Legal
Privacy Policy
Last updated: August 26, 2026
Overview
This Privacy Policy explains how Coinlee handles information when you use our crypto portfolio, dashboard, watchlist, news, and AI-assisted features.
Coinlee is designed as an informational workspace. We do not ask for private keys, wallet seed phrases, or exchange login credentials.
Information we collect
- Account information handled through Clerk, such as authentication identifiers and basic profile details you provide.
- Portfolio information you choose to enter, such as portfolio names, holdings, transactions, notes, risk preferences, watchlist items, and settings.
- Usage and technical information needed to operate the service, such as device, browser, session, logs, and error information.
- Prompts, context, and related inputs you submit to AI features such as Terminal, Analyst, portfolio build, or exit strategy tools.
How we use information
- To provide and secure your account and product experience.
- To save preferences, portfolio data, watchlists, transaction history, and risk/profile settings.
- To generate AI-assisted outputs when you intentionally use AI features.
- To monitor reliability, fix bugs, prevent abuse, and improve the service.
Portfolio and financial data
Portfolio and transaction data you enter may be stored in our database and/or in your browser localStorage depending on the feature. This data is used to show holdings, performance, allocation, activity, and risk context.
Coinlee is not a wallet, exchange, broker, or custodian. You should not enter private keys, seed phrases, API secrets, or exchange credentials.
AI features and data use
When you use AI features, Coinlee may send your prompt and relevant app context to OpenAI or other AI providers so the feature can generate a response. This may include portfolio context, watchlist context, market context, or user-entered text.
Do not submit secrets, private keys, seed phrases, sensitive personal information, or confidential information to AI features.
Cookies, browser storage, and downloaded files
Coinlee and its providers may use cookies, browser storage, and localStorage for authentication, preferences, session behavior, theme settings, portfolio workspace state, and product functionality.
Browser-held data—including local Portfolio caches, Watchlist data, drafts, preferences, Terminal history, and similar local state—may remain separately on each device and browser until cleared. Account deletion cannot automatically erase browser storage or downloaded exports.
Third-party providers
Coinlee uses third-party services such as Clerk for authentication, OpenAI for AI features, Vercel for hosting, Supabase/Postgres for database storage, and market data or news APIs for crypto information. These providers may process data as needed to provide their services.
Account deletion and data retention
Deleting your account permanently deletes the active Coinlee application records tied to it: the AppUser record, owned Portfolios, transactions, Risk Profiles, Activity history, Watchlist Notes, and attachment metadata.
Private attachment objects are deleted asynchronously. Cleanup is bounded and retried, so removal may require additional time.
Coinlee retains a pseudonymous deletion record solely to prevent a deleted identity from recreating server records. This security record is not anonymous and is not used as an active account.
Limited copies may remain temporarily in backups, security logs, or service-provider systems according to their applicable retention policies. Coinlee does not promise immediate erasure from those systems or claim verified provider deletion timing.
Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict certain personal information. Contact us if you want to make a privacy request.
Security and administrator access
We use reasonable technical and organizational safeguards for an MVP-stage SaaS product, but no online service can guarantee complete security. Keep your account credentials secure and do not enter crypto secrets into Coinlee.
Authorized infrastructure administrators can technically access server-side plaintext application data when required for operation, security, or support. Coinlee is not end-to-end encrypted. This access is restricted and does not allow ordinary users to access another user’s data.
Contact
Contact: coinlee.app@gmail.com