CoinmicoCoinmico

Legal

Privacy policy

Coinmico is a market data service, not an advertising business. This policy sets out exactly what we collect on coinmico.com, why we collect it, who processes it for us, how long it stays and how you can have it removed.

Effective
27 August 2026
Last updated
27 August 2026

1.Scope of this policy

This policy explains how Coinmico (“Coinmico”, “we”, “us”) handles personal data when you visit coinmico.com, create an account, or use our market data API. It applies to every page and endpoint served from coinmico.com and its subdomains.

It does not apply to the exchanges, block explorers, wallets and social networks we link to. Once you follow such a link, that operator's own policy governs what happens to your data.

2.Who is responsible for your data

Coinmico is the controller of the personal data described here. You can reach us about anything in this policy at [email protected]. For contractual or legal notices, write to [email protected].

We answer requests about your own data within 30 days. If we need more time because a request is complex, we will tell you why before that deadline passes.

3.Data we collect

Coinmico works without an account: browsing coins, charts, exchanges and categories requires no personal data at all. The categories below are collected only for the features you actually use.

CategoryWhat it contains and why
AccountYour email address, and either a password digest or the identifier Google returns when you sign in with Google. We need it to create the account, sign you in and recover access. Passwords are never stored in a readable form.
Public profileUsername, display name, biography, website and social links, and an avatar seed — all optional beyond the username, all visible on your profile page because that is the point of it.
Product dataYour watchlist, portfolio entries, price alerts, baskets, the accounts you follow and the sentiment votes you cast. Stored against your account so it follows you between devices.
SessionsFor each active sign-in: a digest of the session cookie, the date it was opened and the browser user agent, so you can recognise your devices on the account page and end sessions you do not recognise.
API keysOnly for keys issued before API access was paused: a name, a short visible prefix, a digest of the key itself and hourly usage counts. New keys cannot be created.
SubmissionsDetails you send through the coin submission form, and the address the submission came from, so the same address cannot flood the queue.
Technical logsIP address, user agent, requested URL, response status and timestamp, recorded by our hosting and infrastructure providers, plus short-lived counters used for rate limiting.

We do not collect payment data, we do not ask for identity documents, and we never ask for a wallet private key, seed phrase or exchange API secret. Nobody at Coinmico will ever request them.

4.Data that stays on your device

Signed out, your watchlist is kept in your browser's local storage and never reaches us. The same is true of your display currency, theme, chart interval, indicators and drawings, and the row count you last chose on a table. Clearing site data erases them, and we cannot restore them.

5.The Coinmico Android app

The Android app talks only to coinmico.com and our content network, and it collects nothing the website does not. Signed out, your watchlist, price alerts, portfolio holdings, display currency and theme live in the app's private storage on the phone and never leave it; uninstalling the app erases them. Signed in, the watchlist and alerts are stored against your account exactly as described above, and the app keeps the same coinmico_session cookie in private storage so you stay signed in.

Price alerts are checked by the app itself, on the device, by requesting public prices from our API; a notification is shown only if you granted the notification permission, and you can revoke it at any time in Android settings. The app requests no other permission: no location, contacts, camera, microphone or storage access. It contains no advertising SDK, no analytics SDK and no third-party tracking, and it does not read your device identifiers.

6.Cookies and similar technologies

We set one cookie, coinmico_session. It is strictly necessary: it holds your sign-in token, is HTTP-only and secure, and expires 30 days after it was issued or as soon as you sign out. A short-lived cookie is also used during Google sign-in to protect the request against cross-site forgery.

We run no advertising cookies, no third-party analytics and no cross-site trackers, so there is no consent banner to dismiss. Where we must fetch an asset from a content network, that request carries nothing beyond the technical data a request always carries.

7.How and why we use your data

  • To provide the service you asked for: signing you in, storing your watchlist, portfolio, alerts and baskets, and publishing the profile you chose to publish. Legal basis: performance of a contract.
  • To keep the service standing up: rate limiting, abuse detection, quota enforcement, and diagnosing faults from logs. Legal basis: legitimate interest in a secure and available service.
  • To act on submissions and reports you send us, including checking that a submitted asset is real before it is listed. Legal basis: legitimate interest in data quality.
  • To meet legal obligations and respond to lawful requests, where we are required to. Legal basis: legal obligation.

We do not profile you, we do not make automated decisions with a legal effect on you, and we do not use your data to train third-party models.

8.Who we share data with

We do not sell personal data and we do not share it for advertising. Data is disclosed only to the providers that run the service on our behalf, under contract and only for that purpose:

  • Application hosting and content delivery for coinmico.com, which necessarily processes request logs.
  • Database, cache and server infrastructure that stores accounts, product data and market data.
  • Object storage for the images and brand assets the site serves.
  • Google, if — and only if — you choose to sign in with Google, which tells us the account identifier and email you approved.

Beyond that, we disclose data only where the law requires it, or where it is necessary to establish or defend a legal claim, or to protect the service and its users from abuse.

9.International transfers

Our providers operate data centres in several countries, so your data may be processed outside the country you live in. Where data leaves the European Economic Area or the United Kingdom, it is transferred on the basis of the European Commission's standard contractual clauses or an adequacy decision covering the destination.

10.How long we keep it

  • Account, profile and product data: until you delete the account. Deleting it removes the account row and everything that references it — watchlist, portfolio, alerts, baskets, follows, sessions and API keys.
  • Sessions: 30 days from issue, or immediately when you sign out or end the session from the account page.
  • API keys: until you revoke them; the record of a revoked key is kept only as long as its usage counters, which roll off hourly.
  • Technical logs and rate-limit counters: kept briefly, the counters for minutes or hours and provider logs for the short retention those providers apply.

Market data — prices, volume, candles, on-chain swaps — is not personal data and is retained under our own retention schedule independent of this policy.

11.Security

Traffic to coinmico.com is served over TLS. Passwords are stored as a scrypt digest with a per-user salt; session tokens and API keys are stored only as digests, so a copy of our database cannot be replayed as a login or as a key. Access to production systems is limited to the people who operate them.

No service can promise perfect security. If a breach affects your personal data and presents a risk to you, we will notify you and the competent authority as required by law. Security issues can be reported to [email protected].

12.Your rights

Depending on where you live, you have some or all of the following rights over your personal data: access, correction, deletion, restriction of processing, objection to processing based on legitimate interests, portability of the data you gave us, and withdrawal of any consent you gave.

Most of these you can exercise yourself: edit your profile, watchlist, portfolio and alerts at any time, end sessions on the account page, and delete the account outright from the same page. For anything else, write to [email protected] from the address on the account.

If you are in the European Economic Area or the United Kingdom, you may also complain to your local data protection authority. If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA, we do not use it for cross-context behavioural advertising, and exercising a right will never lead to a worse service for you.

13.Children

Coinmico is not directed at children and accounts are not intended for anyone under 16. If you believe a child has created an account, tell us and we will remove it.

14.Changes to this policy

We update this policy when the service changes what it collects. The effective date above always reflects the current version, and material changes are published here before they take effect. Continuing to use coinmico.com after that date means the revised policy applies to you.

Read alongside our terms of service and methodology.

Privacy policy | Coinmico