Legal

Privacy policy

Version 1.2 · Last updated 24 September 2026

The short version

1. Who we are

Peil is a Chrome extension and website run by the business below. We are the controller of the personal data described here under the EU General Data Protection Regulation (GDPR).

Business
[legal name]
Address
[address]
Chamber of Commerce (KvK)
[KvK number]
Privacy questions
[contact email]

We are not required to appoint a data protection officer. Privacy questions go to the address above and are answered by a person.

2. What we collect

Your account

Your email address and an account number. You log in with a one-time code that we email to you; there is no password. Your email address is required to have an account: without it we cannot log you in or restore your credits.

Chart screenshots

Each analysis sends an image of the chart area of your TradingView tab, its size, the symbol and timeframe, your language and trading style, the optional “extra context” text from your settings, and a short summary of the previous read (zones and price levels) so changes can be named. The image shows what is on that chart, including your own drawings and any order or position lines you display there. We process this to produce the read and do not save the image or the text. See section 3.

Usage and credits

For every analysis we record the time, the symbol and timeframe, the AI model that answered, token counts, our cost, the credits charged and whether it succeeded. Every change to your credit balance (trial credits, monthly credits, purchases, analyses, refunds) is recorded in a ledger. We do not record the content of the read.

Payments

Stripe handles checkout, invoices and the customer portal. We receive your Stripe customer number, your plan, its status and the end of the paid period. Stripe holds your name, billing address, country, payment method and IP address. We never receive your full card number.

Technical data

Our hosting providers log requests to the website and the server: IP address, time, the address requested and browser type. Our login provider records the IP address and browser of each login session. We use these logs for security and troubleshooting only.

Messages you send us

Emails to us, and the name, email address, purchase and message you enter in the withdrawal form.

What we do not collect

Peil has no access to your TradingView account, watchlists, broker, exchange, positions or balances, and it does not read pages other than TradingView charts. The one exception is what you choose to show on the chart itself: order or position lines you display there are part of the image. We do not collect your browsing history.

3. Chart screenshots and AI

When you run an analysis, the extension captures the chart area only and sends it to our server, which forwards it to OpenAI to generate the read. We hold the image in memory for the duration of the request and do not save it. We send no email address, name or account number to OpenAI.

OpenAI processes the image on our behalf and does not use it to train its models. We ask OpenAI not to store the request. OpenAI may still keep requests in secured abuse-monitoring logs for up to 30 days, or longer where the law requires it, before deleting them.

Keep personal details out of the chart area and out of the “extra context” field. A chart normally shows a symbol and prices, not you. If you do not want your order or position lines in the image, hide them on the chart before a read.

4. Why we use it, and on what basis

PurposeDataLegal basis (GDPR art. 6)
Your account, login codes, running analyses, keeping your credit balance, supportAccount, screenshots, usage and credits, messagesPerforming our contract with you (1)(b)
Taking payments, subscriptions, refunds and withdrawalsPayments, withdrawal formContract (1)(b)
Invoices, VAT and bookkeepingPayments, country, invoicesLegal obligation (1)(c): Dutch tax law
Rate limits, preventing abuse and fraud, security logs, handling legal claimsUsage, technical dataOur legitimate interest (1)(f) in keeping the service secure and fairly used. You can object: see section 9.
Service emails: login codes, receipts, notices about your subscription or about changes to these termsEmail addressContract (1)(b)

We do not send marketing email unless you have asked for it, and every such email has an unsubscribe link.

5. Who receives your data

We use the providers below to run Peil. Each works under a data processing agreement and may only use the data for the purpose listed.

