This Privacy Policy explains how boti collects, uses, stores, shares, and protects personal data when you visit boti.live, create or use an Account, purchase access, or use the personal workspace and related features (the "Service").
boti is responsible for the personal databases used to operate the Service. Personal data is handled under Argentina's Personal Data Protection Law No. 25,326, its implementing and complementary rules, and other applicable Argentine requirements.
1. Scope and acceptance
This Policy applies to boti's website, authenticated features, account management, payments, and communications. It does not govern independent websites or services reached through external links.
By providing personal data or using the Service, you acknowledge this Policy. Where consent is required, boti will request it in a clear manner. You may withdraw consent where the processing depends on consent, without affecting processing already performed or processing supported by another lawful basis.
2. Personal data boti collects
- Account data: email address, a protected lookup value used to locate the Account, password hash when password sign-in is used, and account creation and status information. Email addresses are encrypted at rest.
- Google sign-in data: verified email address only. boti does not store the profile name Google returns, nor the Google access token, once the sign-in flow has finished.
- Consent and membership data: the versions of the Terms and Privacy Policy accepted, acceptance time, trial start, plan status, access period, and activation information.
- Personal workspace data: watchlist symbols and groups, notes, tags, journal entries, trade dates, entry and exit values, alert references, and activity records that you choose to save.
- Payment data: boti order identifiers, the payment provider's payment and invoice identifiers, payment status, quoted and paid amounts, currencies, access granted, timestamps, and limited provider callback or reconciliation records. boti does not receive or store payment-card details, exchange credentials, wallet private keys, or seed phrases.
- Technical and security data: essential session and CSRF cookies, request timestamps, visited routes, browser or device information, IP address and similar request metadata that may appear in hosting, proxy, security, or server logs.
- Communications: information you provide when requesting support, reporting a problem, exercising a privacy right, or otherwise contacting boti.
boti does not intentionally request sensitive personal data. Do not enter sensitive data, third-party confidential data, passwords, private keys, or seed phrases in notes or journal fields.
3. Sources of personal data
boti receives personal data directly from you, automatically from your browser and the Service infrastructure, from Google when you choose Google sign-in, and from the public blockchain network when you report an on-chain payment. Market and economic data displayed by boti is not used to identify Users.
4. Why boti uses personal data
boti uses personal data to:
- create, authenticate, secure, and administer Accounts;
- provide the selected access tier, alerts, personal workspace, and saved preferences;
- start and calculate trials, process subscription access, reconcile payments, and answer payment issues;
- send password resets and necessary account, security, policy, and service communications;
- send news and product emails, only where you have given separate, optional consent at signup or in your profile, and never as a condition of using the Service;
- prevent fraud, abuse, unauthorized access, duplicate trial misuse, and attacks on the Service;
- diagnose failures, maintain availability, support Users, and improve reliability and usability;
- maintain records of consent and enforce the Terms; and
- comply with valid obligations, requests, and dispute or accounting requirements.
boti does not sell personal data. boti does not currently use personal data for third-party behavioral advertising.
You can withdraw consent for news and product emails at any time, without giving a reason and without affecting your Account or your access: use the unsubscribe link included in every such email, or turn them off under Email preferences in your profile. Withdrawal takes effect immediately. It does not stop the necessary account, security, policy, and service communications described above, which boti sends because you hold an Account, not because you consented to marketing.
5. Grounds for processing
Depending on the purpose and the circumstances, boti processes personal data with your consent, to provide the Service or take steps you request before using it, to comply with applicable obligations, and to protect legitimate security, fraud-prevention, support, and operational interests to the extent permitted by Argentine law.
Required account and security data must be provided for authenticated features to work. If you do not provide it, boti may be unable to create or maintain an Account. Optional workspace fields may be left blank.
