Skip to content

Legal

Privacy Policy

What we collect, why we have it, who else is involved, and what you can ask us to do. Written from the actual data flows in the product rather than from a template.

Last updated

The short version.

  • We collect very little about you. We do not ask for your name, your address or your phone number. Your account is an email address.
  • We never see your card number. Stripe handles payments.
  • We never take custody of your crypto, and we cannot withdraw from your exchange.
  • The YUKUZ application ships no analytics and no advertising trackers, and we set no advertising cookies. See the note in section 4 about one setting that lives outside our code.
  • We do not sell your personal information, and we do not share it for advertising.
  • We keep exchange API credentials encrypted, and you can delete them.

1. Who we are

YUKUZ, ABN 39 679 009 646 provides the YUKUZ software and website. We are based in Canberra, Australian Capital Territory, Australia.

  • ABN: 39 679 009 646
  • Location: Canberra, Australian Capital Territory, Australia
  • Privacy contact: support@yukuz.com

We do not publish a street address at this stage. Please write to us at support@yukuz.com about anything in this policy, including a privacy request.

2. What we collect, and why

2.1 Your account

WhatWhy we have it
Email address It is your account identity, it is how you sign in, and it is where verification and password reset messages go
Password Kept only as an Argon2id hash. We cannot read your password
Language preference, if you choose one So the interface and our emails are in your language
Account status, failed sign in count, lockout time To slow down someone trying to guess your password

We do not collect your name, postal address, date of birth or telephone number, and we do not ask you to prove your identity.

2.2 Signing in and keeping you signed in

WhatWhy we have it
A hashed session token To keep you signed in for up to 30 days
Your IP address, recorded against the session So a session record is meaningful, and to help detect misuse
Your browser and device string, the user agent So you can recognise your own sessions in Settings and end ones you do not recognise
Hashed verification and password reset tokens, with their expiry and whether they were used To confirm you control your email address, and to make each link work only once
A short lived registration continuation credential So the browser that started a signup can continue after you verify, including when you verify on your phone. It lasts 20 minutes

2.3 Two factor authentication, if you turn it on

WhatWhy we have it
Your TOTP secret To check the codes from your authenticator app
A marker of the most recent code accepted So a code cannot be used twice, even by someone who saw it
Hashed recovery codes So you can get back in if you lose your authenticator. We store hashes only, so we cannot tell you what a code is

2.4 Subscription and billing

WhatWhy we have it
Your Stripe customer identifier To connect your YUKUZ account to your Stripe record
Your subscription state: plan, status, period end, whether cancellation is scheduled, grace period To know what your account is entitled to, and to show you an accurate billing page
A record of each billing event Stripe sends us: its identifier and type, whether we processed it and the result, and which customer and subscription it refers to To process each event exactly once and to investigate billing problems

We do not receive or store your card number, expiry date or security code. Those go directly to Stripe on Stripe's own checkout page.

We do not keep the body of a Stripe event. The messages Stripe sends about a subscription often contain your email address and details such as your card brand and its last four digits. We keep only the identifiers listed above, and when we need the state of your subscription we ask Stripe for it directly rather than relying on what a message contained.

2.5 Exchange connections, if you create one

WhatWhy we have it
The exchange name, the label you chose, and the connection status To show you your connections
Whether the key was found to allow reading, and whether it allows trading, plus when it was last checked and any last error So we can tell you honestly whether a key works
Your exchange API key, secret and passphrase To check the key works and to read your balances when you ask

Your credentials are encrypted before storage using AES-256-GCM, with a fresh random nonce for every record. They are sent to your exchange when we validate the key or read your balances, and to nobody else.

The YUKUZ connector is read only. It is built without the ability to place or cancel orders, and without any withdrawal capability. This is not a setting we could flip by accident.

Balances we read for you are shown to you and are not stored.

2.6 Your Rule Bot configuration

The rules you write, the names you give bots, the pairs you assign and the settings you choose are stored so we can show them back to you. This is information you author. We do not sell it, and we do not use it to build a profile of you.

2.7 The Intelligence Report

We record that your account is signed in when it requests the report, through the ordinary session mechanism. We do not build a reading history and we do not track which sections you look at.

2.8 Security and audit records

We keep an audit record of security and account events, for example signing in, a failed sign in, enabling two factor, creating or deleting an exchange connection, and billing events. These records include the action, a timestamp, the account involved, an IP address and a request identifier.

