The Market Robo™

trade-hub Privacy Notice

Version v1-2026-09-27 · Effective 10/27/2026

Who we are

trade-hub is operated by TMKR Global, LLC ("we", "us"), Georgia, Tbilisi, Nadzaladevi district, Kursebi street, N 15. We decide why and how your personal data is processed in trade-hub: under the GDPR we are its controller. You sign in to trade-hub with the same account you use across TheMarketRobo; the platform notice describes that account.

Privacy contact: privacy@themarketrobo.com. This mailbox handles privacy requests only, and it is separate from customer support. We log each request on the day it arrives. For requests about your own data, we answer within one month of receipt, as the GDPR requires.

What this notice covers

This notice covers trade-hub's web app (trade.themarketrobo.com), its API (trade.themarketrobo.xyz), and the MCP connection through which you can let an AI assistant of your choice work with your trade-hub data.

What we collect

•

Your account. You sign in with your TheMarketRobo account, which is held by Amazon Web Services' identity service. trade-hub keeps your user id, e-mail address and username.

•

Your trading work. This is the content you create; see "User-authored content" below.

•

Your credits, wallet and purchases inside trade-hub, and your marketplace listings and orders.

•

Records of what happens in your account. Every request to our servers is recorded in an access log. The record holds the time, the route (never the data you sent), the result, how long it took, a request identifier, your IP address, your browser's user agent, and a pseudonymous reference to your account. We also keep:

◦

an application log of errors and events (never request bodies);

◦

a security log of sign-in and authorisation outcomes;

◦

an audit log of the actions you take on documents, credits, the marketplace and your AI connections.

The audit log records the real IP address and user agent of each audited action, for the audit retention below.

•

Errors in your browser. When the trade-hub web app hits an error, it sends an error report to Sentry. Before the report leaves your browser it is scrubbed of personal data, and addresses are reduced to route patterns. We do this under our legitimate interest in keeping the product working. The web app runs no analytics, session replay or performance tracking. If we add any, we will ask for your consent first, and we will never run it while your browser sends a Global Privacy Control signal.

•

What trade-hub keeps in your browser (preferences and drafts). It is stored under your account and cleared when you sign out.

User-authored content

This is the content you write or build in trade-hub:

•

strategies, signals, filters, order and deal-stage documents;

•

indicators and the alert sounds you upload;

•

modules you share, and the products you compile;

•

marketplace listings;

•

your conversations with the AI Strategy Builder.

How long we keep it. Your documents are yours. We keep them for as long as your account exists, and erase or de-identify them when you delete your account or ask us to erase it. The exceptions are:

•

AI Strategy Builder conversations. Your prose, the builder's replies, drafts and plans are de-identified 30 days after the conversation was last used. The conversation record stays, empty of its content. Your conversations are also erased with your account.

•

Marketplace listings that buyers have bought stay visible to those buyers, because their licences still name the product.

•

Compiled products. Their file names, and alert sounds embedded in products you compiled, stay with the compiled product.

•

Audit records of your actions survive erasure with your identity pseudonymised. The law requires us to keep an accountable record of financial and administrative actions (see the table below).

AI inference and training

The AI Strategy Builder sends the prose you write and the conversation it belongs to to an external AI inference provider, and returns the provider's answer to you. Today that provider is Groq, Inc. (United States), running the model gpt-oss-120b. The provider is not permitted to use your content to train its models, and we choose providers whose terms say so. If we change provider, we will update this notice before the change takes effect.

We keep an operational log of each AI request: its timing, the model used, the outcome and the token count. The log never includes your prose, and we keep it for 183 days.

Our engineers use an AI coding assistant, Anthropic's Claude, to investigate incidents. It reads our logs through a tier that carries no name, e-mail address or IP address, only pseudonymous references and request identifiers. That content is not used to train Anthropic's models.

You can also connect your own AI assistant through trade-hub's MCP connection. The data you allow that assistant to read then goes to its provider, under your agreement with them.

Who processes your data for us

•

Hetzner (Germany) hosts our servers and databases, where trade-hub's data and every log line are first written. The disk of trade-hub's server is not yet encrypted at rest. Access to it is limited to named operators using individual keys. Full-disk encryption is planned.

•

Cloudflare (USA; storage in the EU) handles every connection to our servers, and keeps the primary copy of our log archive in its EU storage region.

•

Amazon Web Services (AWS, Ireland) holds your sign-in account and the second copy of our log archive, and sends our e-mail.

•

Grafana Labs (USA; our data is stored in Frankfurt, Germany) keeps our searchable logs and metrics and runs our alerting.

