We do not sell personal data for advertising. Core product surfaces do not require third-party ad pixels.
This Policy describes real processing for the SaaS tool.
1. Controller / who we are
GenuisenL (“GNL”, “we”, “us”) operates genuisenl.com and related web and mobile
applications that provide software tooling for optional Spot automation on your own exchange account.
Support: info@clickilink.com.
Authentication and payments may be powered by ClickiLink as a technical partner.
2. What we collect
Account: email, username, display name, country (if provided), age confirmation
and/or date of birth, password hashes and/or encrypted partner session tokens.
Trading metadata (tenant-scoped): balances, positions, orders, signals, activity logs,
equity snapshots, settings, performance metrics — isolated to your account.
Exchange credentials: API key and secret you paste — encrypted at rest; never returned
after save; Spot-oriented product path.
Device / push: Expo push tokens, platform, device name, app version when notifications are on.
Billing: subscription status, plan, period end, payment IDs/URLs via ClickiLink.
We do not store full card numbers on GenuisenL servers.
Technical logs: IP address, timestamps, and request data for security, rate limits, and abuse prevention.
Support: messages you send us; optional in-app assistant content.
3. Why we use data
Provide, secure, and improve the Service (auth, engines, dashboards, alerts).
Process subscriptions and prevent fraud/abuse.
Send transactional email and push (e.g. trade closes, safety, password reset) — not marketing spam by default.
Payment rails used by ClickiLink (e.g. Ziina) for card/checkout processing.
Binance — your keys authenticate your account; we are not Binance.
Hosting / infrastructure operators.
SMTP providers if email is configured.
Expo for mobile push delivery.
LLM / AI providers for optional trading/advisor features — prompts may include market
and portfolio context needed to operate; vault secrets are not sent as credentials.
We may disclose information if required by law or to protect rights, safety, and integrity of the Service.
6. International transfers
Data may be processed in the UAE and other regions where our infrastructure or partners operate.
We apply contractual and technical safeguards appropriate to a SaaS tool of this nature.
7. Retention
Account and operational data while the account is active and for a reasonable period afterward for
disputes, security, and legal retention (billing records may be kept longer). Encrypted keys remain until
you delete them or the account is closed via support process.
8. Security
HTTPS/TLS in transit; encryption for vault and partner sessions at rest; multi-tenant isolation;
JWT sessions for clients (mobile apps should store tokens in the OS keychain). No system is perfectly secure.
9. Your rights
Subject to applicable law, you may request access, correction, export, or deletion by emailing
info@clickilink.com or using signed-in
POST /api/account/data-request. We may verify identity and retain limited data where legally required.
10. Children
The Service is not directed to users under 18. We do not knowingly collect data from under-18 users.
11. Cookies / local storage
The web app may store JWT and UI preferences (e.g. theme) in browser storage. Mobile stores tokens in secure storage.
No ad-network tracking is required for core product function.
12. Changes
We may update this Policy and bump privacy_version in
/api/legal/meta. Material changes may require re-acceptance or notice.