6. When personal data is shared
boti may provide only the data reasonably necessary to:
- hosting, database, cache, security, infrastructure, and email providers that operate the Service for boti;
- Google, when you choose Google sign-in;
- the public blockchain network over which you send a payment, and any payment processor identified at checkout;
- professional operational providers that assist with incident response, accounting, fraud prevention, or support, subject to confidentiality and purpose restrictions;
- a successor or acquirer involved in a reorganization or transfer of the Service, subject to applicable safeguards; and
- a competent authority or other recipient when disclosure is required or permitted by applicable law, or is necessary to protect Users, boti, or another person's rights and security.
External links to Telegram, books, articles, market sources, or other websites do not transfer Account data from boti merely because the link is displayed. If you follow a link, the destination may collect data under its own policy.
7. International processing and transfers
Some service providers may process or store information outside Argentina. Where personal data is transferred internationally, boti will use providers, contractual measures, consent, or another mechanism permitted by Law No. 25,326 and applicable regulations, taking into account the destination and the nature of the processing.
8. Cookies and similar technologies
boti uses cookies that are necessary to keep Users signed in, protect forms against cross-site request forgery, preserve secure sessions, and operate requested features. Blocking these cookies may prevent login or authenticated features from working.
boti does not currently use advertising or cross-site behavioral tracking cookies. If optional analytics or advertising technologies are introduced, this Policy and the relevant consent controls will be updated before they are used where consent is required.
9. Security
boti applies technical and organizational measures appropriate to the Service and the data handled. These include password hashing, encrypted storage of Account email addresses, protected lookup values, access controls, CSRF protection, secure session handling, payment callback verification, backups, logging, and restricted administrative access.
No internet service can guarantee absolute security. Users must protect their passwords and devices and should promptly report suspected unauthorized Account access.
10. Retention and account deletion
Account information, membership information, saved watchlists, notes, journal entries, activity records, and consent records are generally retained while the Account exists and are removed from the active application database when the User permanently deletes the Account from Profile.
Active sessions associated with the Account are also removed during deletion. Residual copies may remain temporarily in protected backups or rotating infrastructure logs until their normal deletion cycle ends.
Payment and reconciliation records may be retained after Account deletion and de-linked from the deleted Account where necessary for accounting, blockchain-payment reconciliation, fraud prevention, disputes, security, or an applicable retention obligation. Other information may be retained when required by law or necessary to establish, exercise, or respond to a claim. When retention is no longer necessary, data is deleted, anonymized, or securely isolated.
11. Rights under Argentine data-protection law
Subject to Law No. 25,326 and its applicable exceptions, you may request information about databases containing your personal data and may exercise rights of access, rectification, updating, suppression, or confidentiality. Exercising these rights is free of charge under the conditions established by applicable law.
Requests for access will be answered within the period required by Argentine law, currently no more than 10 calendar days. Valid requests for rectification, updating, or suppression will be addressed within the legally required period, currently no more than 5 business days. Suppression may not apply where data must be retained to protect legitimate third-party rights or comply with an applicable obligation.
12. How to exercise your rights
You may permanently delete your Account directly from the Account controls on the Profile page. For access, correction, updating, suppression, confidentiality, consent withdrawal, or another privacy request, contact the privacy address displayed on this page.
The request should identify the Account email, the right being exercised, the data concerned, and a method for receiving the response. boti may request reasonable proof of identity before disclosing or changing data so that another person cannot misuse your rights.
If a response is not provided within the applicable period, or you consider the response insufficient, you may submit a complaint to Argentina's Agency for Access to Public Information (Agencia de Acceso a la Informacion Publica, AAIP), the enforcement authority for Law No. 25,326. Information is available at https://www.argentina.gob.ar/aaip.
13. Children
The Service is intended for persons aged 18 or older. boti does not knowingly create Accounts for children. If you believe a child has provided personal data, contact the privacy address so the situation can be reviewed and the data removed where appropriate.
14. Changes to this Policy
boti may update this Policy to reflect changes in features, providers, security practices, or applicable requirements. The current version and update date will remain available on this page. Material changes will be communicated through the Service or by Account email when appropriate. Renewed consent will be requested where required.
15. Contact
Questions or requests about personal data may be sent to the boti privacy address displayed on this page. The operator and jurisdiction information shown there identifies the responsible party for this Service.