← All markets

Instinkt Exchange

Privacy Policy

This notice explains the data used by Instinkt Exchange and the current behavior of the app. It is not a request for blanket consent. Operator details and the outstanding retention and vendor arrangements must be confirmed before publication as a final policy.

Document status

Status: draft for owner/legal review; not yet effective.

Draft date: 19 September 2026.

Operator / data controller: [FULL NAME OF RESPONSIBLE INDIVIDUAL — TO COMPLETE]

Contact address: [CONTACT ADDRESS — TO COMPLETE], Serbia.

Instinkt Exchange is not currently operated by a registered company.

Support, privacy requests and complaints: support@instinkt.rs. This mailbox is monitored.

Effective date: [TO COMPLETE BEFORE PUBLICATION].

1. Information we process

Account information includes email, username, display name, account dates and email-verification status. For password accounts we store a password hash, not the plaintext password. Google sign-in supplies account identity information such as email and name; we do not receive your Google password. Initial Google usernames are derived from the email address and can be changed in the username flow.

Game and social records include virtual balances, trades, positions, transactions, market activity, league membership, comments, chat messages, friendships, rivalries, invitations and achievements. Activity timestamps support bonuses and inactivity reminders. Verification/reset token hashes, IP-based rate-limit records and technical error or usage information support authentication and operation. Support correspondence contains the information you send us.

3. What other people can see

Public profiles and rankings display usernames and game information. Public profiles show markets in which an account holds positions; comments and shared achievement links can be public. Other users may save or redistribute public information. Choose a username that does not identify you if you prefer a pseudonym.

Private league pages and chat are restricted to members through the app, but authorized service administrators and providers may process that data. A private league is not an encrypted confidential conversation.

4. Providers and international processing

The app uses Vercel for hosting and web analytics, Neon for the database, Google for optional sign-in, Resend for email and Pusher for live updates and chat. Sentry processes error and performance information when configured. Providers receive the information necessary for their role, which can include identifiers, technical data or message content. Google also processes sign-in information under its own privacy terms.

Hosting is configured for Frankfurt, but this does not mean every provider processes all data only in Germany or Serbia. Provider access, subprocessors and international transfers require appropriate contractual and legal safeguards. The operator must confirm the applicable transfer arrangements and make information about safeguards available on request before this notice is finalized.

5. Cookies, storage and analytics

Authentication uses cookies to maintain and secure sessions. A locale cookie stores your language choice; local storage remembers the theme. Session storage can prevent duplicate analytics events. The service worker caches static app assets and an offline page, rather than private account pages or live balances.

Vercel Analytics collects page-usage and event information. Optional Sentry monitoring collects technical errors and sampled performance data. Page addresses are reduced before they are reported to these providers: an address containing an email-verification or password-reset token is not reported to analytics at all and has the token replaced in any error report, and a username, market, league or rivalry identifier in an address is replaced with a placeholder. Query strings and any submitted form values are removed from error reports. Browser controls can clear cookies and storage, but doing so may sign you out or reset preferences. Any required permission for nonessential tracking must be implemented separately; reading this notice does not grant it.

6. Emails

Account verification and password-reset emails are sent when needed for those functions. The current app also contains an inactivity reminder that uses the last activity date and verified email address. This promotional reminder must be disabled or made subject to appropriate prior permission and withdrawal before launch; this policy does not supply that permission.

7. Retention and account deletion

Account information is kept while the account operates. Deleting an account replaces its email and username, clears its display name, password hash and verification status, and removes authentication tokens and several social links. The service retains the underlying user ID, virtual transaction history, trades, positions, league memberships, comments and league-message records. These records are not guaranteed to be anonymous: content and context may still identify someone. Deleting a chat message hides it in the app but currently retains its body in storage.

You can request review or erasure of identifying content through support. Necessary retention must be justified by its purpose and applicable law, not simply by the existence of a record. Verification links expire after 24 hours and reset links after one hour; expiry does not itself erase token records. Rate-limit cleanup is best-effort. Exact record, log, backup and provider retention periods and deletion procedures remain to be confirmed before this policy is finalized.

8. Your rights and requests

Depending on the applicable conditions, you may request access, correction, erasure, restriction or portability of your information and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting prior lawful processing. Contact the address below; we may need proportionate information to verify your identity. Do not send identity documents unless requested through a suitable secure process.

Under Serbian law, the ordinary response period is 30 days; a permitted extension must be explained. You may complain to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection (Poverenik), or seek judicial protection. You do not have to contact us first to exercise those remedies.

9. Security, children and changes

The app uses measures including password hashing, expiring authentication tokens, access checks and rate limits. No online service can guarantee absolute security. Report suspected unauthorized access or exposed information to support.

The proposed launch is for adults aged 18 and over. Contact support if you believe a child has created an account or provided personal information. Material changes to this notice will be reflected in its revision date and communicated as required.