Skip to the document
Knowledge base Articles MCPNew
Open the simulator
Privacy Terms Disclaimer

Privacy Policy

What we collect, why, who it goes to, and how to have it deleted. This describes what the software actually does — it was written from the code, not from a template.

Effective 23 August 2026 · Last updated 30 September 2026

The short version. We collect your email address and, if you subscribe, the billing identifiers Stripe gives us. We never see your card number. We set no cookies and run no ad tracking. Your email goes into our email system so we can contact you about your account and the product. You can delete your account yourself from Account → Delete account at any time, and it happens immediately.

1. Who we are

BTC DCA Engine is operated by Matchless Web Studio LLC, a limited liability company organized in the State of Mississippi, United States. For privacy purposes we are the data controller for the information described here.

Contact for any privacy question, data request or deletion: support@btcdcaengine.com.

2. What we collect

If you use the simulator in your browser, we collect nothing about you personally. You can run a simulation without an account, and we do not ask for or store anything identifying in order to do it. If an AI assistant runs simulations for you through our agent endpoint, see section 6.

If you create an account, we collect:

  • Your email address. Required to create the account, log in, reset your password and receive receipts.
  • Your password, hashed. Authentication is handled by Supabase. Passwords are stored as a one-way hash; we cannot read yours, and neither can anyone at Matchless Web.
  • A display name, only if you choose to set one in your account settings.
  • Your plan state — whether the account is Free or Pro, and when that last changed.

If you subscribe to Pro, we additionally store the billing identifiers that Stripe returns to us: your Stripe customer ID, your subscription ID, the subscription status, whether you are on the monthly or annual plan, the date the current period ends, and whether the subscription is set to cancel at the end of that period. We keep these so the app can show your correct plan and renewal date, and so cancellation works.

What we never receive. We do not see, receive or store your card number, expiry, security code or billing address. Those go directly to Stripe, which handles them as an independent controller under its own privacy policy.

We do not collect your name (unless you type one), phone number, postal address, date of birth, government ID, or any financial account details. We do not ask what you actually own or invest — the simulator runs entirely on the numbers you type into it.

3. How we use it

  • To run your account — authenticate you, keep you logged in, and unlock the features your plan includes.
  • To take payment — create and manage your subscription through Stripe, and restore Pro if you resubscribe.
  • To contact you — service messages such as password resets, email confirmations, receipts and failed-payment notices; and occasional product email about new features and changes.
  • To keep the Service working — diagnose faults, prevent abuse and fraud, and meet our legal and tax obligations.

We do not sell your personal information. We do not share it with advertisers. We do not build advertising profiles, and we do not use your data to train machine-learning models.

4. Email — please read this one

We want to be explicit about something that is easy to gloss over: when you create an account, your email address is added to our email system (SureContact) and tagged with your plan — for example Free Tier, Pro Tier, or a tag noting a failed payment. That record is created as part of account creation and is how we manage customer communication. It does not by itself sign you up for marketing.

We use it to send:

  • Service email you cannot opt out of while you hold an account — password resets, email confirmation, payment receipts, failed-payment warnings and material changes to these policies. These are necessary to operate your account.
  • Product email — occasional messages about new features, improvements and things we have written. You only receive these if you ticked the box asking for them when you created your account. It is unticked by default, and leaving it unticked means we never send you any. Every one that we do send carries an unsubscribe link, and unsubscribing takes effect immediately. Opting out of product email never affects your account or your Pro access.

We do not sell, rent or share your email address with third parties for their own marketing.

There is one exception to the tick box, and we would rather name it than let you find it: if you buy Pro, we send you a short series explaining what you have just paid for. That is onboarding for a product you bought rather than marketing, so it goes out whether or not you ticked anything — and it carries the same unsubscribe link, which we honor the same way.

5. Cookies, analytics and what your browser stores

This site sets no cookies. That is why you have never seen a cookie banner here — there is nothing to consent to.

Analytics. We use Fathom Analytics to count page views and anonymous interaction counts. Fathom is privacy-focused and cookieless: it does not track you across sites, does not build a profile of you, and does not give us the ability to identify an individual visitor. We see aggregate numbers such as how many people opened the Knowledge Base, or how many copied a link to a result — never which result, and never tied to a person. The names we record are fixed labels chosen in advance, such as “share link copied”; the figures you type into the simulator are not part of them. Links produced by an AI assistant through our agent endpoint carry a fixed marker, utm_source=mcp, so we can count how many are opened and whether those visits go on to create an account or subscribe. The marker says the link came from an assistant and nothing else, and the resulting counts use the same kind of fixed label, such as “agent link opened”.

Local storage. The app keeps a few things in your browser's local storage so it behaves sensibly between visits. These live on your device, are readable only by this site, and are not transmitted to us:

WhatWhy
Theme preferenceRemembers whether you chose light or dark
Cached plan tierAvoids a flash of locked features while your session loads
Cached price historyStops the app re-downloading the same market data every visit
Your simulation setupRestores the plans you were working on
Interface preferencesPanel sizes, dismissed hints, which sections you had open
Login sessionStored by Supabase so you stay logged in between visits

Clearing your browser's site data removes all of it. Doing so logs you out but does not delete your account.

6. AI assistants and the agent endpoint

The simulator also answers AI assistants such as Claude and ChatGPT through a Model Context Protocol endpoint at /mcp. It is read-only, and anonymous unless you give your assistant an API key from your account or sign in to your account from the assistant: it sets no cookie and returns simulation results, not information about you. What the assistant does with your conversation is governed by that assistant's own privacy terms, not ours.

