NMNH.TRADE

Privacy Policy

Last updated: September 29, 2026

NMNH.TRADE is a crypto futures trading terminal developed and operated by an individual developer. This page describes what data the terminal receives, why, where it is stored and how to delete it.

What data we receive

Only what the terminal cannot work without:

  • Your Telegram login data: numeric ID, username and avatar
  • Your exchange account UID - to link the account and determine access terms
  • Exchange API credentials (key, secret, passphrase) or access tokens if the account is connected via exchange login (OAuth)
  • Trading data from the account: balance, positions, orders and trade history - for the journal and position management
  • What you add yourself: journal notes and screenshots, risk settings, the name on your trade card
  • Service records: login times and last visit

How API keys and tokens are stored

Keys and tokens are stored server-side only and only in encrypted form. The encryption master key is provided through the server environment and is kept neither in the database nor in the source code. Without it the trading module does not start, so there is no unencrypted mode at all.

A key is never sent back to the browser, not even to you: the dashboard shows only its last four characters. Keys and tokens are never written to server logs.

The terminal needs read and trade permissions only. Withdrawal permission is never requested or used - create your key without it.

How we use data

To place your orders on the exchange, manage positions and the journal, calculate statistics and show your dashboard. Data is not sold, not used for advertising and not shared with third parties beyond those listed below.

Who data is shared with

  • The exchange where your account is held - orders and requests are sent on your behalf with your key
  • Cloudflare - site delivery and protection network; all traffic passes through it, and its R2 storage holds backups and uploaded screenshots, encrypted at rest
  • Render - hosting of the website pages
  • Telegram - login and bot notifications
  • Anthropic - only for market analysis you request; market data is sent, without keys or account data

Browser storage and cookies

To keep you signed in, the browser stores session tokens and interface settings in local storage. The site uses no third-party advertising or analytics cookies. A new login ends the previous session.

Retention

For as long as your account exists. When you disconnect an exchange in your profile, the stored key is deleted immediately. Database backups are kept for up to one year and then deleted automatically.

Your rights

You can request a copy of your data, correct it or delete your account entirely. You can delete the key on the exchange side at any time - the terminal loses access immediately.

Security

The site and server work over HTTPS only. The server is closed to the public network; requests reach it through a Cloudflare tunnel with DDoS protection. Server access is by SSH key only, for a single operator, with password login disabled; there is no staff with access to data.

Changes and contact

If this policy changes, the new version will be published on this page with a new date. Data questions and deletion requests: [email protected]. Report a vulnerability: [email protected].