Privacy policy

What data Prophetia collects, why, who it is shared with, how long it is kept and how to exercise your rights.

Last updated:

Data controller

PROPHETIA, 94 allée des Vignes, 34280 La Grande-Motte, France, is the controller for the processing described below. For any question about your data: contact@prophetia.fr.

Data we collect

We collect only what the service needs to work:

  • Your email address, which is your login identifier.
  • Your password, stored as an irreversible hash — we do not know it and cannot remind you of it.
  • Your preferences: language, display currency, analysis reading level, subscription plan.
  • The transactions and positions you import or enter, and the portfolios you create.
  • The analyses you request and their history.
  • Technical logs (IP address, timestamp, page visited) kept for security and abuse prevention.
Prophetia never holds your crypto-assets, your private keys or your exchange credentials, and cannot place any order on your behalf. The files you import are accounting exports: they do not contain those items.

Purposes and legal bases

  • Providing the service you signed up for — account, portfolios, analyses, tax file: performance of the contract.
  • Securing the service and preventing abuse — technical logs, rate limiting: legitimate interest.
  • Meeting our accounting and tax obligations when you subscribe to a paid plan: legal obligation.

We do not use your data for advertising or commercial profiling, and we neither sell nor rent it to anyone.

Who receives your data

The service relies on technical providers. Here is precisely what each one receives.

Artificial intelligence providers (OpenAI, Google, xAI), to produce the text of the analyses:

  • Asset analysis: only the requested symbol (for example BTCUSDT), the time interval, the language and the reading level are sent. No data about you leaves our servers.
  • Portfolio analysis: aggregated statistical indicators, expressed only as proportions and relative changes. No amount, no transaction, no date, no exchange and no data that could identify you is sent.
  • Support assistant: your question and extracts from the frequently asked questions.

Brevo (France) delivers the emails the service sends you and therefore receives your email address.

IONOS SARL (France) hosts the servers and the database.

OpenAI, Google and xAI are established in the United States: the indicators described above are therefore transferred there, on the basis of the European Commission's standard contractual clauses. Your transactions, however, do not leave our servers in France.

Market data shown comes from public sources (Binance, CoinGecko). Those requests are made by our servers, never by your browser: those providers do not see you.

Cookies and analytics

Prophetia uses no analytics tool, no advertising tracker and no third-party cookie. That is why this site shows you no consent banner.

Only strictly necessary cookies are set: the one that keeps your session open after login, and the one that remembers your language. Regulations exempt these from prior consent.

Retention periods

  • Account data, portfolios and transactions: kept as long as your account exists, then deleted when it is deleted.
  • Analysis history: kept as long as your account exists.
  • Technical logs: twelve months at most.
  • Accounting records linked to a subscription: ten years, as required by French commercial law.

Your rights

You have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to give instructions on what happens to it after your death.

To exercise them, write to contact@prophetia.fr. We answer within one month. Proof of identity may be requested if there is reasonable doubt about who is making the request.

If our answer does not satisfy you, you may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or with the supervisory authority of your own country of residence.

Security

Traffic between your browser and the site is encrypted (HTTPS/TLS). Passwords are stored as irreversible hashes. Database access is restricted to the application server and is not exposed to the internet.

No system is infallible. If you find a vulnerability, please write to us rather than exploit it: we will handle the report seriously and will not pursue you for it.