To keep a daily limit on free use, we keep a counter per calling address for the current day. The counter is stored under a one-way hash of the address, the date and a secret we hold — never under the address itself — and it expires after two days. We also keep aggregate statistics about the endpoint: which tool was called, whether the call succeeded or was refused, which protocol version the assistant spoke, how long the call took, and whether the caller was anonymous, used a Free or Pro key, or was signed in to a Free or Pro account. Those statistics carry no address, no identifier and none of the figures in the plan, and Cloudflare keeps them for three months.

If you create an API key under Account, the key itself is shown to you once and stored only as a one-way hash, so nobody — including us — can read it back. We keep its first characters, the label you gave it, when it was created and the day it was last used, so you can tell your keys apart and revoke one. Calls made with a key are counted against that key for the day rather than against an address, under the same hashed counter. Revoking a key deletes its record; deleting your account deletes all of them.

If you sign in from an assistant instead, the assistant sends you to a page on this site that names it and asks you to allow or decline. Allowing it records a connection between your account and that assistant — its name and the date — with our authentication provider, which then issues the assistant a token for your account; the token is ordinary sign-in data and is never stored by us beyond the counters and statistics above. Calls made this way are counted against your account for the day. You can see and disconnect every connected assistant under Account; disconnecting one ends its access, and deleting your account ends all of them.

7. Who else processes your data

We keep the list short on purpose. Each of these is bound by its own agreement with us and may only process data to provide its service:

ProviderWhat it doesWhat it sees
SupabaseAuthentication and databaseEmail, hashed password, display name, plan state, billing identifiers
StripePayments and subscriptionsEmail, payment details you enter with them, billing history
SureContactCustomer email and CRMEmail address and plan tags
CloudflareHosting and deliveryIP address and request logs, for security and delivery; for the agent endpoint, the hashed daily counters and the aggregate call statistics described in section 6
FathomCookieless analyticsAggregate page views and anonymous interaction counts; no personal profile

In addition, loading the site fetches chart and animation libraries from jsDelivr and the live Bitcoin price from CoinGecko; fonts are served from this site. Like any request your browser makes, these expose your IP address and browser version to those services. No account information is sent to them, and CoinGecko receives no information about you at all — only a request for the current price.

8. How long we keep it

We keep your account data for as long as your account exists. Deleting your account in the app removes it immediately; if you ask us to do it instead, we do so within 30 days.

Two exceptions: records of completed transactions are retained by Stripe and by us for as long as tax and accounting law requires, typically seven years; and aggregate analytics contain no personal data and are kept indefinitely. Backups are cycled out on a rolling basis, so deleted data may persist in a backup for a short period before it is overwritten.

The agent endpoint's daily counters expire after two days and its aggregate call statistics after three months; neither contains personal data.

9. Your rights, and how to delete your account

Whatever jurisdiction you are in, you may ask us to:

  • tell you what personal data we hold about you;
  • correct anything inaccurate;
  • send you a copy of your data;
  • delete your account and personal data;
  • stop sending you product email.

You can delete your account yourself, at any time. Open Account → Delete account and confirm with your password. The account is deleted immediately: your profile, your plan state and your saved settings are removed. This is permanent and cannot be undone.

If you have a subscription that is still set to renew, we ask you to cancel it first from Account → Manage billing. That way the billing decision is made deliberately in Stripe, which sends you its own confirmation, rather than happening as a side effect of deleting your account. Once it is canceled you can delete straight away — you do not have to wait for the paid period to run out. Deleting then closes the subscription out immediately, so you give up any remaining paid days under the refund terms.

If you would rather we did it, email support@btcdcaengine.com from the address on the account and we will delete it within 30 days. We do not charge for any of this and we will not make you jump through hoops.

What happens to your email address. The moment you delete your account we mark you unsubscribed in our email system, so nothing further can be sent to you. The contact record itself is then erased within seven days — the short delay exists only so a deletion made in error, or one raised alongside a billing dispute, can still be looked into. Records of completed transactions are the one thing that survives — Stripe and we keep them for as long as tax law requires, and we cannot delete those.

If you are in the UK or EEA, our legal bases are: performance of a contract (running your account and subscription), legitimate interests (keeping the Service secure, preventing fraud, and telling existing customers about the product they bought), consent (product email, given by the tick box at signup and withdrawable at any time through the unsubscribe link in any of it), and legal obligation (tax records). You also have the right to object to processing, to request restriction, to data portability, and to complain to your local supervisory authority.

If you are in California, you have the right to know what we collect, to request deletion, to request correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months.

10. Security

Traffic is served over HTTPS. Passwords are hashed by Supabase and never stored in readable form. Database access is restricted by row-level security so one account cannot read another's data, and the columns that control your plan cannot be written by the browser — only by our server after Stripe confirms a payment. We hold no card data at all, which removes the most sensitive category of risk entirely.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and any regulator required, without undue delay.

11. Where your data lives

We operate from the United States and our providers process data in the United States and other countries where they run infrastructure. If you use the Service from outside the U.S., you understand your data will be transferred to and processed there, under safeguards our providers maintain, including standard contractual clauses where applicable.

12. Children

The Service is not directed at anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, email support@btcdcaengine.com and we will delete it.

13. Changes to this policy

We may update this policy. The date at the top of the page always reflects the current version. If a change materially affects how we handle your personal data, we will tell you by email or in the app before it takes effect.


Questions, requests, or a deletion: support@btcdcaengine.com.

See also the Terms of Service and the Disclaimer.

Same money.
Same dates.
One axis.

Historical dollar-cost averaging on real closes. Not financial advice.

Explore Simulator Knowledge base Articles MCP Data sources About
Calculators Bitcoin investment Ethereum DCA Solana DCA XRP DCA
Legal Privacy Terms Disclaimer
© BTC DCA Engine support@btcdcaengine.com
Menu
Simulator Knowledge base Articles MCPNew Data sources About

Privacy · Terms · Disclaimer