MacroView · legal
Privacy Policy
Last updated: 2026-07-30
1. Controller
CuriosityDistrict, Bukovacka cesta 174, 10000 Zagreb, Croatia — reachable at contact@macro-view.com — is the data controller for macro-view.com.
2. What we store, and why
- Account: when you sign in with GitHub or Google we store the provider's user id, your display name, email address and avatar URL, so the account works and receipts can reach you (contract performance).
- Session: a functional, HttpOnly session cookie keeps you signed in for up to 30 days. It is the only cookie we set.
- Settings & content: your theme, watchlists, alert-notification preferences and paper-trading simulator positions are stored on your account row so they follow you across devices.
- API keys: we store only a hash of your API key — the plaintext is shown once at mint and never kept.
- Billing: your Stripe customer id and subscription status. Card details go directly to Stripe and never touch our servers.
- Push notifications (optional, paid plans): if you enable background alerts we store your browser's push-subscription endpoint and its delivery keys (consent — unsubscribe anytime in Settings).
- Logs: our host (Cloudflare) processes connection metadata (IP address, user agent) to serve and protect the site; we keep only short-lived operational logs (legitimate interest: security and abuse prevention).
There are no advertising trackers, no cross-site tracking and no third-party analytics scripts. Interface preferences may also live in your browser's localStorage, which never leaves your device.
3. AI assistant
Messages you type into the MacroView AI assistant, together with the market context needed to answer them, are sent to Google's Gemini API to generate the reply. Don't put personal data into assistant chats; conversations are not used to train our systems.
4. Processors and recipients
- Cloudflare — hosting, edge network and storage.
- Stripe — payments, invoicing and VAT.
- Google (Gemini API) — assistant replies (section 3).
- GitHub / Google sign-in — the OAuth handshake; each acts as its own controller for what happens on their side.
These processors may process data outside the EEA; where they do, the transfer is covered by an adequacy decision (e.g. the EU–US Data Privacy Framework) or standard contractual clauses. We do not sell personal data to anyone.
5. Retention
Account data is kept while the account exists; sessions expire after 30 days; operational logs are short-lived. Billing records are retained as long as tax law requires. To delete your account and its data, email contact@macro-view.com from the account's address — deletion is currently handled manually and confirmed by reply.
6. Your rights
Under the GDPR you can request access to, correction of, deletion of, or a portable copy of your personal data, object to processing based on legitimate interest, and withdraw consent (e.g. push notifications) at any time. Write to contact@macro-view.com. You also have the right to complain to a supervisory authority — in Croatia, the Personal Data Protection Agency (AZOP, azop.hr).
7. Changes
We may update this policy; the "last updated" date above changes when we do, and material changes will be announced on the site.