LEGAL · PRIVACY

Privacy Policy

Last updated: May 29, 2026 · Effective: May 29, 2026 · [email protected]

Short version: NeverHodl collects only what is necessary to provide the service. We never sell your data. We never share it with third parties for commercial purposes. You can export or delete all your data at any time from your profile. We comply with GDPR (EU 2016/679), LOPDGDD (Spain), and LGPD (Brazil).

1. Who We Are (Data Controller)

NeverHodl ("NeverHodl™", "we", "us", "our") is a cryptocurrency market cycle intelligence platform operated by Luis Armando Fraga, NIF 110.039.537-78, registered in Spain. Trademark: OEPM M4370276 (Classes 36 and 42).

Website: neverhodl.com · Contact: [email protected] · Supervisory authority: AEPD (Spain)

2. Data We Collect

2.1 Account data (when you sign up)

2.2 Optional profile data

2.3 Payment data

2.4 Usage data (collected automatically)

2.5 Community data

2.6 What we do NOT collect

3. How We Use Your Data

4. Legal Basis (GDPR Art. 6)

5. Notification Preferences

You have granular control over every notification channel. Manage preferences in your profile settings:

ChannelDefaultType
Marketing emails (NHCI updates, insights)OffOpt-in required
Product emails (welcome, payment, subscription)OnTransactional
Push notifications (phase changes, score alerts)OnConsent via device permission
Telegram alerts (daily briefing)OffOpt-in required

You can unsubscribe from marketing emails instantly via the one-click unsubscribe link in every email (RFC 8058 compliant).

6. Cookies

7. Data Sharing

NeverHodl never sells, rents, or trades your personal data. We do not share data with advertisers or data brokers.

We use the following sub-processors:

ProviderPurposeData processed
SupabaseDatabase, authenticationAccount data, encrypted at rest
StripePayment processingPayment method, billing info
ResendEmail deliveryEmail address, email content
VercelHosting, serverless functionsServer logs, IP addresses
UpstashRate limiting (Redis)IP hashes (no PII)
FirebasePush notificationsDevice tokens
Google Analytics 4Anonymised analyticsPage views, sessions (consent-gated)

8. Data Retention

Data typeRetention
Account profileUntil you delete your account
API usage logs90 days
Activity logs1 year
Audit logs (compliance)2 years (anonymised on account deletion)
Points ledger2 years
Deleted chat messages90 days after deletion
Analytics (GA4)14 months (Google default)
Expired admin sessions24 hours

Automated data cleanup runs weekly to enforce these retention periods.

9. Data Security (Art. 32)

We implement technical and organisational measures to protect your data:

In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by GDPR Art. 33/34.

10. Your Rights

Under GDPR (EU 2016/679), LOPDGDD (Spain), and LGPD (Brazil), you have the following rights:

Most rights can be exercised directly from your profile page without contacting us. For requests that require manual processing, email [email protected] — we respond within 30 days (GDPR Art. 12.3).

You also have the right to lodge a complaint with the AEPD (Agencia Espanola de Proteccion de Datos) at aepd.es.

11. International Transfers

Your data may be processed in the EU and the United States by our sub-processors. Transfers outside the EU/EEA are covered by Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework as required by GDPR Chapter V.

12. Children

NeverHodl is not directed at children under 16. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a child, contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated via a notice on the website. The "Last updated" date at the top indicates when the policy was last revised.

14. Disclaimer

NeverHodl is a market data and educational intelligence platform. Nothing on this website constitutes financial advice, investment advice, or a recommendation to buy or sell any asset. All investment decisions are the sole responsibility of the user. Crypto assets are highly volatile and can lose all their value.

Contact & Data Requests

For privacy-related questions, data access requests, or to exercise your GDPR rights:

[email protected]

We respond within 30 days as required by GDPR Art. 12.3.