1. What this covers
This describes what twoke collects when you use the platform at twoke.io, why, who else can see it, and how to get a copy or have it deleted. It covers the platform only — your exchange and your crypto wallet handle your data under their own policies.
The operating legal entity, its registered address and the applicable data-protection regulator are being finalised and are not yet named. Until then, contact enfo@twoke.io for anything in this document.
2. What we collect
Account and security data:
- your email address, and a hashed password if you set one;
- session records, and one-time email codes stored only as hashes with a short expiry;
- an audit record of security-relevant actions — role changes, exchange-credential additions and rotations, and any support impersonation;
- your IP address, used transiently for rate limiting and abuse prevention.
Exchange and trading data:
- your exchange API key, with the secret stored only in encrypted form, plus the venue, a label you choose, and whether the account is demo or live;
- positions, orders and executions that twoke opened on your account, each linked to the master decision that produced it;
- balance snapshots taken when sizing a trade, and the risk settings you configure.
Payment data: the wallet address you pay from, the on-chain transaction, and the plan, price and duration purchased.
Support data: anything you send us by email or WhatsApp.
3. What we never collect
twoke never asks for, receives or stores a wallet private key or seed phrase. Nothing in the product requires one: payments are signed in your own wallet and never leave it.
twoke does not need, and asks you not to grant, withdrawal permission on the exchange API key you connect.
There are no advertising cookies, no third-party analytics and no tracking pixels on this site. The only browser storage used is a session cookie for signing in, and a local preference for your light/dark theme and chart colours, which stays in your browser.
4. Why we use it
To operate the service you asked for: authenticating you, placing and managing trades on the exchange account you connected, sizing them against your balance and risk settings, and showing you what happened.
To keep accounts secure: verifying second factors, rate limiting, and keeping an audit trail of sensitive actions so that who did what is answerable.
To meet legal and financial recordkeeping obligations relating to subscriptions and trading activity.
5. Who else processes it
- Your exchange (Bybit or Binance) — receives the orders twoke places on your account, under your agreement with them.
- Our email provider — delivers sign-in codes and transactional email, and therefore processes your email address.
- Our cloud host and its key-management service — stores the encrypted data and holds the key that protects your exchange credentials.
- The Polygon network — see the next section.
twoke does not sell your data, and does not share it with advertisers or data brokers.
6. Payments are public and permanent
Subscription payments happen on Polygon, a public blockchain. The transaction, the wallet address it came from, the amount, and identifiers linking the payment to a subscription are visible to anyone and cannot be edited or deleted by us or by you. This is inherent to paying on-chain, not a choice twoke makes about your data.
If you would prefer that a wallet address not be publicly associated with a twoke subscription, pay from a wallet you keep separate for that purpose.
7. How long we keep it, and what deletion means
Deleting your account anonymises it and removes your connected exchange credentials. Trade and payment records are retained with your identity stripped from them, because keeping financial records is a legal obligation while keeping them attached to you is not.
This is stated plainly because it is the honest answer rather than the reassuring one: twoke cannot erase everything, and any platform handling subscription payments and trading history that claims otherwise should be questioned. On-chain payment data cannot be deleted at all — see section 6.
8. Your rights
From the Privacy section of your settings page you can:
- export your data — your account, subscriptions, connected accounts, trading history and security audit trail;
- request deletion, which anonymises the account as described above.
Both actions require a fresh code sent to your email, including the export. Exporting is gated deliberately: deletion is loud and you would notice it, whereas a silent download of everything about your account leaves the product working normally and gives you no reason to look.
To correct information, or to ask anything else about your data, email enfo@twoke.io.
9. How it is protected
Exchange API secrets are encrypted with AES-256-GCM. The key that protects them is held by a managed key service and exists in readable form only inside the running process, so a copy of the database or the configuration does not decrypt anything on its own.
Sensitive actions require a second factor: a fresh emailed code, verified at the moment of the action. Connecting an exchange key is additionally enforced at the database level, so the check cannot be bypassed by calling the API directly.
No system is perfectly secure. Use a unique password, keep your email account protected, and never enable withdrawal permission on the key you connect.
10. Children
twoke is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a minor has created an account, write to enfo@twoke.io and it will be removed.
11. Changes and contact
Material changes to this policy will be reflected in the date shown at the top of this page. For any question about your data, or to exercise any right described here, contact enfo@twoke.io.