ORIN holds a trading journal. That is more revealing than most software gets to be about a person, so this policy is specific rather than general: it lists every category of data we hold, what each one is for, how long it stays, and who else can see it.
Three things are true and unusual enough to state before the detail. We set no advertising trackers, and the one analytics tool we use does not run until you say yes. We do not sell or share personal information, and never have. And we hold no third-party credentials of yours — ORIN pays for its own market data, so there is nothing of yours to keep.
01Who is responsible for your data
Autusus LLC, c/o ZenBusiness Inc., 5511 Parkcrest Drive, Suite 103, Austin, TX 78731, United States (“ORIN”, “we”) is the controller of the personal data described here. Requests, questions and complaints go to privacy@tryorin.xyz.
Data Protection Officer. We have not appointed one. Our processing does not meet the Article 37 GDPR thresholds — we carry out no large-scale systematic monitoring of individuals and process no special-category data. Privacy requests are handled directly by the operator.
EU and UK representatives. We are established outside the European Union and the United Kingdom and have not yet appointed representatives under Article 27 of the GDPR or of the UK GDPR. If we begin offering the Service to data subjects in those territories on an established basis, we will appoint representatives and name them here before doing so.
This policy covers the ORIN website and application. It does not cover third-party sites we link to, which have their own policies.
02What we collect
The table below is the complete set. Each row names the California statutory category alongside the plain description, so the CCPA disclosure and this policy are one document rather than two that can drift.
| What | Examples | CCPA category | Where it comes from |
|---|---|---|---|
| Identifiers | Email address, display name, account ID. | § 1798.140(v)(1)(A) — identifiers | You, at signup. |
| Authentication credentials | A salted hash of your password, session tokens. We never see or store your password itself. | § 1798.140(ae)(1)(D) — sensitive personal information | You, via our authentication provider. |
| Commercial information | Plan, billing period, subscription status, renewal date, payment history, Stripe customer identifier. | § 1798.140(v)(1)(D) — commercial information | You and Stripe. We never receive your card number. |
| Risk settings you enter | Self-declared account size, risk percentage, daily loss cap, strategy rules, default timeframe. | § 1798.140(v)(1)(B) — Cal. Civ. Code § 1798.80(e) personal information | You, in Settings. These are figures you type, not connected accounts. |
| Analysis records | Symbols analysed, timeframes, grades, computed evidence, price levels, risk plans, the candles the read was computed on. | § 1798.140(v)(1)(K) — inferences drawn from other information | Generated by the Service when you run an analysis. |
| Journal and decisions | Trades you record, entry, stop, size, dollar risk, outcome, adherence, and any notes you write. | § 1798.140(v)(1)(K) — inferences; and § 1798.80(e) | You, plus outcomes resolved from market data. |
| Watchlists and alerts | Instruments you follow, trigger levels, alert status. | § 1798.140(v)(1)(D) — commercial information | You. |
| Event log | Timestamped records of analyses created, decisions made, outcomes resolved. This is the dataset the calibration figures are computed from. | § 1798.140(v)(1)(K) — inferences | Generated by the Service as you use it. |
| Uploaded images | Chart screenshots you choose to upload. | § 1798.140(v)(1)(J) — audio, electronic, visual information | You. Today these are read in your browser and not uploaded to us. |
| Technical and log data | IP address, user agent, timestamps, request paths, error traces — generated by our hosting and database providers. | § 1798.140(v)(1)(F) — internet or network activity | Automatically, when you use the Service. |
| Correspondence | Emails you send us and our replies. | § 1798.140(v)(1)(A) — identifiers | You. |
We hold no API keys or credentials of yours for any third-party service. ORIN pays for its own market data and calls the provider itself, so there is nothing of yours to store — no column in our database, no field in our write path, and nothing kept in your browser.
What we do not collect. We do not collect payment card numbers, bank details, government identifiers, precise geolocation, biometric data, contacts, browsing history on other sites, or any special-category data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation). We do not buy personal data from data brokers and we do not enrich your profile from third-party sources.
Sensitive personal information. The only category of California “sensitive personal information” we handle is your account log-in credential. We use it solely to authenticate you. We do not use or disclose it to infer characteristics about you, so the right to limit its use under Civil Code § 1798.121 does not arise; you may nevertheless ask us about it at any time.