We keep them so that we can investigate suspicious activity and so that you can be told what happened to your account.

These records are append only by design, which has a consequence for deletion that we explain honestly in section 8.

2.9 Email we send you

We send transactional email only: verify your address, reset your password, and a notice when your password has changed. Each contains your email address and, where relevant, a single use link.

We send no marketing email, because no marketing email capability exists in the product.

2.10 Support

If you email us at support@yukuz.com, we hold that correspondence in our mailbox so we can help you. How long we keep it is covered in section 7.

2.11 Cookies and browser storage

See the separate YUKUZ Cookie Policy. In short: two strictly necessary cookies, one cookie remembering your chosen language, a small amount of browser storage for interface preferences, and no analytics or advertising cookies at all.

3. What we do not do

  • We do not sell personal information.
  • We do not share personal information for advertising or cross context behavioural advertising.
  • We do not run advertising or social media trackers on our site.
  • The YUKUZ application contains no analytics script. Our website is delivered by Cloudflare, and Cloudflare offers a privacy focused, cookieless analytics feature that can be switched on from its dashboard rather than in our code. We mention it rather than stay silent, because it is a setting outside our source code. If it is on, Cloudflare counts page views without setting a cookie and without identifying you.
  • We do not profile you, and we make no automated decision that produces a legal or similarly significant effect on you.
  • We do not ask for or store identity documents.

4. Who else is involved

Who What they do for us What reaches them
Stripe Subscriptions, hosted checkout, the billing portal Your email address, your card details which you give them directly, and your payment history
Cloudflare Hosts our public website and sits in front of our API Your IP address and ordinary request information, as with any website
Microsoft Sends our transactional email through Microsoft 365, using Microsoft Graph Your email address and the message content
Your exchange, currently KuCoin The account you choose to connect Your API credential, when we validate it or read your balances at your request
CoinGecko Public market prices on our homepage demonstration Your browser requests these prices directly, so your IP address reaches CoinGecko when you view that page. We do not send them anything about you
Our hosting provider Runs our API server and database Data at rest and in transit on that server

5. Where your data is processed

The YUKUZ website is served by Cloudflare's global network. Our API and database run on a virtual server.

We are based in Australia. Stripe, Cloudflare and Microsoft all operate internationally, so your information may be processed or stored outside Australia, and outside the country you live in. Australian Privacy Principle 8 places obligations on us when we disclose personal information to an overseas recipient, and we take those obligations as they apply to each provider.

6. Why we are allowed to handle your information

We are an Australian business, and we work to the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

We collect and use your information for the purposes set out in section 2, and for no other purpose: providing the service you asked for, keeping your account secure, taking payment for the plan you chose, and meeting our legal obligations. We do not use it for advertising, and we do not sell it.

If you are outside Australia you may have further rights under the law where you live.

7. How long we keep things

We keep information only for as long as it is needed for the purpose it was collected for, and for as long as we need it to keep the service secure and to meet our legal, billing, tax and dispute obligations.

Here is the position category by category.

CategoryHow long we keep it
1. Data needed to run your account: password hash, language, plan entitlements For as long as your account exists, because the service cannot work without it
2. Your email address, after your account is closed 90 days. After that it is replaced with a value that is not a working address and from which your address cannot be worked out
3. Security and audit records: the audit log Kept. The IP address in an entry is removed after 18 months, and the rest of the entry stays. The log is append only by design, so the application itself can neither remove nor alter an entry: see section 8
4. Billing records: your Stripe customer identifier and subscription state 7 years after the record is complete, to meet Australian tax and record keeping obligations. These records hold no name, address or card detail: they are an internal account reference, which plan you had, its status and its dates
5. Billing event records: the identifier, type, result and customer and subscription references for each Stripe event 7 years. The body of the event is not stored at all
6. Session records: hashed session token, IP address, browser and device string 90 days after the session ends or expires, then removed
7. Authentication token records: verification, password reset and registration continuation tokens The token itself is stored only as a hash. Verification and password reset records are removed 30 days after they are used or expire, and the short lived credential that continues a signup after 7 days
8. Rule Bot configuration Kept while your account exists. The configuration of a bot you deleted is removed 180 days later
9. Exchange connection data Connection details are removed when you delete the connection. Stored credentials are genuinely deleted, and this is the one place where deletion is immediate and complete
10. Support correspondence Held in our mailbox. No period is defined

How these are carried out, honestly. The software that applies the periods in rows 2 and 5 to 8 is built and tested, and today it is run by us rather than on a schedule. We are not going to tell you a timer is running before one is.

