Privacy Policy
Last updated · 23 June 2026
Introduction and scope
ARMA EDGE provides an independent, read-only verification and attribution layer for trading track records. We ingest broker-sourced trading history through read-only exchange connections and turn it into performance analytics, a binary Verified Track status, and an Edge Score (0 to 1000) with a letter grade. We are not an investment adviser, broker-dealer, exchange, or fund; we do not manage money, hold or move funds, place trades, or give investment advice.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have over it. It applies to traders who connect accounts, investors who browse published strategies, and visitors to our website. By using ARMA EDGE you agree to the practices described here.
Two commitments sit at the center of this policy and we restate them throughout: we never sell your personal data, and we never expose your exchange API credentials. Exchange connections are read-only; we reject any key that carries trade or withdrawal permissions.
- •Last updated: 23 June 2026.
- •Entity: ARMA EDGE — the operating entity and governing law are being finalized and will be specified in an update once confirmed.
- •Contact for all privacy and data requests: hello@armaedge.com.
Personal data we collect
We collect data that you provide directly, data generated when you use the service, and data we receive from the exchanges you connect. We aim to collect only what we need to operate, secure, and improve ARMA EDGE.
For read-only exchange connections, we store the API secret only as encrypted ciphertext. The secret is never displayed back to you and is never returned through our interfaces. The connection is read-only by design: keys with trade or withdrawal scope are rejected at connection time.
- •Account data: name, email address, password credentials (stored hashed), and account settings and preferences.
- •Exchange connection data: the exchange identifier, a label for the connection, the API key reference, and the API secret stored only as encrypted ciphertext. The secret is never returned.
- •Ingested trading history: broker-sourced records such as trades, fills, orders, positions, timestamps, instruments, and realized and unrealized performance figures used to compute analytics, Verified Track status, and the Edge Score.
- •Report and publishing data: generated reports, grades, scores, publication status, public share links you create, and unpublish actions.
- •Investor activity data: strategies you browse, saved items, and double opt-in introduction requests you submit.
- •Billing data: records of one-time Advanced report purchases (for example $19 per strategy). Payment card details are handled by our payment processor; we do not store full card numbers. Billing may be in free preview at launch.
- •Usage and device data: log data, IP address, browser and device type, operating system, pages viewed, and interactions with the service.
- •Cookies and similar technologies: identifiers used for authentication, security, preferences, and analytics, as described below.
- •Communications: messages you send to us, including support and legal or privacy requests.
Read-only exchange connections in detail
When you connect an exchange (Bybit today), you provide a read-only API key. We use this connection solely to ingest your historical trading data so we can produce analytics, a Verified Track status, and an Edge Score. We do not and technically cannot use these connections to place trades, move funds, or take custody of any assets. ARMA EDGE is non-custodial.
Your API secret is protected with envelope encryption: a per-record AES-GCM data key encrypts the secret, and that data key is itself wrapped by a key wrapper or key management service (KMS). Because of this design the plaintext secret is never stored, never logged, and never returned to you or any third party. You can disconnect a key at any time, which removes our ability to ingest further data from that connection.
How we use your data and our legal bases
We use personal data to deliver the verification and attribution service, to keep it secure, to comply with law, and to improve what we offer. Where data protection law requires a legal basis (such as the GDPR or UK GDPR), we rely on the bases listed below. The applicable basis depends on the specific processing activity.
We process trading history to generate analytics and scores; we process account and device data to authenticate you and protect the service; and we process limited contact data to respond to you and to send essential service messages.
- •Performance of a contract: to create and operate your account, ingest trading history, generate reports, scores and Verified Track status, and process Advanced report purchases.
- •Legitimate interests: to secure the platform, prevent fraud and abuse, maintain logs, debug, and improve and develop features, balanced against your rights.
- •Consent: for non-essential cookies and analytics where required, for publishing a report to a public link, and for double opt-in introductions. You may withdraw consent at any time.
- •Legal obligation: to meet tax, accounting, security, and other legal requirements.
Verification attests to history, not the future
Verification, the Verified Track status, and the Edge Score attest to the authenticity and integrity of historical, broker-sourced data as we received it. They are not a prediction, guarantee, endorsement, or recommendation of any trader or strategy, and they say nothing about future performance.
We do not endorse or recommend traders to investors. Investors remain responsible for their own decisions, and any introduction we facilitate is informational only.
How we share data
We never sell your personal data, and we never share your exchange API credentials with anyone. We share other personal data only in the limited circumstances described below, and only to the extent necessary.
