Privacy Policy
Version: 2026-06-09 · Effective: 2026-06-09
1. Plain-language summary
VolatilityFarmer is a software tool that connects to your personal Kraken exchange account to automate trading according to settings you configure. We are committed to protecting your privacy. This policy explains in plain language what personal information we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have over it.
The short version:
- We collect the minimum data needed to operate the service: your account credentials (encrypted password and 2FA), your email, your encrypted Kraken API keys, your trading configuration, and security audit logs.
- We never see or store your Kraken account password, and we never custody your funds. Your money stays at Kraken at all times.
- We do not sell your personal information. We never have, and we never will.
- We share data only with the third parties we genuinely need to run the service (Stripe for billing, an email provider for transactional emails, Kraken using the API keys you provide).
- You can request a copy of your data, correct it, or delete your account at any time.
- The Service is currently available to residents of Canada (except Quebec) and the United States only.
2. Who we are
VolatilityFarmer (the “Service”) is operated by Dylan Knapman as a sole proprietorship registered in the Province of Ontario, Canada:
- Business name: VOLATILITY FARMER
- Business Identification Number: 1001423967
- Registered in: Ontario, Canada
- Effective date: 24 November 2025
- Privacy contact: privacy@volatility.farm
- Mailing address: 144 University Ave W, Cobourg, Ontario K9A 4X2, Canada
Under Canadian privacy law (PIPEDA, Schedule 1, Principle 1), every organization must designate an individual accountable for privacy compliance. For VolatilityFarmer, that person is the sole proprietor named above. Email privacy@volatility.farm with any privacy-related question, complaint, or request.
3. What we collect
We collect only the personal information we need to operate the Service, secure it, and meet our legal obligations. Specifically:
Account information
- Username (chosen by you)
- Password (stored as a one-way Argon2id hash — we cannot recover or read your password)
- Email address (used for verification, security alerts, billing notifications, and password reset)
- If you enable two-factor authentication: an encrypted TOTP secret and a set of hashed backup codes
- Country and province of residence (used to confirm eligibility — see Section 13)
- Acceptance record for our Terms of Service: timestamp, IP address, and ToS version
- Optional profile fields you choose to provide: display name, avatar image, short bio, leaderboard opt-in preference, profile visibility setting
Trading configuration
- Per-pair trading parameters you set (which pairs, trade size, sell targets, DCA settings, risk limits, etc.)
- Your Kraken API key and secret, stored encrypted at rest using authenticated symmetric encryption (Fernet, with a key file readable only by the service account)
- Subscription tier and Stripe customer identifier, if you become a paying customer
Activity and audit data
- The historical record of trades the Service has placed for you (order IDs, sizes, fill prices, fees, realized profit and loss)
- Bot status and snapshot data (current position, equity, recent activity)
- Security-relevant events: logins, password changes, key rotations, settings changes, billing events
- Active web sessions: a session identifier, an associated cross-site-request-forgery token, the originating IP address, and the browser user-agent string
Technical data
- The IP address from which you connect (used for security audit logs and rate limiting)
- Browser type and operating system (used to identify session devices and detect new-device logins)
What we do not collect: we do not collect your Kraken account password, government identification, social insurance or social security number, biometrics, precise geolocation, or any data we have not listed above.
4. Why we collect it
Under Canadian privacy law we must identify, before or at the time of collection, the purpose for which each category of personal information is collected. The purposes are:
- To operate the Service. Trading configuration, Kraken API credentials, and trade history are required to place orders on your behalf. Without them the Service does not function.
- To secure your account. Password hashes, TOTP secrets, backup codes, session identifiers, and IP addresses are used to authenticate you and prevent unauthorized access.
- To bill you (paid customers only). Email address, Stripe customer identifier, and subscription tier are required to process payments. Payment-card numbers are never seen by VolatilityFarmer — Stripe handles the card and returns only a customer reference.
- To communicate with you. Email address is used to send transactional messages (signup verification, password resets, security alerts, billing notices). We do not send marketing email without separate, explicit opt-in.
- To meet our legal and compliance obligations. Audit logs, IP addresses, and ToS acceptance records are kept to support fraud investigation, respond to lawful requests, and meet our obligations under applicable law.
- To support you. When you contact us for help, we may reference your activity logs to diagnose the issue.
We will not use personal information for any new purpose without first telling you and obtaining your consent where required.
5. Who we share it with
We share personal information only with the third parties listed below, and only for the purpose of operating the Service.
Service providers
- Stripe Payments (Stripe, Inc., USA). If you become a paying customer, your email address, subscription tier, and a unique identifier are shared with Stripe so Stripe can process payments. Stripe is the payment processor — we never see your card number. Stripe’s privacy policy is at https://stripe.com/privacy.