03Why we process it, and on what legal basis
If you are in the European Economic Area, the United Kingdom or Switzerland, the GDPR requires us to identify a lawful basis for each purpose. These are ours.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and running your account; letting you sign in from any device. | Identifiers, credentials. | Performance of a contract — Art. 6(1)(b). |
| Delivering the analysis product: running reads, storing your journal, watchlist and settings. | Risk settings, analysis records, journal, watchlists. | Performance of a contract — Art. 6(1)(b). |
| Taking payment, renewing subscriptions, issuing receipts, handling failed payments. | Identifiers, commercial information. | Performance of a contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c). |
| Enforcing usage allowances and preventing abuse of a metered, paid-for reasoning model. | Identifiers, usage counts, technical data. | Legitimate interests — Art. 6(1)(f): keeping the service economically viable and available to paying users. |
| Security: detecting unauthorised access, investigating incidents, keeping backups. | Technical and log data, identifiers. | Legitimate interests — Art. 6(1)(f): protecting the service and its users. Legal obligation where breach notification applies — Art. 6(1)(c). |
| Computing published calibration statistics in aggregate, de-identified form. | Event log, analysis records, resolved outcomes. | Legitimate interests — Art. 6(1)(f): publishing an honest record of how the product performs, which is the product’s central claim. See the balancing note below. |
| Diagnosing faults and improving the Service. | Technical and log data, error traces. | Legitimate interests — Art. 6(1)(f). |
| Service emails you cannot opt out of: confirmations, password resets, receipts, material changes to these documents, security notices. | Identifiers. | Performance of a contract — Art. 6(1)(b). |
| Optional emails: weekly performance report, outcome and alert notifications. | Identifiers, journal, alerts. | Consent — Art. 6(1)(a). Withdraw at any time in Settings, without affecting anything else. |
| Complying with law and responding to lawful requests; establishing or defending legal claims. | Any of the above, as strictly necessary. | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f). |
Balancing note on calibration. ORIN publishes how its own grades have actually resolved, including when that reads badly. Producing those figures requires the outcome of trades recorded by real users. We consider this a legitimate interest because the statistics are computed only in aggregate, are never published below a minimum sample size, cannot be traced back to an individual, and are the basis on which anyone can judge whether the product works. You may object to this processing at any time — see clause 8 — and we will exclude your records from the aggregate.
04Automated processing and profiling
ORIN is an automated system. It grades market instruments, computes price levels and produces written analysis without a human in the loop.
That automation is directed at a financial instrument, not at you. It does not evaluate your creditworthiness, employability, reliability, behaviour, location, or personal characteristics; it does not decide anything about you; and it produces no legal or similarly significant effect concerning you within the meaning of Article 22 of the GDPR. Nothing the Service computes changes your access to credit, insurance, employment, housing or any service.
The Service does compute statistics about your own decisions — for example how often you followed a grade versus overrode it, and how those choices resolved. Those figures are shown to you, are not used to make decisions about you, and are not shared with anyone.
We do not use personal data to build advertising profiles, and we do not sell or share it for cross-context behavioural advertising.
06International transfers
We are established in the United States and our infrastructure providers operate globally. If you are in the EEA, the UK or Switzerland, your personal data will be transferred to and processed in the United States and potentially other countries whose laws differ from your own.
Where we make such a transfer, we rely on one or more of:
- the European Commission’s Standard Contractual Clauses (Decision 2021/914), supplemented by the UK International Data Transfer Addendum and the Swiss equivalent;
- an adequacy decision, where one covers the recipient country or certification framework;
- for a provider certified under the EU–US Data Privacy Framework and its UK extension, that certification;
- where no other mechanism is available, your explicit consent or the necessity of the transfer for the performance of our contract with you (Art. 49).
We carry out a transfer risk assessment for each provider and apply supplementary measures — encryption in transit and at rest, access limited to what the provider needs — where the assessment calls for them. You may request a copy of the relevant safeguards from privacy@tryorin.xyz.
You can reduce the transfer surface yourself: we let you choose the region your database sits in where our provider offers one, and we will honour a request to host an account in a specific region where technically possible.
07How long we keep it
We keep personal data only as long as we need it, and we can say exactly how long.
| Data | Retention | Why |
|---|---|---|
| Account, profile and settings | For the life of the account, then deleted within 30 days of closure. | Needed to provide the Service; the 30 days lets you reverse an accidental closure. |
| Analyses, journal, watchlists, alerts | Until you delete them, or 30 days after account closure. | This is your trading record. We do not prune it on a timer — losing a year-old journal entry would defeat the purpose of keeping one. |
| Event log | Deleted with the account. Aggregate statistics already computed from it are irreversibly de-identified and are not deleted. | Once aggregated below the point of re-identification, the statistics are no longer personal data. Deleting them would corrupt a published record. |
| Billing and tax records | Seven years from the transaction. | Tax and accounting law. This is a legal obligation and survives an erasure request. |
| Security and access logs | Up to 90 days, longer where an investigation is open. | Incident detection and investigation. |
| Correspondence | Up to 24 months from the last message. | Continuity of support and defence of claims. |
| Backups | Rolling, overwritten within 35 days. | Disaster recovery. Deleted records persist in backups until the cycle overwrites them; they are not restored to live systems. |
08Your rights
Whoever and wherever you are, you can export everything we hold about you from Settings, at any time, in machine-readable JSON, without asking us and without limit. That is a product feature rather than a request process because a right that requires a formal request and a 30-day wait is a right most people never exercise.