Row 3 is carried out by a separate database procedure, performed by hand, for a reason worth stating: our audit log is built so that the application can only ever add to it, which means the application cannot quietly rewrite your security history, and it also means removing an IP address from it has to be done deliberately from outside the application.

We may keep information longer than the periods above where we still need it for an unresolved billing dispute or chargeback, a security investigation, or a legal obligation to preserve it.

About the billing event records. We keep one small record per Stripe event so that each event is processed exactly once and so that a billing problem can be investigated later. That record holds the event's identifier and type, whether we processed it and what the result was, and which customer and subscription it refers to. It does not hold the event itself, so the email address and card details those messages carry are not stored here.

8. Your choices, and what we can honestly do today

Depending on where you live you may have rights over your personal information, such as access, correction, deletion, objection and portability. As an Australian business we work to the Australian Privacy Principles, which give you rights to access and correct the personal information we hold. If you are outside Australia you may have further rights under your local law, as noted in section 6.

What the software can do today:

You want toCan we do it now?
See and correct your email address and language Yes, in Settings
Change your passwordYes
End a session on a device you no longer use Yes, in Settings
Turn two factor authentication on or offYes
Delete an exchange credential or a whole connection Yes, and the credential really is deleted
Delete a Rule Bot Yes, though the configuration record is retained in a deleted state
Cancel your subscription Yes, effective at the end of the paid period
Delete your whole account yourself No. This is not built yet.

Asking us for something

For any privacy request, including access, correction or closure, email support@yukuz.com. We handle these manually today.

Four different things, which we keep separate on purpose

People often use "delete my account" to mean any of the following, so here is what each one actually means at YUKUZ.

1. Account closure. We close the account so it can no longer be signed into or billed. Ask us at support@yukuz.com. There is no self service account deletion today, and we will not pretend otherwise.

2. Credential deletion. You can delete a stored exchange credential, or a whole exchange connection, yourself and at any time. This one is a real deletion. The encrypted credential is removed from our database.

3. Personal information deletion. Removing the personal information we hold about you is a broader request than closing an account. We will do what we reasonably can on request, and we will tell you specifically what was removed and what was kept.

4. Records we may need to keep. Some records are not removed, either because we are required to keep them, or because of how they are stored:

  • Security audit records. Our audit log is append only by design. The application can add an entry and cannot change or remove one, and in production the database account it uses has insert only permission on that table. That is a deliberate protection: it means nobody, including us, can quietly rewrite the security history of an account. The consequence is honest and worth stating, which is that audit entries, which include an IP address, cannot be erased by the application.
  • Billing records, where tax and record keeping obligations apply.

We will not promise you complete erasure, because the software cannot deliver it today. When a retention and de identification policy exists and is implemented, this section will say something better, and we would rather change it then than overstate it now.

9. How we protect your information

  • Passwords are hashed with Argon2id. We never store the password itself.
  • Exchange credentials are encrypted at rest with AES-256-GCM.
  • Session cookies are HttpOnly, Secure and SameSite=Lax, so a script cannot read them and they are not sent from another site.
  • Every action that changes something requires a CSRF token.
  • Two factor authentication is available, and codes cannot be replayed.
  • Sign in, registration, verification, password reset and two factor endpoints are rate limited, and there is a separate cap on how many emails a single address can receive per hour.
  • The website is served with a strict Content Security Policy and standard security headers.
  • Stripe webhooks are verified by signature and processed only once.
  • Our credential input model masks the key, secret and passphrase in its own debug output, so they cannot leak into an error report.

No system is perfectly secure, and we do not claim otherwise.

10. Children

YUKUZ is not intended for children. You must be at least 18 to use YUKUZ, as set out in the Terms of Service, and we do not knowingly collect information from anyone younger.

11. Changes to this policy

If we change this policy we will update the date shown at the top of this page, and we will give notice of significant changes by email or in the product.

12. Contact us and how to complain

For any privacy question, request or complaint, email support@yukuz.com. We do not publish a street address at this stage.

If you are not satisfied with how we have handled your privacy complaint, you may be able to take it to the Office of the Australian Information Commissioner. Customers outside Australia may be able to raise a complaint with the privacy regulator where they live.