1. What we collect
This platform is designed as a privacy-first market intelligence tool. We do not require an account, email, or any personal identifier to browse or use the core features. Because there is no server-side user database, we do not collect names, addresses, or payment information.
- Watchlist and preferences — stored entirely in your browser's localStorage (see §3). We never see them.
- API keys you choose to paste — held in server memory for the current process only (see §4).
- Technical logs — standard server logs (IP address, timestamp, requested paths) that any Node server produces for operations and security.
2. How we use your data
The limited data above is used solely to operate, secure, and improve the platform — for example, serving requested pages, honoring your locally-saved API keys, diagnosing errors, and preventing abuse. We do not sell your data, build advertising profiles, or share it with third parties for marketing.
3. Local storage
The following are stored only in your own browser using the Web Storage API and never transmitted to us unless you
explicitly act (e.g., pasting a key): your Gmail for alerts, your saved watchlist, and your chosen theme.
You can clear all of it at any time via your browser's "Clear site data" option, or by removing the individual
pgmia_* localStorage keys. We have no server-side copy of this data.
4. API keys
When you paste a free API key (e.g., Twelve Data, GNews, CoinGecko) on the Profile page, it is sent to the server
and held in memory only so the live features can call that provider. It is never stored to disk, never logged
in plaintext in our code base, and is lost the moment the server process restarts. Environment-variable keys set on
the server (.env) take priority and their values are never displayed.
5. Third-party data providers
To show live market data, news, and economic events, we call public APIs and RSS feeds from third parties (Binance, Frankfurter/ECB, gold-api, Twelve Data, GNews, CoinGecko, Yahoo Finance RSS, and others). When these providers are reached, your IP address is transmitted to them as part of a standard network request, subject to their own privacy policies. We do not control their data handling. Google Fonts is loaded for typography; your browser contacts Google's servers to fetch font files.
6. Cookies & analytics
This platform does not use advertising cookies, cross-site tracking, or third-party analytics scripts. The only persistence mechanisms are browser localStorage (preferences above) and, for theme preference, the same localStorage. No advertising or marketing cookies are set.
7. Data security & retention
We apply reasonable technical safeguards appropriate to the data handled. API keys are kept in memory (not on disk) and cleared on restart. Server logs are retained only as long as needed for operations/security and then purged. Because we are largely stateless, there is very little to retain or delete.
8. Your rights
Depending on your jurisdiction (e.g., GDPR in the EU/UK, CCPA in California, DPDP in India), you may have rights to access, correct, or delete personal data. Since we hold no personal account data server-side, exercising these rights typically means clearing your browser's local site data. For anything else, contact us (see §11).
9. Children's privacy
This platform is a professional financial-information tool and is not directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided data, contact us to have it removed.
10. Changes to this policy
We may update this policy from time to time. The "Effective date" at the top of this page reflects the latest revision. Material changes will be noted here. Continued use of the platform after changes constitutes acceptance of the revised policy.
11. Contact
Questions about this policy or your data can be directed through the platform's support channel, or the email you save in your Profile for alerts. We will respond as promptly as possible.