Last updated: July 17, 2026
Million Candles LLC ("Million Candles", "we", "us", "our"), a Wyoming, USA limited liability company, operates millioncandles.com and related services (the "Service"). This policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it. By using the Service you agree to this policy. Questions: admin@millioncandles.com.
Account data: name, email address and password. Passwords are hashed with bcrypt before storage — we never store or see plain-text passwords.
Payment data: all payments are processed by Stripe, Inc. Your card number never touches our servers. We store only your Stripe customer reference, subscription status, plan and invoice history.
Trading & usage data: chart images you upload for analysis, AI analysis results, options scans, asset-intelligence lookups, paper-trade entries, journal entries, scan history, AutoPilot rules and execution logs. This is your account history and is required to provide the Service.
Browser extension data: if you install the Million Candles Chrome extension, it captures a screenshot of your active browser tab, and the URL of that tab, only at the moment you click Scan — never in the background and never from other tabs. The screenshot is sent to our servers for the same AI analysis described above; the tab URL is used only to pre-fill the ticker symbol for that scan and is not stored beyond it. The extension does not read browsing history and does not run without your explicit action.
Push notification data: if you enable push notifications, we store the push subscription endpoint and keys issued by your browser/device so we can send you alerts (such as a saved setup being invalidated). You can disable this at any time in Settings, which removes the subscription.
Broker connections: if you connect a brokerage account, we store the OAuth access tokens issued by your broker (for Indian brokers such as Zerodha, you authenticate on the broker's own official login page — your broker password never touches our systems) and/or API keys you provide. All tokens and keys are encrypted with AES-256-GCM before storage, decrypted only at the moment of order transmission, and never shared with any third party or used for any purpose other than executing the actions you explicitly configure or confirm. Indian broker sessions expire daily in line with SEBI requirements.
Technical data: IP address, approximate location (country-level, used to default your currency), browser type, device type, timezone and pages visited.
Communications: emails you send us, feature requests and support tickets.
(a) To provide the Service — running analyses, storing your history, executing AutoPilot rules you set; (b) to process payments and send transactional emails (receipts, password resets, security alerts); (c) to secure the Service — fraud prevention, abuse detection, rate limiting; (d) to improve the Service — aggregate, de-identified usage statistics; (e) to comply with law — tax, accounting and lawful requests. We do not sell your personal data, and we do not use it for third-party advertising.
We share data only with processors needed to run the Service, each bound by their own security and privacy obligations:
Stripe (payments, fraud prevention) · Supabase (database hosting) · Vercel (application hosting & CDN) · Anthropic (AI processing — chart images you submit are sent to the Claude API solely to generate your analysis) · Resend (transactional email delivery) · ipapi.co (IP-to-country lookup for currency defaults). For broker connectivity: Alpaca (your API keys, encrypted, used only to transmit your orders), Rithmic (your credentials are transmitted over encrypted connections to establish your trading session), and Zerodha Kite Publisher (runs entirely in your browser on Zerodha's own pages — no Zerodha credentials or data pass through our servers).
If you connect a broker, order instructions are transmitted to that broker. We are not responsible for a broker's handling of your data under your separate agreement with them.
Where GDPR or similar laws apply, we process data on the bases of: contract (providing the Service you signed up for), legitimate interests (security, fraud prevention, service improvement), consent (optional communications — withdrawable at any time), and legal obligation (tax and accounting records).
Account data is retained while your account is active and deleted within 30 days of account deletion. Security and server logs are kept up to 90 days. Payment and tax records are retained for 7 years as required by law. Encrypted broker credentials are deleted immediately when you disconnect a broker or delete your account.
Depending on your jurisdiction (including GDPR, UK GDPR and CCPA/CPRA), you may have the right to: access a copy of your data, correct inaccurate data, delete your data, export your data in a portable format, restrict or object to certain processing, and withdraw consent. California residents: we do not "sell" or "share" personal information as defined by the CCPA. To exercise any right, email admin@millioncandles.com from your account email — we respond within 30 days. You can also delete your account directly in Settings.
Our infrastructure is located in the United States. If you access the Service from outside the US, your data is transferred to and processed in the US. Where required, we rely on standard contractual clauses and our processors' compliance frameworks.
All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest. Passwords are bcrypt-hashed; broker credentials are AES-256 encrypted; access to production systems is restricted and logged. No system is 100% secure — if we learn of a breach affecting your data we will notify you without undue delay.
The Service is strictly for users 18 years or older. We do not knowingly collect data from minors; if we learn we have, we delete it.
We may update this policy and will post the new version here with an updated date. Material changes will be announced by email or in-app notice.