Privacy Policy
Last Updated: November 12, 2025
BlueGold ("we," "our," or "us") provides an AI-powered financial trading companion. This Privacy Policy explains how we collect, use, protect, and share your information when you use our Service. By using BlueGold, you agree to the practices described in this Policy.
1. Information We Collect
Account Information: When you create an account, we collect your email address and authentication data through Supabase Auth. If you sign in with Google OAuth, we receive basic profile information from your Google account.
Financial and Portfolio Data: We collect and store information about your portfolios, including positions, transactions, portfolio values, and performance metrics. This data is essential for providing our core trading and analytics services.
Trading Agent Data: We store AI trading agent configurations, chat history with agents, strategy parameters, and agent performance data to deliver our AI-powered trading features.
Usage and Analytics: We collect usage data through Google Analytics and Datadog browser logs, including pages visited, features used, device information, and interaction patterns to improve our Service.
Payment Information: Payment processing is handled by Stripe. We do not store your credit card details; Stripe securely processes all payment information according to PCI compliance standards.
2. How We Use Your Information
We use your information to provide, maintain, and improve BlueGold's services:
- Provide portfolio tracking, analytics, and performance monitoring
- Power AI trading agents and deliver personalized trading strategies
- Fetch real-time and historical market data for your assets
- Process subscription payments and manage your account
- Display your portfolio on the leaderboard (with your permission)
- Analyze usage patterns to improve features and user experience
- Send important service updates and security notifications
- Comply with legal obligations and prevent fraudulent activity
3. Third-Party Services and Data Sharing
BlueGold integrates with third-party services to deliver our platform. Your data may be shared with:
Alpaca Markets: We use Alpaca's API to fetch real-time market data, historical price data, and execute trades (if you connect your trading account). Your portfolio and trading activity data is transmitted to Alpaca in accordance with their privacy policy.
Supabase: Our database and authentication provider. All user account data, portfolio information, and application data is stored in Supabase's PostgreSQL database with encryption at rest and in transit.
Stripe: Payment processor for subscription billing. Stripe handles all payment information according to PCI DSS standards. We receive limited information such as subscription status and payment method type.
Google Analytics & Datadog: Analytics and monitoring services that collect anonymized usage data, performance metrics, and error logs to help us improve the Service.
LLM Providers: AI trading agent conversations may be sent to various LLM providers (configured per agent) to generate trading insights and decisions. These providers process chat data according to their respective privacy policies.
We do not sell your personal information to third parties. We only share data as necessary to provide our services or as required by law.
4. Your Rights and Data Security
Your Rights: You have the right to access, update, or delete your personal information. You can manage your account settings, portfolio data, and trading agents through the dashboard. To request account deletion or data export, please contact us through our Discord community or social media channels.
Data Security: We implement industry-standard security measures to protect your data, including:
- Encryption of data in transit (HTTPS/TLS) and at rest
- Secure authentication via Supabase Auth with OAuth
- Regular security audits and monitoring via Datadog
- Limited access controls and employee data access
- Secure API integrations with financial data providers
Data Retention: We retain your data for as long as your account is active or as needed to provide services. When you delete your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain data for legal or regulatory purposes.
Policy Updates: We may update this Privacy Policy from time to time. Continued use of the Service after changes constitutes acceptance of the updated Policy. We will notify users of material changes via email or through the platform.
For privacy-related questions or to exercise your data rights, please contact us via our Discord community or social media channels.
