← Oscilla Lab
Privacy Policy
Version 0.3 · Effective 23 August 2026 · Oscilla Lab is operated by TOKEN ESTATE LLP (Singapore)
1. What we collect
- Account: your email address, and — if you sign in with Google or GitHub — the
identifier and email those providers share. We never see or store passwords.
- Usage records: your subscriptions, token balance and spend history, strategy
configurations and backtest results you create on the platform.
- Bridge & devices: a pairing token and an anonymous machine identifier for each
computer you pair (used to enforce your device limit). Optional: your Telegram chat id if
you link Telegram alerts.
- Technical logs: standard server logs (IP address, timestamps, requested pages),
kept briefly for security and debugging.
- Community price-agreement reports (optional, on by default): for each Library
strategy you subscribe to, OL Desktop compares your broker's prices against Oscilla Lab's
at the moments that listing entered, and sends us the result. What leaves your computer
is a handful of aggregate numbers — the median, worst and regular-hours gap, a sample
count, your broker's name and a fingerprint of the series — never a price bar, never a
quote, never anything you traded. These are shown on the listing, per broker, as a
distribution across reporting peers. You can switch this off at any time in OL Desktop's
live-trading settings; nothing else changes when you do.
2. What we deliberately do not collect
- Broker credentials and API keys never reach our servers. The bridge runs on your
computer and talks to your own broker gateway locally. Your broker's market data stays
there too: the optional price-agreement report above carries only aggregate differences,
and is designed so that no price can be reconstructed from it.
- Card details are handled entirely by Stripe, our payment processor. We receive
only a confirmation of payment, never your card number.
- Live positions synced to your phone travel through an end-to-end-encrypted relay:
our servers store and forward ciphertext they cannot read.
- Images you send the assistant are not stored. An attached image is held in
memory only for as long as it takes to read it, then discarded. It is never written to
our disks or database. We strip EXIF metadata (which can carry GPS coordinates, device
serial numbers and timestamps) by re-encoding the image before it is sent onward.
The one exception you control. Everything above is enforced by how the software
is built — except an image you choose to attach. If you screenshot a window showing your
balance, positions or account number and send it to the assistant, that information
reaches us and our AI provider, however briefly. Please crop it out, or describe the
problem in words instead.
3. How we use it
To operate the service: sign-in, subscriptions, signal delivery, licensing, alerts you
asked for, support, and fraud prevention. That is all. We do not sell or rent personal
data, we do not run third-party advertising, and we do not profile you beyond what the
features above require.
4. Third parties we rely on
- Stripe — payment processing.
- Resend — transactional email (sign-in links, alerts).
- Google / GitHub — optional single sign-on.
- Telegram — optional alerts, only if you link it.
- DeepSeek — powers the in-app assistant. Messages you send it, and the stored
conversation context, are transmitted there to generate a reply.
- Alibaba Cloud Model Studio (Qwen) — reads images you optionally attach to the
assistant. Used only when you attach one; no image is sent otherwise.
Each processes your data under its own privacy policy, only as needed to provide its
function to us.
5. Cookies
We use a session cookie to keep you signed in, and a referral cookie (30 days) if you
arrive via a referral link. No advertising or cross-site tracking cookies.
6. Retention & deletion
Account data is kept while your account is active. You may request a copy of your data
or deletion of your account at any time by emailing us; we will action it within 30 days,
except records we must keep for legal, tax or fraud-prevention reasons.
7. Security
HTTPS everywhere, encrypted position relay, minimal data collection, and access limited
to the operator. No system is perfectly secure; we notify affected users of any breach as
required by law.
8. Contact
Data questions or requests: hello@oscillalab.com.
This policy complies with Singapore's Personal Data Protection Act (PDPA). Material
changes will be announced on this page.
Terms of Service · Home