Legal
Privacy policy
Coinmico is a market data service, not an advertising business. This policy sets out exactly what we collect on coinmico.com, why we collect it, who processes it for us, how long it stays and how you can have it removed.
- Effective
- 27 August 2026
- Last updated
- 27 August 2026
1.Scope of this policy
This policy explains how Coinmico (“Coinmico”, “we”, “us”) handles personal data when you visit coinmico.com, create an account, or use our market data API. It applies to every page and endpoint served from coinmico.com and its subdomains.
It does not apply to the exchanges, block explorers, wallets and social networks we link to. Once you follow such a link, that operator's own policy governs what happens to your data.
2.Who is responsible for your data
Coinmico is the controller of the personal data described here. You can reach us about anything in this policy at [email protected]. For contractual or legal notices, write to [email protected].
We answer requests about your own data within 30 days. If we need more time because a request is complex, we will tell you why before that deadline passes.
3.Data we collect
Coinmico works without an account: browsing coins, charts, exchanges and categories requires no personal data at all. The categories below are collected only for the features you actually use.
| Category | What it contains and why |
|---|---|
| Account | Your email address, and either a password digest or the identifier Google returns when you sign in with Google. We need it to create the account, sign you in and recover access. Passwords are never stored in a readable form. |
| Public profile | Username, display name, biography, website and social links, and an avatar seed — all optional beyond the username, all visible on your profile page because that is the point of it. |
| Product data | Your watchlist, portfolio entries, price alerts, baskets, the accounts you follow and the sentiment votes you cast. Stored against your account so it follows you between devices. |
| Sessions | For each active sign-in: a digest of the session cookie, the date it was opened and the browser user agent, so you can recognise your devices on the account page and end sessions you do not recognise. |
| API keys | For each key you create: a name, a short visible prefix, a digest of the key itself and hourly usage counts, so quotas can be enforced and you can see your own usage. |
| Submissions | Details you send through the coin submission form, and the address the submission came from, so the same address cannot flood the queue. |
| Technical logs | IP address, user agent, requested URL, response status and timestamp, recorded by our hosting and infrastructure providers, plus short-lived counters used for rate limiting. |
We do not collect payment data, we do not ask for identity documents, and we never ask for a wallet private key, seed phrase or exchange API secret. Nobody at Coinmico will ever request them.
4.Data that stays on your device
Signed out, your watchlist is kept in your browser's local storage and never reaches us. The same is true of your display currency, theme, chart interval, indicators and drawings, and the row count you last chose on a table. Clearing site data erases them, and we cannot restore them.
6.How and why we use your data
- To provide the service you asked for: signing you in, storing your watchlist, portfolio, alerts and baskets, publishing the profile you chose to publish, and answering API requests against your key. Legal basis: performance of a contract.
- To keep the service standing up: rate limiting, abuse detection, quota enforcement, and diagnosing faults from logs. Legal basis: legitimate interest in a secure and available service.
- To act on submissions and reports you send us, including checking that a submitted asset is real before it is listed. Legal basis: legitimate interest in data quality.
- To meet legal obligations and respond to lawful requests, where we are required to. Legal basis: legal obligation.
We do not profile you, we do not make automated decisions with a legal effect on you, and we do not use your data to train third-party models.
8.International transfers
Our providers operate data centres in several countries, so your data may be processed outside the country you live in. Where data leaves the European Economic Area or the United Kingdom, it is transferred on the basis of the European Commission's standard contractual clauses or an adequacy decision covering the destination.
9.How long we keep it
- Account, profile and product data: until you delete the account. Deleting it removes the account row and everything that references it — watchlist, portfolio, alerts, baskets, follows, sessions and API keys.
- Sessions: 30 days from issue, or immediately when you sign out or end the session from the account page.
- API keys: until you revoke them; the record of a revoked key is kept only as long as its usage counters, which roll off hourly.
- Technical logs and rate-limit counters: kept briefly, the counters for minutes or hours and provider logs for the short retention those providers apply.
Market data — prices, volume, candles, on-chain swaps — is not personal data and is retained under our own retention schedule independent of this policy.
10.Security
Traffic to coinmico.com is served over TLS. Passwords are stored as a scrypt digest with a per-user salt; session tokens and API keys are stored only as digests, so a copy of our database cannot be replayed as a login or as a key. Access to production systems is limited to the people who operate them.
No service can promise perfect security. If a breach affects your personal data and presents a risk to you, we will notify you and the competent authority as required by law. Security issues can be reported to [email protected].
11.Your rights
Depending on where you live, you have some or all of the following rights over your personal data: access, correction, deletion, restriction of processing, objection to processing based on legitimate interests, portability of the data you gave us, and withdrawal of any consent you gave.
Most of these you can exercise yourself: edit your profile, watchlist, portfolio and alerts at any time, revoke API keys and end sessions on the account page, and delete the account outright from the same page. For anything else, write to [email protected] from the address on the account.
If you are in the European Economic Area or the United Kingdom, you may also complain to your local data protection authority. If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA, we do not use it for cross-context behavioural advertising, and exercising a right will never lead to a worse service for you.
12.Children
Coinmico is not directed at children and accounts are not intended for anyone under 16. If you believe a child has created an account, tell us and we will remove it.
13.Changes to this policy
We update this policy when the service changes what it collects. The effective date above always reflects the current version, and material changes are published here before they take effect. Continuing to use coinmico.com after that date means the revised policy applies to you.
Read alongside our terms of service and methodology.

