Last Updated: July 26, 2026
This Privacy Policy explains how CandleVix (“CandleVix,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you access or use our website and its related features (the “Service”). This Policy should be read together with our Terms of Service.
This Policy is intended to reflect the requirements of the EU/UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”), as applicable to your use of the Service, in addition to describing our practices generally.
CandleVix determines the purposes and means of processing personal information collected through the Service and acts as the data controller (or “business,” under the CCPA) for that information. As described in our Terms of Service, CandleVix is currently operated on an unincorporated basis and has not yet completed formal business registration; this Policy will be updated with our registered entity details once that process is complete. You can reach us using the contact details in Section 15.
| Category | Examples |
|---|---|
| Account information | Email address and password (your password is managed and hashed by our authentication provider, Supabase — we never see or store it in plain text) |
| Uploaded charts | Chart image files you upload for analysis |
| Analysis context | Your answers to contextual questions (e.g., market/asset type, trading pair, timeframe) and your selected response language |
| Payment metadata | Transaction identifiers, invoice amounts, selected cryptocurrency and network, and payment status relayed to us by NOWPayments. We do not collect or store your wallet private keys, seed phrases, or full payment credentials — these never pass through our systems |
| Support communications | Information you provide when you contact support via email or Telegram |
| Category | Examples |
|---|---|
| AI-generated analysis | The written Analysis output produced in response to your chart upload |
| Usage and device data | IP address, browser type, device type, and general usage activity, collected automatically via cookies and our analytics tool (PostHog) — including page views, clicks, session data, feature usage, and performance data |
| Error and diagnostic data | Crash reports, stack traces, browser/device information, and request metadata, collected automatically via our error-monitoring tool (Sentry) when something goes wrong |
| Cookies | Session and authentication cookies (via Supabase Auth) necessary to keep you signed in, and analytics cookies (via PostHog); see Section 6 |
We do not collect government ID documents, payment card numbers, or bank account details. Because all payments are processed in cryptocurrency through NOWPayments’ hosted invoice pages, we never receive or store your card or bank information, and we never receive your wallet’s private keys or seed phrase.
We use the information described above to:
Where the GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service you signed up for, including generating Analyses and processing payments); legitimate interests (to secure the Service, prevent fraud/abuse, and understand aggregate usage through analytics and error monitoring); consent (for non-essential cookies, where required by your jurisdiction); and legal obligation (where we must retain or disclose information to comply with the law).
When you submit a chart for analysis, the image (via a short-lived, access-controlled link) and your contextual answers are sent to our third-party AI provider (currently OpenAI’s vision-capable models) solely to generate the requested Analysis. We do not use your uploaded charts, your Analyses, or any of your Content to train, fine-tune, or otherwise improve any AI model — ours or our provider’s. We may change, add, or replace our AI provider at any time without prior notice; regardless of provider, your Content continues to be used only to generate the specific Analysis you requested, subject to that provider’s own processing terms.
We use cookies and similar technologies for two purposes:
We intend to implement a cookie consent banner allowing you to manage non-essential cookie preferences where required by applicable law (such as under the GDPR/ePrivacy rules). You can also control cookies through your browser settings, though disabling essential cookies may prevent you from signing in or using the Service.
We do not sell your personal information, and we never will. We share personal information only with the following categories of third-party service providers (“subprocessors”), each of which processes data on our behalf and only to the extent necessary to provide the Service:
| Provider | Purpose | Data Involved |
|---|---|---|
| Supabase | Database, authentication, and private file storage | Account data, uploaded charts, Analyses, credit/payment records |
| Vercel | Application hosting | Request/traffic data necessary to serve the Service |
| Upstash | Asynchronous workflow processing and rate limiting | Analysis job data (chart reference, context, language) |
| OpenAI (or successor AI provider, see Section 5) | AI chart analysis | Chart images and contextual answers, for the duration of processing |
| NOWPayments | Cryptocurrency payment processing | Transaction/invoice metadata, wallet addresses used for payment |
| Sentry | Error monitoring | Crash reports, device/browser data, request metadata |
| PostHog | Product analytics | Usage events, device/browser data, IP address |
We may also disclose information: (a) to comply with a legal obligation, court order, or governmental request; (b) to protect the rights, property, or safety of CandleVix, our users, or the public; or (c) in connection with a merger, acquisition, or sale of assets (including formalizing our business registration), subject to this Policy continuing to apply to the transferred information.
Our service providers may process information in countries other than your own, including the United States. Where personal information originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to such countries, we rely on appropriate safeguards recognized under the GDPR (such as Standard Contractual Clauses or equivalent mechanisms offered by our subprocessors) to protect that information.
| Data | Retention Period |
|---|---|
| Uploaded chart images and their associated Analysis | 30 days from creation, after which they are automatically and permanently deleted from our database and storage by an automated process |
| Account information (email) | Retained for as long as your account is active, and deleted upon account deletion (see Section 12) |
| Payment and credit-ledger records | Retained for as long as necessary for billing accuracy, fraud prevention, accounting, and legal/tax compliance, even after account deletion, as permitted by law |
| Analytics and error-monitoring data | Retained per our analytics and error-monitoring providers’ standard retention windows, used only in aggregate/diagnostic form |
We use industry-standard technical and organizational measures to protect your information, including: private, access-controlled file storage with no public bucket access; short-lived signed URLs (expiring after one hour) for any temporary image access; database-level Row Level Security ensuring you can only access your own data; encrypted connections (HTTPS/TLS); and session-based authentication managed by Supabase Auth. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security of your information.
You have the right to: access the personal information we hold about you; request correction of inaccurate information; request erasure of your information; request restriction of, or object to, certain processing; request a portable copy of your information; and lodge a complaint with your local data protection authority. To exercise any of these rights, contact us at the email in Section 15.
If you are a California resident, you have the right to: know what personal information we collect, use, and disclose; request deletion of your personal information; correct inaccurate personal information; and not be discriminated against for exercising these rights. We do not sell or “share” (as defined under the CCPA) your personal information, so no opt-out mechanism for sale/sharing is required; if this changes in the future, we will update this Policy and provide the required opt-out tools.
Contact us at support@candlevix.com with your request. We may need to verify your identity (typically by confirming access to your registered email) before acting on a request.
You may delete your own account at any time from your account settings by completing the required typed confirmation, or by requesting deletion via our support email. When you delete your account (or your deletion request is processed), we delete your uploaded chart images, AI-generated Analyses, and email address from our active systems, other than information we are required to retain for billing, accounting, fraud-prevention, or legal-compliance purposes as described in Section 9. Any remaining unused Credits are forfeited and non-refundable upon account deletion, as described in our Refund Policy.
The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete it. If you believe a child under 13 has provided us with personal information, please contact us at support@candlevix.com.
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes your acknowledgment of the revised Policy.
For any privacy-related questions or requests, please contact us: