We do not sell your personal data for advertising. We do not require third-party ad tracking pixels
on the GNL product surfaces. This policy describes real processing for the SaaS product.
1. Who we are
GenuineNL (“GNL”, “we”) operates the website https://genuisenl.com and related web and mobile apps
offering AI-assisted Spot trading automation on your own exchange account. Support:
info@clickilink.com. Authentication and payments may be powered by
ClickiLink as a partner platform.
2. Data we collect
Account: email, username, display name, country (if provided), date of birth or age confirmation,
password hashes (local) and/or ClickiLink Partner session tokens (encrypted at rest where stored by GNL).
Trading (tenant-scoped): balances, positions, orders, signals, activity logs, equity snapshots,
settings, performance metrics — all isolated per account.
Exchange credentials: API key and secret you paste — encrypted in a vault; never returned
to clients after save; Spot-oriented product path.
Device / push: Expo push tokens, platform, device name, app version when you enable notifications.
Billing: subscription status, plan, period end, payment IDs/URLs from ClickiLink.
We do not store full payment card numbers on GNL servers.
Logs: IP address, timestamps, and request metadata for security, debugging, and rate limiting.
Communications: support emails you send us; optional product assistant chat content.
3. How we use data
Provide, secure, and improve the SaaS (auth, trading engines, dashboards, alerts).
Process subscriptions and prevent fraud / abuse.
Send transactional email and push (trade closes, safety, password reset) — not marketing spam by default.
Binance — your keys authenticate your account; GNL is not Binance.
Hosting / infrastructure — server operator and network.
Email (SMTP) if configured for transactional mail.
Expo for mobile push delivery.
LLM / AI providers (e.g. Ollama Cloud or similar) for trading/advisor features —
prompts may include market and portfolio context needed to operate, not your vault secrets.
We may disclose information if required by law or to protect rights and safety.
6. International transfers
Servers and sub-processors may process data outside your country (including UAE and other regions).
We apply contractual and technical safeguards appropriate to the Service.
7. Retention
Account and trading history while your account is active and for a reasonable period thereafter
for disputes, security, and legal retention (billing records may be kept longer). Vault keys remain
until you delete them or the account is closed per support process.
8. Security
HTTPS/TLS in transit; secrets encryption for vault and partner sessions at rest;
tenant isolation in the multi-user engine model; JWT session tokens for clients
(mobile apps should store JWT in the OS keychain / secure storage). No method is 100% secure.
9. Your rights
Subject to law, you may request access, correction, export, or deletion of personal data by emailing
info@clickilink.com or using in-app data-request where available.
We may verify identity and retain limited data where legally required (e.g. fraud, accounting).
10. Children
GNL is not directed to children under 18. We do not knowingly collect data from under-18 users.
11. Cookies / local storage
The web app may store JWT and UI preferences (e.g. theme) in browser storage for authentication and UX.
Mobile stores tokens in secure device storage. No ad network pixels are required for core product function.
12. Changes
We may update this Policy and bump privacy_version in
/api/legal/meta. Material changes may require re-acceptance at signup
or in-app notice.