Privacy policy
Last updated 5 August 2026. This page describes exactly what this site stores about you, why, and how to get rid of it. It is written from the code that runs, not from a template.
The short version
Without an account, this site stores nothing about you beyond the standard web-server log described below. There is no analytics tool, no advertising network, no tracking pixel and no third-party script of any kind — every font, icon and stylesheet is served from this domain.
With an account, it stores what you type in: your sign-in identity and the crypto positions you choose to declare. Those positions are declarative figures in a database. This site never connects to an exchange, a wallet or a bank, holds no funds, and cannot place an order.
What is stored
If you never sign in
- Server log. Like every web server, this one records each request: IP address, date, the page requested, the referring page and your browser's user-agent string. It is written by the hosting platform and used for security and diagnosis only.
- A usage event. We record that a visit happened, and which asset pages were opened. Each record holds the event name, the time, and a random visit identifier that lives only as long as your browser session. It carries no IP address, no user-agent, no page URL and no click tracking, and it cannot be traced back to you or joined to any other site.
If you have an account
- Identity — a username, a display name, and an email address. If you signed in with Google, we receive and store your email address, your display name and Google's stable account identifier. We never receive your Google password, and we ask Google for nothing beyond those three items.
- A password hash, only if you set a password. It is hashed, never stored or storable in readable form. Accounts created through Google have no password at all.
- The date of your last sign-in, and the date the account was created.
- Your declared positions — the assets and quantities you enter yourself, and the value history computed from them.
- The proposals generated for you, if you use the strategy feature, along with the portfolio snapshot each one answered.
- A short list of product events — signing up, signing in, first declaring a portfolio, changing it, opening an asset page, generating a proposal, accepting one. Each record holds the event name, the time, your account identifier and your plan at that moment. We keep these because we need to know whether the product is actually used and whether people come back — questions the site could not answer before. They are never used to profile you, to score you, or to change what the analysis tells you.
That is the whole list. There is no profiling, no behavioural scoring, and no attempt to identify you across other sites. We deliberately do not record your IP address, your browser, the full URL of the pages you open, or anything you click inside a page.
When the site operator views an account in support mode, nothing is recorded at all — that browsing would otherwise be counted as your activity.
Why, and on what basis
- Identity and password hash — to let you sign in and to keep your data separate from anyone else's. Necessary to provide the service you asked for (contract).
- Declared positions and generated proposals — they are the service. Without them there is nothing to analyse.
- Email address — to identify your account and to send a password-reset link if you ask for one. It is not used for marketing; this site sends no newsletter and no promotional message.
- Server log — security and troubleshooting (legitimate interest).
Who else sees it
Nothing is sold, rented or shared for advertising. Three third parties are involved, each for one purpose:
- Google — only if you choose « Continue with Google ». Google tells us your email address, display name and account identifier; Google learns that you signed in to this site. Google privacy policy.
- OpenRouter — when you generate a strategy proposal, the composition of the selected lines (asset names, quantities, values and computed figures) is sent through OpenRouter so a language model can propose a reallocation. OpenRouter routes the request to the model provider we have configured, currently Google ; the provider may change, and this page is updated when it does. Your name, email address and account identifier are never included ; the request carries figures, not an identity. OpenRouter privacy policy.
- The hosting provider — which necessarily processes the server log and the database on our behalf.
Market data (prices, candles, derivatives) is fetched by scheduled server-side jobs. Those requests carry no information about you, and your browser never contacts an exchange.
The site operator
The person who runs this site can read your account in the database, and can open your pages as you see them, for support and administration. Two limits apply to that, and they are enforced in code rather than promised here: the session is read-only — nothing about your account can be changed, and no billable action can be triggered, while it is being viewed — and every such view is written to a server-side log with the date, the administrator and the account concerned.
Cookies and tracking
This site sets one cookie: GLOPPRSESS, which
holds your session. It is created on your first page, before any sign-in —
this page previously said it appeared only after signing in, which was
inaccurate and is corrected here. It is
HttpOnly, Secure and SameSite=Lax,
it expires when you close your browser, and it contains no personal data —
only a random session identifier. It is strictly necessary for the site to
work, which is why no consent banner is shown.
Two things are kept in your browser's local storage : your light/dark theme choice, and the date on which you were last shown the invitation to our Telegram channel — so that it appears at most once a day. Neither leaves your device, and neither is ever sent to the server. Clearing your browser data removes both.
There are no analytics, advertising or social cookies, because there are no third-party scripts at all.
How long
- Account data and positions — until you ask for the account to be deleted.
- Server log — rotated by the hosting platform; kept for a matter of weeks, for security purposes only.
- Product events — kept while they are useful for measuring how the product is used. Those attached to an account are deleted with the account; those from anonymous visits carry nothing that identifies anyone.
Your rights
If you are in the European Union or the United Kingdom, the GDPR gives you the right to access your data, correct it, have it deleted, obtain a portable copy, and object to processing. Similar rights exist in several other jurisdictions.
Write to the address below and it will be handled. Deleting the account removes the identity, the declared positions and the generated proposals. You may also lodge a complaint with your national supervisory authority — in France, the CNIL.
Contact
For anything on this page — access, deletion, a question, a mistake you have spotted — write to the Gloppr Team at contact@alldigital.online.
See also the terms of use, which set out what this site does and — importantly — what it is not.