Who is responsible
LIMIT SRL is the website operator and controller for personal data it processes through BTCMox. Privacy contact: [email protected]. The About page provides the registered company identifiers, published address, telephone and further contact information.
Calculator inputs and local files
Values entered in a local browser calculator are processed in the current page. Those calculator forms do not submit values to the operator. Selected CSV/session files are read locally and not uploaded. If you independently use an authenticated API calculation endpoint, its JSON inputs are transmitted to the API server for that calculation; that separate request is not local-browser processing.
Do not include passwords, private keys, seed phrases, identity documents or another person's confidential information in calculator fields, journals or imported files. Local processing does not protect information from other users of your device, browser extensions or malware.
Optional storage on your device
When you deliberately save a favourite, preference, setup or journal entry, the website uses browser storage to retain that item for you. These saved items are not a cloud account and are not synchronised to BTCMox servers. They remain until you remove them, clear this site's data, or your browser removes them. Export a backup before clearing data you want to keep.
The public website does not include advertising cookies, audience analytics or fingerprinting code. The Data controls page explains the locally saved items and how to remove them. Browsers may independently cache website files. A hosting or security provider may also process connection data as described below.
Automatic public-market connections and requested lookups
Market views automatically send public GET requests to the providers named on the page when opened, and may refresh them while the page is active. Direct requests expose your IP address, connection time and browser request metadata, and identify the public market or network being requested. These requests do not include exchange credentials, your imported holdings or your journal.
An address or transaction lookup is different: its identifier is sent only when you submit that lookup. The selected provider then receives the public blockchain address or transaction identifier as well as request metadata. An address can reveal financial activity and can be associated with an individual. BTCMox does not infer a named owner from an address alone.
We use these limited public-data connections to provide current market observations, based on our legitimate interest in operating the research view. Automatic loading is not treated as consent to tracking or as a waiver of privacy rights. The supplied code does not add analytics, advertising or fingerprinting, and its HTTP market requests explicitly omit browser credentials. Public WebSocket connections follow the browser’s WebSocket and cookie rules; BTCMox supplies no exchange API key to them. A provider may process request information for its own purposes under its own policy.
Pause stops the public-feed requests and scheduled refreshes controlled by the current tab, and attempts to abort requests still in flight. It cannot withdraw a request that the provider already received. It is not a permanent account-wide or cross-tab preference: other tabs and newly opened or reloaded pages can connect separately. Local calculators do not require these market feeds.
Available providers and request purposes are shown in the data-source directory. Their endpoints, availability and processing locations can change. A public API does not establish a promise about a provider's retention, geographic processing arrangements or commercial reuse rights.
Website delivery and security records
Loading any hosted website necessarily exposes connection information to the web server and its network infrastructure. For BTCMox this can include an IP address, requested page, time, response status and user-agent information. The actual hosting and security services may retain access or error records for operation, troubleshooting and abuse prevention.
We use connection information to deliver the site and protect its availability, based on our legitimate interest in operating a secure public service. Records should be kept only while needed for those purposes, an identified security incident, or an applicable legal obligation. The exact host, any proxy or CDN, enabled logs and deletion schedule depend on the deployed service. You can request the current arrangements through the privacy contact above.
Messages you choose to send
If you email us, we receive your address, message and any attachments through our email service. We use them to respond to the request and maintain necessary correspondence. This is based on our legitimate interest in handling enquiries, or on steps you request before a contract where applicable. We do not add an enquiry sender to a marketing list merely because they contacted us.
Correspondence is kept while needed to resolve the enquiry, document the response and handle a related complaint or legal obligation. Relevant records may be retained for a dispute; unrelated material should be removed. You can ask for the retention criteria for your particular correspondence. Required information is limited to what is needed to answer; withholding it may prevent a meaningful reply.
Recipients and international processing
Authorised people acting for LIMIT SRL and relevant hosting, security and email providers may handle the data needed for their tasks. Information may be supplied to competent authorities when legally required. Local calculator entries are not deliberately disclosed through these services by the calculator code.
Where LIMIT SRL arranges a transfer outside the EEA, the applicable transfer mechanism and safeguards must be established for the recipient. Automatic loading, an API button and continued browsing are not waivers of these requirements. Contact us for information about the recipients and transfer arrangements applicable to processing for which LIMIT SRL is responsible. An external provider may separately process information under its own policy when a market view or a requested lookup connects to it.