If the GDPR or UK GDPR applies to you
You have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data (“right to be forgotten”), subject to our need to retain records the law requires us to keep;
- restrict processing while a dispute about accuracy or legitimate interests is resolved;
- portability — receive your data in a structured, commonly used, machine-readable format and transmit it elsewhere;
- object to processing based on legitimate interests, including the calibration processing described in clause 3;
- withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal;
- complain to your supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority for your country of residence. We would rather you came to us first, but you are not required to.
If you are a California resident
Under the CCPA as amended by the CPRA, you have the right to:
- know what personal information we have collected, the sources, the purposes, the categories disclosed, and the specific pieces of information;
- delete personal information we collected from you, subject to statutory exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information. We do neither, so there is nothing to opt out of — but we honour Global Privacy Control signals regardless, and a “Do Not Sell or Share My Personal Information” request sent to us will be recorded and confirmed;
- limit the use of sensitive personal information. We use it only to authenticate you, which is an exempt purpose, so the right does not arise here;
- non-discrimination — we will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights. We operate no financial incentive programme in exchange for personal information.
Authorised agents. You may use an authorised agent. We will ask for written proof of authorisation and may ask you to verify your identity directly.
Shine the Light. California Civil Code § 1798.83 lets residents request details of personal information shared with third parties for their direct marketing purposes. We share none, and this remains true each year.
If you live in another US state with a privacy law
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with comprehensive privacy statutes have broadly equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling with legal effects. We extend the rights described above to you regardless of which state you are in, and we do not carry out targeted advertising, sale or that kind of profiling in the first place. Where your state provides an appeal from a refused request, you may appeal to privacy@tryorin.xyz and, if still dissatisfied, to your state Attorney General.
How to exercise a right
Export and delete are available directly in Settings. For anything else, email privacy@tryorin.xyz from the address on your account. We will:
- acknowledge within 10 business days;
- respond substantively within 30 days (GDPR) or 45 days (US state laws), extendable once where the request is complex, with notice to you;
- verify your identity proportionately to the sensitivity of the request — usually by confirming control of the account email, never by asking for a government ID for a routine request;
- charge nothing, unless a request is manifestly unfounded or repetitive, in which case we will say so first.
You can download everything we hold and delete your account yourself, today, without emailing anyone. For anything else, write to us and we will answer within a month.
This summary is for readability. The numbered clause above it is what binds.
09Security
Concretely, and not as a list of adjectives:
- All traffic is encrypted in transit (TLS). Data is encrypted at rest by our database provider.
- Passwords are never stored or transmitted in plain text. Authentication is handled by a specialist provider; we never see your password.
- Every database table enforces row-level security, so a request can only ever return rows belonging to the authenticated user. This is enforced by the database itself rather than by application code, which means a bug in our code cannot expose another user’s records.
- The key that authorises payment-plan changes is held server-side only and is never present in anything your browser downloads.
- Access to production data is limited to the operator and used only to run and repair the Service.
- The event log is append-only: it cannot be silently rewritten, including by us.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights.
Report a vulnerability to security@tryorin.xyz. We will not pursue legal action against good-faith security research that respects user privacy, avoids service degradation, and gives us reasonable time to fix the issue before disclosure.
11Children
The Service is for adults. We do not knowingly collect personal data from anyone under 18, and the Terms of Service require you to be 18 or older. If you believe a minor has given us personal data, contact privacy@tryorin.xyz and we will delete it and close the account. We do not knowingly sell or share the personal information of consumers under 16 — and we do not sell or share anyone’s.
12Changes to this policy
We may update this policy. The effective date at the top always reflects the current version. Where a change materially affects how we use data you have already given us, we will give at least 30 days’ notice by email before it takes effect, and — where the law requires consent for the new use — we will ask for it rather than assume it from continued use.
13Contact
Autusus LLC, c/o ZenBusiness Inc., 5511 Parkcrest Drive, Suite 103, Austin, TX 78731, United States.
- Privacy, data rights and complaints: privacy@tryorin.xyz
- Security disclosures: security@tryorin.xyz
- Everything else: support@tryorin.xyz
If you are unhappy with our response you may complain to your supervisory authority (EEA/UK) or your state Attorney General (US). We would prefer you gave us the chance to fix it first.
Questions about this document go to legal@tryorin.xyz. The other documents in this set are listed here.