Privacy Policy
Last Updated: 2026年9月14日
Blave ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal information when using the Blave mobile application and its related services.
1. Information We Collect
We collect the following types of data to provide you with a complete and secure experience:
- Account Information: Your email address and encrypted login credentials.
- Exchange API Data: If you choose to connect your exchange API, we may access your account details, trading history, and positions.
- Blave Agent Instance Data: Strategy execution status, positions, order records, and system and execution logs, used for display, anomaly notifications, and troubleshooting.
- Device Information: Device type, operating system, IP address, and app version.
- Usage Data: Your interactions with the app, preferences, and behavior analytics.
- Cookies and Analytics Identifiers: cookies and similar technologies store your sign-in session, language preference, and an anonymous analytics identifier. See Section 8.
- Blave for Desktop Usage Events: when you use Blave for Desktop, the app sends a limited set of usage events. See Section 9.
- Contact and Report Data: when you contact us or report content through the channels on the Contact Us page (email, Discord), the email address or Discord username and the message content you provide, used to reply to and handle your message or report.
- Server Access Logs: when anyone visits this site (including public research pages viewed without signing in) or connects to our servers through Blave for Desktop, our servers record the IP address, time, requested URL, and browser information as part of routine security operations, and keep them for no more than 14 days.
2. How We Use Your Information
Your data is used for the following purposes:
- To provide core features like charting, portfolio insights, and trading analytics.
- To improve app performance and user experience.
- To send important system updates and notifications (you may opt out of marketing messages).
- To ensure account and platform security.
- To generate de-identified and aggregated insights that may be used for internal analytics or offered to users as premium features.
- To reply to your messages and handle reports about published content.
3. Sharing of Information
We do not sell your personal data to third parties in an identifiable form. Data is only shared under the following conditions:
- When required by law or government authorities.
- With trusted technical partners (e.g., cloud service providers), under strict confidentiality obligations.
- When you explicitly choose to share content (e.g., screenshots or portfolio summaries).
- Aggregated and de-identified data may be used internally or as part of features offered to users or partners. See Section 4 for more details.
- With third-party analytics providers (currently Google Analytics 4), which process site usage data on our behalf. See Section 8.
- When you choose to use Blave's AI in Blave for Desktop, the content of your conversations is sent to the provider of the model you select (currently Anthropic and DeepSeek) for processing. See Section 9.2.
- When you publish a Blave Agent research report; if you choose to be credited, your display name is published with it.
- When you contact us through Discord, Discord's handling of that data is governed by its own privacy policy.
4. Use of Aggregated and Anonymized Data
We may use de-identified and aggregated data derived from user-linked exchange APIs to generate statistical insights and market indicators. These insights:
- Do not contain any personal identifiers.
- Cannot be linked back to individual accounts.
- May be made available to other users as part of premium features.
You can opt out of contributing to such analytics by contacting us or managing your privacy settings in the app.
5. Data Retention and Deletion
We retain your data only for as long as necessary to fulfill its intended purpose. You may request to delete your account and associated data at any time by contacting us.
- Snapshots and publication records of reports that are or were published are kept for 180 days after account deletion, under Section 8.8 of the Terms of Service.
- Messages and report data are deleted within a reasonable time after they have been handled.
- Blave for Desktop usage events are kept for 25 months from receipt. See Section 9.1.
- AI usage records and credit transaction records are kept for the period required by law.
6. Your Rights
You have the right to:
- Access, correct, or update your personal data.
- Request account and data deletion.
- Revoke API access at any time.
- Opt out of receiving marketing communications.
7. Data Security
We implement appropriate technical and organizational safeguards to protect your information, including encryption and access control.
8. Cookies and Third-Party Analytics
We use cookies and similar technologies (such as local storage) to keep you signed in, remember your language and display preferences, and measure how the site is used.
- Essential: sign-in session, language, and display settings. Blocking these prevents you from signing in.
- Analytics: Google Analytics 4, provided by Google LLC, records page views, referral source, approximate region derived from your IP address, and device type. Google's handling of that data is governed by its own privacy policy (policies.google.com/privacy).
We do not use advertising or cross-site tracking cookies. You can block or delete cookies in your browser settings, or install Google's opt-out add-on (tools.google.com/dlpage/gaoptout).
9. Blave for Desktop
This section applies to Blave for Desktop (macOS) installed on your computer.
The desktop app periodically connects to Blave's update source (download.blave.org) to check for a new version. That connection is served by a content delivery network, and its access logs are not covered by the retention period stated in Section 1.
9.1 Usage Events
To understand where installation and setup break off and how many people are on each version, the desktop app sends us the seven usage events below. Each event answers only one question: which step happened, when, and on which version.
- First open: the first time this installation starts; sent once.
- Open: each time the app starts; we keep one record per installation per day (UTC).
- Connection completed: when you choose which AI to use; we record which option (Blave's AI, Claude Code, or Codex).
