Privacy Policy
Short version: the site collects very little, and your trading credentials never leave your own machine.
1. Summary
Coil is built around a simple privacy principle: the parts that matter most to you never touch our servers. There are two pieces to be clear about, and they are deliberately separate.
- The website, coil.trade, is a static marketing site. It has no login, no account system, and no database of users. It exists to describe the product, and it collects only the minimal technical data described below — plus, if you choose to use the concierge chat, the questions and answers from that conversation (section 4).
- The Coil software is something you download and run yourself on your own Mac or Windows machine, inside your own AI agent, against your own brokerage account. Your broker and market-data API keys stay on your device. They are never transmitted to Coil, and the operator of Coil has no ability to see your credentials, your trades, your positions, or your capital.
In other words: we sell you a tool, you run it, and the sensitive material — your keys and your money — stays with you. This policy explains what little we do handle, who the third parties are, and how to reach us.
Your credentials never leave your machine. The Coil engine runs entirely on your own device. Your brokerage login, your data-API keys, your orders, and your account balances are read and used locally by software you control. None of that is sent to Coil, stored by Coil, or visible to the operator of Coil at any time.
2. Information we do NOT collect
Because the engine runs locally on your device, there is a large category of data we never receive and never want. Specifically, Coil does not collect, store, transmit, or have access to:
- Your brokerage username, password, API keys, tokens, or any other login credentials.
- Your market-data provider keys or credentials.
- Your trades, orders, fills, open positions, or trade history.
- Your account balances, buying power, capital, or portfolio value.
- Any instruction the engine sends to your broker on your behalf.
All of that lives on your machine and flows directly between your device and your broker or data provider. The operator of Coil is not in that path and cannot observe it.
3. Information collected by the website
The coil.trade website is static and hosted on a content-delivery network. Visiting it involves the small amount of routine technical data that any modern website generates:
- Server and CDN logs. Our host, Cloudflare, processes basic request data — such as your IP address, browser user-agent, the pages requested, and timestamps — for security, abuse prevention, and performance. This is standard infrastructure logging, handled by Cloudflare under its own terms.
- Cloudflare Web Analytics. A cookieless, aggregate measurement of page visits (page views, load performance, referrer categories) injected by our host at the edge. It sets no cookies and builds no profile.
- Google Analytics. We also run Google Analytics 4 on this website and on the Gumroad checkout pages for Coil products, so we can see which pages people arrive on, which ones lead to a purchase, and whether a visitor is returning. This one does set a cookie — a first-party
_gaidentifier stored by your browser for up to two years — and it sends your IP address, page URL, referrer, device and browser type, and approximate location to Google, which processes that data under its own privacy policy. Because Google operates across many sites, this is the one measurement on Coil that is not confined to coil.trade. We do not upload customer lists and do not sell visitor data — but we will not describe this as cookieless or tracking-free, because it is neither. How to turn it off: install Google's official opt-out browser add-on, block analytics cookies in your browser settings, or use any content blocker — every part of coil.trade works normally with it blocked. - Google Ads. We advertise Coil, and we run Google's advertising tag (
AW-18333792384) so we can tell which ads actually bring people here. It records when you start a checkout for a Coil product — which product, and its listed price — and reports that to Google as a conversion. It sets an advertising cookie and shares the same connection details Google Analytics does. It is subject to the identical controls: denied until you accept in the EU and the UK, switched off entirely when your browser sends a Global Privacy Control signal, and blocked by any content blocker. We do not upload customer lists to Google, and we do not use it to follow you around other websites. How to turn it off: decline the cookie banner, enable Global Privacy Control, or block it — everything on coil.trade works the same either way. - Coil Scanner license checks. If you subscribe to Coil Scanner and unlock it at coil.trade/scanner, the license key you paste is sent over HTTPS to our edge worker and forwarded to Gumroad to verify your subscription. We never store the key itself on our side: the worker keeps only a one-way (SHA-256) hash of it with an allow/deny verdict, cached for up to six hours to speed up checks, and your browser remembers the key in its own localStorage on your device (clear browser data to remove it).
- No account system. There is no sign-up, login, or user database on coil.trade. We are not storing a profile about you on this site.
4. The concierge chat
The chat window on this site is an AI assistant that answers questions about Coil from our own published documentation. It is optional — if you never open it, it sends nothing.
- What we store. When you send a message, we record your question, the assistant's reply, the page you asked from, the time, and how long the reply took. We read these to learn what people actually want to know and to find questions our site answers badly. There is no automated profiling and no advertising use.
- What we do not store with it. The chat log holds no IP address, no name, no email, and no account — there is no account to attach it to. To tell one conversation apart from another we use a random label your browser generates for that tab; it is not linked to you, is not a cookie, is not shared with anyone, and disappears when you close the tab.
- Where your message goes. Your message and our documentation are sent to Anthropic, which operates the Claude model that writes the reply. Anthropic processes it under its own commercial terms and does not use it to train its models.
