TAURAX

Privacy Policy

Information about the processing of your data pursuant to Art. 13 and Art. 14 GDPR.

1. Overview

We process personal data only to the extent necessary to provide Taurax as your trading journal, and to keep the service secure and reliable. This page explains what data that involves, who processes it, and what rights you have.

↑ Top

2. Controller

Janek Drews
Taurax Softwares
c/o IP-Management #11152
Ludwig-Erhard-Straße 18
20459 Hamburg
Germany

Email: [email protected]

↑ Top

3. What data we process

↑ Top

4. Exchange connection (Bitget)

If you choose to connect an exchange account (e.g. Bitget) by storing your API key, Taurax uses that key to fetch your trading data (positions, trade history, balance) directly from the exchange's own servers, on your behalf and only at your initiation. We recommend using read-only API keys. Exchanges such as Bitget are not necessarily based in the EU/EEA, so this may involve your data being processed outside the EU/EEA by the exchange itself — that processing is governed by the exchange's own privacy policy and terms, which we recommend you review separately. We do not sell or share this data with anyone else.

↑ Top

5. Hosting & service providers

↑ Top

6. Cookies & tracking

We use a single, technically necessary session cookie to keep you signed in (Art. 6(1)(f) GDPR). We do not use analytics, advertising, tracking pixels, or any third-party tracking cookies, and we do not send marketing emails.

↑ Top

7. Sharing of data

We do not sell your data. We only share data with the service providers named above — strictly to operate Taurax — where required by law, or where you've actively connected a third-party service yourself (e.g. your exchange).

↑ Top

8. Data retention

Account and journal data remain stored as long as your account exists. Nightly local backups are automatically deleted after 14 days; deleted data may therefore still exist in a local backup for up to 14 days. We may additionally keep encrypted off-site backup copies (encrypted before they ever leave the server) for disaster-recovery purposes, retained longer than 14 days. Server log files are cleared as part of routine log rotation. You can export or delete your journal data yourself at any time in the app (Settings → Import / Export, and Settings → Danger zone for account deletion).

↑ Top

9. Data security

The connection to the application is encrypted (HTTPS). Passwords are stored only as a hash. Exchange API keys are stored encrypted, separately from the database. Off-site backups, where enabled, are encrypted before they leave the server.

↑ Top

10. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). To exercise these rights, please contact the email address above. You also have the right to lodge a complaint with a data protection supervisory authority. You can export or delete your journal data yourself at any time in the app (Settings → Import / Export, and Settings → Danger zone for account deletion).

↑ Top

Last updated: July 2026

← Back to the app