Skip to content

Legal · Last updated August 10, 2026

Privacy Policy

LiquidONE is operated from Victoria, Australia. This policy explains what personal information we collect, how we hold, use and disclose it, and how you can access, correct or complain about our handling of it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we extend additional rights to users covered by the GDPR, UK GDPR and California privacy laws.

1. Who we are and what this policy covers

LiquidONE ("LiquidONE", "we", "us" or "our") provides an automated trading platform at liquid1trade.com and app.liquid1trade.com, including the strategy builder, execution engine, strategy marketplace, copy trading, AI copilot (AiCopilot), the LiquidONE Terminal CLI, analytics and related services (the "Services"). This policy covers personal information we handle when you visit our websites, use the Services, contact support, or interact with us anywhere else this policy is linked. It does not cover the practices of third parties you connect to LiquidONE, such as your broker or endpoints you configure for webhooks; their own policies apply.

2. Personal information we collect

  • Identity and account data. Name, email address, profile image and authentication identifiers, managed through our identity provider (Better Auth). If you sign in with a social provider, we receive the profile details you authorise. If you complete identity verification, we also hold your verification status and the date it was decided (see section 5).
  • Billing data. Subscription plan, purchase and payout history, prepaid balance activity and referral credits. Card details are collected and held by our payment providers (Autumn and Stripe); we never see your full card number.
  • Trading and configuration data. Connected broker accounts, strategy configurations and custom strategy code, bot settings and risk limits, orders, fills, positions, balances, journal entries, forward tests, backtests and performance metrics.
  • Broker API keys. The API credentials you add to connect a broker or exchange, held encrypted as described in section 4.
  • AI interaction data. Messages you send to AiCopilot, AI Strategy Analysis requests and outputs, and token usage records.
  • Marketplace and referral data. Listings you publish, purchases, reviews you write, seller balances, withdrawal requests including the payout email you nominate, and referral attribution.
  • Alerting and integration data. Webhook URLs and alert destinations you configure, alert preferences, and inbound webhook activity on your accounts.
  • Device pairing data. If you pair the LiquidONE Terminal CLI, the pairing code, the hostname and client details the CLI reports, token identifiers (stored as hashes) and last-seen times.
  • Support and communications. Messages you send us, survey and onboarding responses you choose to give (such as trading experience and goals), notification history, and feedback.
  • Device and usage data. IP address, browser and device type, operating system, pages viewed, actions taken, referral URLs, error and crash reports, and approximate location derived from IP.

Apart from identity verification under section 5, we do not seek to collect sensitive information (such as health information) and ask that you do not include it in free-text fields or AI chats.

3. How we collect it

We collect personal information directly from you when you register, configure the Services, make a purchase or contact us; automatically through cookies, analytics and server logs as you use the Services; from your connected brokers and exchanges via the API keys you provide (for example balances, positions and order status); and from service providers such as Better Auth (sign-in events), Autumn and Stripe (payment outcomes) and Didit (identity verification outcomes). Where practicable you can interact with our public website without identifying yourself, but an account is required to use the platform.

4. Broker API keys and trading data

Broker and exchange API keys are among the most sensitive data we hold. They are encrypted at rest with AES-256, decrypted only inside our backend execution environment when placing or managing your orders, never sent to your browser, never shown to staff in plaintext, and never shared with other users. We recommend keys scoped to trading only, without withdrawal permission. You can delete a connection at any time, and we recommend also revoking the key with your broker. We do not hold your money or assets; trading data we receive from your broker is used to run your bots, compute your analytics and display your dashboard.

5. Identity verification and biometric information

Before you can sell strategies or receive marketplace payouts (and in other cases described in our Terms of Service), you must verify your identity. Verification is performed by our specialist provider, Didit. During verification, Didit collects images of your government-issued identity document and facial images for a biometric liveness and face-match check. Biometric information used for verification is sensitive information under the Privacy Act; we and Didit collect it only with your consent, which you give when you start a verification session. If you do not consent, you can still use the platform, but you cannot sell strategies or receive marketplace payouts.

  • Your document and facial images are captured by and stored with Didit, not on LiquidONE's own systems.
  • We receive the verification outcome, the name extracted from your document (which we compare with your account name), and your date-of-birth check result (18 or over). We store the outcome and its timestamp against your account.
  • We do not use verification data for any purpose other than verification, payout protection, fraud prevention and compliance. We never use it for marketing.
  • Didit's handling of your data is described in its own privacy policy, shown to you inside the verification flow.

