CoinmicoCoinmico

Legal

Privacy policy

Coinmico is a market data service, not an advertising business. This policy sets out exactly what we collect on coinmico.com, why we collect it, who processes it for us, how long it stays and how you can have it removed.

Effective
27 August 2026
Last updated
27 August 2026

1.Scope of this policy

This policy explains how Coinmico (“Coinmico”, “we”, “us”) handles personal data when you visit coinmico.com, create an account, or use our market data API. It applies to every page and endpoint served from coinmico.com and its subdomains.

It does not apply to the exchanges, block explorers, wallets and social networks we link to. Once you follow such a link, that operator's own policy governs what happens to your data.

2.Who is responsible for your data

Coinmico is the controller of the personal data described here. You can reach us about anything in this policy at [email protected]. For contractual or legal notices, write to [email protected].

We answer requests about your own data within 30 days. If we need more time because a request is complex, we will tell you why before that deadline passes.

3.Data we collect

Coinmico works without an account: browsing coins, charts, exchanges and categories requires no personal data at all. The categories below are collected only for the features you actually use.

CategoryWhat it contains and why
AccountYour email address, and either a password digest or the identifier Google returns when you sign in with Google. We need it to create the account, sign you in and recover access. Passwords are never stored in a readable form.
Public profileUsername, display name, biography, website and social links, and an avatar seed — all optional beyond the username, all visible on your profile page because that is the point of it.
Product dataYour watchlist, portfolio entries, price alerts, baskets, the accounts you follow and the sentiment votes you cast. Stored against your account so it follows you between devices.
SessionsFor each active sign-in: a digest of the session cookie, the date it was opened and the browser user agent, so you can recognise your devices on the account page and end sessions you do not recognise.
API keysFor each key you create: a name, a short visible prefix, a digest of the key itself and hourly usage counts, so quotas can be enforced and you can see your own usage.
SubmissionsDetails you send through the coin submission form, and the address the submission came from, so the same address cannot flood the queue.
Technical logsIP address, user agent, requested URL, response status and timestamp, recorded by our hosting and infrastructure providers, plus short-lived counters used for rate limiting.

We do not collect payment data, we do not ask for identity documents, and we never ask for a wallet private key, seed phrase or exchange API secret. Nobody at Coinmico will ever request them.

4.Data that stays on your device

Signed out, your watchlist is kept in your browser's local storage and never reaches us. The same is true of your display currency, theme, chart interval, indicators and drawings, and the row count you last chose on a table. Clearing site data erases them, and we cannot restore them.

5.Cookies and similar technologies

We set one cookie, coinmico_session. It is strictly necessary: it holds your sign-in token, is HTTP-only and secure, and expires 30 days after it was issued or as soon as you sign out. A short-lived cookie is also used during Google sign-in to protect the request against cross-site forgery.

We run no advertising cookies, no third-party analytics and no cross-site trackers, so there is no consent banner to dismiss. Where we must fetch an asset from a content network, that request carries nothing beyond the technical data a request always carries.

6.How and why we use your data

  • To provide the service you asked for: signing you in, storing your watchlist, portfolio, alerts and baskets, publishing the profile you chose to publish, and answering API requests against your key. Legal basis: performance of a contract.
  • To keep the service standing up: rate limiting, abuse detection, quota enforcement, and diagnosing faults from logs. Legal basis: legitimate interest in a secure and available service.
  • To act on submissions and reports you send us, including checking that a submitted asset is real before it is listed. Legal basis: legitimate interest in data quality.
  • To meet legal obligations and respond to lawful requests, where we are required to. Legal basis: legal obligation.

We do not profile you, we do not make automated decisions with a legal effect on you, and we do not use your data to train third-party models.

7.Who we share data with

We do not sell personal data and we do not share it for advertising. Data is disclosed only to the providers that run the service on our behalf, under contract and only for that purpose:

  • Application hosting and content delivery for coinmico.com, which necessarily processes request logs.
  • Database, cache and server infrastructure that stores accounts, product data and market data.
  • Object storage for the images and brand assets the site serves.
  • Google, if — and only if — you choose to sign in with Google, which tells us the account identifier and email you approved.

Beyond that, we disclose data only where the law requires it, or where it is necessary to establish or defend a legal claim, or to protect the service and its users from abuse.

8.International transfers

Our providers operate data centres in several countries, so your data may be processed outside the country you live in. Where data leaves the European Economic Area or the United Kingdom, it is transferred on the basis of the European Commission's standard contractual clauses or an adequacy decision covering the destination.

9.How long we keep it

  • Account, profile and product data: until you delete the account. Deleting it removes the account row and everything that references it — watchlist, portfolio, alerts, baskets, follows, sessions and API keys.
  • Sessions: 30 days from issue, or immediately when you sign out or end the session from the account page.
  • API keys: until you revoke them; the record of a revoked key is kept only as long as its usage counters, which roll off hourly.
  • Technical logs and rate-limit counters: kept briefly, the counters for minutes or hours and provider logs for the short retention those providers apply.

Market data — prices, volume, candles, on-chain swaps — is not personal data and is retained under our own retention schedule independent of this policy.

10.Security

Traffic to coinmico.com is served over TLS. Passwords are stored as a scrypt digest with a per-user salt; session tokens and API keys are stored only as digests, so a copy of our database cannot be replayed as a login or as a key. Access to production systems is limited to the people who operate them.

No service can promise perfect security. If a breach affects your personal data and presents a risk to you, we will notify you and the competent authority as required by law. Security issues can be reported to [email protected].

11.Your rights

Depending on where you live, you have some or all of the following rights over your personal data: access, correction, deletion, restriction of processing, objection to processing based on legitimate interests, portability of the data you gave us, and withdrawal of any consent you gave.

Most of these you can exercise yourself: edit your profile, watchlist, portfolio and alerts at any time, revoke API keys and end sessions on the account page, and delete the account outright from the same page. For anything else, write to [email protected] from the address on the account.

If you are in the European Economic Area or the United Kingdom, you may also complain to your local data protection authority. If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA, we do not use it for cross-context behavioural advertising, and exercising a right will never lead to a worse service for you.

12.Children

Coinmico is not directed at children and accounts are not intended for anyone under 16. If you believe a child has created an account, tell us and we will remove it.

13.Changes to this policy

We update this policy when the service changes what it collects. The effective date above always reflects the current version, and material changes are published here before they take effect. Continuing to use coinmico.com after that date means the revised policy applies to you.

Read alongside our terms of service and methodology.