BackDRAFT — needs legal review before public launch
Privacy Policy

Last updated: 20 September 2026 · Version 2026-09-20

1. Who is responsible for your data

The controller of the personal data described here is legal entity name — to be completed, registered at registered address — to be completed, company number company number — to be completed.

This website runs the FIBIKO trading analysis product and presents our automation and marketing services. What it collects is described in section 2.

For any privacy question or to exercise the rights in section 7, write to info@fibiko.com.

2. What we collect

For owner-only social connections, we store the provider, account ID and display name, requested or returned access scopes, connection and verification dates, expiry, and encrypted access/refresh tokens. Tokens stay on the server and are excluded from account downloads. Disconnecting removes the connection and its tokens from active storage; provider-side authorization can also be revoked in that provider’s settings. Account deletion removes these records. No social passwords are collected and this connection module does not publish content.

Education reading progress and bookmarks stay in this browser’s local storage, keyed to the account. Clear browser site data to remove them; they are not sent to our server.

  • Your email address, which you give us when you sign in. It is the only identifier we require.
  • Sign-in codes, stored only as a salted hash and deleted once used or expired. We never hold a readable copy.
  • Passkeys, if you set one up to sign in with Face ID or a fingerprint: the public key your device creates, a usage counter, a device label such as “iPhone” and the dates it was added and last used. The private key, your face and your fingerprint never leave your device — we could not receive them.
  • A session cookie so you stay signed in. See our Cookie notice.
  • What you create in the product — watchlist symbols, demo trading positions, demo-wallet balances and ledger entries, orders and simulated fills, onboarding answers (interests, simulated capital, default risk), and notification read state.
  • Your settings — language, notification and display choices, the default timeframe and minimum score of your desk, an optional name for the desk to greet you with, and, only if you switch it on, your consent to product-news emails with the date you gave it.
  • Sign-in history — the time, the method (email code or passkey) and the device type, such as “iPhone”, of your last 20 sign-ins, shown to you in Settings so you can spot one that was not you. We do not store your IP address for this.
  • Billing records if you subscribe: plan, status, renewal date and invoice history. Starting checkout also stores one recovery record per account: selected plan and period, request date and provider session ID. This prevents duplicate subscriptions after interrupted requests. That recovery record is included in your account download and removed when you delete the account. Card details are handled by Stripe and never reach our servers.

For the trading product we do not ask for your name, address, phone number, or any special-category data. The one exception is optional: a name you may add in Settings for your desk to greet you with. There is no field for the rest.

If you write to us through the contact form — about automation, marketing or financing — we collect what you put in it: your name, e-mail address, optionally your phone number and company, which service you are asking about, and what you write. We use it to answer you and prepare a quote, and for nothing else. No automatic reply is sent; a person answers.

3. Our other website

FIBIKO also runs a separate website for clients in Croatia. It offers different services, collects different data and has its own privacy notice, published on that website. This policy covers this website only.

4. Why we use it, and on what legal basis

  • To run your account and the trading product — signing you in, storing your watchlist and demo trades. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
  • To take payment and manage subscriptions and invoices. Legal basis: performance of our contract (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)).
  • To keep the service secure and working — rate limiting, your sign-in history, audit logs of administrative actions, error diagnosis. Legal basis: our legitimate interest in a secure service (Art. 6(1)(f)).
  • To send product news by email, only if you switch it on in Settings. Legal basis: your consent (Art. 6(1)(a)), which you withdraw by switching it off again.

We do not use your data for advertising or for profiling.

5. How long we keep it

  • Sign-in codes: 10 minutes, then deleted.
  • Session cookie: 30 days, or until you sign out.
  • Passkeys: until you remove them in Settings or your account is deleted.
  • A message sent through the contact form: 1 year from the day you send it — as long as the conversation it starts plausibly lives. After that it is better to ask you again than to keep you on file.
  • Sign-in history: your newest 20 sign-ins; older entries are deleted automatically.
  • Account and product data: while your account exists, and deleted on request (section 7).
  • Billing and invoice records: retained as long as tax and accounting law requires — retention period — to be completed.
  • Administrative audit log entries: retention period — to be completed.

Each enquiry carries its own deletion date, set when you send it. You do not have to wait for it: ask us and we delete it sooner, unless the law requires us to keep a specific record.

6. Who else processes it

When the owner chooses to connect a social account, FIBIKO exchanges an authorization code and tokens with that selected provider (Meta for Instagram/Facebook, Google for YouTube, TikTok, LinkedIn or X) and requests the approved profile metadata. Their own terms and privacy notices apply on their services. This module requests profile/account access and does not send posts or marketing messages.

We use these processors, each under a data-processing agreement:

  • Stripe — payments and subscription billing.
  • Resend — delivery of sign-in code emails.
  • OpenAI and Anthropic — AI analysis. Market data is sent; your email and account data are not.
  • Our hosting and database providers — hosting provider — to be completed.

Market data (prices, funding, open interest) comes from Binance's public API and other public sources. It contains no personal data. We do not sell your data, and we do not share it beyond the services and owner-selected connections described in this section.

7. Transfers outside the EEA

Some processors above are based in the United States. Where data leaves the EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Details of the specific safeguards per processor: transfer mechanism per processor — to be completed.

8. Your rights

Under the GDPR you can ask us to:

  • give you a copy of your data (access);
  • correct anything inaccurate (rectification);
  • delete your account and data (erasure);
  • restrict or object to a particular use;
  • hand your data to you or another provider in a portable format;
  • withdraw consent where we relied on it, without affecting past processing.

Two of these you can do yourself at any time, in Settings under “Your data”: download a copy of your data as a file, and delete your account. Deleting removes your account and everything in section 2 except billing records, which we must keep for the period in section 5.

Write to info@fibiko.com and we will respond within one month. If you think we have handled your data badly you can complain to your national data protection authority — in Croatia, the Personal Data Protection Agency (AZOP); in Bosnia and Herzegovina, the Personal Data Protection Agency; elsewhere in the EU, the authority where you live or work.

9. Changes

If we change this policy materially we will say so in the product before the change takes effect, and the version number at the top changes with it. Where you have given us data under an earlier version, our record of your enquiry keeps pointing at the version you were actually shown.

Privacy | FIBIKO