Skip to main content
Join

Privacy Policy

Last updated: 28 July 2026 · CoinBatmi

CoinBatmi (https://coinbatmi.com) provides free crypto market research tools. This policy explains what we collect, why, and how you can exercise control. We aim for GDPR-aligned practices: minimisation, transparency, and purpose limitation.

Who is responsible

Controller: CoinBatmi Newsroom / product team. Contact: [email protected] .

Infrastructure

The application is hosted on Oracle Cloud infrastructure. Traffic is served over TLS. We use multi-source public market APIs and free AI providers for research features. We do not sell personal data.

Data we process

  • Account data (if you register or use Google sign-in): name, email, auth identifiers, session tokens.
  • First-party usage analytics: route, event type, pseudonymous session ID, referral domain, campaign tags, device/browser category, language, timezone, and coarse country/region when supplied by our network edge. The analytics store does not contain raw IP addresses, full user-agent strings, city-level location, account email, Batmi messages, or search text.
  • Security logs: infrastructure may process network address, user agent, path, and time transiently to deliver traffic, rate-limit abuse, and investigate faults.
  • Preferences: theme and UI density stored in your browser (local storage).
  • Content you send to Batmi AI or feedback forms (processed to answer and improve quality; not used as paid ads profiling).

Analytics choices

Our cookieless first-party analytics runs under our legitimate interest in understanding aggregate product use. It uses sessionStorage, expires when the browser session ends, honors Global Privacy Control and Do Not Track, and does not create a cross-session advertising profile. Country and region come only from coarse headers added by our own network edge; we do not send an IP address to a geolocation vendor. If you choose "Accept all", Google Analytics 4 and Microsoft Clarity may also process usage information under consent. Advertising storage remains disabled.

Legal bases (GDPR-oriented)

  • Contract / steps prior to contract: account and session features.
  • Legitimate interests: security, abuse prevention, service analytics at aggregate level.
  • Consent: optional non-essential cookies if you choose "Accept all".

Retention

First-party analytics events are retained for 30 days in a bounded store. Pseudonymous session IDs expire with the browser session and are not linked to account records. Infrastructure security logs are kept only as long as needed for operations (typically weeks); account data is kept while your account is active. You may request deletion of account data by emailing us.

Your rights

Depending on your region you may have rights of access, rectification, erasure, restriction, portability, and objection. Contact us at the email above. You may also lodge a complaint with a supervisory authority where you live.

Cookies

See our Cookie Policy for categories and choices.

Security

We apply HTTPS, security headers (HSTS, CSP, frame denial), and HTTP-only session cookies where applicable. Details: Security & trust .