Privacy
Privacy policy
Last updated: 9 September 2026
This policy explains how MarketRooms.fyi handles personal data when you visit the website, use the extension, create an account, or participate in market rooms.
1. Who controls your data
The data controller is SANTIANT LABS LTD, registered in England and Wales under company number 17450301. Its registered office is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. For privacy questions or to exercise your rights, email [email protected].
2. Data we use and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account identity: email, username, display name, avatar, optional bio and public profile links, sign-in identifiers and timestamps | Create and secure your account, authenticate you, recover access and provide community features | Contract; legitimate interests in account and service security |
| Public chart context: symbol, exchange/provider and inferred asset class | Route the extension to the relevant room | Contract |
| Messages, replies, reactions, images, follows and room memberships | Publish the content you choose and operate community chat | Contract; legitimate interests in maintaining conversation integrity |
| Reports, blocks, mutes, moderation actions, reputation, security logs and limited technical identifiers | Prevent fraud and abuse, enforce rules, investigate incidents and defend legal claims | Legitimate interests; compliance with legal obligations where applicable |
| Terms and guidelines version, acceptance timestamp, 18+ declaration, privacy acknowledgment and acceptance surface | Record eligibility and agreement, administer updates and establish or defend legal claims | Contract; legitimate interests in maintaining evidence of agreement |
| Optional product events and bounded campaign tags | Measure adoption and improve MarketRooms | Your consent |
| Support messages and request records | Answer requests and manage legal or privacy enquiries | Contract, legal obligations and legitimate interests |
Chart detection uses public chart context for room routing and does not extract broker or wallet credentials, orders, positions, or account details as structured data. Screenshots you request can nevertheless include any sensitive information visible in the captured area, including positions, balances, orders, and account details. Images you select, paste, or capture are processed for chat and are not automatically redacted. Hide sensitive information before capturing and review images before sharing. The extension does not collect unrelated browsing history. Clipboard images are processed only when you paste them into the focused chat composer.
3. Analytics and browser storage
Web analytics and extension analytics are off by default. If you accept, the service may process an anonymous identifier, event name, surface, source, extension version, low-cardinality room type or asset class, and metadata key names. We do not send message contents, email addresses, raw room IDs, symbols, tokens, portfolio data, or unrelated browsing activity to analytics. See the cookie policy and use “Privacy settings” in the footer to change your choice at any time.
4. Chrome extension Limited Use
The use of information received from Google APIs by MarketRooms will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. The extension handles data only as necessary to provide, secure, maintain, and improve its single purpose: independent public market chat routed to the chart context you choose.
MarketRooms does not sell user data, use or transfer it for advertising or creditworthiness, or permit human access except with your specific consent, for community safety and abuse investigation, or where required by law. Optional analytics are bounded, off by default, and used only to operate and improve this chat service.
Advertising plans
The service launches free of charge without advertising. If we introduce advertising later, we will explain any new processing and obtain any required consent before it begins. Data obtained through the extension or Google APIs will not be used for advertising or advertising profiling. The Limited Use restrictions above continue to apply if the business model changes.
5. Who receives data
We use the following service providers for the stated purposes: Hetzner for application hosting and self-hosted database, Redis and image-storage infrastructure; Cloudflare for network ingress and encrypted off-host backups; MXroute for login and operational email; Google for Google sign-in when you choose it; PostHog EU for optional, consented product analytics; and ClamAV in our hosting environment to scan uploaded images for malware. PostHog does not receive messages, email addresses, raw symbols or raw room identifiers. Sentry error reporting is not enabled at the date of this policy. Providers may act only under appropriate contractual and confidentiality duties. Other users receive information you intentionally make public, such as your profile and room messages. Data may also be disclosed where required by law or necessary to protect rights and safety.
6. International transfers
Providers may process data outside the United Kingdom or European Economic Area. Where a transfer is restricted by applicable data protection law, we use the relevant adequacy regulations or decision, or appropriate contractual safeguards: the UK International Data Transfer Agreement or UK Addendum for UK transfers, and EU Standard Contractual Clauses for EU transfers, as applicable. We assess the protection provided and apply supplementary measures where required. Contact us for information about the safeguard relevant to a specific provider.
7. How long data is kept
- Account and profile data: while the account is active, then deleted or anonymised following a valid deletion request.
- Magic-link challenges: expire after 15 minutes and become eligible for removal 24 hours later.
- One-time stream tickets: expire after 60 seconds and become eligible for removal 24 hours later.
- Authentication rate-limit records: become eligible for removal 24 hours after their last update.
- Public content: until you delete it or it is removed under our rules; limited deleted-user references may remain to preserve conversation integrity.
- Moderation, security and dispute records: only as long as reasonably necessary for abuse prevention, security, legal obligations or legal claims.
- Optional analytics: according to the configured provider retention period. Withdrawal stops future optional collection; it does not automatically erase previously collected records. Contact us to request erasure where applicable. Browser-side identifiers are removed when you clear site or extension data.
8. Account deletion and export
You can download a JSON export from account settings and request deletion on the account deletion page. Deletion anonymises direct account identifiers and removes active relationships and pending sign-in data. Public messages and necessary moderation or audit records may remain under a deleted-user reference for the purposes described above. Removing an account identifier does not necessarily anonymise personal information within a message or image. To request erasure or redaction of that information, contact us with the relevant message or image location. We assess requests under the applicable UK GDPR, EU GDPR or other data protection law, including any lawful retention exceptions, and explain any refusal and your right to complain. Public posting does not waive these rights. We cannot guarantee retrieval of copies independently made by others.
9. Your rights
Subject to applicable UK GDPR, EU GDPR or other data protection law, you may request access, correction, deletion, restriction, portability, or object to processing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. Email [email protected]. We may need to verify your identity and normally respond within one month.
You may complain to the UK Information Commissioner's Office (ICO) or, where applicable, the data protection authority where you live or work, including in the EEA. You can contact us first to seek a resolution, but this does not limit your right to complain directly.
10. Children
MarketRooms is not intended for children under 18. Do not create an account or submit personal data if you are under 18.
11. Security and changes
We use access controls, limited permissions, encrypted transport, session protections, moderation controls and operational monitoring proportionate to the service. No online service can promise absolute security. Material policy changes will be posted here with a revised date and, where required, brought to your attention in the product.