Cheapest exchange this week
Binance · $1.42 all-in avg
$1,000 buy avg · this week
What "0% fee" really costs
MEXC +€1.46 vs cheapest
all-in cost gap (EUR) · latest round
Cheapest way to move USDT at Binance
cheapest: BNB Chain 0.01 USDT · priciest: Tron 1.5 USDT
withdrawal fee · curated
Top reliability score right now
Kraken 88
sourced & dated · never bought
Issue 01 · Privacy
Privacy Policy
Last updated 2026-07-24
Your portfolio data lives in our EU Postgres. Full stop.
1. Who we are
Controller is OptiRisk Consulting e.U., Döblerhofstraße 10/167, 1030 Vienna, Austria (registered FN 626043b, Handelsgericht Wien). Contact: hello@skontro.com. Full operator details are in the Imprint. On €10k annual revenue we transition operations to Skontro GmbH; we update this notice and notify all users at that time.
2. What we process and why
Early-access waitlist
If you join the waitlist, we process your email address, confirmation and referral status, the page or campaign that brought you to Skontro, and the referral or partner code in the link. We use this data to send the requested confirmation, manage your place and referrals, measure which channels bring people to Skontro and, if you asked for it, send you the letter. Campaign labels and any member referral code in the link are stored in your browser for up to 30 days so you can try the open tools before joining without losing the original source. The confirmation button in the email completes double opt-in. Legal basis: steps at your request before entering a contract, Art. 6 (1)(b) GDPR, and our legitimate interest in measuring which channels bring people to Skontro, Art. 6 (1)(f) GDPR.
Optional The Thursday Measure letter
The Thursday Measure — our weekly measurement letter — and launch updates are separate from early access. We add you only if you select the optional checkbox and then confirm through the email. We store the consent version and its timestamps and send the letter through Resend. The same consent and unsubscribe terms cover the monthly True-Cost-Index edition email — one email per edition when it publishes — if you request it on the research page. Every edition includes a one-click, working unsubscribe link that permanently stops it; you can also withdraw consent at any time by emailing privacy@skontro.com. Withdrawal does not affect your waitlist place. Legal basis: consent, Art. 6 (1)(a) GDPR.
Account data
Email, hashed password (or OAuth identifier), language, tax residency. Legal basis: contract performance, Art. 6 (1)(b) GDPR.
Portfolio data
Wallet addresses you connect, encrypted read-only exchange API keys, positions and transactions read from those sources, calculated tax lots. Legal basis: contract performance, Art. 6 (1)(b) GDPR.
Usage analytics
Pageviews and feature interactions via PostHog (EU-Frankfurt). Aggregated, no replays, no session recordings. On public pages the analytics run cookieless — no cookie, no local storage, no cross-visit identifier; events are anonymous. Once you create an account and sign in, product events — including checkout and subscription milestones recorded server-side, so payment funnels are measured from the server rather than inferred from a redirect — are linked to your account under its pseudonymous internal id and stored in our EU database; no amounts, wallet addresses or key material are event properties. These events are deleted automatically after 12 months, and immediately when you delete your account. Legal basis: legitimate interest in product improvement, Art. 6 (1)(f) GDPR — opt out anytime via privacy@skontro.com or the account-wide toggle under Settings → Analytics. The opt-out applies to your whole account and takes effect on each device the next time Skontro loads there.
Partner referral codes
If you arrive through a partner link (a URL containing ?via=CODE), your browser stores that code locally (local storage, max. 90 days, never a cookie) so we can credit the partner if you later subscribe. The code identifies the partner, not you; it is attached to your account only if you sign up, and is never used for advertising or cross-site tracking. Legal basis: legitimate interest, Art. 6 (1)(f) GDPR.
Error telemetry
Stack traces and request metadata via Sentry (EU-Frankfurt) when our services fail. Authorization headers and cookies are stripped before transmission.
Service emails
We send a welcome email on signup, alerts you configured yourself (price thresholds), notices about material reliability changes on exchanges you connected, and a weekly portfolio digest. Reliability notices and the digest can be switched off in Settings at any time; price alerts only exist if you create them. Legal basis: contract performance for alerts you configure, Art. 6 (1)(b) GDPR; legitimate interest for account-related service notices, Art. 6 (1)(f) GDPR. Marketing email is sent only under the separate consent described above.
3. Vendors and where data lives
- Railway (EU-Frankfurt) — application servers + Postgres + Redis
- Supabase (EU-Frankfurt) — authentication identity
- Sentry (EU-Frankfurt,
sentry.deregion) — error monitoring - PostHog (
eu.posthog.com) — product analytics - Vercel (global edge network) — frontend rendering + CDN; may process request data outside the EU
- Cloudflare (global edge) — DNS, CDN and DDoS protection; processes request metadata globally
- Stripe (Stripe Payments Europe, Ireland) — payments + invoicing + EU MOSS VAT; payment data is also processed in the US
- Resend (United States) — transactional email
On-chain providers (Alchemy, Helius, CoinGecko, Zerion) receive only anonymised request data — wallet addresses are public on-chain. When the AI journal launches, Anthropic will receive prompts on the same terms: they will carry no userId, email, or name.
4. Your rights
You may at any time:
- Request a copy of your data (Art. 15)
- Correct inaccurate data (Art. 16)
- Delete your account and all derived data (Art. 17) — self-service in Settings → Your data
- Export your data in a portable format (Art. 20) — self-service in Settings → Your data
- Object to analytics processing (Art. 21)
- Lodge a complaint with the Austrian Data Protection Authority
Export and deletion are both self-service: sign in and use Settings → Your data to download a full portable copy (JSON) or to permanently delete your account at any time. Deletion erases your profile, wallets, exchange connections (including the encrypted API keys), positions, imported history, alerts and snapshots, cancels any active subscription, and removes your sign-in identity. For correction or any other right, email privacy@skontro.com from your account address — we respond within 30 days, usually much faster.
5. Retention
Your account, profile and portfolio data — including imported wallet and transaction history — is retained for as long as your account exists, and is erased when you delete your account (Art. 17 self-service, see §4). A subscription that lapses without renewal simply downgrades the account to the Free tier; it does not delete your data. Billing and invoice records (the payments you made to us) are retained for seven years as required by Austrian commercial law (§§ 132, 207 BAO); these are held by our payment processor, contain no portfolio data, and are not removed by an account deletion. Analytics on public pages are anonymous by design — there is no identifier to retain. Signed-in product events are linked to your account, deleted automatically after 12 months, and immediately with an account deletion.
Waitlist data is retained through the early-access and launch period so we can honour your place and invite status, unless you ask us to delete it sooner. If you subscribed to the optional Brief and later unsubscribe, the email provider may retain the minimum suppression record needed to ensure we do not send again.
6. International transfers
The stores that hold your personal data — authentication (Supabase), our application database (Railway Postgres), error monitoring (Sentry) and product analytics (PostHog) — are hosted in the EU. Some processors necessarily process data outside the EU/EEA: transactional email (Resend, United States), our global edge and CDN (Vercel, Cloudflare) and payment processing (Stripe, United States/global). For those transfers we rely on the safeguards each provider commits to in its Data Processing Agreement — Standard Contractual Clauses and, where applicable, an adequacy mechanism such as the EU-US Data Privacy Framework.
On-chain providers (Alchemy, Helius, CoinGecko, Zerion) route requests through non-EU endpoints, but the data exchanged is pseudonymous public on-chain information or anonymised market queries, not personal data. When the AI journal launches, its prompts to Anthropic will route through non-EU endpoints under the same rule — no userId, email, or name.