Privacy Policy

Last reviewed

This policy explains what personal data StakeBible processes when you visit stakebible.com or use an account, why we process it, on what legal basis, for how long, and what rights you have under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

In short:

  • We process what an account needs in order to work (your email address, a password hash and what you choose to enter), plus the technical data needed to keep the site secure.
  • Our pages run no advertising, no analytics, no tracking pixels and no third-party scripts.
  • We don't sell your data, and we never send it to language models.
  • We never hold your funds and never ask for exchange keys.

1. Who is responsible for your data

The controller of your personal data is PREDICTIVE CAPITAL AI LABS S.R.L., a Romanian company registered with the National Trade Register Office (ONRC) under number J2026056423004 (tax identification code 55656798), which operates StakeBible.

For any question about this policy or your data, write to support@stakebible.com.

2. What we process, why, and on what legal basis

Visiting the site

When you open a page, your browser sends your IP address and technical details such as the page requested and your browser identification string (the "user agent"). Our web server records these in its logs.

  • Why: to deliver the pages, keep the site secure and investigate problems.
  • Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).

Your account

When you create an account, we store:

  • your email address;
  • your password, only as a bcrypt hash, which cannot be turned back into the password;
  • your display name, if you give one; the language of the site and of our emails; and the avatar you pick from our own drawings (we don't accept photo uploads);
  • when the account was created, when your email address was confirmed and when you last signed in.

When we email you a link to confirm your address or to reset your password, we store only a SHA-256 fingerprint of the link's code, when it expires (48 hours for a confirmation link, 30 minutes for a reset link) and the IP address from which it was requested.

  • Why: to create and run your account and keep it secure.
  • Legal basis: performance of our contract with you (Art. 6(1)(b)); our legitimate interest in account security (Art. 6(1)(f)).

Staying signed in

We use two cookies to keep you signed in (see section 3). In our database, each session is recorded with a SHA-256 fingerprint of its renewal token (never the token itself), when it was created, last used and ends, why it was ended, and the IP address and browser identification string at the moment it was opened or renewed. A new record is written each time your session is renewed.

When you change your password or use "Log out everywhere", we also keep a marker in a memory store (Redis) that blocks the access tokens already issued. It is deleted automatically after 15 minutes.

  • Why: to keep you signed in, to let you end all your sessions at once, and to detect a stolen session.
  • Legal basis: performance of our contract with you (Art. 6(1)(b)); our legitimate interest in account security (Art. 6(1)(f)).

Security and abuse prevention

  • Our web server limits how many requests each IP address can make and keeps these counters in memory.
  • For sign-in, registration, password reset and email confirmation, we count attempts per email address and per IP address. Each counter is deleted automatically after 15 minutes. This slows down password guessing without letting anyone lock you out of your own account.
  • An automated tool (fail2ban) reads our server logs and temporarily blocks IP addresses that exceed our request limits or probe for weaknesses: for one hour, or for one week if the same address is blocked three times within a day.
  • Our application logs record security events, such as a password reset or the reuse of an old session token, together with the internal number of the account concerned. These logs are rotated automatically once they reach a fixed size.
  • Legal basis: our legitimate interest in keeping the service and its accounts secure (Art. 6(1)(f)).

Your preferences and settings

In your account we store the display currency you choose, the exchanges you select, your favourite coins, your notification settings (categories, channels, email alerts on or off, quiet hours), your time zone as reported by your browser, and whether you want marketing emails.

  • Why: to show the site the way you set it up, on every device.
  • Legal basis: performance of our contract with you (Art. 6(1)(b)).

Your plans and reported portfolio

  • Investment plans: the plan's name, the one-off and monthly amounts, the horizon, the risk level, the rhythm, how the plan is split between coins, a target return if you set one, the day of the month for scheduled investing and the alerts you switch on.
  • Reported portfolio: the transactions you tell us about, meaning the coin, buy or sell, the date, the amount (stored in US dollars) and/or the quantity, the price and an optional note of up to 280 characters. If you leave out the price, we fill it in from our own price data and mark it as ours.

We don't connect to your exchange accounts or wallets, we hold no funds and we execute no trades: this data is only what you enter. We use it to show your plan, calculate projections and suggestions, and send the reminders and alerts you switch on. These suggestions are calculations shown to you. We make no decisions about you that have legal or similarly significant effects.

Without an account, the plan tool keeps your inputs only in your browser. To show you a preview, it sends them to our server, which calculates the answer and does not store the inputs.

  • Legal basis: performance of our contract with you (Art. 6(1)(b)).

