CandleVix
How It WorksPricingFAQ
Log InSign Up

Product

  • How It Works
  • Pricing
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy

Community

  • Support
  • Send Feedback

© 2026 CandleVix. All rights reserved.

Not financial advice. For informational purposes only.

CandleVix — Privacy Policy

Last Updated: July 26, 2026

1. Introduction

This Privacy Policy explains how CandleVix (“CandleVix,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you access or use our website and its related features (the “Service”). This Policy should be read together with our Terms of Service.

This Policy is intended to reflect the requirements of the EU/UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”), as applicable to your use of the Service, in addition to describing our practices generally.

2. Who We Are

CandleVix determines the purposes and means of processing personal information collected through the Service and acts as the data controller (or “business,” under the CCPA) for that information. As described in our Terms of Service, CandleVix is currently operated on an unincorporated basis and has not yet completed formal business registration; this Policy will be updated with our registered entity details once that process is complete. You can reach us using the contact details in Section 15.

3. Information We Collect

3.1 Information You Provide Directly

CategoryExamples
Account informationEmail address and password (your password is managed and hashed by our authentication provider, Supabase — we never see or store it in plain text)
Uploaded chartsChart image files you upload for analysis
Analysis contextYour answers to contextual questions (e.g., market/asset type, trading pair, timeframe) and your selected response language
Payment metadataTransaction identifiers, invoice amounts, selected cryptocurrency and network, and payment status relayed to us by NOWPayments. We do not collect or store your wallet private keys, seed phrases, or full payment credentials — these never pass through our systems
Support communicationsInformation you provide when you contact support via email or Telegram

3.2 Information Generated Through Your Use of the Service

CategoryExamples
AI-generated analysisThe written Analysis output produced in response to your chart upload
Usage and device dataIP address, browser type, device type, and general usage activity, collected automatically via cookies and our analytics tool (PostHog) — including page views, clicks, session data, feature usage, and performance data
Error and diagnostic dataCrash reports, stack traces, browser/device information, and request metadata, collected automatically via our error-monitoring tool (Sentry) when something goes wrong
CookiesSession and authentication cookies (via Supabase Auth) necessary to keep you signed in, and analytics cookies (via PostHog); see Section 6

3.3 Information We Do Not Collect

We do not collect government ID documents, payment card numbers, or bank account details. Because all payments are processed in cryptocurrency through NOWPayments’ hosted invoice pages, we never receive or store your card or bank information, and we never receive your wallet’s private keys or seed phrase.

4. How We Use Your Information

We use the information described above to:

  • Create and maintain your account and authenticate your sign-ins;
  • Process your chart uploads and generate the requested AI Analysis;
  • Process payments, grant Credits, and maintain your billing history;
  • Send you essential account-related emails (email verification, password reset) via Supabase Auth. We do not currently send marketing emails or credit-expiry notification emails — the only automated emails you will receive relate to authentication;
  • Monitor, debug, and improve the reliability and performance of the Service (via Sentry);
  • Understand aggregate usage patterns and improve the product (via PostHog);
  • Detect, investigate, and prevent fraud, abuse, free-trial circumvention, and violations of our Terms of Service;
  • Comply with applicable law, respond to lawful requests, and enforce our agreements.

4.1 Legal Bases for Processing (GDPR)

Where the GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service you signed up for, including generating Analyses and processing payments); legitimate interests (to secure the Service, prevent fraud/abuse, and understand aggregate usage through analytics and error monitoring); consent (for non-essential cookies, where required by your jurisdiction); and legal obligation (where we must retain or disclose information to comply with the law).

5. How Your Chart Images Are Processed by AI

When you submit a chart for analysis, the image (via a short-lived, access-controlled link) and your contextual answers are sent to our third-party AI provider (currently OpenAI’s vision-capable models) solely to generate the requested Analysis. We do not use your uploaded charts, your Analyses, or any of your Content to train, fine-tune, or otherwise improve any AI model — ours or our provider’s. We may change, add, or replace our AI provider at any time without prior notice; regardless of provider, your Content continues to be used only to generate the specific Analysis you requested, subject to that provider’s own processing terms.

6. Cookies & Tracking Technologies

We use cookies and similar technologies for two purposes:

  • Essential/authentication cookies(via Supabase Auth) — required to keep you securely signed in and to operate core features of the Service. These cannot be disabled without affecting core functionality.
  • Analytics cookies(via PostHog) — used to understand how the Service is used in aggregate (e.g., page views, feature usage) so we can improve it.

