Privacy Policy
This Policy describes how WhaleGPT — an EDUCATIONAL and TRAINING platform only — processes your personal data under EU Regulation 2016/679 ("GDPR"), Italian Legislative Decree 196/2003 as amended, and — where applicable — CCPA/CPRA (California), UK GDPR, LGPD (Brazil) and PIPEDA (Canada).
1. Data controller and contacts
Data controller: Viraly ("WhaleGPT"). Privacy contacts: privacy@whalegpt.io. Data Protection Officer (DPO), if appointed: dpo@whalegpt.io.
2. Categories of data processed
- Account data: email, password (hashed with bcrypt/argon2), display name, avatar, language, time zone, level (beginner/pro).
- User-uploaded content: chart screenshots, journal notes, paper-trading configurations, briefings, prompts and messages sent to AI chat.
- Usage data and technical logs: IP address, user-agent, page visited, timestamp, device, OS, navigation events, errors, latency.
- Payment data: handled entirely by Stripe (PCI-DSS Level 1); we only receive customer ID, subscription status, card brand and last 4 digits. We NEVER store full card data.
- Telegram handle (if voluntarily provided to access the human coach).
- Legal audit: date, version of Terms/Privacy/Risk accepted, IP, user-agent.
- Communications: transactional emails, support tickets, conversations with the coach.
We do NOT knowingly process special categories of data (GDPR art. 9: health, orientation, religion, biometrics) nor data of minors. If you believe you provided them by mistake, write to privacy@whalegpt.io and we will delete them.
3. Purposes and legal bases
- Delivery of the educational Service, account management, billing — basis: contract performance (GDPR art. 6.1.b).
- Tax obligations, AML, response to authorities, audit retention — basis: legal obligation (art. 6.1.c).
- Platform security, anti-fraud, anti-chargeback, abuse prevention, Service improvement, aggregate statistics, internal research — basis: legitimate interest (art. 6.1.f). You may object by writing to privacy@whalegpt.io.
- Non-essential cookies, non-anonymized analytics, direct marketing to non-customers, access to third-party AI modules processing content — basis: consent (art. 6.1.a), revocable at any time.
- Soft-spam to existing customers on similar products (Italian Privacy Code art. 130 c. 4) — one-click opt-out.
4. Recipients and data processors
To deliver the Service we share data with selected processors, bound by Data Processing Agreements (DPAs):
- Hosting / database / auth: Supabase (Lovable Cloud), EU infrastructure.
- Edge / CDN: Cloudflare Workers (global anycast network).
- Payments: Stripe Inc. / Stripe Payments Europe Ltd. (PCI-DSS L1).
- AI providers: Google (Gemini), OpenAI (GPT), Anthropic (Claude) via Lovable AI Gateway. Under gateway agreements, prompts and content are NOT used to train public models.
- Transactional email: Resend or equivalent.
- Analytics (if enabled): Plausible or equivalent privacy-friendly provider with no cross-site profiling.
- Telegram coach: messaging happens via Telegram (Telegram FZ-LLC, Dubai); their privacy policy also applies.
- Meta Pixel / Google Ads (only with prior consent): aggregate conversion tracking.
- External professionals: accountants, lawyers, auditors, secondary cloud providers — bound by NDAs and DPAs.
5. Non-EU transfers
Some providers (Stripe, OpenAI, Google, Cloudflare, Telegram) may process data in the United States, UK, Switzerland or other third countries. Transfers rely on: (a) EU Standard Contractual Clauses 2021/914; (b) EU-US Data Privacy Framework where certified; (c) adequacy decisions for UK, Switzerland, Canada; (d) supplementary measures (encryption, pseudonymisation, additional agreements). You may request a copy of the SCCs by writing to privacy@whalegpt.io.
6. Retention
- Active account data: for the account lifetime + 12 months after termination.
- Uploaded content (screenshots, journal, prompts): for the account lifetime, deletable by the user at any time.
- Security and audit logs: 12 months (24 months if an investigation is ongoing).
- Tax and legal-acknowledgment records: 10 years (Italian law, art. 2214 Civil Code and art. 22 DPR 600/1973).
- Marketing email: until consent withdrawal or relationship termination.
- Backups: maximum 35-day rotation.
7. Your rights (GDPR and equivalents)
You may exercise at any time the rights set out in art. 15–22 GDPR: ACCESS, RECTIFICATION, ERASURE ("right to be forgotten"), RESTRICTION, PORTABILITY, OBJECTION to legitimate-interest or marketing processing, WITHDRAWAL of consent (without affecting prior lawful processing), RIGHT not to be subject to solely automated decisions with significant legal effects (GDPR art. 22 — we do not apply automated profiling of this kind). Write to privacy@whalegpt.io. We will respond within 30 days (extendable to 60 for complex requests).
You also have the right to lodge a COMPLAINT with the Italian Data Protection Authority (www.garanteprivacy.it) or the supervisory authority of your EU/EEA country. California residents: CCPA/CPRA rights — we do not sell or share personal data for cross-context behavioral advertising.
8. Security and data breach
We adopt technical and organisational measures appropriate to risk (GDPR art. 32), including: TLS 1.3 in transit, AES-256 at rest, Row-Level Security on all user tables, delegated authentication (Supabase Auth) with argon2/bcrypt hashing, service-key segregation (service role never exposed to client), least-privilege principle, staff MFA, 24/7 monitoring, periodic vulnerability scans, encrypted backups with 35-day rotation, annual compliance audits. In case of a data breach with high risk to the rights of data subjects, we will notify the Garante within 72 hours and users without undue delay (GDPR art. 33-34).
9. Minors
The Service is reserved to adults (18+). We do NOT knowingly process minors' data. If you become aware that a minor has provided data, write to privacy@whalegpt.io: we will delete it immediately.
10. Automated decisions and profiling
The Service may use algorithms (including AI) to personalise educational suggestions, recommend lessons, flag security anomalies or optimise UX. Such processing does NOT produce significant legal effects on the user nor replaces critical human decisions; it is not "solely automated decision-making" under GDPR art. 22. You may always request human intervention at privacy@whalegpt.io.
11. Cookies and similar technologies
For details on cookies, localStorage, sessionStorage, pixels and SDKs see the dedicated Cookie Policy.
12. Changes
Material changes to this Policy will be notified by email or in-app notice at least 30 days in advance. Historical versions are retained and may be requested at privacy@whalegpt.io.
