CCryptoБур

Privacy Policy — CryptoBur

Effective Date: May 12, 2026 Version: 1.0 Operator: SAVOK AI, Inc., a California C-Corporation (CA Entity No. B20260188410) ("SAVOK," "we," "our," or "us")


§1. Scope

This Privacy Policy ("Policy") describes how SAVOK AI, Inc. collects, uses, discloses, retains, and protects Personal Data in connection with:

This Policy applies to all individuals who visit cryptobur.com, register a CryptoBur account, connect third-party exchange or AI provider credentials to the Service, or otherwise interact with us (each, a "User" or "you").

Definition of "Personal Data." For purposes of this Policy, "Personal Data" means any information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. This definition is intended to be coextensive with "personal information" under the California Consumer Privacy Act of 2018 (Cal. Civ. Code §1798.140), as amended by the California Privacy Rights Act of 2020 (the "CCPA/CPRA"), and "personal data" under Regulation (EU) 2016/679 (the "GDPR") and the UK General Data Protection Regulation (the "UK GDPR").

CryptoBur is an infrastructure platform for AI trading bots. We do not act as a broker, dealer, investment adviser, custodian, or money transmitter. Users connect their own cryptocurrency exchange accounts and their own AI provider accounts to the Service; we do not hold User funds and do not provide investment advice.


§2. Information We Collect

We collect the following categories of Personal Data, organized by source and purpose:

Category Examples Source
Identity Data Full name, display name, email address, Google account identifier, profile photo (if supplied via Google) You, via Google OAuth or direct entry
Authentication Data Google OAuth access and refresh tokens (scoped to identity claims), session cookies, multi-factor recovery codes, password hashes (if password auth is enabled) You, via Google or direct registration
Billing Data Stripe customer identifier, billing country and postal code, payment-method type, last four digits of payment card, subscription tier, invoice history You, via Stripe Checkout (Stripe stores full payment-card data on its own systems; we do not receive or store full card numbers)
Connection Data Encrypted exchange API keys and secrets (e.g., Binance, Coinbase, Kraken, OKX, Bybit), encrypted user-supplied LLM API keys (e.g., OpenAI, Anthropic, Groq, DeepSeek, NVIDIA), exchange account labels, permission scopes you grant on the exchange side You, via the Connections interface; encrypted at rest using AES-256-GCM in Cloudflare Workers KV
Trading Data Strategy configurations, trading-pair selections, position-sizing parameters, backtest results, executed-trade history, open and closed orders, profit-and-loss records, performance analytics, on-chain transaction identifiers when applicable Generated by your use of the Service; mirrored from exchange APIs you connect
Communication Data Support tickets, in-app chat messages, email correspondence, AI prompt history (retained on a rolling debug window), Discord/Telegram handles if voluntarily provided for support You, via the Service or our support channels
Technical Data IP address, device type and identifier, browser type and version, operating system, language preference, timezone, screen resolution, referring URL Automatically, when you access the Service
Usage Data Pages viewed, features used, click events, session duration, error logs, performance traces, crash reports Automatically, via our analytics and monitoring providers

We do not knowingly collect "sensitive personal information" within the meaning of CCPA/CPRA §1798.140(ae) other than (i) account log-in credentials (which fall under Authentication Data above) and (ii) financial account information consisting of your encrypted exchange API keys and Stripe billing references. We use this sensitive Personal Data only for the limited purposes described in §4 below and you may request a limitation on its use as described in §9.


§3. No-Trading Pledge

Limitation on Use of User Data

Notwithstanding any other provision of this Privacy Policy, SAVOK AI, Inc., the operator of CryptoBur, covenants that we will not:

(a) Trade against User positions. We do not engage in proprietary trading using data derived from User activity on the CryptoBur platform. We do not operate a market-making desk, proprietary trading book, principal trading operation, or affiliated hedge fund. We have no economic interest, direct or indirect, in the success or failure of any individual User's trading strategy other than continued payment of subscription fees.

(b) Front-run User orders. We do not pre-position trades, signal our affiliates, or transmit information to third parties based on knowledge of pending User orders. Order-routing logic exists solely to fulfill the User's own instructions to the User's own connected exchange account.