- Kraken (Payward, Inc.). The API keys you provide are sent to Kraken on each order placement. Kraken is your exchange and your direct counterparty — not ours. You agreed to Kraken’s terms when you opened your Kraken account. Kraken’s privacy policy is at https://www.kraken.com/legal/privacy.
- Email delivery provider. Transactional emails (signup verification, password reset, billing notices, security alerts) are delivered through a third-party SMTP provider. Only your email address and the message contents pass through this provider, for the sole purpose of delivery.
- Have I Been Pwned. When you set or change your password, the first five hexadecimal characters of its SHA-1 hash are sent to the Have I Been Pwned service to check whether the password appears in a known breach corpus. The remaining hash characters never leave our server, and the full password is never sent. This is a k-anonymity check; HIBP cannot learn your password from this query.
Legal disclosures
We may disclose personal information when we are legally required to do so — for example, in response to a subpoena, court order, or other lawful request from a competent authority. We may also disclose information to defend ourselves against legal claims, or to protect the safety or rights of users or the public. We will not voluntarily disclose your information beyond what is required by law.
Aggregated and anonymized data
We may publish or share aggregate statistics that do not identify any individual user — for example, total trade count or aggregated realized profit across all users — for marketing, research, and product improvement.
What we do not do
- We do not sell your personal information. We have not, and we will not.
- We do not rent or trade your contact information to marketers.
- We do not use your data to train external AI or machine-learning models.
- We do not share data with advertising networks or social-media platforms.
6. Where your data lives
VolatilityFarmer is hosted on infrastructure in Canada and the United States. Server-side data lives on hardened servers operated by the Operator, behind firewalls, with operating-system-level protections and strict file-permission scoping.
Service providers we use (Stripe, the email provider, Have I Been Pwned) may store and process data in the United States or other jurisdictions. Section 13 describes the international-transfer considerations.
7. How long we keep it
We keep personal information only as long as we need it for the purposes identified above, or as required by law.
- Active account data (account, configuration, Kraken keys, trade history) is retained while your account is active.
- Audit and security logs are retained as part of the operating record. Routine events (logins, configuration saves, bot start/stop) are retained for 90 days; security-relevant events (failed login attempts, password changes, TOTP changes, admin actions, billing webhook events, master-key rotation events) are retained for 365 days for security forensics. After their retention window elapses, entries are permanently deleted by an automated daily process.
- Backups. Our database is backed up daily; backups are retained for up to seven days locally, and longer if archived offsite.
- Deleted accounts. When you delete your account, we remove your account row and cascade-delete dependent records (sessions, backup codes, password-reset tokens, email-verification tokens). Your bot’s working directory is archived for up to 30 days in case of accidental deletion and then permanently removed. Records we are required to retain by law (for example, billing records relevant to tax) are kept for the legally required period.
- Marketing list. If you submitted your email for early-access updates and you are not a customer, we will remove your address from our list on request.
8. How we protect it
We use technical and organizational safeguards proportionate to the sensitivity of the information:
- Passwords are hashed with Argon2id at memory-hard parameters and never stored or transmitted in plaintext.
- Two-factor authentication secrets (TOTP) are encrypted at rest using Fernet authenticated encryption. The master key for this encryption is stored in a separate file readable only by the service account.
- Kraken API keys and secrets are stored encrypted at rest with the same Fernet scheme. They are decrypted only in process memory at the moment the Service needs to place an order.
- Backup codes are stored as Argon2id hashes and are single-use.
- All web traffic is served over TLS with strict transport security and modern cipher suites. The Service does not accept unencrypted HTTP.
- Server hardening: the service runs under systemd with strict process isolation (NoNewPrivileges, ProtectSystem, ProtectHome, MemoryDenyWriteExecute, syscall filtering). Per-user bots run under separate Linux user accounts so one user’s compromised bot cannot read another’s data.
- Session cookies are HttpOnly, Secure, and SameSite=Lax. Cross-site request forgery is mitigated with per-session tokens validated on every state-changing request.
- Access controls: only the Operator has administrative access to the production environment. Administrative actions are recorded in an audit log.
No system is perfectly secure. If you believe your account has been compromised, email security@volatility.farm immediately and rotate your Kraken API keys from your Kraken account.
9. Your rights
Under PIPEDA you have the right to:
- Know what we hold about you and how we use it. This policy is the standing answer; email privacy@volatility.farm for anything specific.
- Access a copy of your personal information. Submit a request to privacy@volatility.farm and we will respond within 30 days (with a 30-day extension if needed and you are notified). We may ask you to verify your identity first.
-
Correct inaccurate information. You can edit most
profile fields directly from
/me. For fields you cannot edit yourself (such as your username under cooldown), email privacy@volatility.farm. - Withdraw consent. You may withdraw consent to our processing of your information at any time, subject to legal or contractual restrictions. In practice this means closing your account; some records (such as billing records required for tax reporting) we are required to keep for the legally required period.
