> For the complete documentation index, see [llms.txt](https://docs.tidelight.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tidelight.app/privacy-policy.md).

# Privacy Policy

This policy explains what Tidelight handles when you research markets, use the community, connect Bitget, or ask the Tide guide for help.

Privacy draft · October 10, 2026

## The short version

Research and account records are tied to your sign-in. Community posts and profiles are public; conversations are limited to participants. Your studio totals appear on your public profile only when you opt in. Connecting Bitget lets the server use encrypted credentials for the trading actions you authorize. Questions sent to AI features can be processed by external model providers.

## Scope

This policy covers the Tidelight website and its research, paper trading, live Bitget connection, and research community features. Third-party websites linked from Tidelight have their own privacy terms. Tidelight is a research product; Bitget is a separate exchange.

## Data we handle

* **Account and settings:** email, account identifier, authentication factors and events, profile name, handle, avatar, theme choice, research preferences, and session data. Google sign-in can provide account profile details when you use it.
* **Research and simulation:** questions, source URLs and passages, generated briefs, watchlists, backtests, paper positions, agent decisions, alerts, and related timestamps.
* **Community:** public posts, replies, reactions, follows, profile details, optional shared studio totals, uploaded media, reports and blocks. Direct messages and their metadata are visible to conversation participants and necessary service administrators, not publicly posted.
* **Trading connection:** Bitget API key, secret, passphrase, connection mode, order requests and responses, and security events. Credentials are encrypted on the server and are not returned in connection responses.
* **Support and technical data:** questions you submit to Tide, the current page context, recent chat context you send, request counts, and server logs needed for operation and abuse prevention. The support request budget records account and time; chat text is not written to its request-budget table.

## Why we use it

We use account data to sign you in and secure your workspace; research data to deliver briefs, simulations and history; community data to publish posts, deliver messages and enforce safety controls; and trading credentials only for the Bitget connection and orders you choose. We process technical records to operate, troubleshoot and protect the service. We do not represent AI generated material as verified fact or personalized investment advice.

## Providers and sharing

**Supabase** supports authentication, database records and media storage. **Vercel** hosts the application and processes requests. Research and support prompts may go to **Bitget’s Qwen gateway** or **Google Gemini** when configured; their handling is subject to their own terms. Market data and user-confirmed orders can be sent to **Bitget**. Public source URLs may be fetched from their publishers. An optional AgentKey research data connection, when enabled, may route selected research requests to AgentKey and its data providers. We do not claim these providers never retain prompts or use them for model training; check their policies before entering sensitive material.

Content you publish to the community is available to other visitors. We do not publish your Bitget credentials, private briefs, direct messages, account email, or trade balances as community content.

## Your privacy choices

You can manage your profile and research preferences in [Settings](/see-the-signal-between-sessions-12.md), remove watchlist entries in [Watchlist](/see-the-signal-between-sessions-7.md), and disconnect Bitget in [Trading](/see-the-signal-between-sessions-5.md). Public studio usage totals are off until you enable them on your [community profile](/see-the-signal-between-sessions-1.md). Turning them off hides the aggregate counts; it does not delete the underlying private activity. Be mindful that others may copy public posts before you remove them. Your browser stores local appearance preferences and essential sign-in state.

## Storage and security

Account-owned tables use access policies to separate users’ private records. Bitget credentials are encrypted before storage; the browser does not receive stored secrets back. Live orders require an explicit confirmation and a recent authenticator check. These controls reduce risk but cannot guarantee absolute security. Use a dedicated Bitget key with only the permissions needed, and revoke it in Bitget if you suspect exposure.

## Retention and deletion

We keep account-linked records while needed for the feature, security or applicable obligations. Individual watchlist entries, community posts and Bitget connections can be removed through their product controls. Deleting a post does not necessarily remove media that was already copied or cached elsewhere. A scheduled cleanup removes eligible community media no longer referenced by a post after seven days; this describes a cleanup rule, not a guarantee that all uploads disappear seven days after posting. Some authentication, security, backup and provider logs can remain for a limited period under their respective systems and obligations. There is currently no in-app account deletion or full export control; see the request guidance below.

## Your rights

Depending on where you live, you may ask to access, correct, export, object to or restrict processing of, or delete personal data, and raise a concern with your data protection authority. Nigerian users can consult the [Nigeria Data Protection Commission](https://ndpc.gov.ng/). You can make many corrections in Settings, and remove supported items in the relevant workspace. For a wider privacy request, use the project contact channel identified in the repository; do not post identity documents or private account details in a public issue. The project owner must publish a dedicated confidential contact channel before this policy is treated as final.

## Updates and contact

We may update this policy as features or providers change. The dated version above will be updated, and significant changes will be called out in the product. Tidelight’s verified legal entity and confidential privacy contact are pending owner publication. Until then, this document describes the product’s current data handling and should be reviewed before production use.

Also read the rules for using the desk. [Terms of Service ↗](/terms-of-service.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.tidelight.app/privacy-policy.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