(c) Sell User data. We do not sell, rent, license, or otherwise monetize User personally identifiable information, trading history, exchange credentials, or strategy configurations to data brokers, advertising networks, analytics firms, hedge funds, exchanges, or any third party for commercial gain. This commitment goes beyond the "sale" definition under CCPA/CPRA and applies even to transactions that would not technically constitute a "sale" or "sharing" under California law.

(d) Use AI keys for non-User purposes. When Users supply their own AI provider API keys (including but not limited to DeepSeek, Groq, NVIDIA, OpenAI, Anthropic, Mistral, xAI, or similar), we relay requests on the User's behalf only. We do not use these keys to train our own models, to serve other Users, to generate marketing content, or for any internal purpose unrelated to the originating User's session.

This No-Trading Pledge is a contractual commitment incorporated by reference into the CryptoBur Terms of Service. A material breach of this Pledge gives rise to a claim by the affected User against SAVOK AI, Inc.


§4. How We Use Personal Data

We use Personal Data for the following purposes:

  1. Service delivery. To create and maintain your account; to relay encrypted API requests to exchanges and AI providers on your instructions; to compute backtests, performance analytics, and strategy outputs; to display your trading history and balances.
  2. Payment processing. To establish and maintain your paid subscription via Stripe; to bill, invoice, refund, and reconcile payments; to detect failed payments and recover overdue amounts.
  3. Transactional communications. To send account confirmations, security alerts, billing notices, terms-of-service updates, and incident notifications. You cannot opt out of transactional communications while you maintain an active account.
  4. Marketing communications (opt-in only). To send newsletters, product announcements, and educational content to Users who have explicitly opted in. You may withdraw consent at any time via the unsubscribe link in any marketing email or by emailing privacy@cryptobur.com.
  5. Security and fraud prevention. To detect, investigate, and prevent unauthorized access, credential stuffing, API abuse, account takeover, market manipulation routed through our infrastructure, and other malicious activity; to enforce our Terms of Service.
  6. Legal compliance. To comply with applicable law, regulations, subpoenas, court orders, and other valid legal process; to enforce our Terms of Service; to defend against legal claims; to respond to government requests in jurisdictions where we operate.
  7. Aggregated and anonymized analytics. To produce aggregate, de-identified statistics about platform usage and performance. We commit not to attempt to re-identify any individual from aggregated data, and we contractually require recipients of any aggregated data to do the same.
  8. Service improvement. To debug, monitor, and improve the Service, including diagnosing failed AI relays, latency issues, and integration breakages.

We do not engage in automated decision-making producing legal or similarly significant effects on Users within the meaning of GDPR Article 22.


§5. How We Share Personal Data

We disclose Personal Data only to the following categories of recipients, and only for the limited purposes described:

Recipient Category Specific Recipients Purpose
Infrastructure Providers Cloudflare, Inc. (Workers, KV, R2, Pages, DNS); Supabase, Inc. (Postgres, Auth) Hosting, data storage, edge compute
Payment Processor Stripe, Inc. Subscription billing, invoicing, tax computation
Error & Performance Monitoring Functional Software, Inc. d/b/a Sentry Crash reporting, performance traces (with PII scrubbing enabled)
Analytics Google LLC (Google Analytics for cryptobur.com only; IP anonymization enabled) Aggregate website usage analytics
Authentication Google LLC (Google OAuth) User identity verification on sign-in
AI Providers (User-supplied keys) The AI provider whose key you supply (e.g., OpenAI, Anthropic, Groq, DeepSeek, NVIDIA, Mistral, xAI) Relay of prompts you initiate; the provider's own privacy policy governs
Exchange Providers (User-supplied keys) The exchange whose API key you supply (e.g., Binance, Coinbase, Kraken, OKX, Bybit) Relay of trade and market-data requests you initiate
Legal / Law Enforcement Courts, regulators, law enforcement agencies Response to valid subpoena, court order, or other legal process; cooperation with investigations of fraud or abuse
Professional Advisors Outside counsel, auditors, accountants Legal, audit, and tax compliance, all under written confidentiality
Successors in Interest Acquirer or successor entity in connection with a merger, acquisition, reorganization, asset sale, or bankruptcy Continuity of the Service

Subprocessor list. A current list of subprocessors is maintained at cryptobur.com/legal/subprocessors and is updated at least 30 days in advance of any material change. Users with a legitimate interest may subscribe to subprocessor change notifications via privacy@cryptobur.com.