By default, your reports are private. Data about a strategy becomes visible to others only through actions you take or services we must use to run the platform.
- •On publish: if you choose to publish a report, the information in that report and the associated grade and score become accessible through the public share link you generate. You can unpublish at any time, which disables the link going forward.
- •Double opt-in introductions: contact or profile details are shared between a trader and an investor only when both sides explicitly agree to the introduction.
- •Sub-processors and hosting: cloud hosting, storage, key management, analytics, email delivery, and payment processing providers that process data on our behalf under contractual confidentiality and security obligations.
- •Legal and safety: where required by law, legal process, or to protect the rights, safety, and security of ARMA EDGE, our users, or the public.
- •Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy and applicable law.
Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, to remember your preferences, to secure the service, and to understand how the product is used. Strictly necessary cookies are required for the site to function. Where the law requires it, we ask for your consent before setting non-essential analytics or preference cookies.
You can control cookies through your browser settings and, where offered, through our cookie controls. Disabling some cookies may affect how the service works.
International data transfers
ARMA EDGE serves a global audience, so your data may be processed in countries other than where you live, including by our sub-processors. Data protection laws in those countries may differ from those in your own.
Where we transfer personal data across borders from regions such as the European Economic Area or the United Kingdom, we put appropriate safeguards in place, for example standard contractual clauses or another lawful transfer mechanism, and we take steps to ensure your data remains protected to the standard described in this policy.
Data retention
We keep personal data only for as long as we need it for the purposes set out in this policy, after which we delete it or anonymize it. The exact period depends on the type of data and the reason we hold it.
When you disconnect an exchange key or close your account, we stop ingesting new data from that connection and begin removing data we no longer need, subject to limited legal and operational exceptions.
- •Account and connection data: kept while your account is active; the encrypted API secret is deleted when you disconnect the key or close your account.
- •Ingested trading history and reports: kept while needed to provide analytics and any published report, and deleted or anonymized after you delete the strategy or close your account.
- •Published report data: a public link stops working once you unpublish; cached or previously shared copies are outside our control.
- •Billing records: retained as required for tax, accounting, and audit obligations.
- •Logs and security data: retained for a limited period for security, debugging, and fraud prevention.
Security
We apply technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and loss. Data is encrypted in transit and at rest.
API secrets receive an additional layer of protection through envelope encryption: an AES-GCM data key encrypts each secret, and that data key is wrapped by a key wrapper or KMS. The plaintext secret is never stored, never logged, and never returned. Combined with the read-only requirement and our non-custodial model, this means a compromised report can never expose tradable credentials or move funds.
No method of transmission or storage is perfectly secure, but we work to protect your data and to detect and respond to incidents. If a breach affects your personal data and the law requires it, we will notify you and the relevant authorities.
Your rights
Depending on where you live, you have rights over your personal data under laws such as the GDPR, the UK GDPR, and CCPA-style frameworks. We honor these rights regardless of where you are located, subject to applicable law and reasonable verification of your identity.
To exercise any of these rights, contact us at hello@armaedge.com. We do not discriminate against you for exercising your privacy rights, and we will respond within the timeframes the law requires.
- •Access: obtain a copy of the personal data we hold about you.
- •Rectification: correct inaccurate or incomplete data.
- •Erasure: request deletion of your data, subject to legal exceptions.
- •Portability: receive certain data in a structured, machine-readable format.
- •Objection and restriction: object to or restrict certain processing, including processing based on legitimate interests.
- •Withdraw consent: withdraw consent at any time where processing relies on it, without affecting prior processing.
- •Disconnect keys and unpublish: disconnect any exchange API key and unpublish any report at any time directly in the product.
- •No sale and no sharing for cross-context advertising: we do not sell your personal data or share it for cross-context behavioral advertising.
- •Complaints: lodge a complaint with your local data protection authority.
Children's privacy
ARMA EDGE is intended only for adults aged 18 or older. The service is not directed to children, and we do not knowingly collect personal data from anyone under 18.
If we learn that we have collected personal data from a person under 18, we will delete it promptly. If you believe a minor has provided us data, please contact us at hello@armaedge.com.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our service, technology, or legal requirements. When we make material changes, we will update the date at the top and, where appropriate, provide additional notice.
Your continued use of ARMA EDGE after an update means you accept the revised policy. We encourage you to review it periodically.
Contact us
If you have questions about this Privacy Policy, want to exercise your data rights, or wish to raise a concern, please get in touch. We are the controller of the personal data described here, and we will route your request to the right team.
You can reach us for all legal, privacy, and data requests at hello@armaedge.com.