This Privacy Policy describes how xSignalFlow (“we,” “us,” or “our”) collects, uses, and shares information when you visit xsignalflow.com or use related services (the “Service”). It is meant to meet California Online Privacy Protection Act (CalOPPA) notice requirements and to explain our practices under other U.S. state privacy laws, including the California Consumer Privacy Act as amended by the CPRA (“CCPA”), to the extent they apply.
Use of the Service is also governed by our Terms & Conditions. Questions or privacy requests can be sent through our contact page.
1. Information we collect
We collect the following categories of information:
- Account information (members): email address, password hash, role and paid-access status, last login time, and preferences you set in Account (for example a chart URL template, email/Telegram/webhook notification settings, and starred picks).
- Security logs: IP address, browser user agent, and the email submitted on login or password-reset attempts, used to rate-limit abuse and ban attacking IPs.
- Usage and device data: pages viewed, referring URL, browser and device type, approximate location derived from IP, and a unique visitor identifier when analytics cookies are present (see Cookies below).
- Communications: messages you send us (for example DMs on X) and records of transactional or member emails we send you.
- Optional third-party links you enable: if you connect Telegram, we store your Telegram user id and username to add you to the members channel. If you configure a webhook, we store the HTTPS URL and message templates you provide so we can POST pick alerts to a destination you control.
We do not collect Social Security numbers, payment-card numbers on this site, precise geolocation, or biometric identifiers. Public self-serve signup is not offered; member accounts are created by us.
2. Cookies and similar technologies
We use a small number of first-party cookies and similar storage:
-
Session cookie (
PHPSESSID): set on page load so the site can keep you signed in, protect forms with a CSRF token, and show flash messages. It is HttpOnly, Secure, and SameSite=Lax, and expires after eight hours of idle time. This cookie is required for the Service to function. -
Analytics cookies (Matomo, hosted by us at sitelog.xsignalflow.com):
first-party cookies such as
_pk_idand_pk_sesthat help us count unique visitors and understand which public pages are used. They are not used to show you ads or to track you across unrelated websites. Admin pages are not tracked. - Local browser storage: some pages remember UI choices (for example feed layout density) in your browser’s localStorage or sessionStorage. That data stays on your device and is not sent to us as a cookie.
We do not use Google Analytics, advertising pixels, or other third-party marketing cookies. We do not sell cookie data. You can block or delete cookies in your browser; blocking the session cookie will prevent sign-in and some form submissions.
3. How we use information
We use the information above to:
- Operate, secure, and improve the Service;
- Authenticate members, prevent abuse, and protect accounts;
- Send password-reset and (if you opt in) member notification emails;
- Deliver optional Telegram or webhook alerts you enable;
- Understand aggregate traffic on public pages; and
- Comply with law and enforce our Terms.
4. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We do not disclose personal information to third parties for their own direct marketing.
We do use service providers who process information on our behalf:
- Hosting for xsignalflow.com and our analytics host (server and access logs);
- Resend, to deliver transactional and member-notification email;
- Telegram, if you choose to link alerts (your Telegram account and our bot/channel);
- A destination you name, if you enable webhooks (we POST pick payloads to the URL you provide).
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, sale, or similar transaction, subject to this Policy.
5. Retention
Account data is kept while your account is active and for a reasonable period after closure if needed for security or legal records. Login-attempt logs are purged on a rolling schedule. Session cookies expire as described above. Matomo visitor data is retained for our own analytics. Email and notification logs are kept long enough to operate and debug delivery.
6. Security
We use HTTPS, hashed passwords, HttpOnly session cookies, and access controls on admin tools. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
7. Your choices and California privacy rights
Depending on where you live, you may have the right to:
- Know what personal information we collect, use, and disclose;
- Access a copy of personal information we hold about you;
- Request correction of inaccurate information;
- Request deletion, subject to legal and operational exceptions;
- Opt out of sale or sharing of personal information (we do not sell or share); and
- Not be discriminated against for exercising these rights.
Members can update passwords, chart-link settings, and notification preferences in Account, and can unsubscribe from member emails via the link in those messages. For access, correction, or deletion of account or log data, contact us through the contact page and tell us which right you want to exercise. We may need to verify that the request comes from the account holder (for example by confirming control of the email on the account).
If we ever sold or shared personal information, we would provide a “Do Not Sell or Share My Personal Information” link and honor browser opt-out signals such as the Global Privacy Control. We do not do that today because we do not sell or share.
California’s “Shine the Light” law (Civil Code §1798.83) lets residents ask about personal information disclosed to third parties for those parties’ direct marketing. We do not make those disclosures.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe we have, contact us and we will delete it.
9. Changes
We may update this Policy from time to time. The “Last updated” date at the top of this page will change when we do. Material changes will be reflected here; continued use of the Service after an update means you should review the revised Policy.
10. Contact
Privacy questions and requests: contact page (we monitor DMs and mentions on X at @xSignalFlow).
Summary (not a substitute for the Policy above): We use a session cookie to run the site, self-hosted Matomo to see which public pages are used, and account data if you are a member. We do not run ads or sell your information. Use Account settings for notification choices, or contact us on X for access or deletion requests.