6. Why we collect, hold and use personal information

  • to provide the Services: authenticate you, connect your brokers, execute the strategies you configure, replicate copy trades, run backtests and forward tests, compute analytics and keep your journal;
  • to process payments, subscriptions, marketplace sales, seller payouts and referral credits, and to send transactional messages such as receipts, security alerts, bot and trade notifications and daily summaries;
  • to operate the AI features you invoke, within your plan's usage limits;
  • to verify identity, protect payouts and meet anti-money-laundering and fraud-prevention obligations (section 5);
  • to secure the platform: detect fraud, abuse, unauthorised access and market misconduct, enforce our Terms, and protect users;
  • to improve the Services: debug errors, measure feature usage and develop new features. We do not use your private strategies or trading data to train public AI models, and we do not sell your personal information;
  • to comply with our legal obligations, including tax, accounting, consumer law and responding to lawful requests; and
  • with your consent, for anything else we describe at the time of collection.

7. AI features and your data

When you use AiCopilot chat, AI Strategy Analysis or the AI strategy compiler, the content of your request, together with relevant context (such as the recent trades of the bot being analysed), is sent to our AI model provider (currently Google) to generate the response. We record token usage to enforce plan limits and billing. We do not permit our AI providers to use your content to train their publicly available models under the API terms we rely on. Avoid pasting secrets, other people's personal information or anything you are not entitled to share into AI features.

8. Who we disclose personal information to

We disclose personal information only as needed to run LiquidONE:

  • Service providers (sub-processors). Better Auth (authentication), Autumn (subscription billing), Stripe (payments and payouts), Didit (identity verification), Supabase (database hosting), Vercel (application hosting), PostHog (product analytics and error tracking), Google (AI model serving), Resend (transactional email), Upstash (queues, rate limiting and caching), Slack (internal operational alerts, for example when a payout request needs review) and Cloudflare (network security and performance). Each processes data only to provide its service to us.
  • Your brokers and exchanges. We transmit order instructions and read account data using the API keys you connected, solely per your configured strategies.
  • Endpoints you configure. If you set up outbound webhooks, Discord alerts or third-party automations, we send the data you selected to the destination you chose. You control these disclosures.
  • Other users, at your direction. See section 9.
  • Law and safety. Regulators, law enforcement or courts where required or authorised by law, and parties involved in protecting our rights, users or the public.
  • Business transfers. A buyer or successor in a merger, acquisition or restructure, subject to this policy continuing to apply.

We do not sell or rent personal information, and we do not share it with data brokers.

9. Information you make public

Some features publish information to other users or to the open web, always at your direction:

  • publishing a marketplace listing displays the listing, its performance snapshot and your name as the seller;
  • writing a review displays the review and your name;
  • sharing a bot publicly or embedding its stats card makes those statistics visible to anyone with the link, and attested figures carry a verifiable signature;
  • your referral link identifies your referral code to whoever you give it to.

Unpublishing a listing, deleting a review or disabling a share stops new access, but copies already made by others may persist.

10. Overseas disclosure (APP 8)

Your account data, including your trading history, is stored in our primary database in Japan (Tokyo), and the application servers that read and write it run in the same region. Our other service providers listed in section 8 store and process data primarily in the United States, and some operate globally, including our identity verification provider Didit. This means your personal information is likely to be disclosed to recipients located in Japan, the United States, and other countries where those providers operate.

Before disclosing personal information overseas we take reasonable steps, including contractual data protection commitments, to ensure recipients handle it consistently with the APPs. For EEA and UK users, transfers rely on safeguards described in section 16.

11. Cookies and analytics

We use cookies and similar technologies to keep you signed in, remember preferences, attribute referrals (a 30-day referral cookie) and understand product usage through PostHog analytics, which we serve through our own domain. Details of each cookie, what it does and how to control it are in our Cookie Policy. You can limit cookies in your browser; essential cookies are required for sign-in to work.

12. Communications and direct marketing

We send transactional and service messages as part of operating the platform: receipts, security alerts, bot and trade notifications, withdrawal confirmations, forward test results and daily summaries, based on your notification settings. We may also send you product news and offers about LiquidONE by email in accordance with the Spam Act 2003 (Cth). Every marketing email includes a working unsubscribe link, and unsubscribing does not affect transactional messages. We do not give your details to third parties for their own marketing.