We DO NOT sell Personal Data. Period. SAVOK AI, Inc. has not sold User Personal Data in the preceding 12 months and has no intention to do so. This commitment is reinforced by the No-Trading Pledge in §3 above.


§6. Tracking Technologies

We and our service providers use the following tracking technologies:

Do Not Track ("DNT") signals. We honor Do Not Track signals transmitted by your browser. When DNT is enabled, we suppress non-essential analytics on cryptobur.com.

Global Privacy Control ("GPC"). We honor the GPC opt-out signal as required under 11 CCR §7025(c). When GPC is detected, we treat it as a valid opt-out of "sale" and "sharing" of Personal Data even though we do not engage in either.

You may manage cookies through your browser settings. Disabling strictly necessary cookies will prevent you from signing in to the Service.


§7. Data Retention

We retain Personal Data only for as long as necessary for the purposes described in this Policy and to meet our legal, tax, accounting, and dispute-resolution obligations. Specific retention periods are:

Data Type Retention Period
Identity Data Lifetime of account, plus 7 years post-deletion (US federal and California tax-records minimum)
Trade History 5 years from the date the trade occurred (for audit, regulatory inquiry, and dispute resolution)
Encrypted Exchange API Keys Until account deletion; immediate cryptographic purge from Cloudflare Workers KV upon User request
Encrypted LLM API Keys Until account deletion; immediate cryptographic purge upon User request
Communication Data (support tickets) 2 years from last interaction
AI Prompt Debug Logs 30 days rolling window, then automatic purge
Marketing Data 30 days after opt-out or account termination
Technical Data 90 days
Usage Data 90 days (raw); aggregate retained indefinitely
Stripe Billing Records 7 years (per US Internal Revenue Code §6001 and California Revenue & Taxation Code recordkeeping rules)
Error / Crash Logs (Sentry) 90 days

When the retention period expires, we delete or irreversibly de-identify the Personal Data. Where deletion is technically infeasible (e.g., backup tapes), we will isolate the data and prevent further processing until deletion occurs in the ordinary course of backup rotation.


§8. Data Security

We implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Personal Data, including:

Breach notification. In the event of a confirmed personal-data breach, we will notify affected Users and applicable regulators no later than 72 hours after we become aware of the breach. This timeline meets both the California Civil Code §1798.82 "most expedient time possible and without unreasonable delay" standard and the strict 72-hour notification window under GDPR Article 33. Where the applicable jurisdiction imposes a stricter timeline, the stricter timeline controls.

User responsibilities. You are responsible for:

No security control is perfect. We cannot and do not guarantee that Personal Data will never be subject to unauthorized access, but we will continuously work to maintain and improve our safeguards.


§9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"):

9.1. Right to Know

You may request that we disclose:

You may make a Right to Know request twice in any 12-month period.

9.2. Right to Delete

You may request that we delete Personal Data we have collected from you, subject to the exceptions enumerated in CCPA §1798.105(d), which include (i) completing the transaction for which the Personal Data was collected, (ii) detecting security incidents, (iii) complying with legal obligations, (iv) exercising rights provided by law, and (v) internal uses reasonably aligned with your expectations.

9.3. Right to Correct

Under CCPA §1798.106 (added by CPRA), you may request that we correct inaccurate Personal Data we maintain about you. We will use commercially reasonable efforts to correct verified inaccuracies.

9.4. Right to Opt-Out of "Sale"

We do not sell Personal Data, as described in §3 and §5 above. You nonetheless have the right to opt out of any future sale, and submitting a Global Privacy Control signal will be honored as a valid opt-out request.

9.5. Right to Opt-Out of "Sharing" for Cross-Context Behavioral Advertising

We do not "share" Personal Data for cross-context behavioral advertising, as that term is defined under CCPA §1798.140(ah). You nonetheless have the right to opt out, and we honor Global Privacy Control signals.