Notifications

  • Inbox: each notification we create for you (what happened, which coin or plan it concerns, when, and whether you have read it) is kept in your account.
  • Email alerts: sent to your account address for the categories you keep switched on. Every alert email contains a one-click link to stop that category by email, and a switch in your account turns all alert emails off.
  • Browser notifications (Web Push): only if you turn them on and allow them in your browser. We then store the push address your browser gives us (a web address at the push service of your browser's maker), the encryption keys that go with it, a label such as "Chrome on macOS" derived from your browser identification string, your language and the session under which it was registered. Logging out on that browser, "Log out everywhere", a password change or a detected session theft switches that browser off. Messages are encrypted for your browser, so the push service delivers them without being able to read them, and they never show amounts on your lock screen.
  • Delivery records: for each notification sent, the channel, status and time, and the reason if it was skipped or failed.
  • Legal basis: performance of our contract with you, since you ask for these alerts (Art. 6(1)(b)). Browser notifications also require your permission in the browser, which you can withdraw at any time in its settings.

Paid plans and payments

When you buy a plan, we store the plan, the amount and currency, how you paid (card or crypto), the payment provider's references for the payment (and, for a card subscription, for the subscription and for you as its customer), the status of each payment, the dates it covers, and when you ticked the box asking for access to start immediately.

We never receive your card number or the keys to your wallet: you pay on the provider's own page. Stripe processes card payments and Plisio processes crypto payments, each under its own terms and privacy policy, which also cover what you enter on their page.

  • Why: to take your payment, give you the plan you paid for, run a card subscription, and keep the accounting records the law requires.
  • Legal basis: performance of our contract with you (Art. 6(1)(b)); our legal obligations in accounting and tax (Art. 6(1)(c)).

Emails we send

  • Account emails: confirmation of your address and password reset. They are part of how the account works and cannot be switched off.
  • Payment confirmations: sent after each payment, with the plan, the amount and the period covered. They are part of the contract and cannot be switched off.
  • Alert emails: as described under Notifications.
  • Marketing emails: only if you switch on "Marketing emails" in your account. The switch is off by default, and at the moment we send no marketing emails. Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time by switching it off.

Our emails are sent from support@stakebible.com through our email provider (see section 4).

When you write to us

We use your email address and the content of your message to answer you.

  • Legal basis: our legitimate interest in answering you (Art. 6(1)(f)); for requests about your rights, our legal obligation under the GDPR (Art. 6(1)(c)).

Backups

Before each software update, we take a full copy of the database. It is stored on our server, readable only by the system account that runs the service, and copies older than 14 days are deleted automatically each time a new copy is taken.

  • Legal basis: our legitimate interest in being able to restore the service after a failure (Art. 6(1)(f)).

3. Cookies and browser storage

We use two cookies, both strictly necessary for signing in, and we keep a few settings in your browser's local storage. We use no advertising or analytics cookies and load no third-party scripts. Local storage stays in your browser and is not sent to us with your requests.

Everything below is either strictly necessary for a service you asked for or keeps a choice you made, so it does not require your consent under the rules on electronic communications (in Romania, Law no. 506/2004). You can delete it at any time in your browser settings; deleting the cookies signs you out.

Name Type What it does How long
sb_at Cookie (HttpOnly, Secure) Shows our server that you are signed in 15 minutes
sb_rt Cookie (HttpOnly, Secure), sent only to our sign-in service Renews your session; replaced with a new one each time it is used 30 days
sb_scheme Local storage Light or dark theme No expiry
sb_fx Local storage Your display currency and the rate used to convert amounts Until you log out
sb_authed, sb_pro, sb_hasplan Local storage Display hints, so the page draws the right menu before our server answers; they grant no access No expiry
sb_avatar, sb_ini Local storage Your chosen avatar and your initials, to draw the account button No expiry
sb_markets Local storage The exchanges you selected Until you log out
sb_favs Local storage Your favourite coins No expiry
sb_profile Local storage The inputs of your investment plan; without an account, this is the only copy No expiry
sb_push_owner, sb_push_synced Local storage Which account turned on browser notifications in this browser, and when that was last renewed Until you turn notifications off or log out
/sw.js Service worker Receives browser notifications Registered only when you turn them on; stays until you remove it in your browser settings

"No expiry" means the item stays until you clear this site's data in your browser.