We intend to implement a cookie consent banner allowing you to manage non-essential cookie preferences where required by applicable law (such as under the GDPR/ePrivacy rules). You can also control cookies through your browser settings, though disabling essential cookies may prevent you from signing in or using the Service.

7. How We Share Your Information

We do not sell your personal information, and we never will. We share personal information only with the following categories of third-party service providers (“subprocessors”), each of which processes data on our behalf and only to the extent necessary to provide the Service:

ProviderPurposeData Involved
SupabaseDatabase, authentication, and private file storageAccount data, uploaded charts, Analyses, credit/payment records
VercelApplication hostingRequest/traffic data necessary to serve the Service
UpstashAsynchronous workflow processing and rate limitingAnalysis job data (chart reference, context, language)
OpenAI (or successor AI provider, see Section 5)AI chart analysisChart images and contextual answers, for the duration of processing
NOWPaymentsCryptocurrency payment processingTransaction/invoice metadata, wallet addresses used for payment
SentryError monitoringCrash reports, device/browser data, request metadata
PostHogProduct analyticsUsage events, device/browser data, IP address

We may also disclose information: (a) to comply with a legal obligation, court order, or governmental request; (b) to protect the rights, property, or safety of CandleVix, our users, or the public; or (c) in connection with a merger, acquisition, or sale of assets (including formalizing our business registration), subject to this Policy continuing to apply to the transferred information.

8. International Data Transfers

Our service providers may process information in countries other than your own, including the United States. Where personal information originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to such countries, we rely on appropriate safeguards recognized under the GDPR (such as Standard Contractual Clauses or equivalent mechanisms offered by our subprocessors) to protect that information.

9. Data Retention

DataRetention Period
Uploaded chart images and their associated Analysis30 days from creation, after which they are automatically and permanently deleted from our database and storage by an automated process
Account information (email)Retained for as long as your account is active, and deleted upon account deletion (see Section 12)
Payment and credit-ledger recordsRetained for as long as necessary for billing accuracy, fraud prevention, accounting, and legal/tax compliance, even after account deletion, as permitted by law
Analytics and error-monitoring dataRetained per our analytics and error-monitoring providers’ standard retention windows, used only in aggregate/diagnostic form

10. Data Security

We use industry-standard technical and organizational measures to protect your information, including: private, access-controlled file storage with no public bucket access; short-lived signed URLs (expiring after one hour) for any temporary image access; database-level Row Level Security ensuring you can only access your own data; encrypted connections (HTTPS/TLS); and session-based authentication managed by Supabase Auth. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security of your information.

11. Your Privacy Rights

11.1 If the GDPR Applies to You

You have the right to: access the personal information we hold about you; request correction of inaccurate information; request erasure of your information; request restriction of, or object to, certain processing; request a portable copy of your information; and lodge a complaint with your local data protection authority. To exercise any of these rights, contact us at the email in Section 15.

11.2 If the CCPA Applies to You

If you are a California resident, you have the right to: know what personal information we collect, use, and disclose; request deletion of your personal information; correct inaccurate personal information; and not be discriminated against for exercising these rights. We do not sell or “share” (as defined under the CCPA) your personal information, so no opt-out mechanism for sale/sharing is required; if this changes in the future, we will update this Policy and provide the required opt-out tools.

11.3 How to Exercise Your Rights

Contact us at support@candlevix.com with your request. We may need to verify your identity (typically by confirming access to your registered email) before acting on a request.

12. Account Deletion

You may delete your own account at any time from your account settings by completing the required typed confirmation, or by requesting deletion via our support email. When you delete your account (or your deletion request is processed), we delete your uploaded chart images, AI-generated Analyses, and email address from our active systems, other than information we are required to retain for billing, accounting, fraud-prevention, or legal-compliance purposes as described in Section 9. Any remaining unused Credits are forfeited and non-refundable upon account deletion, as described in our Refund Policy.

13. Children’s Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete it. If you believe a child under 13 has provided us with personal information, please contact us at support@candlevix.com.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes your acknowledgment of the revised Policy.

15. Contact Us

For any privacy-related questions or requests, please contact us:

  • General support: support@candlevix.com
  • Telegram support: @CandleVixSupportBot