NuxGrid Privacy

Privacy

Data controller

The data processing described here is carried out by the NuxGrid publisher to provide, secure and administer the service. For any request concerning your data, use the Support feature available from your NuxGrid account.

Data used

NuxGrid uses the login identifier, password hash, account role, account status, and creation and last-login dates.

To create a standard account, the form currently requests only a username and password. NuxGrid does not require an identity document, postal address, telephone number or email address.

The server retains only the metadata needed for connector operation: the name chosen by the user, public key, status, version, synchronization activity and desired strategy configuration. The machine hostname is not used.

The desired configuration may describe the trading strategy (market, amount, spacing, profit target and associated options), but does not contain exchange secret keys, available capital or executed orders.

For login attempts recorded by the application, the IP address is replaced with a technical fingerprint to limit abuse. Security logs may be retained for as long as needed for their purpose.

Orders, capital and trading data

The connector’s local database is the source of truth for orders, executions, balances, available capital, metrics and trading events. This data is not stored permanently in NuxGrid server operational tables.

To display the dashboard, the server may relay a snapshot requested by the browser. This snapshot may contain the orders, metrics and capital needed for display, but the technical relay record is deleted after consumption and is not used as a server-side history.

The browser may locally retain the latest snapshot in IndexedDB to display the dashboard when the connector is temporarily unavailable. This storage remains under the user’s control and can be deleted through the browser’s site data.

Exchange security and secrets

Exchange keys are encrypted in the browser before transmission. The server never receives the values in plaintext; the encrypted envelope may be temporarily relayed to the connector and its contents are erased after validation or revocation.

After validation, usable keys are installed locally on the connector. They are not included in metric or order synchronizations.

Account passwords are stored as hashes and are not kept in plaintext.

Purposes and legal bases

This data is used to create and administer accounts, authenticate users, secure connections, limit abusive attempts, synchronize connectors, display the console and retain the records needed to administer it.

Depending on the purpose, processing is based on performing the requested service, applicable legal obligations, or the legitimate interest related to security and abuse prevention.

Recipients and third-party services

Data is accessible only to people authorized to administer NuxGrid and providers needed for its operation, notably the IONOS host.

When the user configures a connector or an exchange, strictly necessary data may be transmitted to the explicitly configured device and, for real orders, to the exchange selected by the user. No public or advertising-related sharing is planned.

Sharing between accounts is optional and limited to the active positions needed for the shared view. It does not turn the server into an archive of orders or balances.

Cookies and trackers

The application uses a session cookie strictly necessary for authentication and session maintenance. It is deleted when the session closes or expires.

NuxGrid currently uses no advertising cookie, profiling tool or audience measurement tool requiring consent.

Retention and requests

Accounts, connector metadata, configurations and associated data are retained for as long as necessary to operate the service, ensure security and comply with applicable obligations. Trading orders, balances and metrics remain in the connector’s local storage and, where applicable, the browser’s local storage.

Dashboard snapshots relayed by the server are temporary transport data: they are deleted after reading or expiration. They do not constitute a durable server-side history.

Old login attempts are automatically purged after two days. Other logs are retained for as long as necessary for their purpose or to defend rights.

For a request for access, rectification, erasure, restriction or objection, use the Support feature from your NuxGrid account.

Your rights

Under the conditions provided by applicable regulations, you may request access, rectification, erasure or restriction of processing, object to certain processing and recover your data where the right to portability applies.

To exercise your rights, use the Support feature in your NuxGrid account. You may also lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL).

NuxGrid © 2026