Last updated: April 2026
Abu Terminal ("we", "us", "our") operates the website at abu-terminal.com and the Abu Terminal application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Information we collect
We collect information in the following ways:
- Account information: When you create an account via Google OAuth or magic link, we receive your email address and display name. We do not collect or store passwords.
- Usage data: We collect anonymized analytics about how you interact with the application, including pages visited, features used, session duration, and simulation decisions. This data is used to improve the product.
- Simulation data: Your trading decisions, quiz answers, and behavioral patterns within the simulator are stored to provide personalized feedback, track your progression, and generate your trader profile.
- Device information: We automatically collect basic technical data such as browser type, operating system, screen resolution, and language preference.
- Feedback data: If you submit feedback through the in-app feedback widget, we collect your message, category selection, and rating.
What we do with your information
We use the collected information to:
- Provide, maintain, and improve the Abu Terminal service
- Generate your trader profile, behavioral analytics, and personalized coaching
- Track your progression across simulations, quizzes, and campaigns
- Send transactional emails (account verification, magic links) — never marketing emails
- Analyze aggregate usage patterns to improve the product
- Detect and prevent abuse or technical issues
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
Third-party services
Abu Terminal uses the following third-party services that may process your data:
- Supabase — authentication and database hosting. Your account data and simulation records are stored in Supabase with Row Level Security (RLS) enabled.
- PostHog — anonymized product analytics. PostHog receives usage events with no personally identifiable information attached.
- Google OAuth — if you choose to sign in with Google, Google's privacy policy applies to the authentication process.
- Google AdSense — when ads are enabled, Google may use cookies to serve personalized advertisements. You can opt out via Google's ad settings.
- Vercel — hosting and serverless functions. Vercel processes requests and may log IP addresses per their privacy policy.
- TradingView — embedded chart widgets. TradingView widgets may set their own cookies per their privacy policy.
- Binance — real-time price data via WebSocket. No personal data is sent to Binance.
- OpenAI — AI chat and embeddings. When you use Ask Abu (chat), your messages and retrieved knowledge base context are sent to OpenAI's API (gpt-4o-mini for chat, text-embedding-3-small for RAG retrieval). OpenAI's data usage policy applies. To avoid sending data to OpenAI, select "Knowledge Base Only" mode in Settings → AI Provider.
- Paddle — payment processing. If you subscribe to a paid plan, Paddle processes your payment details (email, billing address, payment method). Abu Terminal does not store credit card numbers. Paddle's privacy policy governs payment data.
Your rights (including GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or any jurisdiction with data protection laws, you have the following rights:
- Right of Access (GDPR Art. 15) — request a copy of the data we hold about you. Use the "Download My Data" button in Settings, or email us.
- Right to Rectification (GDPR Art. 16) — update your profile information at any time through Settings.
- Right to Erasure (GDPR Art. 17) — request complete deletion of your account and all associated data.
- Right to Data Portability (GDPR Art. 20) — download your simulation history and behavioral analytics via Settings → Download My Data.
- Right to Restrict Processing (GDPR Art. 18) — request that we limit how we process your data.
- Right to Object (GDPR Art. 21) — opt out of analytics tracking at any time.
- Right to Withdraw Consent — where processing is based on consent, you may withdraw it at any time without affecting prior processing.
- Right to Lodge a Complaint — you may file a complaint with your local data protection authority.
To exercise any of these rights, use the self-service tools in Settings or contact us at privacy@abu-terminal.com. We will respond within 30 days.
Data retention
We retain your account data and simulation history for as long as your account is active. If you request account deletion, we will remove all personal data within 30 days. Anonymized, aggregated analytics data may be retained indefinitely as it cannot be linked back to any individual.
Children
Abu Terminal is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that we have collected data from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@abu-terminal.com.
International data transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States (where our hosting infrastructure is located) and Israel (where the developer is based). By using Abu Terminal, you consent to these transfers. We ensure appropriate safeguards are in place to protect your data in accordance with this privacy policy.
Security
We take the security of your data seriously. Measures we implement include:
- Row Level Security (RLS) on all database tables ensuring users can only access their own data
- HTTPS encryption on all connections
- Content Security Policy (CSP) headers to prevent cross-site scripting
- No API keys or secrets exposed on the client side
- DOMPurify sanitization on all dynamic content
- Regular security audits via our automated agent squad
No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of Abu Terminal after changes constitutes acceptance of the revised policy.
Contact
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at privacy@abu-terminal.com.