ProviderPurposeDataWhere
Supabase Pte. Ltd (hosted on Amazon Web Services)Database, login, server functions, logsAccount, usage and credits, withdrawal statements, technical data; screenshots in transit onlyDatabase and login in the United Kingdom (London), which is covered by an adequacy decision of the European Commission. The server functions that handle the chart image run in the European Union (Frankfurt). Support staff in the US and Singapore can access data when needed.
OpenAI Ireland Ltd (with OpenAI OpCo, LLC)AI analysis of the chart imageScreenshot and the context listed in section 2. No account details.United States
Stripe Payments Europe, Ltd (with Stripe, LLC)Payments, subscriptions, invoices, VAT calculationEmail, name, billing address, country, payment method, IP address, transactionsIreland and United States
Google Ireland Ltd (Gmail)Sending login codes and service emails, and our mailbox for your messages to usEmail address and the emails themselvesEuropean Union and United States
Cloudflare, Inc.Hosting this websiteIP address and request data of website visitorsWorldwide network

Stripe also uses payment data as a controller in its own right, for fraud prevention and to meet its own legal duties. Checkout and the customer portal run on Stripe’s website under Stripe’s privacy policy.

Beyond this list we share data only with our accountant and the tax authorities as the law requires, with authorities that present a valid legal demand, and with a successor if the business is transferred, in which case we will tell you first. We do not sell personal data and we do not share it for advertising.

6. Transfers outside Europe

Some providers are located in, or can access data from, the United Kingdom, the United States or Singapore. For those transfers we rely on an adequacy decision of the European Commission where one applies (the United Kingdom has one, as do providers certified under the EU-U.S. Data Privacy Framework) and otherwise on the European Commission’s Standard Contractual Clauses. You can ask us for a copy of the safeguards that apply to a provider.

7. How long we keep it

DataKept for
Chart screenshots and analysis contextNot saved by us. OpenAI: up to 30 days in abuse-monitoring logs.
Account, usage records and credit ledgerWhile you have an account. Deleted within 30 days after you ask us to delete your account; backups expire within a further 30 days.
Inactive accountsDeleted after 24 months without a login, after a warning email.
Invoices, payments and VAT records7 years, and 10 years for the records of EU sales that Dutch VAT law requires us to keep that long. These stay after account deletion.
Withdrawal statements and refund records7 years, as part of our financial records.
Login-code emails in our mailboxUp to 90 days. Order confirmations and withdrawal acknowledgements are kept with our financial records.
Server and security logsUp to 30 days.
Support email2 years after the conversation ends.

8. Security

All traffic is encrypted in transit (HTTPS) and the database is encrypted at rest. The browser can only read your own account data; every change to credits or subscriptions runs on the server. Access to the systems is limited to the owner of the business. If a breach puts your data at risk, we will tell you and the supervisory authority as the law requires.

9. Your rights

You can ask us to:

Email [contact email] from the address of your account. It is free. We answer within one month; if a request is complex we may need up to two more months and will tell you so within the first.

You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in your own country. We would like the chance to fix it first.

10. Cookies and browser storage

This website does not use cookies, analytics or tracking. The extension stores your settings, your login session and your agreement to the data notice locally in your browser. That storage is strictly necessary to provide the service you asked for, so no consent banner is needed. Logging out removes your login session; your settings and your agreement stay until you remove the extension, which clears everything. When you pay you go to Stripe, which uses its own cookies under its own policy.

The extension also keeps a history of your most recent reads, up to 300, in your browser: time, symbol, timeframe, price, direction, structure, any entry, stop and target levels, and the text of the read. Never the chart image. This history stays on your device and is not sent to us or to anyone else. You can export or clear it in the extension’s settings, under History. Logging out leaves it in place; removing the extension deletes it.

11. Chrome Web Store: Limited Use

Peil’s use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. In plain terms: the extension has one purpose, analysing the TradingView chart you are viewing and drawing the result on it. We collect only what that purpose needs, transfer it only to the providers in section 5, never use or sell it for advertising, and no person reads your data unless you ask us for support, it is needed for security, or the law requires it.

12. Automated decisions

We do not use your personal data for automated decision-making or profiling that has legal or similarly significant effects. The AI analyses a chart image, not you.

13. Age

Peil is for adults. It is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a minor has an account, email us and we will delete it.

14. Outside the EU

If you are in the United Kingdom you have equivalent rights under the UK GDPR and can complain to the Information Commissioner’s Office. Wherever you live: we do not sell personal information, we do not share it for cross-context behavioural advertising, and you can contact us to access or delete your data.

15. Changes

When we change how we handle data we update this page and its version number. If the extension starts to collect or share something new, it will tell you in the extension and ask for your agreement before that happens.

Version history