9.6. Right to Limit Use of Sensitive Personal Information

Under CCPA §1798.121, you may request that we limit our use and disclosure of "sensitive personal information" to the purposes specified in CCPA Regulation §7027(m). We do not use sensitive Personal Data (your account credentials and financial-account references) for any purpose beyond what is necessary to operate the Service, but you may formally exercise this right by contacting privacy@cryptobur.com.

9.7. Right to Data Portability

You may request a copy of your Personal Data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) that you can transmit to another service.

9.8. Right to Non-Discrimination

We will not discriminate against you for exercising any CCPA/CPRA right. We will not deny you access to the Service, charge you a different price, or provide a different level of quality because you exercised a right.

9.9. How to Exercise Your Rights

You may submit a CCPA/CPRA request:

We will acknowledge your request within 10 business days and respond within 45 calendar days. We may extend the response period by an additional 45 calendar days (for a total of 90 days) where reasonably necessary, and we will notify you of the extension within the initial 45-day window.

9.10. Verification

To verify your identity, we will ask you to confirm Personal Data already in our possession (e.g., the email address associated with your CryptoBur account, the approximate date of account creation, recent billing-card last-four). For sensitive requests, we may require additional verification proportionate to the risk of disclosure.

9.11. Authorized Agents

You may designate an authorized agent to submit a request on your behalf. The agent must provide (i) written, signed permission from you, (ii) proof of the agent's identity, and (iii) a power-of-attorney or notarized authorization for Right to Delete or Right to Correct requests. We may contact you directly to confirm the agent's authority.

9.12. Annual Disclosure Metrics

In accordance with 11 CCR §7102, beginning July 1 of each year, we will publish on cryptobur.com/legal/privacy-metrics the following metrics for the prior calendar year: (i) number of Requests to Know received, complied with in whole or part, and denied; (ii) number of Requests to Delete received, complied with in whole or part, and denied; (iii) number of Requests to Correct received, complied with in whole or part, and denied; (iv) number of Requests to Opt-Out received, complied with, and denied; and (v) the median and mean number of days to substantively respond.

9.13. "Shine the Light" — Cal. Civ. Code §1798.83

California residents may request information about the disclosure of Personal Data to third parties for those third parties' direct marketing purposes during the prior calendar year. We do not disclose Personal Data to third parties for their direct marketing purposes, but you may submit a written request to privacy@cryptobur.com for confirmation.

9.14. Do Not Track

As described in §6, we honor browser Do Not Track signals and Global Privacy Control opt-out signals.


§10. EU / UK Residents — GDPR Rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following provisions apply to you under the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection.

10.1. Controller of Your Personal Data

For purposes of the GDPR, SAVOK AI, Inc. is the controller of your Personal Data. Contact details are in §15 below.

10.2. Lawful Bases for Processing

We process your Personal Data under the following lawful bases (GDPR Art. 6):

Processing Purpose Lawful Basis
Account creation, service delivery, AI/exchange relay Performance of a contract (Art. 6(1)(b))
Subscription billing Performance of a contract (Art. 6(1)(b))
Security, fraud prevention, system integrity Legitimate interests (Art. 6(1)(f)) — interest in protecting our infrastructure and Users
Service improvement, debugging, error monitoring Legitimate interests (Art. 6(1)(f)) — interest in maintaining a reliable Service
Legal and regulatory compliance Legal obligation (Art. 6(1)(c))
Marketing communications Consent (Art. 6(1)(a)), which you may withdraw at any time
Aggregate analytics on cryptobur.com Consent via cookie banner (Art. 6(1)(a))

10.3. Your GDPR Rights

You have the following rights:

10.4. How to Exercise Your Rights

Email privacy@cryptobur.com with the subject line "GDPR Request." We will respond within 30 calendar days. Where the request is complex or we receive a high volume of requests, we may extend by up to two further months, with notice to you within the initial 30-day period.

10.5. Right to Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority in your EU member state, the UK Information Commissioner's Office ("ICO"), or the Swiss Federal Data Protection and Information Commissioner ("FDPIC"). We would, however, appreciate the opportunity to address your concerns directly first.

