BackTest Studio: Privacy Policy
DRAFT v0.1, 3 October 2026. Not legal advice; to be reviewed by a lawyer before publication.
This policy explains what personal data we handle when you use BackTest Studio and why. Short version: the application runs on your computer, we have no usage analytics or telemetry, and your strategies and market data stay on your machine. To use the application you create a free account; beyond that we receive data only if you buy a subscription or turn on optional features.
1. Who is responsible
Baturalp Yatıcı, Akácfa utca 34, 1/12, 1072 Budapest, Hungary ("we"), is the controller of the data described below. Contact: destek@backteststudio.dev.
2. What we handle, why, and on what basis
a) What the application sends without an account
Nothing, until you sign in. After you create your account (b), the application contacts our license server to keep you signed in and renew your licence document. (The application may also check for updates, see 2e.)
b) BackTest Studio account (license server, hosted on Cloudflare)
One account is used to sign in to the application (including the free Basic plan), for paid plans, and for the community.
| Data | Why | Basis (GDPR) |
|---|---|---|
| E-mail address | create and identify your account, send verification and password-reset codes, support | contract (Art. 6(1)(b)) |
| Username (public) | identify you in the application and, if you use it, in the community, where it is visible to other users | contract |
| Marketing e-mail consent (yes/no, with date) | send you e-mails about new features, updates, promotions and discounts only if you ticked the optional box; you can withdraw at any time in Settings, and withdrawal does not affect earlier processing | consent (Art. 6(1)(a)) |
| Password | log in. Stored only as a salted hash (PBKDF2-SHA256), never in plain text | contract |
| Computer identifier (a one-way hash derived from your Windows installation) and computer name | enforce the one-computer-at-a-time rule and show you which computer holds the account | contract / legitimate interest (6(1)(f)): preventing account sharing |
| Plan, subscription end date, payment-provider customer and subscription IDs, account creation time, last-seen time | give you the right plan; match payments to your account | contract |
| Login attempts: e-mail + IP address, short-lived | block password guessing | legitimate interest: security; deleted automatically after 24 hours |
| Time and version of the terms you accepted at sign-up | prove that you accepted the Terms, Privacy Policy and Risk Disclosure | legitimate interest (6(1)(f)) / legal claims |
| Community identifier (an internal ID of your community profile) | keep your community profile linked to your account, for example when you change your e-mail address or delete your account | contract |
| One-time codes (stored only as a hash) | verify e-mail, reset password; expire after 15 minutes | contract |
| Purchase record: the purchase e-mail, plan, end date and customer/subscription numbers reported by the payment provider; for account-less activation also a computer identifier and computer name | activate the plan you bought with a code sent to your e-mail, apply the right plan and enforce the one-computer-at-a-time rule | performance of the contract |
| Plan tier (Basic, Starter, Pro, Ultra) | show a publicly visible account-level badge (Bronze, Silver, Gold, Diamond) on your community profile and next to your posts. The badge follows your plan, cannot be changed or hidden by the user, and updates automatically when your plan changes | performance of the contract / legitimate interest (accuracy of account levels in the community) |
| Bug reports: the text you write, images you attach (optional), app version, operating system; your account e-mail and username if signed in, otherwise the optional contact e-mail you give | investigate the bug and reply if needed (the report is also forwarded to our support mailbox) | your request / legitimate interest; deleted automatically after 180 days |
c) Payments
Payments are handled by Lemon Squeezy as merchant of record. It collects and processes your name, billing details, card data, tax data and e-mail as its own controller under its own privacy policy. We receive only: a customer/subscription ID, plan and renewal/end dates, and the account ID we attach to the checkout. We never receive card numbers. Legal basis for our part: contract and legal obligations (accounting).
d) E-mails
Marketing e-mails (new features, updates, promotions, discounts) are sent only to accounts that ticked the optional consent box; every such e-mail has an unsubscribe link, and you can also switch it off in Settings. Account e-mails (verification, password reset, e-mail change) are always sent. Verification and reset e-mails are sent through Resend, which processes your e-mail address and the message for delivery.
e) Updates
If automatic updates are enabled the application contacts our update server, which receives the usual technical connection data (IP address, application version) to deliver the file. Legal basis: contract / legitimate interest (software maintenance).
f) Optional features you choose to use
- AI analysis: test results and strategy code are sent to Anthropic using your own API key, directly from your computer. We do not receive them. Anthropic's terms and privacy policy apply. Your key is stored only on your computer.
- Market-data downloads and live prices: your computer connects directly to third-party sources (for example Dukascopy, Yahoo Finance, Swissquote); they see your IP address as with any website. We do not receive this traffic.
- Python indicators: the first use may load a Python runtime from a public content delivery network (the CDN sees your IP address).
- Community (if enabled in your version): uses your BackTest Studio account (no separate registration) and has its own terms; it processes your e-mail, username, avatar and content you publish on infrastructure of our provider Supabase.
- Support: if you e-mail us we keep the correspondence to help you and to document the support case.
g) What we do NOT do
No advertising, no analytics or tracking in the application, no selling of data, no profiling.
3. Where your data is processed and who receives it
We use these processors: Cloudflare (hosting and database of the license server; data may be processed worldwide), Resend (e-mail delivery, United States), Lemon Squeezy (payments, separate controller), and for community Supabase. Some of them are outside the EEA/Türkiye; transfers rely on the providers' contractual safeguards (for example standard contractual clauses). We may disclose data to authorities where the law requires it.
4. How long we keep data
- Account data: while your account exists. You can delete your account yourself in Settings (password required): the account, the device records and the community profile with everything you posted are deleted immediately. If you have an active paid subscription, cancel it first. Data we must keep by law (for example accounting records, usually the payment provider's, for the statutory period) is kept only for that period. You can also ask us by e-mail; we respond within 30 days.
- Login-attempt records: deleted automatically after 24 hours (an hourly clean-up job). One-time codes: valid 15 minutes, expired codes are removed by the same job. Device-change records: 60 days. Support e-mails: up to 3 years or as the law requires.
- Bug reports: deleted from the server automatically after 180 days; the copy sent to the support mailbox follows the "support e-mails" period below. Do not put passwords, card details or personal data in a report.
- Images you attach to a bug report are not stored on the server; they are only forwarded to the support mailbox as attachments and follow the support e-mail retention below. Do not show passwords, card details or personal data in images.
- Purchase records: kept as long as needed for your license and payment/tax obligations; you may ask for deletion (legal retention duties reserved).
- Marketing consent: kept while your account exists, or until you withdraw it; after withdrawal we keep only the fact that you opted out so we do not e-mail you again.
5. Security
Passwords are salted and hashed; licence documents are digitally signed; the sign-in session on your computer is stored encrypted with Windows protection; connections use HTTPS. No system is perfectly secure; we will notify you and the authorities of a breach as the law requires.
6. Your rights
Depending on your country (GDPR, UK GDPR, Turkish KVKK Art. 11, others) you may ask for access, correction, deletion, restriction, portability, objection, and withdraw consent where we rely on it. E-mail destek@backteststudio.dev from the account address; we answer within 30 days. You can also complain to your data-protection authority (in Türkiye the Personal Data Protection Authority, KVKK).
7. Children
The Software is for adults (18+). We do not knowingly collect data from children.
8. Changes
We will publish changes here and, if material, announce them in the Software or by e-mail before they apply.
9. Contact
Turkish privacy notice (KVKK)
The Turkish text (tr-gizlilik-politikasi.md) includes the information notice ("aydınlatma metni") required by Turkish KVKK Art. 10.