Privacy
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit our website or use features such as alerts, push notifications, or the Follow/tracker feature of LETF.io. Personal data is any data that can be used to personally identify you.
Data Collection on Our Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. Contact details can be found in the imprint of this website.
How do we collect your data?
Some data is collected when you actively provide it to us, for example when using the alert feature with your email address or the voluntary feedback feature. Other data is processed automatically or locally in your browser as soon as you use the website or app. In particular, this concerns technical data, locally stored preferences, and aggregated, non-personal usage statistics.
What do we use your data for?
Some of the data is collected to technically provide the website. Additional data is used to store your preferences, authenticate and deliver alerts, and analyze usage behavior in an aggregated, non-personal way.
2. General Information and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.
Responsible Party
The responsible party for data processing on this website is:
Andre Basche
Hauptstraße 91
53474 Bad Neuenahr-Ahrweiler
Germany
Email: info@letf.io
Revocation of Your Consent to Data Processing
Where data processing is based on your consent, you may revoke it at any time with effect for the future.
3. Data Collection on Our Website
Local Data Storage and Similar Technologies
For usage analysis, we use a cookieless, privacy-friendly analytics system without persistent identifiers. Technically required local storage entries are used exclusively for the proper operation of the website and app.
Technically Required Storage
These entries are required so that explicitly requested functions can be provided reliably:
- language, theme, and display settings
- local strategy configurations and optional saved input aids
- technical session data for the alert feature
Website Analytics
To analyze website and app usage, we operate an internally managed, cookieless analytics system that works without persistent identifiers. Only aggregated, non-personal data is processed. In particular, the following information may be collected:
- visited pages, navigation paths, and time spent
- referrer or referring website
- technical data such as browser, operating system, screen size, or app platform
- approximate country or region assignment (no individual IP address stored)
- date and time of the visit
- selected language, general usage events, and general characteristics of the functions used
- aggregated technical performance metrics such as loading time, interaction delay, and layout stability (Core Web Vitals)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in aggregated, non-personal usage analysis to improve the service). The system used does not use analytics cookies or persistent identifiers.
Retention: usage data is stored only as long as necessary for analysis and further development of the service.
Recipient: analytics processing takes place within our own server infrastructure. Aggregated usage data is not shared with external third parties.
Third-country transfer: since analytics processing takes place within our own server infrastructure, no third-country transfer takes place.
Local Data Storage (LocalStorage)
LETF.io stores certain information locally in your browser or in the app so that requested functions remain available. This includes, in particular, configurations, display and language settings, and other convenience features triggered by you. This data is not transmitted to us automatically and can be deleted through your browser or app settings.
Server Log Files and Hosting
When our website or API is accessed for purely informational purposes, technical access data is automatically processed in server and proxy log files. This is required to ensure the secure and stable operation of our services. In particular, the following data may be processed:
- IP address of the requesting device
- date and time of access, requested URL, and transferred data volume
- HTTP status code, referrer URL, and technical details about browser, operating system, and user agent
- additional technical log data required for error analysis, abuse detection, and system security
- where applicable, an approximate country or region assignment determined locally on the server based on the IP address
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure hosting, abuse detection, technical error analysis, and stable provision of the website and API).
Recipients/categories of recipients: hosting and infrastructure service providers used by us, in particular Hetzner Online GmbH as the hosting provider of our server infrastructure, as well as technical service providers to the extent required for operation and security.
Retention: server log files are stored only for a limited period and then deleted unless longer retention is required to investigate security incidents, abuse, or legal violations.
A third-country transfer is currently not intended as part of regular hosting. If access from a third country is nevertheless enabled by service providers used by us, this takes place only on the basis of suitable safeguards or a relevant adequacy decision.
4. Alerts and Email Communication
Use of the Alert Feature
When you create, request, or manage alerts, we process in particular the following data:
- your email address
- selected product- and function-related parameters of the alert configuration
- technical authentication and verification data
- technical metadata and status information required for delivery, security, and error analysis
Processing is carried out to provide the alert feature, verify email-based access, deliver transactional alert and magic-link emails in the appropriate language, display active alerts, and manage or delete existing alerts. We currently do not send marketing emails through this feature.
Legal basis: Art. 6(1)(b) GDPR insofar as the processing is required to provide the alert feature requested by you.
Recipients/categories of recipients: hosting and API service providers used by us, as well as Amazon Web Services (AWS), in particular Amazon Simple Email Service (SES) in the Frankfurt region (eu-central-1), to the extent necessary for operation, authentication, and delivery.
Retention: active alerts generally remain stored until you delete them or until the service is discontinued; technical verification, security, and delivery data are stored only as long as required for those purposes.
Any third-country transfers take place only on the basis of suitable safeguards or a relevant adequacy decision where this is necessary for service providers we use.
5. Technical Error Analysis and System Security
Use of a Self-Hosted Error Analysis System
To ensure the stability, security, and technical functionality of our website, app, and API, we use a self-hosted system for technical error analysis. In particular, the following technical data may be processed:
- error and exception information including stack traces, timestamps, and affected components
- technical details about browser, operating system, device type, app platform, and application version
- visited page or request information as well as general technical metadata
- technical process and performance data to reconstruct errors and response times
- where technically required, sanitized context information; sensitive form contents are not intended to be deliberately collected
Processing is carried out solely to detect technical errors, analyze causes, resolve stability issues, limit abuse and service disruptions, and improve the reliability of our offering. The data is not used for advertising purposes or to create user profiles.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure, stable, and low-error service).
Recipients/categories of recipients: the error analysis system is self-hosted by us on our own server infrastructure. To that extent, data is not transferred to an external SaaS provider for this monitoring. Access may be possible only for hosting and infrastructure service providers used by us where technically required.
