Privacy Policy

Last Updated: October 1, 2026

1. Overview

Welcome to ChartLense. Your privacy is a top priority for us. This Privacy Policy explains what information we collect, how we use and protect it, and your rights regarding your data. Our practices are designed to comply with applicable privacy law, including the General Data Protection Regulation (GDPR).

2. Our Service

ChartLense provides AI-powered visual analysis of trading charts through our website, browser extension, and mobile app. All the data we collect and process is strictly necessary to fulfill this core function.

3. Information We Collect and How We Use It

a. Screenshot Data

When you choose, capture, or share a trading-chart image, that image is the primary data we process. On mobile, access to your camera or photo library is requested only when you choose that feature. We use the image exclusively to provide the AI analysis you requested.

b. Account and Usage Information

  • **Account Information:** When you create an account using Google Firebase Authentication, we collect your email address for authentication and communication purposes.
  • **Payment Information:** If you subscribe to a paid plan, our payment processor, Stripe (as Merchant of Record via Managed Payments), will collect and process your payment information. We do not store your full credit card details.
  • **Usage Data:** We collect data about your interactions with our service, such as the number of analyses you perform, to manage your quota and improve our service.
  • **Newsletter Subscription:** If you subscribe to our Weekly Market Flow Report newsletter, we collect your email address for the purpose of delivering the newsletter. This is separate from account registration — no account is required to subscribe. The legal basis for this processing is your explicit consent (GDPR Art. 6(1)(a)), given by checking the consent box on the subscription form.

c. Technical and Interaction Data

Extension context: When you use the browser extension, it may read the active page URL to determine whether it can capture a chart. We do not use this to build a browsing history. The mobile app does not access browser tabs or URLs.

User Interaction: We process your click on the "Analyze" button to initiate the chart analysis. We do not monitor other user activities like mouse movements or keyboard input.

d. Cookies and Analytics

We use cookies and similar technologies to improve your browsing experience and understand how our website is used. Here's what we use:

  • Essential Cookies: Required for basic website functionality, including the cookie consent banner (CookieYes).
  • Analytics Cookies: Google Analytics (GA4) helps us understand how visitors use our site. We anonymize IP addresses and only activate analytics after you consent. You can manage your preferences using the cookie banner.

You can change your cookie preferences at any time by clicking the cookie icon in the bottom corner of our website or by managing your browser settings.

4. Disclosure to Third Parties

To provide our service, we need to share your screenshot data with a few trusted third-party service providers. We have carefully vetted these providers to ensure they meet our strict privacy and security standards.

  • **Cloudflare, Inc.:** We use Cloudflare as a secure proxy to process and route your requests. Your screenshot data passes through Cloudflare's network on its way to the AI provider.
  • **Google (Gemini):** We send your screenshot to Google, which performs the visual analysis and returns the result to us.
  • **OpenAI:** If you use a custom prompt, its text (never your screenshot) is checked by OpenAI's moderation service.
  • **Stripe:** We use Stripe as our Merchant of Record for payment processing and subscription management via Stripe Managed Payments. Stripe handles all payment transactions, tax calculation and remittance, fraud prevention, dispute management, and refund processing on our behalf. When you make a purchase, Stripe collects and processes your payment information in accordance with their privacy policy and GDPR requirements.
  • **Google Firebase:** We use Firebase Authentication for secure account creation and management. This service securely handles your login credentials.
  • **Brevo (formerly Sendinblue):** We use Brevo as our email marketing platform to manage newsletter subscriptions and deliver the Weekly Market Flow Report. When you subscribe, your email address is shared with Brevo for this purpose. Brevo processes your data in accordance with their privacy policy and GDPR requirements.

We do not sell, rent, or share your personal information with any other third parties for their own marketing purposes.

5. Data Retention and Human Access

a. Data Retention

Screenshots are deleted immediately after analysis. Screenshots you save to your Trading Journal are kept until you delete the entry or your account. Our AI provider retains data for abuse monitoring:

  • Google logs requests for a limited period, solely to detect policy violations.
  • Your account information and usage data are retained for as long as your account is active and for a maximum of 36 months after your last activity to comply with legal obligations.
  • Newsletter subscriber email addresses are retained for as long as the subscription is active. You can unsubscribe at any time using the link in any newsletter email, after which your data is removed from our mailing list within 30 days.

b. Human Access to Data

We have a strict policy prohibiting human access to your data. The only exceptions are:

  • When it is necessary for security purposes, such as investigating abuse.
  • To comply with applicable laws.
  • When you give us your explicit consent to access your data to resolve a technical issue.

6. Browser Extension Data

Where the browser extension receives information from Google APIs, its use and transfer to other apps adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. This section applies to the browser extension and does not grant the mobile app access to your browser data.

7. Your Rights Under GDPR

Under the GDPR, you have the following rights:

  • Right to access your personal data
  • Right to rectification of incorrect data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.

8. Security

We are committed to protecting your data. We use commercially acceptable means to protect your personal data against unauthorized access or alteration, including:

  • Encryption of all data in transit using SSL/TLS.
  • Secure storage of your account information.
  • Regular security assessments of our systems.
  • Strict access controls and authentication measures.

9. Changes to This Policy

We may update our privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date at the top.

10. Contact Us

If you have any questions or concerns about your privacy, you can contact our Data Protection Officer at [email protected].

11. Data Controller

The data controller responsible for the processing of your personal data is Kolmira UG (haftungsbeschränkt).

For complete company details and contact information, please see our Imprint.