Maxim Sadovnikov operates the CryptoProfit mobile application (the "App"). This Privacy Policy explains what information the App collects, how it is used, and your choices.
Information We Collect
Account information
Your email address and password, used solely to create and authenticate your account via Supabase, our backend provider. Your password is never stored in plain text — it is hashed using industry-standard hashing before storage.
Financial records you enter
Bitcoin purchase and deposit records you manually add or import: amounts, dates, fees, and computed BTC quantities/prices. This data exists solely to power the portfolio tracking and profit/loss calculations shown in the App, and is never shared with or sold to any third party.
Bybit API credentials (optional)
If you choose to connect a Bybit account, your API key and secret are sent to our server, where the secret is encrypted at rest (AES-256-GCM) before storage. We use it only to fetch your own deposit and trade history from Bybit's API on your behalf, so you can import it into your portfolio log. The App never requests withdrawal permissions and cannot place trades or move funds — we verify with Bybit that your key is read-only before saving it, and again every time it's used, and reject any key that has trading or withdrawal permissions.
What we do NOT collect
We do not collect your location, contacts, camera/photo data, or advertising identifiers. The App does not use any third-party analytics, advertising, or tracking SDKs.
How We Use Your Information
To authenticate you and keep your portfolio data associated with your account.
To calculate and display your portfolio's profit/loss, purchase history, and related statistics.
To fetch live and historical BTC prices from Bybit's public market data (no personal data is sent for this — it's an unauthenticated, public price lookup).
To sync your deposit/trade history from Bybit when you explicitly request it, using your own API credentials.
Data Storage & Security
All data is stored with Supabase (PostgreSQL) and accessed exclusively over encrypted HTTPS/TLS connections.
Row-level security policies ensure your data is readable only by your own authenticated account.
Session tokens are stored on your device encrypted, with the encryption key held in OS-level secure storage (iOS Keychain / Android Keystore).
Bybit API secrets are encrypted at rest (AES-256-GCM) using a server-held key that is never exposed to the app or its users.
Data Sharing
We do not sell, rent, or share your personal or financial data with third parties for marketing purposes. Your data is only transmitted to:
Supabase — our database, authentication, and backend hosting provider.
Bybit — only if you explicitly connect an API key, and only to read your own account's deposit/trade history on your behalf.
Your Rights
Delete your account — go to Settings → Danger Zone → Delete Account in the App. This immediately and permanently deletes your account along with all associated purchases, deposits, and Bybit credentials. This action cannot be undone. As of this policy's last update, our database plan does not include automated backups, so no backup copies of your data persist after deletion.
Access or correct your data — you may request a copy of your data, or ask us to correct it, at any time by contacting us at maxsadovnikov77@gmail.com.
Children's Privacy
CryptoProfit is not directed at, and is not intended for use by, children under the age of 13. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.