Privacy Policy
Last updated: April 30, 2026
1. Information We Collect
We collect the following information when you use Hex37:
- Account information: email address, full name, username (if set), and password (hashed with bcrypt).
- Profile information: bio, profile visibility setting, and copy-trading enrollment if you provide them.
- Educational practice activity: simulated orders, trades, positions, journal notes, watchlist, price alerts, and portfolio snapshots. All educational practice data refers to virtual balances; no real assets are involved.
- Usage data: request timestamps, IP address, user agent, and feature usage. Used for security, abuse prevention, and product analytics.
- Payment information: processed by Razorpay. We store the order ID, plan, billing interval, and amount. We do not store card numbers, CVVs, or bank details.
- AI tutor prompts: when you use the AI tutor feature, the practice trade context you submit is sent to our AI provider (Anthropic) for processing.
2. How We Use Your Information
We use your information to: operate the educational trading sandbox; render skill rankings, practice challenges, public profiles, and shareable trades you have opted into; process subscription payments; deliver transactional and product emails; enforce our Terms of Service; detect and prevent abuse; and improve the Service.
3. What We Make Public
By default your account is private. Some features publish data about you when you opt in: skill rankings rank users by simulated practice performance; public profiles (under /p/<username>) and shareable trade pages (under /t/<slug>) are visible to anyone with the link when you make them public; study mode exposes your practice fills to followers when you enable it; practice challenges display participant standings to other entrants. None of these surfaces ever expose your email address.
4. Third-Party Services
We use the following third-party services to operate Hex37:
- Razorpay: payment processing. Subject to Razorpay's Privacy Policy.
- Binance: source of live cryptocurrency market data displayed in the Service. We do not send your personal data to Binance.
- Anthropic: AI provider for the AI tutor feature. The practice trade context you submit is sent to Anthropic for inference. Subject to Anthropic's Privacy Policy.
- Email provider: transactional email (verification, password reset, billing notices) is delivered via a third-party email service.
5. AI Tutor Data Handling
When you submit a practice trade for analysis by our AI tutor feature, the trade details (instrument, side, quantity, entry/exit prices, journal notes you have voluntarily attached) are transmitted to a third-party large-language-model provider for educational analysis.
The third-party provider processes this data to generate the analysis only. We do not transmit personally identifying information (your name, email, account ID) to the provider as part of the analysis request.
Analysis outputs are stored in your account so you can revisit them. You can delete an analysis from your account, which removes it from our systems on a rolling basis.
6. Data Retention
Account data is retained while your account is active. Practice trading history (orders, trades, positions) is retained for as long as your account exists so that journal, leaderboard, and analytics surfaces continue to work. Dispatched event-bus rows are pruned after 7 days. If you delete your account, your personal data and trading history are removed within 30 days, except where we are required to retain billing records for tax and accounting purposes.
7. Data Security
We use industry-standard security measures to protect your data, including encrypted connections (HTTPS), hashed passwords (bcrypt), and JWT-based authentication. No method of transmission over the Internet is 100% secure; we cannot guarantee absolute security.
8. Your Rights
You have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your account and associated data; flip your profile and trades back to private at any time; and disable copy-trading enrollment. To exercise these rights, contact us using the link below.
9. Cookies and Local Storage
Hex37 uses browser localStorage to store authentication tokens, theme preference, watchlist UI state, and onboarding state. We do not use tracking cookies or third-party advertising cookies.
10. Children
Hex37 is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notice. The "Last updated" date at the top indicates when this policy was last revised.
12. Contact
For privacy-related questions, contact us.