that customer is deleted and an active web subscription is ended; transaction, invoice or tax data that must be retained by law may remain with the payment provider. Apple or Google subscriptions may need to be cancelled separately in store settings but do not prevent account deletion. Data strictly required by law or for legal defence are restricted and retained only for that purpose. Requests can also be sent to the controller by email.

Your privacy rights and right to complain

Under Articles 15 to 21 GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time for the future without affecting the lawfulness of earlier processing. Under Article 77 GDPR, you may also complain to a data-protection authority. Requests can be sent to the controller; reasonable identity verification may be required to prevent unauthorised disclosure. Requests are generally answered within one month.

Specific notice of the right to object

Where we process personal data under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then cease that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is required to establish, exercise or defend legal claims. You could object to direct marketing at any time without giving specific grounds; BTC Cycle Cockpit currently conducts no personalised direct marketing.

Competent data-protection authority

The Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, datenschutz-hamburg.de. You may also contact another supervisory authority competent under Article 77 GDPR.

Data security

We use risk-appropriate technical and organisational measures, including TLS-encrypted transport, HttpOnly/Secure cookies, protected device storage, server-side secrets, role- and user-based access controls, Row Level Security, input and origin checks, rate limits, logging, backups and controlled account deletion. Measures are reviewed and adapted to the state of the art. No internet-based service can guarantee absolute security. A personal-data breach requiring notification will be reported and communicated under Articles 33 and 34 GDPR.

Changes to this Privacy Policy

This Privacy Policy will be updated when functions, providers, legal requirements or data-processing practices materially change. The current version remains available at btccyclecockpit.com/privacy and btccyclecockpit.com/datenschutz. Material changes will also be highlighted within the service where required.

Back to CockpitRisk & MethodologyLegal Notice