VoltaVOLTA
MarketHow it worksSign in

Privacy Policy

What we store, why we store it, who else sees it, and how to get rid of it.

Last updated 17 August 2026

Draft — not yet reviewed. This document is a working draft. It has not been reviewed by a lawyer and the entity and jurisdiction details are still placeholders. Do not rely on it, and do not publish this site to real users until it has been checked by a qualified adviser in the relevant jurisdiction.

This policy describes how [Legal entity name] (“we”) handles personal data in the Volta web application, the browser extension and the Telegram delivery integration.

1. The short version

We hold an email address, the records needed to keep you signed in, and the metadata of chart calls you asked for. We do not run advertising, we do not sell data, and we do not load third-party analytics or tracking scripts. The one meaningful exposure is that chart images you submit are sent to Google for analysis — see section 4, which you should read before using the extension.

2. What we collect, and why

Account

When you sign up we store your email address, an optional display name, and the date the account was created. The email address is the account identity: it is how sign-in links reach you, and it is the only thing we require.

Signing in

Volta uses emailed sign-in links rather than passwords. For each request we store a SHA-256 hash of the link token, its creation, expiry and consumption times, the IP address the request came from, and the browser user agent string.

The token itself exists only in the email — we hold a hash, so a copy of our database does not let anyone sign in as you. The IP address and user agent are retained to investigate abuse of the sign-in endpoint, such as someone requesting links for an address that is not theirs. They are not used to build a profile of you and are not shared.

Sessions and extension tokens

A signed-in session is a row holding a hash of the session token, the browser user agent, and when the session was created, last seen, expires and was revoked. The session is carried by a single cookie named volta_session, which is HttpOnly (page scripts cannot read it), SameSite=Lax, and expires after 30 days.

Extension tokens are stored the same way: a hash, plus the last four characters so you can tell one token from another in the interface, a label, and usage timestamps. We cannot reconstruct a token from what we store.

Telegram delivery

If you connect a Telegram bot, we store the bot token encrypted at rest (AES-256-GCM, key derived with scrypt), along with the channel identifiers you nominate and a record of what was delivered and when. The token is never written to logs and is never returned by our API, including to you — it can be replaced but not read back.

That token is a credential for a bot you own. Anyone holding it can post as that bot, which is why it is treated as a secret rather than as configuration.

Chart calls

When you ask for a call on a chart, we record the broker, the symbol, whether the instrument is OTC, the timeframe, the payout, which model answered, the direction it returned and the number it stated.

We do not store the image. It is held in memory for the duration of one request and is not written to disk or to the database.

3. Cookies

One cookie, volta_session, described above. It is strictly necessary to keep you signed in and there is no version of the signed-in product that works without it. We set no analytics, advertising or cross-site cookies, so there is no consent banner because there is nothing to consent to.

4. What we send to other companies

Read this before using the extension. Chart analysis is performed by Google’s Gemini models. The screenshot you submit is transmitted to Google’s Generative Language API, and it is processed under Google’s terms, not ours.

One of the two analysis modes sends a screenshot of your entire browser window, not a cropped chart. Anything else visible in that window at the time — other tabs’ contents in view, account balances, personal information, open documents — is included in what is sent. Close or hide anything you would not hand to a third party before invoking it.

Google (Gemini / Generative Language API)
Receives chart screenshots and the recent price context sent with them, for one request each. We do not retain the images; Google’s own retention is governed by its API terms.
Our email provider
Receives your email address in order to deliver sign-in links. Nothing else is sent.
Our database and hosting provider
Stores everything in section 2 on our behalf, in the European Union (eu-west-1). They do not use it for their own purposes.
Telegram
Receives the messages we deliver on your instruction, only if you have connected a bot.
Google Fonts
The interface loads two typefaces from Google’s font CDN, which means your browser makes a request to Google carrying your IP address and user agent when a page loads. No cookie is set by it.

We do not sell personal data, we do not share it for advertising, and we do not use it to train models.

5. How long we keep it

  • Sign-in links expire shortly after they are issued, and are marked consumed the first time they are used.
  • Sessions expire 30 days after they are created, or immediately when you sign out, which revokes the row on the server rather than only clearing your cookie.
  • Account data and call history are kept for as long as the account exists.
  • Signals and their outcomes are part of a verification chain that is published in aggregate and is designed so that no entry can be altered after the fact. Deleting your account unlinks it from you, but the chain itself is not rewritten.

6. Your rights

Depending on where you live you may have the right to access a copy of your data, correct it, have it deleted, restrict or object to how it is used, and receive it in a portable format. To exercise any of these, write to [privacy@example.com].

Deleting your account removes the account row, and the sessions, extension tokens, Telegram bot records and channel configuration attached to it are deleted with it. If you are in the UK or EU and think we have handled your data badly, you can also complain to your national data protection authority.

7. Security

Sign-in tokens, session tokens and extension tokens are stored only as hashes. Telegram bot tokens are encrypted at the application layer before they reach the database. The session cookie is HttpOnly and the API refuses cross-site POST requests.

No system is perfectly secure, and this one is under active development. If you find a vulnerability, please report it to [privacy@example.com] before disclosing it publicly.

8. Children

Volta is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

9. Changes

If this policy changes materially we will update the date at the top and, where the change affects how we use data you have already given us, tell you by email before it takes effect.

10. Contact

[Legal entity name]
[Registered address]
[privacy@example.com]

Questions about this document: [contact@example.com]

VoltaVOLTA

Measured trading intelligence. Every instrument screened for whether it is a real market or a generated feed, every signal committed to a chain anyone can recompute.

Product

SignalsMarketRecords

Delivery

Browser extensionTelegram

Start here

How it worksSign in

Volta · probabilistic decision support, not financial advice · trading carries a real risk of loss

Privacy·Terms·© 2026 Volta