ProbaAIJoin the waitlist

Privacy Policy

Effective 11 October 2026 · Version 2026-10-11

1. Who is responsible for your data

The controller of your personal data is ProbaAI (Vincent Reynders), established in Bulgaria (EU). Contact for all privacy questions and requests: support@probaai.com. We process personal data under the EU General Data Protection Regulation (GDPR) and the Bulgarian Personal Data Protection Act. This policy is governed by Bulgarian law.

2. What data we collect

  • Account data: your email address, a one-way hash of your password (we never store the password itself), and, if you turn on two-factor login, your 2FA secret and hashed recovery codes.
  • Bybit details: your Bybit UID, and the trade-only API key and secret you connect, stored encrypted. We refuse keys that can withdraw or transfer funds.
  • Trading data from Bybit: through your key we read your account balance and equity, open positions, orders, executed trades, fees, funding and closed profit and loss, and we place and close the trades we copy.
  • Plan and payment data: your plan, invoices, amounts, the receiving wallet address and the blockchain transaction hashes (tx IDs) of your USDT payments. Blockchain transactions are public by nature.
  • Technical data and logs: IP address, browser user agent, login and session times, security events (e.g. failed logins), and an audit log of actions on your account.
  • Communication data: emails you send us and emails we send you, including your notification settings.
  • Marketing consent: whether you agreed to receive updates and offers, and when.
  • Waitlist data: email, optional Bybit UID, preferred plan and referral information.

3. Why we use it and on what legal basis

  • Providing the service (account, copying trades, dashboards, alerts you switch on, reports): performance of our contract with you (Art. 6(1)(b) GDPR).
  • Payments, invoicing and accounting: contract and our legal obligations under Bulgarian accounting and tax law (Art. 6(1)(b) and (c)).
  • Security, fraud and abuse prevention, keeping logs and protecting accounts: our legitimate interest in a secure service (Art. 6(1)(f)).
  • Checking your referral for the FREE plan: contract (Art. 6(1)(b)).
  • Marketing emails: only with your consent (Art. 6(1)(a)), which you can withdraw any time with the unsubscribe link or in your account.
  • Service and account emails (verification, password reset, payment and security notices): contract and legitimate interest.

We do not sell your data, do not use it for advertising profiles and do not make decisions about you that have legal effects based solely on automated processing. Trading decisions are made by the desk for all members alike; your account copies them.

4. How long we keep it

  • Account, Bybit and trading data: while your account is open. After you delete your account we stop copying and delete these data within 30 days. Your API key is deleted immediately when you remove it or close your account.
  • Payment and invoice records: 10 years, as required by Bulgarian accounting law.
  • Logs, session and security records: up to 12 months.
  • Waitlist data: until you sign up, ask us to remove you, or 24 months after you joined, whichever comes first.
  • Marketing consent records: as long as the consent applies, plus 3 years as proof of consent.

5. Who processes data for us

  • Luxvps: hosts our server (EU) where the application and database run.
  • Namecheap (Private Email): sends and receives our email (support@probaai.com) and provides our domain.
  • Bybit: the exchange where your account is held. We send your trades to Bybit and read your account data through your API key. Bybit is an independent controller of the data you give it under its own privacy policy, and may process data outside the EU.
  • Public blockchain services (e.g. TronGrid) to check incoming USDT payments; they receive only public wallet addresses.

Our processors act only on our instructions under data processing terms. Where data leave the EU/EEA, we rely on adequacy decisions or the EU Standard Contractual Clauses.

6. Your rights

You have the right to access your data, to correct it, to have it erased, to restrict or object to processing (including at any time to processing based on legitimate interest), to data portability, and to withdraw consent at any time without affecting earlier processing. To exercise a right, email support@probaai.com from your account's email address; we answer within one month. You can also delete your account from My account.

You have the right to lodge a complaint with a supervisory authority, in particular the Commission for Personal Data Protection (CPDP), Sofia, Bulgaria, www.cpdp.bg, or the authority in your EU country of residence.

7. Cookies

We use one strictly necessary cookie, hgm_session, to keep you logged in (HttpOnly, Secure, SameSite=Strict, expires after 12 hours or when you log out). We use no analytics, advertising or tracking cookies, so no cookie consent banner is needed.

8. Security

All traffic uses HTTPS. Passwords are stored as strong one-way hashes; API keys and secrets are encrypted at rest; 2FA is available for every account. API keys must be trade-only and should be IP-restricted to our server, so they cannot withdraw funds and are useless elsewhere. Access to member data is limited to the operator. No system is perfectly secure; if a breach affects your data we will inform you and the CPDP as the GDPR requires.

9. Children

ProbaAI is for adults only (18+). We do not knowingly collect data from minors.

10. Changes

We may update this policy. The version and effective date are at the top; for material changes we will email members before they take effect.

Home · Risk Disclosure & Terms · FAQ · support@probaai.com