Effective 4 September 2026
INFORMATION WE COLLECT
When an account is issued, Meowl Capital processes the account email address, authentication and session information, subscription status, API-key metadata, API usage totals, and settings connected to the account. If Telegram updates are enabled, the linked Telegram account identifier, username and notification preferences are also processed.
The service may record basic technical information needed for reliability and security, such as request times, endpoint usage, error details, IP addresses and browser or device information.
PASSWORDS, API KEYS AND THIRD-PARTY TOKENS
Authentication and application records are stored in a private PostgreSQL database operated by Meowl Capital. Passwords are stored only as one-way hashes. Generated Meowl Capital API-key secrets are displayed when created and retained only in a non-retrievable verification form.
If a restricted feature asks for a third-party access token, the feature explains how that token is handled. Never send such a token by email or enter it anywhere other than the intended secure input.
HOW INFORMATION IS USED
- To authenticate users and provide the requested website and API functions.
- To apply access controls and rate limits.
- To deliver Telegram updates chosen by the user.
- To diagnose failures, protect the service and prevent abuse.
- To understand aggregate service usage and improve reliability.
SERVICE PROVIDERS AND DISCLOSURE
Meowl Capital uses service providers including Amazon Lightsail for hosting, Upstox for market-data integrations, and Telegram for opted-in bot messages. These providers process information under their own terms and privacy policies.
Personal information is not sold. It may be disclosed where required by law, to protect users or the service, or to a successor operating the service, subject to appropriate safeguards.
COOKIES AND RETENTION
The website uses essential cookies or equivalent browser storage to maintain authenticated sessions and security controls. It does not use advertising cookies.
Account and operational records are retained only as long as reasonably needed to provide the service, meet legal obligations, resolve disputes and prevent abuse. Backup copies may remain for a limited period after primary records are removed.
YOUR CHOICES
You can revoke an API key or disconnect Telegram from the account page. To request access to, correction of or deletion of personal information, use the details on the Contact page. Some records may need to be retained for security or legal reasons.
SECURITY AND CHANGES
Reasonable technical and organisational safeguards are used, but no internet service can guarantee absolute security. This policy may be updated as the service changes. The effective date above will be revised when a material update is published.