nocappov (the “Service”) is operated by the nocappov team (the “Operator”, “we”, “us”), an independent research and product team. A corporate entity is being established; this policy will be updated with its details and registered address once registration is complete.
For any privacy question or request, write to support@nocappov.com.
| Data | Why we have it | When |
|---|---|---|
| Email address | Account identity, login, service notices, support replies | At sign-up |
| Password (hashed) | Login. We store a one-way hash, never the password itself | At sign-up |
| Telegram user ID, username, display name | Linking your account to the Telegram bot and delivering signals to you there | If you connect Telegram |
| Crypto wallet address | Paying out withdrawals you request | If you register one |
| Exchange API key and secret | Placing orders on your own exchange account. Stored encrypted | If you enable automated trading |
| Exchange UID | Verifying that the account was opened through our referral link, and support | If you register a bot account |
| Trading and bot activity | Showing your history, calculating results, diagnosing faults | While automation runs |
| Points, referral and tier records | Running the points system and referral rewards | Throughout |
| Usage and technical data — IP address, approximate region, browser/device type, timestamps, error logs | Security, abuse prevention, debugging, basic usage statistics | Automatically |
| Support messages | Answering you and keeping a record of the issue | If you contact us |
What we do not collect. We do not require your legal name, government ID, passport, national ID number, home address, date of birth, phone number, bank account, or payment card. We do not run identity verification (KYC) on the Service, and we do not ask you to upload identity documents. Please do not send us any of these — if you do, we will delete them.
We do not knowingly collect any special-category data (such as health, biometric, religious, or political information). Please do not send us any.
Create keys with trading permission only. Never enable withdrawal, transfer, or wallet permissions on a key you give us. Where your exchange supports IP binding, bind the key to the address we show you on the registration screen.
You can revoke the key at your exchange at any time. That takes effect immediately and stops all automated activity — it is the fastest and most reliable way to cut access, faster than asking us.
Where we rely on consent, you can withdraw it at any time; that does not affect processing already carried out.
Signals and AI summaries are generated automatically. If you enable automated trading, orders are placed automatically according to the settings you chose. These processes act on market data and your settings — they do not profile you or make decisions about you as a person, and they produce no legal or similarly significant effect on you other than the trades you asked the system to make on your behalf. You can turn automation off at any time, and revoking your exchange API key stops it immediately.
We do not sell your personal data, and we do not share it for third-party advertising. We share only what is needed, with:
Referral relationships are visible in a limited form: someone who referred you can see that you joined and the reward activity connected to it. They cannot see your email address, wallet address, API keys, balances, or trading history.
The Service is operated and hosted outside your country in most cases, and our providers operate globally. Using the Service means your data may be processed in countries whose data-protection laws differ from your own. Where required, we rely on appropriate safeguards such as standard contractual clauses with our providers.
After account closure we delete or anonymise what we no longer need. During beta we may reset test data.
We use encryption in transit, encryption at rest for API secrets, hashed passwords, access controls, and restricted administrative access. No system is perfectly secure, and we cannot guarantee absolute security. Use a strong, unique password, keep your Telegram account secure, and grant your exchange keys the minimum permissions needed.
If a breach affects your data and poses a significant risk to you, we will notify you and any required authority as the law requires.
Depending on where you live, you may have the right to:
To exercise any of these, email support@nocappov.com from the address registered on your account. We aim to reply within 30 days. We may ask you to confirm control of the account before acting on a request. We do not charge for these requests, and we will not treat you differently for making one.
We use browser storage for essential purposes only: keeping you signed in, remembering your interface state, and basic security. We do not use advertising cookies or third-party tracking pixels for advertising. Clearing your browser storage signs you out and resets those preferences.
The Service is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has given us data, contact us and we will delete it.
We may update this policy. The version in force is the one published here, with its effective date at the top. For material changes we will give reasonable notice through the Service where practical.
See also our Terms of Service.
nocappov · Privacy Policy v1.0 · 9 September 2026