Privacy Policy
Last reviewed: July 2026 · v2 (template-drafted)
This is a plain-language description of what CryptoEntry actually collects and does today, drafted from a standard template and reviewed for accuracy against this app — not a lawyer-reviewed policy. If anything here is unclear, email us (see Contact below) rather than guess.
Account identity
TL;DR: signing in shares your email (and name/photo if using Google or Apple) — used only to identify your account.
If you sign in, we receive whatever your sign-in method shares with us — typically your email address and, if you use Google or Apple sign-in, your name and profile photo. This is handled by Firebase Authentication (Google Cloud) and is used only to identify your account and keep your data (trial status, synced keys if enabled) scoped to you.
Your exchange and AI keys
TL;DR: your keys are encrypted in your browser, never stored on our servers in plaintext.
CryptoEntry is bring-your-own-key: you provide your own exchange API keys (Coinbase, Binance, Bybit, OKX, Kraken, MEXC, BingX) and your own AI provider keys (OpenAI, Anthropic, Mistral, Qwen) to use those features. These keys are encrypted and stored in your browser — we do not hold a copy of them in plaintext, on our servers, by default.
When a request needs to reach an exchange or AI provider, it is sent either directly from your browser, or — for a few providers that require server-side request signing or do not allow direct browser calls — proxied once through our server per request. That proxy forwards the request and returns the response; it does not log or store your keys.
Encrypted key sync (optional)
TL;DR: opt-in cross-device sync is end-to-end encrypted — we can't read it even if we wanted to.
If you turn on cross-device key sync, an encrypted copy of your key vault is stored in our database (Firestore), protected by a passphrase only you know. We never see that passphrase and cannot decrypt the vault ourselves — if you lose the passphrase, we cannot recover it either. Sync is off by default; using the app locally never sends your keys anywhere.
Trial and account status
TL;DR: we track your trial/subscription status — nothing about your keys or trades.
We store a small record per account — when your trial started and whether your subscription is active — so the app knows what you are entitled to use. This record contains no key material and no trading data.
Billing (once purchases launch)
TL;DR: Dodo Payments handles payment details directly — we never see or store card numbers.
Once paid checkout is live, purchases are processed through Dodo Payments. They receive whatever payment details are needed to complete your purchase (e.g. card details) directly — we never see or store your full card number. We receive only the resulting entitlement status (which plan you're on, whether it's active) to unlock the right features.
Who processes this data
Firebase / Google Cloud (authentication, database hosting). The exchanges and AI providers you connect your own keys to — we never share your keys with anyone besides the specific provider you are calling. Dodo Payments, once purchases launch (see Billing above).
What we do not do
TL;DR: no ad tracking, no selling data, no analytics yet.
No ad tracking, no selling or renting personal data, no third-party analytics yet (if that changes, this page will be updated first). We do not read your trading strategies or positions for any purpose beyond showing them to you in the app.
Deleting your data
There is no self-serve delete-account flow yet. Email us and we will delete your account record and any synced vault data.
Contact
Questions about this page or your data: support@cryptoentry.net.