Privacy Policy 

Last updated: 18.07.2026

Below we inform you in accordance with Art. 13/14 GDPR about the processing of personal data when using SHORT RADAR (shortradar.app, dash.shortradar.app).

1. Controller

Michael Jajagin, self-employed Software Engineer (natural person; ZER0ONE OÜ, Estonia, in formation), Dunavska obala 79, 25245 Bogojevo, Republic of Serbia. Email: kontakt@shortradar.app, Phone: +381 62 1759388. The controller is based outside the EU; an EU representative under Art. 27 GDPR will be appointed where required [EU-Vertreter ergänzen, sobald benannt].

2. What data we process

  • Registration/account: name (optional), email address, password (stored only as a hash), plan/role.
  • Usage: access/usage data, technical log data (IP address, timestamp, user agent) for provision and protection (including rate limiting).
  • Payments (for paid plans): handled via Stripe; we store a customer/subscription identifier, but no complete payment data.
  • Sign-in with Google: when using “Continue with Google” we process the basic data transmitted by Google (email, name) to create the account/sign in.
  • Email delivery: transactional and alert emails (e.g. password reset, crisis/signal alerts, newsletter) are sent via SMTP through Google (Gmail).
  • AI tutor (chat): when using the optional AI chat, the messages you enter are transmitted to our AI service provider Anthropic (USA) in order to generate a response.
  • Telegram alerts (optional): if you enable Telegram notifications, we process your Telegram chat ID in order to deliver alerts via Telegram.
  • Newsletter (optional): upon registration we process your email address using the double opt-in procedure; you may unsubscribe at any time.
  • Broker connection (optional, read-only): if you connect a real broker account, we store your broker API credentials encrypted and read only your account balance/positions for display. No orders are transmitted; the connection is made with your express consent and can be disconnected at any time.

3. Purposes & legal bases

  • Provision of the service, account and contract handling — Art. 6(1)(b) GDPR.
  • Security, abuse/fraud prevention, stability (logs, rate limiting) — Art. 6(1)(f) GDPR.
  • Payment processing — Art. 6(1)(b) GDPR.
  • Optional services (newsletter, Telegram alerts, AI tutor) — consent, Art. 6(1)(a) GDPR; revocable at any time with effect for the future.
  • Reach measurement (cookieless statistics) — legitimate interest, Art. 6(1)(f) GDPR.
  • Fulfilment of legal obligations (e.g. retention) — Art. 6(1)(c) GDPR.

4. Recipients / processors

  • Hosting/servers: Contabo GmbH, Munich, Germany (servers in the EU).
  • Payments: Stripe (Stripe Payments Europe, Ltd., Ireland; where applicable Stripe, Inc., USA).
  • Sign-in: Google (Google Ireland Ltd. / Google LLC) when using “Continue with Google”.
  • Email delivery: Google (Gmail SMTP) for transactional, alert and newsletter emails.
  • AI tutor: Anthropic, PBC (USA) — processing of chat inputs to generate responses.
  • Telegram alerts (only when enabled): Telegram Messenger Inc.
  • Reach measurement: Plausible (Plausible Insights OÜ, Estonia/EU) — cookieless, without personal profiles.
  • Broker (only when connected): the broker you choose (e.g. Alpaca, Interactive Brokers) — exclusively read-only retrieval of your account/position data.
  • Market data sources (yfinance, FRED, etc.) do not process any personal user data.

5. Data transfer to third countries

With Stripe, Google, Anthropic and Telegram, a transfer to the USA or other third countries may occur. This is based on appropriate safeguards (including EU standard contractual clauses or, where applicable, the EU-US Data Privacy Framework). The controller itself is based in Serbia; the GDPR is treated as applicable (Art. 3(2) GDPR).

6. Cookies / local storage

We use only technically necessary storage: a sign-in token (JWT) is kept in the browser (localStorage) in order to maintain the session. We do not use tracking/marketing cookies. Reach measurement is carried out via Plausible without cookies and without personal profiles. “Continue with Google” loads a Google script; this only becomes active when the Google sign-in is used.

7. Storage period

Account and usage data are stored for the duration of the usage relationship and are deleted after account deletion, unless statutory retention obligations preclude this. Password reset tokens are short-lived (30 minutes).

8. Your rights

You have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). An account can be deleted or exported in the settings; alternatively by email to kontakt@shortradar.app. You have the right to lodge a complaint with a data protection supervisory authority.

9. No automated decision-making in individual cases

The crisis scores displayed are general model assessments and do not constitute an automated decision with legal effect concerning you (Art. 22 GDPR), nor investment advice.

Datenschutzerklärung — SHORT RADAR