Fortuna (the "Service") values members' personal data and complies with applicable laws including the Personal Information Protection Act. This policy explains what personal data the Service collects, uses, retains, provides, and destroys.
1. Personal Data Collected
Required items (at sign-up)
- Email address
- Password (stored hashed; no plaintext storage)
Automatically collected during use of the Service
- Trade inputs (coin, entry price, stop-loss, target, account, risk, etc.)
- AI research results and trade outcome records
- Access IP, browser information, access time (cookies/session)
Upon paid payment (where applicable)
- Payment identifier (issued by the payment processor; no direct storage of card numbers)
- Payment receipt information (business information when a tax invoice is requested)
Optional items
- Telegram chat ID, Discord webhook URL (when notifications are used)
2. Purpose of Collection and Use
- Member identification, account management, identity verification
- Generating AI research results and storing trade records
- Processing Paid Plan payments and refunds
- Responding to customer inquiries
- Statistical analysis to improve the Service (in a form that cannot identify individuals)
- Fulfilling statutory obligations
3. Retention and Use Period
- Member information: until the member closes their account. Permanently deleted immediately upon closure and removed from backups within 30 days.
- Payment records: 5 years under the Act on Consumer Protection in Electronic Commerce
- Access logs: 3 months under the Protection of Communications Secrets Act
4. Provision to Third Parties
The Service does not provide members' personal data to third parties. The following are exceptions, however.
- When the member has consented in advance
- When required by law or upon a lawful request by an investigative agency
5. Entrustment of Processing
For stable operation, the Service entrusts some tasks to external processors.
- Supabase Inc. — database and user authentication (storage location: AWS Tokyo/Seoul regions)
- Vercel Inc. — web service hosting
- Anthropic PBC — AI research API (zero data retention enabled; analysis request data is not used for training)
- Payment processor (planned: Stripe, Toss Payments, etc.) — payment processing
6. Member Rights
Members may exercise the following rights at any time.
- Request to access, correct, or delete personal data
- Request to suspend processing
- Withdraw consent and close the account (by contact form or email request)
- Right to data portability (download your own data in a processable form)
7. Security Measures
- One-way hashed password storage (bcrypt, etc.)
- Per-user data isolation via database Row-Level Security
- HTTPS applied across the entire path
- Minimization of access rights and retention of access logs
8. Use of Cookies
The Service uses cookies to maintain login sessions and improve the user experience. Members may refuse cookie storage in their browser settings, but in that case some features such as login may be limited.
9. Personal Data Protection Officer
For inquiries about personal data processing, please contact us below.
- Email: privacy@alphagate.app
- General inquiries: Contact page
10. Changes to This Policy
This policy may be revised in accordance with changes in law or the Service's policies, and notice will be given from 7 days before the effective date.