- Sign-in: when you successfully sign in to your Blave account in the desktop app.
- First backtest completed: the first time a strategy finishes a backtest on this installation; sent once.
- Trading started: when you start order placement and it succeeds; we record whether it is paper trading or a real account, not which exchange.
- Cloud run started: when you successfully start a cloud host from the desktop app.
Each event carries only: an installation identifier, the event name, the single option value described above (if any), the app version, the operating system name and version, your system locale, the time on your computer, and the time we received it.
Usage events never include: the content of your conversations with the AI, strategy code, strategy names, traded symbols, amounts, positions, keys, or file paths. Events have no free-text field; our server stores only the listed fields and discards everything else.
- How you are identified: the installation identifier is a random code generated the first time the desktop app starts. It is stored on your computer and does not change; it is not derived from your hardware or your account. After you sign in to your Blave account in the desktop app, subsequent events carry your sign-in credential so that we can associate this installation with your account. While you are signed out, events are not associated with any account.
- IP address: usage event records do not contain your IP address or browser information. As with any network request, however, connections between the desktop app and our servers appear in our server access logs (see Section 1).
- Purpose: usage events are used only to measure completion of installation and setup, retention, and version distribution, in order to improve the product.
- Retention: usage events are kept for 25 months from receipt.
- How to turn it off: usage events are on by default. You can turn them off at any time under Settings › Privacy in the desktop app. Once turned off, the desktop app sends no usage events at all, including "First open" and "Open", and including any event queued but not yet sent at that moment. Turning it off does not delete records already sent. Turning it back on resumes sending immediately. If an event cannot be delivered because you are offline or the request times out, the app discards it; it does not retry or queue it for later.
- Requesting deletion: for usage events that are not associated with an account, you can email info@blave.org with your installation identifier and ask us to delete the usage events for that installation. You can view and copy the installation identifier under Settings › Privacy in the desktop app.
- When you delete your account: we remove the association between usage events and your account. The events themselves are kept, unlinked from any account, until the retention period ends. Desktop sign-in credentials issued to your account are revoked, and events received after deletion are not associated with that account.
- Keys: exchange API keys and bring-your-own data source keys that you set up in the desktop app are written to a workspace file on your own computer (~/Blave/workspace/.env) and are not sent to Blave's servers for storage. That file sits on your computer, and Blave Agent, your strategy code and the desktop app itself can read it — that is how they trade and fetch data for you. When you use Blave's AI, the results of tools the AI agent runs are relayed to the model provider under Section 9.2; if you ask it to read a file that contains keys, that content falls within what is relayed on that call. Two exceptions, both started by you: (1) when you send a strategy to the cloud, the data-source keys that strategy uses travel with it to your Blave Agent cloud machine, governed by Section 7 of the Terms of Service — the confirmation dialog lists what moves and what does not, and exchange API keys do not move; (2) when you connect an exchange for your cloud machine from the desktop app, the exchange API key you enter is relayed through Blave's servers to your own cloud machine and written there; the relay queue entry is removed as soon as your machine picks it up, an entry never picked up expires within 15 minutes, and Blave keeps no further copy. Exchange API connections you make on the website remain governed by "Exchange API Data" in Section 1.
9.2 Conversation Data When You Use Blave's AI
The desktop app lets you choose who provides the AI:
- Claude Code or Codex on your own computer: the desktop app runs the tool already signed in on your computer and does not use Blave's AI relay. Your conversations do not pass through Blave's servers; they are handled by that tool's provider under your own terms with it.
- Blave's AI: the content of your conversations — including the messages you enter, system prompts, the results of tools the AI agent runs, and images you attach — is relayed through Blave's servers to the provider of the model you select for processing, and the reply is relayed back to you. The providers are currently Anthropic and DeepSeek, depending on the model you select in the desktop app. Requests are sent under Blave's account with the provider. The request content is produced by the AI agent software and relayed as is; Blave's relay service does not add your Blave account identifier to it.
When you use Blave's AI in the desktop app, Blave's servers do not keep conversation content: it is not written to any database, cache, or log file. Reply content is held in memory only while it is being relayed, in order to read usage figures, and is released when the request ends.
For billing, we record for each AI call: your account identifier, the request path, the model name, input and output token counts, the number of web searches, and the time. Your credit transaction history records the amount charged and a description containing only the model name and those counts. None of these records contain conversation text. They are kept for the period required by law.
Content received by a model provider is handled under that provider's terms and policies. How long it is kept and how it is used are determined by the provider's current documents:
- Anthropic: Commercial Terms of Service, Privacy Policy
- DeepSeek: Open Platform Terms of Service, Privacy Policy
Conversation history for the desktop app is stored on your own computer.
10. Policy Updates
We may update this Privacy Policy from time to time. The updated version will be posted here with a revised "Last Updated" date.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us: info@blave.org