Retention: error and monitoring data is stored only as long as necessary for technical analysis, incident resolution, and system security; data that is no longer required is reviewed and deleted on an ongoing basis.
A third-country transfer as part of the self-hosted error monitoring is not intended by us. If hosting or infrastructure service providers nevertheless enable access from a third country, this takes place only on the basis of suitable safeguards or a relevant adequacy decision.
Browser Security Reports
To detect security-relevant misconfigurations and unauthorized resource requests, browsers may also transmit technical security reports to our monitoring infrastructure. Such reports may in particular contain the affected document URL, the blocked resource, referrer information, policy data, and technical metadata. Processing is carried out solely for security and error analysis purposes on the basis of Art. 6(1)(f) GDPR.
6. Push Notifications in the App
Use of Push Notifications
If you enable push notifications in the native app, we process technical data required to register, deliver, and manage the push channel. In particular, the following data may be processed:
- a technical registration or delivery token for push notifications
- technical identifiers and status information of the respective app installation
- technical details about platform, app version, language, and permission status
- server-side information indicating whether push is enabled or disabled for a given installation
- technical data required for delivery through the push infrastructure services used
Processing is carried out solely to provide the push notifications requested by you, technically register the push channel, keep tokens up to date, deliver notifications, and analyze push-related errors. Push notifications are used only if you have enabled them on your device.
Legal basis: Art. 6(1)(b) GDPR insofar as the processing is required to provide the push feature requested by you. Where an additional operating-system or device-level permission is required, processing in this respect is based on the consent or permission granted by you there.
Recipients/categories of recipients: hosting and API service providers used by us, as well as Google Firebase Cloud Messaging and, on iOS, Apple Push Notification Service, to the extent required for technical delivery.
Retention: push registration data and tokens are stored only as long as push is enabled for the respective installation or as long as the data is required for synchronization, delivery, and error analysis. When deactivated or unregistered, the data is deleted or dereferenced within the limits of technical feasibility.
When using Firebase Cloud Messaging and Apple Push Notification Service, processing in third countries, in particular the United States, cannot be ruled out. Any transfers take place only on the basis of suitable safeguards or a relevant adequacy decision where applicable.
7. Server-Side Usage and Activity Analysis
Technical Activity Events in the Backend
To secure, technically provide, and improve our alert and market-data features, we process selected activity events on the server side. In particular, the following data may be processed:
- technical events relating to the use of core features such as market data, alerts, or sign-in flows
- pseudonymized technical identifiers where no direct user association exists
- where an alerts session is active, the association with an alert user account insofar as required to provide and evaluate the feature
- event-related technical metadata and general usage parameters
Processing is carried out solely to technically understand usage and stability of core features, detect abuse, narrow down errors, support product decisions on an aggregated basis, and improve the reliability of our alert and market-data features. The data is not used for advertising purposes or profile-based marketing.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical operations analysis, abuse detection, product security, and further development of our service).
Recipients/categories of recipients: hosting and infrastructure service providers used by us. Processing takes place within our own backend and database infrastructure.
Retention: activity data is stored only as long as necessary for technical analysis, operational control, abuse detection, and further development; data that is no longer required is regularly deleted or aggregated.
A third-country transfer is not intended in this respect. If service providers used by us nevertheless enable access from a third country, this takes place only on the basis of suitable safeguards or a relevant adequacy decision.
8. Strategy Tracking and Follow Feature
Server-Side Storage of Tracker and Strategy Configurations
If you use the Follow or tracker feature, we store configuration data server-side, linked to your email session. In particular, the following data may be processed:
- your email address as a session identifier
- tracker and strategy configurations set up by you (e.g. chosen strategy, rebalance settings, slot assignment)
- actions confirmed by you and rebalance notifications
- waitlist entries as well as status and timestamp information
Processing is carried out to provide, store, and manage the Follow and tracker configurations you have set up, and to authenticate the feature within your session.
Legal basis: Art. 6(1)(b) GDPR insofar as processing is required to provide the Follow/tracker feature requested by you.
Recipients/categories of recipients: hosting and infrastructure service providers used by us. Processing takes place within our own backend and database infrastructure.
Retention: tracker and strategy configurations and confirmed actions are stored as long as the respective follow configuration is active. When the follow is ended or the session expires, the data is deleted within the limits of technical feasibility.
A third-country transfer is not intended in this respect. If hosting or infrastructure service providers used by us nevertheless enable access from a third country, this takes place only on the basis of suitable safeguards or a relevant adequacy decision.
9. Feedback Feature
Use of the Feedback Feature
When you use the voluntary feedback feature, we process the data you enter as well as automatically collected data, in particular:
- the free-text message you entered
- your email address, if you voluntarily provide it
- the current page URL at the time of submission
- technical device data (user agent of your browser or app)
- technical context data such as platform, viewport, language setting, theme, connection type, and online status
- for bug reports, an optional screenshot attached by you
Processing is carried out solely for the purpose of handling the feedback and improving the app. Data is not shared with third parties for advertising purposes, and no automated decision-making takes place. The email address is only used if a reply is requested.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the quality of the offering). Voluntary submission of an email address is based on Art. 6(1)(a) GDPR (consent).
Recipients/categories of recipients: hosting and API service providers used by us as well as a self-hosted support system operated by us for handling support and feedback requests.
Retention: feedback data is deleted after processing, at the latest after 12 months.
Any third-country transfers take place only on the basis of suitable safeguards or a relevant adequacy decision.
10. Your Rights
Within the scope of the applicable law, you have in particular the right of access, rectification, erasure, restriction of processing, and data portability. You also have the right to withdraw consent at any time with effect for the future and the right to lodge a complaint with a data protection supervisory authority.
Last updated: July 23, 2026