-
Delete your account and data. Use the
“Delete account” option under
/me→ Danger Zone. The deletion is immediate and irreversible. Your bot is stopped, your stored Kraken keys are wiped, your account row and cascading dependent records are deleted, and your bot’s working directory is archived for 30 days, then removed. - Complain to the Privacy Commissioner of Canada if you are unsatisfied with how we have handled your personal information. Visit https://www.priv.gc.ca/ for the complaints process. You can also complain to your provincial privacy regulator if applicable.
10. California residents
If you are a resident of California, the California Consumer Privacy Act and the California Privacy Rights Act may give you additional rights. We respect those rights even though, given our size, we are below California’s applicability thresholds. The information in Sections 3 (what we collect), 4 (purposes), 5 (recipients), 7 (retention), and 9 (your rights) constitutes the disclosures we would make to you under the California regime.
In particular:
- We do not sell or share your personal information. Under California law, “sale” includes disclosure for monetary or other valuable consideration, and “sharing” includes disclosure for cross-context behavioural advertising. We do neither. There is therefore no “Do Not Sell or Share My Personal Information” link to surface, but if you wish to confirm this in writing, email privacy@volatility.farm.
- You may request access to the specific pieces of personal information we hold about you, the categories of personal information we have collected, the categories of sources, the business purposes, and the categories of third parties with whom we have shared the information.
- You may request deletion of your personal information, subject to the legal-retention carveouts described in Section 7.
- You may request correction of inaccurate personal information.
- You may designate an authorized agent to make these requests on your behalf. We will require reasonable proof of agency.
- We will not discriminate against you for exercising these rights.
To exercise any California right, email privacy@volatility.farm with the subject line “California privacy request.” We will verify your identity before acting on the request and respond within 45 days (with a 45-day extension if reasonably necessary, with notice to you).
11. Cookies and tracking
The Service uses only strictly-necessary cookies. We do not use analytics cookies, advertising cookies, or third-party tracking cookies of any kind.
| Cookie | Purpose | Lifetime |
|---|---|---|
vf_sid |
Session identifier used to keep you logged in. HttpOnly, Secure, SameSite=Lax. | Sliding 7-day idle, 30-day absolute maximum. |
Because all cookies are strictly necessary for the Service to function, we do not display a cookie-consent banner. If at any point we introduce non-essential cookies (for example, optional analytics) we will update this policy and seek your consent before doing so.
We do not honor the browser “Do Not Track” signal because we do not track you in the first place.
12. Children
The Service is not intended for individuals under 18 years of age, and we do not knowingly collect personal information from anyone under 18. The Service’s minimum age is set by our Terms of Service. If you believe a child has provided us with personal information, please email privacy@volatility.farm so we can delete the data and the account.
13. International transfers
VolatilityFarmer is currently available to residents of Canada (except the Province of Quebec) and the United States. We restrict signups from other jurisdictions because the legal and operational work to support them responsibly is not yet complete.
If you are a Canadian user, your personal information may be transferred to and processed in the United States in the course of being delivered to one of our service providers (Stripe and the email-delivery provider are US-based). US law may permit law enforcement and national-security agencies in the United States to access information held there. We choose service providers with strong privacy and security commitments to limit this exposure.
Quebec residents: the Province of Quebec’s Act respecting the protection of personal information in the private sector (Law 25) imposes specific obligations on businesses serving Quebec residents. We have not yet completed the work required to offer the Service in Quebec under Law 25. We therefore do not accept signups from Quebec residents at this time. If you are a Quebec resident interested in being notified when we expand into Quebec, please reach out at privacy@volatility.farm.
14. Data breach notification
If we determine that a security incident has caused or is reasonably likely to cause a real risk of significant harm to any user, we will:
- Notify the Office of the Privacy Commissioner of Canada as required by PIPEDA;
- Notify affected users by email without unreasonable delay, with information about what happened, what data was involved, and what we recommend you do;
- Keep a record of the incident and our response.
If you believe your account or data has been compromised, email security@volatility.farm with details and we will investigate.
15. Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change — one that meaningfully expands what we collect, changes who we share with, or affects your rights — we will update the version date at the top of the page and notify active users by email. Continued use of the Service after a material change indicates acceptance of the updated policy. If you do not agree with a change, you may close your account.
Non-material changes (typo fixes, clarifications, formatting) may be made without separate notice but are always reflected in the version date.
16. How to contact us
For any privacy-related question, request, or complaint:
- Privacy contact: privacy@volatility.farm
- Security incident: security@volatility.farm
- General support: support@volatility.farm
- Mailing address: VOLATILITY FARMER, 144 University Ave W, Cobourg, Ontario K9A 4X2, Canada
We aim to acknowledge privacy requests within five business days and to provide a complete response within 30 days. If your request is complex and we need more time, we will tell you within the first 30 days and provide an updated response date.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/. California residents may complain to the California Privacy Protection Agency at https://cppa.ca.gov/.