Legal
Privacy Policy
What data Axyra collects, why, and your rights. Axion is local-first: your project data stays on your machine.
Last updated: June 14, 2026
[…] items are placeholders.1. Who we are
[Axyra legal entity name] ("Axyra", "we") is the data controller for the limited personal data described here. Contact: [privacy@axyra.one].
2. Our local-first principle
Axion is a desktop application. Your projects, datasets, indicators, models, and connector credentials are stored locally on your device in a sealed vault and are not sent to us. Credentials never leave your machine. We do not receive your market data or trading activity.
This policy covers the account, license, payment, and website data we do process — not your local project contents.
3. Data we collect
- Account data: your email address, optional name, and authentication identifiers (including a Google account identifier if you sign in with Google).
- License and device data: your entitlement (plan, packs), and an opaque device fingerprint and optional device label used to enforce activation limits.
- Payment data: handled by our Merchant of Record. We receive order and subscription metadata (such as product, status, and a customer reference) but not your full card details.
- Trial data: your email and an opaque device fingerprint, to enforce one trial per person and per device.
- Website/technical data: standard server logs (such as IP address and request metadata) used for security, abuse prevention, and rate limiting.
4. Why we use it (legal bases)
- To provide the Service: create your account, issue and validate your license, and manage devices (performance of a contract).
- To process payments and prevent fraud (contract and legitimate interests).
- To send transactional email such as verification and password-reset links (contract).
- To secure the Service and prevent abuse, including rate limiting (legitimate interests).
- To comply with legal obligations such as tax and accounting.
We send transactional emails needed to operate your account. We do not sell your personal data.
5. Sharing and processors
We share data only with service providers that help us run the Service, under contract: our Merchant of Record (LemonSqueezy (Lemon Squeezy LLC)) for payments, our hosting and database providers, and our email provider. We may disclose data where required by law.
6. Signing in with Google
If you choose "Sign in with Google", Google provides us with a signed identity token. From it we receive the email address, basic profile information (such as your name), and the Google account identifier for the Google account you select. We use this data solely to create or sign you in to your Axion account.
Axion's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only basic sign-in scopes (email and profile), do not access any other Google data, do not use this data for advertising, and do not transfer it to others except as needed to provide and secure the Service.
Signing in with Google is optional — you can use an email and password instead. You can revoke Axion's access at any time from your Google Account security settings.
7. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers. [Confirm transfer mechanism with counsel.]
8. Retention
We keep account and license data for as long as your account is active and as needed to provide the Service, then for the period required for legal, tax, and accounting purposes. Verification and reset tokens are short-lived and single-use. Server logs are retained for a limited period.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, contact [privacy@axyra.one]. You may also have the right to lodge a complaint with your local data-protection authority.
10. Cookies
The website uses strictly necessary cookies, including an authentication session cookie set after you sign in. [Add detail here if analytics or non-essential cookies are introduced, with consent where required.]
11. Children
The Service is not directed to children and is intended for users who can form a binding contract. We do not knowingly collect data from children.
12. Changes
We may update this policy and will post the new version here with a revised date; material changes will be notified where appropriate.
13. Contact
Privacy questions: [privacy@axyra.one]. [Axyra legal entity name], [registered business address].