•

Sentry (USA; our data is stored in Frankfurt, Germany) receives the scrubbed error reports.

•

Vercel (USA) hosts the trade-hub web app and keeps its short-lived runtime logs.

•

GitHub (USA) hosts our source code and our build and release records. By rule, your personal data does not go there.

•

Groq (USA) answers AI Strategy Builder requests (see above).

•

Anthropic (USA) provides the AI assistant our engineers use (see above).

•

healthchecks.io alerts us when a scheduled job stops running. It receives no personal data.

•

Telegram carries our alert messages to the on-call engineer. It receives no personal data.

How long we keep logs and records

"Searchable" means our engineers can search the record in our hot log store. "Archive" is the sealed, locked copy we keep for accountability and investigations, stored in two separate places. After the stated period a record is deleted.

ClassWhat it holdsSearchableArchiveWhy we keep it
Class

access

What it holds

Request log: time, route, result, duration, request id, IP address, user agent, pseudonymous account reference

Searchable

14 days

Archive

348 days; the IP address is replaced by a salted hash after 14 days

Why we keep it

Security and service delivery: legitimate interest (GDPR Art 6(1)(f), Recital 49)

Class

app

What it holds

Application and error log, never request bodies

Searchable

14 days

Archive

348 days

Why we keep it

Running and fixing the service: legitimate interest

Class

security

What it holds

Sign-in, authorisation and signature outcomes

Searchable

30 days

Archive

713 days; the person is pseudonymised after 30 days

Why we keep it

Security, and establishing or defending legal claims

Class

audit

What it holds

Ledgers and administrative decisions: documents, credits, marketplace, account actions

Searchable

90 days

Archive

2540 days (about seven years), de-identified before it is locked; kept after erasure

Why we keep it

Accountability and the financial-records period (GDPR Art 5(2), 24, 32, 17(3)(b))

Class

evidence

What it holds

Evidence of a security incident

Searchable

for the incident

Archive

Kept indefinitely under legal hold, reduced to counts and categories of the people affected

Why we keep it

Documenting a personal-data breach (GDPR Art 33(5))

Class

ai-ops

What it holds

AI request log: timing, model, outcome, token counts — never your prose

Searchable

30 days

Archive

183 days

Why we keep it

Operational logging of AI systems (EU AI Act Art 12)

Class

ai-content

What it holds

Your AI Strategy Builder conversations

Searchable

30 days

Archive

not archived; de-identified 30 days after last use, erased with your account

Why we keep it

Keeping it no longer than needed (GDPR Art 5(1)(e))

Class

debug

What it holds

Diagnostic output that could contain personal data

Searchable

7 days

Archive

not archived

Why we keep it

We try not to capture it at all

Class

metrics

What it holds

Counts and timings with no identifiers

Searchable

counts only

Archive

not archived; kept indefinitely, as counts are not personal data

Why we keep it

Operating the service

Class

deploy

What it holds

Records of our software releases

Searchable

—

Archive

2557 days (seven years)

Why we keep it

Accountability (GDPR Art 5(2))

Class

browser-storage

What it holds

What trade-hub keeps in your browser

Searchable

until you sign out

Archive

not archived; cleared when you sign out

Why we keep it

Scoped to your account

International transfers

Your data is stored in the European Union: in Germany (Hetzner, Grafana Labs, Sentry) and in Ireland (AWS), and our log archive is held in Cloudflare's EU storage region. Some providers are companies based in the United States, so they may access or process data from there: Cloudflare, Vercel, GitHub, Grafana Labs, Sentry, Groq and Anthropic. Where that happens, we rely on the European Commission's Standard Contractual Clauses, or on the EU–US Data Privacy Framework where the provider is certified. Our company is registered in Georgia.

Your rights

Everyone. You can ask us to:

•

give you a copy of your data;

•

correct it;

•

erase it;

•

restrict or object to our use of it;

•

move it to another service.

Write to privacy@themarketrobo.com. You can also delete your account yourself in the app.

European Union and United Kingdom (GDPR and UK GDPR). You may complain to your local data-protection authority. Where we rely on legitimate interest, you have the right to object.

California (CCPA / CPRA). You have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and not to be discriminated against for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

Australia (Australian Privacy Act 1988 and the Australian Privacy Principles). You may access and correct your personal information. We disclose personal information to the overseas recipients named above, in the United States, the European Union and Georgia (APP 8). You may complain to us first; if you are not satisfied, you may complain to the Office of the Australian Information Commissioner.

Changes to this notice

When we change this notice, we publish a new version. It shows its own version number and effective date, both taken from our document records. Before a material change takes effect, we will tell you by e-mail or in the app.