Privacy Policy

Version 2026-09-24. DRAFT for legal review: items marked in yellow must be filled in before publication.

1. Who we are

The service Helova Screener (helovascreener.com, "the Service") is operated by [COMPANY LEGAL NAME], [REGISTRATION NUMBER], [ADDRESS, COUNTRY] ("we"). Contact for privacy matters: [PRIVACY EMAIL]. We are the data controller for the personal data described below.

2. What data we process and why

DataPurposeLegal basis (GDPR Art. 6)Retention
Google account id, email, name, profile pictureCreating and signing in to your accountPerformance of a contract (Art. 6(1)(b))Until you delete your account
Your settings, presets, drawings, alert rules, alert notification historyProviding the Service and syncing it between your devicesPerformance of a contractUntil you delete them or your account; notification history is capped per account
Telegram bot token and chat id you provideDelivering your alerts to your own Telegram botPerformance of a contractUntil you disconnect the bot or delete your account. Stored encrypted.
Browser push subscriptionDelivering alerts as browser notificationsConsent (you enable it in the browser)Until you revoke it or delete your account
IP address and country (derived from the IP by our CDN), browser typeSecurity, abuse prevention, rate limiting of guest access, aggregate usage statisticsLegitimate interest (Art. 6(1)(f)): keeping the Service secure and availableUsage events: 90 days. Server logs: [N] days
Bug reports you send (text and screenshots)Fixing the problem you reportedLegitimate interest30 days (text); screenshots are delivered to our support channel and not stored on the Service's servers

We do not sell personal data and we do not use it for advertising.

3. Cookies and browser storage

The Service uses only what is strictly necessary to work: your sign-in token and your settings in the browser's local storage, and the security cookies set by our CDN provider (Cloudflare). We do not use analytics or advertising cookies from third parties. Because none of this storage is optional, no consent banner is shown; you can clear it at any time by signing out or clearing site data in your browser.

4. Who receives the data (processors)

Market data is obtained from cryptocurrency exchanges' public APIs; no personal data is sent to them.

5. Your rights

You have the right to access, rectify, export and erase your personal data, to restrict or object to processing based on legitimate interest, and to lodge a complaint with a supervisory authority (in [COUNTRY]: [SUPERVISORY AUTHORITY]). You can exercise export and erasure yourself: in the Service, open the account menu, then "Your data & legal". Erasure is immediate and permanent. For anything else write to [PRIVACY EMAIL]; we answer within 30 days.

6. Security

Data is transmitted over TLS and stored on servers in the EU. Secrets you give us (Telegram bot tokens) are stored encrypted. Access to production systems is restricted to the operator. In the event of a personal data breach that is likely to result in a risk to you, we will notify the supervisory authority within 72 hours and inform you without undue delay.

7. Children

The Service is intended for persons aged 18 and over. We do not knowingly process data of children.

8. Changes

When this policy changes in substance, you will be asked to review and accept the new version at your next sign-in. The version in force is shown at the top of this page.