Privacy Policy

Last Updated: November 30, 2025

1. Introduction

This Privacy Policy explains how PLScaler ("Service," "we," "us," or "our") collects, uses, discloses, and protects your personal information. We are committed to protecting your privacy and complying with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and Singapore's Personal Data Protection Act (PDPA). This Policy applies to all users of the Service.

For questions or to exercise your rights, please visit our Support page and select "Privacy/Terms" as the category.

2. Information We Collect

We collect only the minimum data necessary to provide the Service, in line with data minimization principles.

Account Information (Necessary for Authentication)

  • Email address, name (optional), profile image (if using social login)
  • Nostr public key (if using Nostr authentication)

Portfolio and Strategy Data (User-Input, Optional)

  • Bitcoin holdings, transaction history, loan positions, yield product details
  • Strategy preferences and settings you provide
  • This data is stored locally on your device where possible and encrypted if synced to our servers

Technical Data (Automated for Security and Functionality)

  • IP address (for fraud prevention and compliance)
  • Browser type/version, device information, session logs
  • Legal acceptance timestamps

Payment Information (If Subscribing)

Processed by third-party providers (e.g., Stripe); we do not store your card details.

We do not collect sensitive personal data (e.g., racial origin, health) or cryptocurrency private keys/wallets.

3. How We Use Your Information

We use your information solely for the purposes described below:

  • To provide and maintain the Service, including generating Power Law analyses, volatility regimes, and portfolio tracking based on your inputs
  • To authenticate your identity and secure your account
  • To store and display your user-configured data (e.g., yield products and buffer settings)
  • To communicate Service updates, security alerts, or responses to your inquiries
  • To comply with legal obligations, such as audit trails or regulatory reporting
  • For internal analytics to improve the Service (anonymized/aggregated only)

We do not use your data for marketing, profiling, or automated decision-making that produces legal effects.

4. Legal Basis for Processing (GDPR/UK GDPR)

We process personal data based on:

  • Contractual Necessity (Art. 6(1)(b)): To provide the Service you requested
  • Legitimate Interests (Art. 6(1)(f)): For security, fraud prevention, and Service improvements (balanced against your rights)
  • Legal Obligation (Art. 6(1)(c)): For compliance with laws (e.g., tax reporting)
  • Consent (Art. 6(1)(a)): For non-essential communications (withdrawable anytime)

5. Data Sharing and Disclosure

We do not sell, rent, or share your personal information for marketing purposes. In the past 12 months, we have not sold or shared personal information as defined under CCPA/CPRA. Sharing is limited to:

  • Service providers (e.g., hosting via AWS, payments via Stripe) under strict data processing agreements
  • When required by law, subpoena, or governmental request
  • To protect our rights, safety, or property, or that of our users
  • In the event of a merger, acquisition, or asset sale (with notice to you)

For CCPA/CPRA: You can opt out of any future "sale" or "sharing" via our Support page (select "Privacy/Terms") or the "Do Not Sell/Share My Personal Information" link below.

6. Cookies and Tracking Technologies

We use only essential cookies necessary for the Service's core functionality:

  • Session cookies: For authentication and maintaining your login state
  • Security cookies: To prevent fraud and unauthorized access

We do not use advertising, analytics, or tracking cookies. No third-party trackers (e.g., Google Analytics) are employed. You can manage cookies via your browser settings, but disabling essential cookies may impair Service functionality.

7. Data Retention

We retain personal data only as long as necessary:

  • Account and portfolio data: For the duration of your active account plus 6 months (or longer if required by law)
  • Technical/log data: Up to 12 months for security audits
  • Legal records (e.g., consent timestamps): Up to 7 years for compliance

You may request deletion at any time; we will respond within 30–45 days (per GDPR/CCPA).

8. Your Rights

GDPR/UK GDPR Rights

Access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and withdrawal of consent. Exercise these rights via our Support page.

CCPA/CPRA Rights

Know (disclosure), delete, opt-out of sale/sharing, limit sensitive data use, and non-discrimination. Use the "Do Not Sell/Share My Personal Information" link or email. We respond within 45 days (extendable).

Other Jurisdictions

Equivalent rights under PDPA (Singapore) or similar laws. No fee for requests unless manifestly unfounded.

To opt out of any data processing or request deletion, please visit our Support page.

9. Data Security

We implement reasonable technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256 for stored data)
  • Access controls, multi-factor authentication, and regular vulnerability scans
  • Secure third-party processors compliant with ISO 27001/SOC 2
  • Incident response plan: We notify affected users of data breaches within 72 hours (GDPR) or as required by law

Despite these measures, no system is 100% secure; you use the Service at your own risk.

10. International Data Transfers

Your data may be transferred to and processed in Singapore or other countries. For transfers from the EEA/UK, we use Standard Contractual Clauses (SCCs) or equivalent safeguards approved by the European Commission. For adequacy decisions (e.g., Singapore), we rely on those frameworks.

11. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete it immediately and terminate the account. If you believe we have collected child data, please contact us via our Support page.

12. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be notified via email, in-app notice, or by updating the "Last Updated" date. Your continued use constitutes acceptance. Review this Policy regularly.

13. Contact Us

For privacy questions, rights requests, or complaints, please visit our Support page and select "Privacy/Terms" as the category.

For CCPA/CPRA: Use the "Do Not Sell/Share My Personal Information" link to opt out.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

We use essential cookies for authentication and session management only. No tracking or advertising cookies are used. By continuing to use this site, you accept our use of essential cookies. Learn more

PLScaler

Never Panic Sell Again

A decision-support tool that helps you plan for volatility, model scenarios, and make confident Bitcoin decisions based on the Power Law framework.

1
Assess Position
2
Model Scenarios
3
Execute with Clarity

Sign in with Google, GitHub, X, Apple, Email, or Nostr

Built for Bitcoiners

Power Law Tracking
Real-time fair value calculations with zone alerts and regime detection.
Portfolio Management
Lot-based tracking, loan monitoring, yield positions, and cash reserves.
Scenario Simulator
Model different strategies and stress-test decisions before committing.

PLScaler is an educational planning tool. Not financial advice.

© 2026 PLScaler. All rights reserved.

v1.0.0 • Last Updated: Nov 29, 2025, 07:56 PM UTC

We use essential cookies for authentication and session management only. No tracking or advertising cookies are used. By continuing to use this site, you accept our use of essential cookies. Learn more