SIGMA / PRIVACY
Privacy policy · what we collect and why
// legal // privacy policy

Privacy Policy

Sigma runs on deliberately little of your data. The whole model: your email identifies your subscription, Stripe handles your card so we never see it, and your watchlist never even leaves your browser. This page lists everything collected, why, who else touches it, and how to have it deleted.
Effective date: August 6, 2026
Operator: Americana Invests (sole proprietorship), doing business as Americana Invests / Sigma
Contact: americanacrypto@gmail.com

01What we collect

DataWhat it is & why we have it
Email addressYour subscription identity. Used for login/access, billing receipts, service notices, and support. It's the one piece of contact data Sigma keeps.
Billing — via StripePayments run entirely on Stripe. Your card number never touches Sigma's servers and we cannot see it. We keep only what Stripe reports back: subscription status, invoice/charge history, and similar billing metadata tied to your email.
API key hashWe store your API key only as a SHA-256 hash labeled by your email. We can verify your key when you use it, but we cannot read or recover the key itself — lost keys are reissued, not recovered.
Server logs / IPStandard request logs (IP address, timestamp, endpoint) kept for rate limiting, abuse prevention, and debugging. Not used to profile you.
Discord user IDOnly if you link your Discord account for members-only role sync. We store the ID to grant/revoke the role; unlink it and it goes.
Support emailIf you email support, we keep the correspondence so we have context next time.

02What we don't do

03Cookies & your browser

A trust point worth spelling out: your watchlist lives in your browser's localStorage, on your machine. It is never transmitted to Sigma's servers — we genuinely cannot see which tickers you watch.

The app sets no advertising or analytics cookies. It sets exactly one functional cookie: sigma_s, a signed member-session token created when you log in with your access key. It exists so you stay signed in (up to 30 days), it is HttpOnly and never readable by page scripts, and it contains no personal information — only a hashed reference to your access key. Log out and it is deleted.

04How we use what we have

05Third parties that touch data

PartyWhat they get
StripePayment processing: your card and billing details, under Stripe's own privacy policy. This is the only place your payment data lives.
DiscordOnly if you link it: role assignment on the members-only server, under Discord's own terms and privacy policy.
Hosting providerRuns the servers, so requests (and therefore IPs/logs) pass through its infrastructure. Hostinger (VPS hosting).
Email providerDelivers receipts and service notices to your address. Stripe sends billing emails; support correspondence runs through Google (Gmail).
Market-data providersSupply the price data Sigma analyzes. They receive nothing about you — traffic to them carries no subscriber data.

We disclose data beyond this list only if legally compelled (e.g., a valid legal request), and we keep no partners beyond those needed to run the service.

06Retention

07Deletion & your choices

08Security

Proportionate and honest: traffic is encrypted in transit (HTTPS), API keys are stored only as hashes, card data is outsourced to Stripe entirely, and the amount of personal data held is kept deliberately small — the best protection for data is not holding it. No system is unbreakable; if a breach ever affects your data, we'll notify you by email as required by law.

09Children

The service is for adults: 18+. We don't knowingly collect data from anyone under 18; if that happens, we delete it.

10Changes to this policy

If this policy materially changes, we'll email you before the change takes effect and update the effective date above. Continued use after that date means you accept the updated policy.

11Contact

Privacy questions, deletion requests, anything: americanacrypto@gmail.com.

Related: Terms of Service