10.6. Cross-Border Transfers

SAVOK AI, Inc. is located in the United States and processes Personal Data on infrastructure located primarily in the United States (Cloudflare US edge, Supabase US region). When we transfer Personal Data from the EEA, UK, or Switzerland to the US or other third countries, we rely on:

You may request a copy of the relevant transfer mechanism by emailing privacy@cryptobur.com.

10.7. Data Protection Officer

Evgeny Zuev (Founder, acting Data Protection Officer) Email: privacy@cryptobur.com

10.8. EU Representative (GDPR Art. 27)

An EU representative under Article 27 GDPR has not yet been appointed. SAVOK AI, Inc. will appoint and publicly designate an EU representative once the Service's processing of EU residents' Personal Data reaches the threshold described in Article 27 (systematic monitoring or large-scale processing of special categories of data). Until that time, EU Users may contact SAVOK directly at privacy@cryptobur.com for all GDPR-related inquiries.


§11. Other Jurisdictions

11.1. Brazil (LGPD)

If you are a resident of Brazil, you have rights substantially similar to those described in §10 under the Lei Geral de Proteção de Dados (Federal Law No. 13,709/2018). Direct requests to privacy@cryptobur.com with subject line "LGPD Request."

11.2. Canada (PIPEDA)

If you are a resident of Canada, you have rights under the Personal Information Protection and Electronic Documents Act and applicable provincial laws (Quebec's Law 25, Alberta PIPA, BC PIPA). Direct requests to privacy@cryptobur.com.

11.3. Other Jurisdictions

For Users in jurisdictions with comprehensive privacy laws not specifically named above (including but not limited to Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and similar US state laws), we will honor the substantive rights granted under applicable law on the same terms described in §9. Submit requests to privacy@cryptobur.com.


§12. Children's Privacy

CryptoBur is intended exclusively for individuals aged 18 years or older. We do not knowingly collect Personal Data from, or allow registration by, anyone under the age of 18.

If we discover that a User is under 18, we will terminate the account, refund any unused subscription balance, and delete the associated Personal Data (subject only to such retention as is required by law). If you believe a child under 18 has provided Personal Data to us, please contact privacy@cryptobur.com so that we can investigate.

We do not apply a 13-year or 16-year carve-out: the minimum age for CryptoBur is 18, without exception.


§13. International Data Transfers

Our primary production infrastructure is hosted in the United States:

If you access the Service from outside the United States, your Personal Data may be transferred to, processed in, and stored in the United States. We rely on Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers from the EEA, UK, and Switzerland, as described in §10.6.

By using the Service, you acknowledge this cross-border transfer. If you do not consent to such transfer, you must not use the Service.


§14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes that affect your rights or how we use Personal Data, we will:

  1. Post the revised Policy at cryptobur.com/legal/privacy with a new "Effective Date";
  2. Display a banner on cryptobur.com and within the authenticated application for at least 30 days; and
  3. Send an email notice to the address associated with your account at least 30 days before the revised Policy takes effect.

For non-material changes (clarifications, typographical corrections, vendor-name updates that do not change processing purposes), we will update the Policy and the Effective Date without separate notice.

Your continued use of the Service after the Effective Date of any revised Policy constitutes acceptance of the revised Policy. If you do not accept the revised Policy, you must close your account and cease using the Service before the Effective Date.


§15. Contact

General Privacy Inquiries

Email: privacy@cryptobur.com

Data Protection Officer

Evgeny Zuev (Founder, acting Data Protection Officer) privacy@cryptobur.com

California (CCPA/CPRA) Requests

Email: privacy@cryptobur.com — Subject: "CCPA Request" Web form: cryptobur.com/legal/privacy-rights

EU / UK / Swiss (GDPR / UK GDPR) Requests

Email: privacy@cryptobur.com — Subject: "GDPR Request"

Security Incidents and Vulnerability Reports

Email: security@cryptobur.com

Postal Address

SAVOK AI, Inc. Attn: Privacy Officer 2108 N St, Ste N Sacramento, CA 95816