Privacy Policy
Last updated: March 5, 2026
1. Introduction
Darwin Lab ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data. This policy applies to all users of the Darwin Lab website, Telegram channels, APIs, and related services (collectively, "the Service").
2. Information We Collect
2.1 Information You Provide
- Email address: Provided during account creation or subscription signup, used for account management, billing notifications, and service communications.
- Telegram username: Provided to enable signal delivery through Telegram channels and bots.
- Payment information: Payment details (credit card numbers, billing addresses) are processed and stored exclusively by our payment processor, Stripe. We also process cryptocurrency payments (SOL, USDT) and may record wallet addresses and transaction hashes for payment verification purposes. We do not store full credit card numbers on our servers.
- Communications: Any messages, feedback, or support requests you send to us via email or other channels.
2.2 Information We Collect Automatically
- Usage data: Pages visited, features used, signals viewed, timestamps, and interaction patterns with the Service.
- Device and browser information: IP address, browser type and version, operating system, device identifiers, and screen resolution.
- Cookies and similar technologies: We use essential cookies to maintain session state and preferences. We do not use third-party advertising or tracking cookies.
2.3 Information We Do NOT Collect
- ✓ We do NOT collect your exchange account credentials (API keys, passwords, secret keys).
- ✓ We do NOT collect personal financial data (bank account numbers, portfolio balances, trading history).
- ✓ We do NOT collect government-issued identification documents.
- ✓ We do NOT monitor, access, or interact with your trading accounts on any exchange.
- ✓ We do NOT sell, rent, or trade your personal data to advertisers or data brokers.
3. How We Use Your Data
We use the information we collect for the following purposes:
- Service delivery: To provide, operate, and maintain the Service, including delivering trading signals via Telegram and API.
- Account management: To create and manage your account, process subscriptions, and verify payments.
- Service improvement: To analyze usage patterns and improve our strategies, signals, and user experience. This analysis is performed on aggregated, anonymized data.
- Communications: To send you service-related notices, subscription confirmations, billing receipts, and responses to your inquiries. We do not send unsolicited marketing emails.
- Security: To detect, prevent, and address fraud, abuse, security issues, and technical problems.
- Legal compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
4. Third-Party Data Sharing
We share your personal data only with the following categories of third parties, and only to the extent necessary to provide the Service:
- Stripe (Payment Processor): We share billing information with Stripe to process payments. Stripe's handling of your data is governed by Stripe's Privacy Policy.
- Telegram (Signal Delivery): Your Telegram username is used to deliver signals through Telegram bots and channels. Telegram's handling of your data is governed by Telegram's Privacy Policy.
- Hosting and Infrastructure Providers: We use third-party cloud hosting services to operate our servers. These providers may process your data as part of providing their infrastructure services.
- Legal Requirements: We may disclose your data if required to do so by law or in response to valid legal process (court order, subpoena, or government request).
We do not sell, rent, lease, or otherwise commercially transfer your personal data to any third party for their marketing or advertising purposes.
5. Data Retention
We retain your personal data for as long as your subscription is active and for a period of thirty (30) days following the cancellation or expiration of your subscription. After this retention period, your personal data will be permanently deleted from our active systems.
Certain data may be retained beyond this period where required by law (e.g., financial transaction records for tax or accounting purposes) or for the establishment, exercise, or defense of legal claims. Anonymized and aggregated data that cannot be used to identify you may be retained indefinitely for analytical and service improvement purposes.
6. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS/SSL), access controls, secure server infrastructure, and regular security assessments. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your Rights (GDPR and International)
Regardless of your location, we extend the following data rights to all users:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): You may request the deletion of your personal data, subject to legal retention requirements.
- Right to Data Portability: You may request a copy of your data in a structured, commonly used, machine-readable format (JSON or CSV).
- Right to Restriction of Processing: You may request that we limit the processing of your personal data under certain circumstances.
- Right to Object: You may object to the processing of your personal data for certain purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise any of these rights, contact us at darwinlab.ai@proton.me. We will respond to your request within thirty (30) days. We may request verification of your identity before processing your request.
8. International Data Transfers
Your data may be processed and stored in countries other than your country of residence. By using the Service, you consent to the transfer of your data to countries that may have different data protection laws than your jurisdiction. We take appropriate safeguards to ensure that your data remains protected in accordance with this Privacy Policy.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have collected personal data from a minor, we will take immediate steps to delete such data.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on the Service with a revised "Last updated" date. Your continued use of the Service after such changes constitutes acceptance of the updated Privacy Policy.
11. Contact
For questions, concerns, or data requests regarding this Privacy Policy, contact us at: