Legal
Privacy Policy
What we collect, where it goes, how long we keep it, and what you can ask us to do with it. Sentinel carries no analytics and no third-party trackers, so most of this policy is about data you give us deliberately.
Last updated 5 September 2026
01Who is responsible for your data
Sentinel is the controller of the personal data described in this policy. Sentinel is operated independently and is not currently incorporated as a company; the operator is the individual who provides the service.
For any privacy question or request, including the rights set out in §8, contact sentinelsupport3@gmail.com.
02What we collect
Account data. Your email address, and an account identifier. If you sign in with Google we receive your email address and basic profile information from Google; we do not receive your Google password.
Credentials you supply. API keys for market-data providers, your Trading 212 key (and secret, if your account has one), and your Gemini key if you enable the AI Advisor. These are stored encrypted (see §5).
Configuration. Your automation rules, Shari'ah screening thresholds, chosen theme, and similar preferences.
Activity generated by the product. Rating snapshots, the automation decision log — every order and every refusal, with the gate and reason — and paper-trading history. This exists so the engine can be audited and held to account for its own output.
Technical data. Standard server logs including IP address and request paths, retained for security and abuse prevention.
What we do not collect. No analytics, no advertising identifiers, no behavioural tracking, and no third-party JavaScript in the application. We do not use cookies for tracking; the only browser storage used is your session token and local preferences such as theme.
03Why we can use it
Performance of a contract. Providing the account, running scans, and executing the automation you configure.
Legitimate interests. Keeping the service secure, preventing abuse, and diagnosing faults — balanced against your interests, which is why logging is limited to what is needed.
Legal obligation. Where we are required to retain or disclose data by law.
04Who your data is shared with
We use the following processors and services:
- Supabase — authentication and encrypted storage of your account, credentials and settings.
- Google — sign-in if you use Google OAuth, and the Gemini API if you enable the AI Advisor. When you use the Advisor, your question and the engine context relevant to it are sent to Google.
- Trading 212 — when you connect a broker key, we send requests to Trading 212 on your behalf.
- Market data providers — Yahoo Finance, Finnhub, Financial Modeling Prep, Polygon, Tiingo and Alpha Vantage. These receive ticker symbols, not your identity.
- Cloudflare — hosting and delivery of this website.
Company logos are fetched by our server and cached, never loaded directly by your browser. The logo provider therefore never learns which companies you are looking at.
We do not sell your data, and we do not share it for advertising.
05How credentials are protected — and the honest limit
API keys are encrypted at rest in the database, and access is restricted at the row level so one account cannot read another's. Keys are never returned to the browser: the settings screen shows a masked preview and a configured flag, never the value.
This is server-side encryption, not end-to-end encryption. The encryption key is held by the server, which is what allows your credentials to follow you between devices. It also means an operator with both database access and key access could decrypt them. We state this plainly rather than implying a guarantee we cannot make.
If that trade-off is unacceptable to you, run Sentinel locally, where your keys never leave your machine.
06International transfers
Some processors listed above operate outside the UK and EEA. Where data is transferred internationally it is done under an adequacy decision or Standard Contractual Clauses, as applicable to that provider.
07How long we keep it
Account, credentials and settings — for as long as your account exists, and deleted when you delete it.
Rating snapshots and decision logs — retained while the account exists, because they are what makes the engine auditable. You can ask us to delete them sooner.
Server logs — a rolling window, typically no more than 90 days.
08Your rights
Under UK GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive it in a portable format. You can withdraw consent where consent is the basis for processing.
Write to sentinelsupport3@gmail.com and we will respond within one month. If you are not satisfied with how we handle a request, you can complain to the Information Commissioner's Office at ico.org.uk.
09Breach notification
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay where the risk is high.
10Changes to this policy
We will post any update here with a revised date, and give notice by email where the change is material.
See also our Terms of Service.