Privacy policy
What we collect, why, and the controls you have. Last updated 2026-08-30.
1. Data we collect
Account data: your email address (the only identifier we require), plan, preferences (language, currency, electricity price), watchlist, price alerts and API keys (stored hashed).
Session data: when you sign in we record the session's IP address and browser user-agent so you can review your sign-in history and spot anything unusual.
API usage: per-key request counters (daily totals) to enforce quotas and show your dashboard. We do not log the content of your API queries beyond standard, short-lived server logs.
Contact and submissions: what you send through the contact and listing forms, including your email if you provide it.
Browsing: anonymous, cookieless audience measurement runs by default. Cookie-based analytics and advertising only run after you accept them in the cookie banner.
2. What we use it for (and the legal basis)
Running the service you asked for — accounts, watchlist, alerts, API quotas, billing (performance of a contract).
Sending the emails you triggered — magic links, price alerts, replies to your messages (performance of a contract).
Securing the service — abuse and fraud prevention, sign-in history (legitimate interest).
Measuring audience and funding the site with ads — only with your consent, given through the cookie banner and revocable at any time.
We do not sell personal data, and we do not use it for automated decisions with legal effects.
3. Who processes it with us
Hosting and database: our infrastructure providers in the EU/US under standard contractual clauses.
Stripe for payments — we never see card numbers. Resend for transactional email. Sevio for advertising (only after consent). Google Analytics, if enabled, only after consent; audience stats otherwise come from cookieless measurement.
These providers act as processors under their own GDPR commitments; we share only what each needs.
4. Retention
Account data lives as long as your account. Deleting your account (Account page, Danger zone) immediately removes watchlist, alerts, preferences, sessions and API keys.
Sessions expire after 30 days. Sign-in tokens after 15 minutes. Invoices are kept by Stripe as long as tax law requires. Aggregated, non-personal statistics (API call totals) may be kept longer.
5. Your rights (GDPR)
You can access, rectify, export or erase your data, object to or restrict processing, and withdraw consent at any time. Most of it is self-service: preferences and alerts from your account, cookie consent from the cookie policy page, account deletion from the Danger zone.
For anything else, or to exercise a right we have not automated, use the contact page; we answer within 30 days. You may also lodge a complaint with your local supervisory authority (CNIL in France).
6. Security
Passwordless sign-in (nothing to leak), API keys stored as SHA-256 hashes, TLS everywhere, least-privilege access to production data, and separate environments for development. No system is perfect: if a breach affects your data we will notify you as the GDPR requires.
7. Children
The service is not directed at children under 15 and we do not knowingly collect their data.
8. Changes and contact
We may update this policy; material changes are announced on the site. Questions: use the contact page.
See also the cookie policy and the terms of use.