Last updated 29 September 2026
Privacy Policy
This document explains what data ACARO collects on the website and in the ACARO Terminal and ACARO Reflex applications, why we need it, who we share it with and how to have it deleted.
In short
- We do not sell data, show ads or embed third-party trackers.
- We do not have your exchange API keys: in ACARO Terminal they stay in your computer's system keychain, in ACARO Reflex — on your own server.
- The applications never take deposits, never withdraw funds and never hold your crypto.
- We collect what an account, a subscription and support cannot work without — plus the logs needed to protect the service from abuse.
Who processes the data
The data is processed by ACARO — the website and the ACARO Terminal and ACARO Reflex applications that we develop and operate.
For any question about data processing, including a request for a copy or for deletion, write to support@acaro.xxx. Security questions and vulnerability reports go to security@acaro.xxx.
What we collect
We only collect data you provide yourself or that the service produces while you use it.
- Account: name, email address, password hash, interface language, two-factor authentication settings.
- Subscription and payment: the chosen plan, amounts, invoice status, blockchain address and transaction hash. We never take or store card details — payment is made by crypto transfer.
- Devices and applications: device identifier, its name and platform, application version, IP address and time of the last request. This lets you see your sessions and revoke access.
- Trading terminal activity: session events — the exchange, the mode (demo or live), your exchange account identifier, an aggregate USD balance, the last characters of a key so it can be recognised, the list of running instruments and the accumulated result. This is shown back to you in the cabinet and used to prevent subscription bypass.
- Strategy configurations ("Lab"): the parameters and metrics of the runs you chose to save.
- Optional, at your request: your TradingView username, to grant indicator access; a Telegram link, to send you notifications.
- Where you came from: the referring site, link tags (utm), short link, first page opened and country by IP address. On sign-up this is saved to your account together with your answer to the optional question "How did you hear about us?".
- Site visits: date, country, traffic source and a visitor identifier that is recalculated every day. The IP address itself is not stored in the visit log.
- Subscribers of our Telegram channels: Telegram ID, username (@username), first and last name from the profile, language, Telegram Premium flag, join and leave dates and the invite link the person used. Telegram provides this to channel administrators. If a subscriber uses our notification bot, we match them with their account on the site.
- Technical logs: IP address, client details, request time and error codes.
What we do not have
A note on ACARO Reflex: the application contacts our servers only for sign-in, subscription status and saved configurations. Trading commands travel directly from the application to your own server, bypassing our infrastructure.
- Your exchange API keys. In ACARO Terminal they are stored in your computer's system keychain; in ACARO Reflex — in the daemon's storage on your own server. They are never sent to our servers.
- Access to your funds. We do not take deposits, do not initiate withdrawals and do not operate your exchange account.
- Plain-text passwords, card details, wallet seed phrases or private keys.
Why we process data
- To perform our contract with you: access to the cabinet and the applications, subscription handling, support.
- Legitimate interest: service security, error diagnostics, protection against subscription bypass and abuse, and understanding which posts and placements bring people to the site and to our Telegram channels.
- Your consent: the optional TradingView and Telegram links. Consent can be withdrawn at any time by removing the link.
- Legal obligations: accounting for received payments.
Who we share data with
We do not sell data and never pass it to advertising networks. Sharing happens only to the extent the service requires.
- The hosting and infrastructure provider that runs the website and the database.
- Blockchain networks — a crypto payment is public by its very nature.
- Telegram — only if you connected notifications yourself.
- TradingView — only the username you supplied, in order to grant indicator access.
- Public authorities — upon a lawful and justified request.
How long we keep data
Account data and saved configurations are kept while your account exists. Payment records are kept for as long as applicable accounting law requires. Technical logs and session events are kept for the limited period needed for diagnostics and security.
The site visit log, short link clicks and join and leave events in our Telegram channels are kept for up to 400 days. Data about a subscriber who left a channel is deleted 400 days after they left.
After an account is deleted we erase or anonymise the data, except what we are legally required to retain.
Your rights
To exercise these rights, write to support@acaro.xxx from the address registered on the account. We reply within a reasonable time and no later than 30 days.
Account deletion: on request to support@acaro.xxx we delete the account, its linked devices and saved configurations. An active subscription ends with it and cannot be transferred.
- Obtain a copy of your data and learn how it is processed.
- Correct inaccurate data — much of it you can edit yourself in profile settings.
- Delete your account together with its data.
- Delete the data we hold about you as a subscriber of our Telegram channels — include your @username or Telegram ID in the email.
- Withdraw consent for the optional links.
- Lodge a complaint with the supervisory authority in your country.
Cookies
All cookies are set by the site itself and their contents are not shared with anyone. There are no third-party advertising or analytics trackers on the site.
- Functional: the session identifier, the selected language, the interface appearance and cross-site request protection.
- acaro_src — where you came to the site from the first and the last time: the referring site, link tags, the first page. Kept for 90 days.
- acaro_seen — only a date, so one visit is not counted several times. Kept for up to 30 days.
- acaro_partner_ref — the code of the partner whose link you followed. Kept for 90 days.
Security
Connections to the website and the applications are protected by TLS. Passwords are stored as irreversible hashes and a second factor is available. Application tokens can be revoked from the cabinet. Staff access to data is limited to what the job requires.
No measure is a hundred-per-cent guarantee. If you notice signs that your account has been compromised, write to security@acaro.xxx immediately.
Age of users
The service is intended for adults. We do not knowingly collect children's data. If we learn that an account was created by a minor, we delete it together with its data.
International transfers
Our servers and infrastructure providers may be located outside your country. By using the service you agree to such transfers to the extent the service requires.
Changes to this policy
We may update this policy. The current version is always available at /privacy and the date of the last update is shown at the top of the page. We announce material changes in the cabinet or by email.
Contact
Data processing questions, copy or deletion requests — support@acaro.xxx. Vulnerability reports — security@acaro.xxx. General enquiries — hello@acaro.xxx.