4. Who receives your data

We don't sell or rent personal data. We share it only with the providers that help us run the service:

Recipient Role What it processes
Our hosting provider Rents us the virtual private server that runs the site, the database and the memory store All the data described in this policy, as stored on the server
Cloudflare, Inc. Delivers the site and protects it against attacks All traffic between your browser and our server, including your IP address
Namecheap, Inc. (Private Email) Email service for support@stakebible.com The emails we send you and the messages you send us
Stripe Payments Europe, Limited (Ireland) Processes card payments and card subscriptions Your email address, the plan and amount, and the card details you enter on Stripe's page
Plisio Processes crypto payments Your email address, the plan and amount, and the payment you send
The push service of your browser's maker, such as Google, Mozilla, Microsoft or Apple Delivers browser notifications, only if you turn them on Your push address and the encrypted messages, which it cannot read

The language models we use for research receive questions about crypto projects and public data only, never personal data.

We may also disclose data to public authorities when the law requires us to.

Transfers outside the European Economic Area

Cloudflare, Namecheap and the push services of browser makers are based in the United States, so your data may be processed outside the European Economic Area. Such transfers take place only with a safeguard required by the GDPR: an adequacy decision of the European Commission (for US companies, certification under the EU–US Data Privacy Framework) or the European Commission's standard contractual clauses. You can ask us for information about the safeguard that applies.

Stripe may transfer data to Stripe, Inc. in the United States under the same safeguards. Plisio may process data outside the European Economic Area; ask us which safeguard applies.

5. How long we keep data

Data How long
Account, preferences, plans, reported portfolio, notifications and browsers registered for notifications As long as your account exists. Plans and transactions you delete in your account are deleted straight away.
Session records (including IP address and browser identification string) and records of email links As long as your account exists
Sign-in and email counters 15 minutes
Marker blocking issued access tokens 15 minutes
Automatic blocks of IP addresses 1 hour, or 1 week for repeated blocks
Application logs Rotated automatically once they reach a fixed size
Web server logs Only as long as needed for security and troubleshooting
Database backups Deleted once older than 14 days, when the next backup is taken
Messages you send us As long as needed to deal with your request
Payment records: plans bought, amounts, payment references and the consent given at checkout Up to ten years after the end of the financial year of the payment, as Romanian accounting law requires, even if your account is deleted
Browser storage Until you clear it (see section 3)

When your account is deleted, everything linked to it is deleted with it, except the payment records we must keep by law (see the table). Stop any card subscription before asking us to delete your account. A copy may remain in a database backup until that backup is deleted, as described above.

6. Your rights

Under the GDPR, you have the right to:

  • access your personal data and receive a copy of it;
  • rectification of data that is wrong or incomplete;
  • erasure of your data;
  • restriction of processing;
  • portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another controller;
  • object to processing based on our legitimate interests;
  • withdraw your consent at any time, where processing is based on consent, without affecting processing already carried out;
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you. We make no such decisions.

How to use them

In your account you can already change your display name, language and avatar; change your password; change your display currency, exchanges and notification settings; switch alert and marketing emails on or off; delete plans; stop notifications in a browser; and log out everywhere. Reported transactions can be deleted from your plan, and favourites removed with the star next to each coin.

For everything else, including a copy of your data, a change of email address or the deletion of your account, write to support@stakebible.com from your account's email address. Accounts cannot yet be deleted from the account page, so we delete them on request.

We answer within one month. If a request is complex, that period can be extended by up to two further months; we will tell you within the first month if that happens, and why. Using your rights is free of charge, unless a request is manifestly unfounded or excessive.

7. Complaints

You can lodge a complaint with the Romanian data protection authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), at dataprotection.ro, or with the supervisory authority of the EU country where you live, where you work or where the alleged infringement took place. We would appreciate the chance to deal with your concern first.

8. How we protect your data

  • Every page and request uses an encrypted connection (HTTPS, TLS 1.2 or 1.3).
  • Passwords are stored only as bcrypt hashes. Session tokens and the codes in email links are stored only as SHA-256 fingerprints.
  • The session cookies are HttpOnly, Secure and SameSite=Lax, so the scripts on a page cannot read them, and session tokens never appear in the body of our responses.
  • A strict Content Security Policy lets our pages run only our own scripts.
  • Rate limits and automatic blocking slow down attacks on accounts.
  • The database is not reachable from the internet: it accepts connections only from the server itself, and administrative access goes through SSH with keys. The memory store requires a password.

No system is completely secure. If a personal data breach is likely to put your rights at risk, we will notify ANSPDCP and, where the GDPR requires it, you.

9. Children

StakeBible is not intended for anyone under 18, and accounts are for adults only. If you believe that a minor has created an account, write to us and we will delete it.

10. Changes to this policy

When we change this policy, we update the date at the top of this page. If a change materially affects how we use your data, we will tell account holders by email before it takes effect.

Questions: support@stakebible.com. See also our terms of use and contact page.