13. How we hold and protect personal information

Personal information is held in access-controlled cloud infrastructure. Safeguards include encryption in transit (TLS) and at rest, AES-256 encryption of broker API keys, hashed (never plaintext) CLI tokens and pairing codes, signed webhooks from our payment and identity providers, network security headers and rate limiting, least-privilege access for staff, audit logging, and separation between the execution environment and the public application. No system is perfectly secure, so we also maintain monitoring and an incident response process (see section 18). You can read more on our Security page.

14. Retention and deletion

We keep personal information for as long as your account is active and as needed for the purposes in section 6. If you delete your account:

  • your live bots are stopped and your connected accounts are deactivated immediately;
  • your name, email address and profile image are removed from our active systems and replaced with anonymised placeholders;
  • records the law requires us to keep are retained for the required period before deletion: financial and tax records such as purchases, payouts and referral credits (generally 7 years under Australian law), records needed for existing disputes or legal obligations, and minimal logs kept for security and fraud prevention;
  • identity verification outcomes may be retained as part of our fraud-prevention and compliance records; the underlying documents remain subject to Didit's retention policy;
  • backups are purged on a rolling schedule.

Deleting a broker connection removes the stored API key. Revoking a paired terminal invalidates its token. You can export your trading history from the dashboard at any time before deleting your account.

15. Access, correction and complaints (Australia)

You may request access to the personal information we hold about you and ask us to correct it. Much of your data is directly visible and editable in your account, and you can export your trading history from the dashboard. For anything else, email privacy@liquid1trade.com. We respond within a reasonable period (usually 30 days) and do not charge for making a request. If we refuse access or correction, we will tell you why and how to complain. Note that if you have completed identity verification, your account name is locked to your verified name; contact us to correct it if your legal name changes.

If you believe we have breached the APPs, complain to us first at privacy@liquid1trade.com and we will investigate and respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

16. Additional rights for EEA and UK users

If the GDPR or UK GDPR applies to you, LiquidONE is the controller of your personal data. Our legal bases are: performance of our contract with you (providing the Services), our legitimate interests (securing and improving the Services, preventing fraud), compliance with legal obligations, and consent where we ask for it, including explicit consent for biometric identity verification (which you may withdraw at any time; withdrawal does not affect processing already carried out). You have the rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to solely automated decisions with legal or similarly significant effect. Trading automation acts only on instructions you configure. Identity verification includes an automated document and biometric check by Didit; if verification is declined you can contact us for human review of the decision. Transfers outside the EEA and UK rely on adequacy decisions (including the EU-US Data Privacy Framework where our providers are certified) and standard contractual clauses. Exercise these rights via privacy@liquid1trade.com; you may also complain to your local supervisory authority.

17. Additional rights for California users

If the CCPA/CPRA applies to you, you have the right to know what personal information we collect, use and disclose (as described in this policy), to access and delete it, to correct it, and not to be discriminated against for exercising your rights. We do not sell personal information and do not share it for cross-context behavioural advertising, so no opt-out is needed. Sensitive personal information (government identifiers and biometric data collected during identity verification) is used only for identity verification, security and fraud prevention, purposes permitted by the CPRA, so no right-to-limit action is required. Submit requests to privacy@liquid1trade.com; we will verify your identity via your account email. Authorised agents may act for you with written permission.

18. Data breach notification

We participate in the Notifiable Data Breaches scheme under the Privacy Act. If a data breach occurs that is likely to result in serious harm, we will notify affected users and the OAIC as soon as practicable, describe what happened and what data was involved, and recommend steps you can take. Where the GDPR applies, we will also notify the relevant supervisory authority within the required timeframe.

19. Children

The Services are for adults. We do not knowingly collect personal information from anyone under 18, and identity verification confirms age before payouts. If you believe a minor has created an account, contact privacy@liquid1trade.com and we will delete it.

20. Changes to this policy

We may update this policy as the Services and the law evolve. For material changes we will notify you by email or in-app before they take effect. The date at the top shows the current version. Earlier versions are available on request.

21. Contact us

Privacy Officer, LiquidONE, Victoria, Australia. privacy@liquid1trade.com for privacy matters, or hello@liquid1trade.com for anything else.