Your choices and rights
Where applicable, you may request access, correction, deletion, restriction and portability of personal data, and object to processing based on legitimate interests. Where consent is the basis, you can withdraw it prospectively. We normally respond within one month; a permitted extension will be explained. We may request proportionate information to verify a request, not automatically an identity document.
You can complain to Romania's ANSPDCP or another competent supervisory authority. An ANSPDCP complaint link appears below. Local records that the operator never receives are best managed through your browser or Data controls. The site does not use your calculator inputs for decisions producing legal or similarly significant effects about you.
Changes and separate services
The optional API processing is described below. The static website does not automatically send its calculator inputs to that API or require a paid key. If checkout, trade execution, analytics or other processing is added, the notice and controls must be updated before it begins. Following an external link opens a separate service with its own terms.
Shared input links and desktop alerts
If you choose Share inputs, the link includes the entered values in its fragment. Anyone receiving the link can read them; clipboard, history or software with access to your browser may retain them. Share only information you intend to disclose. The fragment is processed locally and is not part of the page’s HTTP request.
Optional terminal desktop notifications can appear on your operating system or lock screen. Browser notification permission can be revoked in browser settings. This permission is separate from deleting BTCMox local data.
CSV analysis and local execution-payload validation
CSV files you select are read in this browser for the requested analysis. The tool does not upload the file or send its rows to BTCMox or a data provider. Imported analysis remains in page memory unless you deliberately use a separately labelled local-save action. A report you download is a file on your device and is not deleted by Clear local data.
When an analysis uses a public-market connection, the named provider receives your IP address, request metadata and the requested public market identifier. Market views may make that connection automatically. The tools do not send imported quantities, trade history or file contents with the request.
The execution-payload lab validates example JSON locally. It does not deliver a webhook, submit an order, connect an exchange account or provide a continuously running execution service. Use placeholders: do not paste API keys, passwords, signatures, seed phrases or real webhook secrets.
Session observations and market proxies
Heatmap and depth-history views keep a bounded series of retrieved market observations in current-page memory. Pausing can leave those earlier observations visible with their timestamps; it does not turn them into fresh data. Reloading or closing the page discards this unsaved session history. Downloaded exports remain on your device until you remove them.
Order persistence, pressure, accumulation or distribution labels are defined analytical proxies. They do not identify an order owner, confirm a wallet balance, establish that visible orders traded, or prove a trader's intention. The service does not build a confirmed ownership profile of a named person from these labels.
Optional API access, credentials and quota records
If the optional API service is activated for you after an agreed manual invoice, the operator maintains a key identifier, credential hash, administrative label, plan, issue/expiry/revocation times, monthly quota, per-minute limit, current UTC month/minute usage counters and last-used time. A label should use a customer reference rather than unnecessary personal information. The application database stores a SHA-256 hash of a randomly generated key, not the raw key. The raw credential is issued once and used in an authentication header.
API JSON calculation inputs are received and processed on the server. The supplied application does not store those inputs, request bodies, raw credentials, client IP addresses or a per-request history in its database. A request identifier is returned for the response. Web servers, operating-system error logs, reverse proxies and hosting infrastructure may still handle connection information; their actual configuration and retention must be considered separately.
We use access records and quota counters to perform the agreed API service and enforce its limits, and use proportionate security records to protect it. Billing/contact correspondence is handled separately for contract administration and applicable accounting or legal obligations. Key records currently have no automatic purge in the supplied service: revocation prevents access but does not erase the record. The operator must remove or retain records according to the actual service, dispute and legal-retention needs; contact the privacy address for the applicable schedule.
If licensed market-data access is enabled, the API server requests an allowlisted public instrument from the approved provider. That provider receives the API server connection and public request parameters; the backend does not forward your API key or calculator request body. Provider access is disabled by default until the operator records appropriate rights. This configuration is not a provider licence or a transfer safeguard.
Clear local data and Pause on the public website do not revoke an API key, erase server-side key/quota records or stop requests sent independently by your software. Request revocation or exercise privacy rights through the contact on this page. Do not put API keys in public pages, browser storage, shared URLs, logs or unrelated correspondence.