- Please do not paste secrets. The assistant is instructed never to ask for credentials, account numbers, or payment details, and to refuse them if offered. Do not send them anyway. For anything about your own account, email support@coil.trade.
- Deletion. Chat records are kept for up to 12 months and then deleted. If you want a conversation removed sooner, email support@coil.trade with the approximate date and page and we will delete it.
5. Payments
When you buy Coil, the checkout, billing, and payment processing are handled by Gumroad as the merchant of record. Your purchase is technically a transaction with Gumroad, and Gumroad's own privacy policy and terms apply to the data you enter at checkout.
- What Gumroad handles: your full payment details, including card or other payment-method information, billing address, and any tax information — plus receipts, license keys, and refunds. This data is processed by Gumroad, not by Coil.
- What Coil receives: limited order information needed to deliver and support your license — for example, confirmation that a purchase occurred, the product purchased, and the email address you used so we can send your license or download. We do not receive your full card number or complete payment details.
For details on how your checkout and payment data are handled, please refer to Gumroad's privacy policy, which governs that part of the transaction. You can manage your purchases at any time from your Gumroad Library at app.gumroad.com/library.
6. Email and support
If you email support@coil.trade — for support, billing questions, a refund request, or anything else — we use your message and email address solely to respond to you and to keep a record of the conversation for support and accounting purposes. We do not use support emails for marketing, and we do not sell them.
7. Cookies
Coil keeps its cookie use small and accounts for it here in full. There are three kinds, and no others:
- Strictly necessary. Security and fraud-prevention cookies set by Cloudflare on this site, and by Gumroad during checkout. Without them the site or the payment cannot function.
- Analytics. A first-party
_gacookie set by Google Analytics, described in section 3, which distinguishes a returning visitor from a new one. It is the only non-essential cookie we set, and you can block it without losing any functionality. - Your own settings. If you unlock Coil Scanner with a license key, your browser stores that key in
localStorageon your device. That is not a cookie, is never sent to anyone but our license check, and clearing your browser data removes it.
We run Google Ads conversion measurement (see the third-party list above), so we do set an advertising cookie when you have not declined. We do not sell visitor data, do not upload customer lists, and do not run retargeting that follows you to unrelated sites. We honour Global Privacy Control signals sent by your browser.
Asking first, where the law asks us to. Visitors in the UK and the EU are asked before the analytics cookie is written, and analytics stays switched off until they accept — that is what the small notice at the bottom of the page is for. Elsewhere the cookie is set by default, and this page, the opt-out methods in section 3, and the Global Privacy Control signal are how you turn it off. Either way you can change your mind here:
8. Third parties
Coil relies on a small set of well-established service providers, each handling a narrow, defined role:
- Cloudflare — hosting and delivery of the static website, plus security and performance.
- Gumroad — merchant of record, handling checkout, payment processing, billing, tax, receipts, license keys, refunds, and delivery.
- Anthropic — operates the Claude model behind the concierge chat, processing the messages you send it as described in section 4.
- Google — provides Google Analytics 4, the visitor measurement described in section 3, on this website and on the Gumroad checkout pages for Coil products. Google receives your IP address, the pages you view, your referrer, and device details, and processes them under its own privacy policy. You can opt out at any time using the methods listed in section 3.
Each of these providers processes data under its own privacy policy and terms. We do not sell your personal data to anyone.
9. Data retention and your choices
We keep the limited information we do hold — chiefly order records, support correspondence, and concierge chat records (kept up to 12 months) — only as long as needed to provide and support your license, to meet tax and accounting obligations, and to comply with applicable law.
You can email support@coil.trade at any time to ask what data we hold about you, to request a copy, or to ask us to delete information that we are not legally required to retain. Because the Coil engine runs entirely on your own machine, any data the software itself stores locally is under your control and can be removed by you directly on your device.
10. Children
Coil is intended for adults and is not directed at children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, please contact us so we can address it.
11. Changes to this policy
We may update this Privacy Policy from time to time as the product, our providers, or applicable law evolve. When we make a material change, we will revise the effective date at the top of this page. Your continued use of the website or the software after an update constitutes acceptance of the revised policy.
12. Contact
Questions about this policy, or about privacy and data at Coil generally, can be sent to support@coil.trade. This policy is provided by the operator of Coil and is governed by the law of the jurisdiction in which the operator is established.
The free API key
Requesting a free API key at POST /api/key sends us one thing: an email address. We store it only as a one-way SHA-256 hash (computed with a fixed application salt), used solely to return the same key on re-request and to limit abuse — never in plaintext, never for marketing, never shared. Key records expire after 90 days of inactivity. The paid license key is likewise stored only as a one-way SHA-256 hash for verification caching.
Coil is software you install and run yourself, with your own brokerage credentials and capital. It is long-only and not investment advice, not a managed account, and not a signal service. Leveraged ETFs, where the engine uses them, can lose value rapidly, including total loss. All performance figures are research backtests — point-in-time and survivorship-free, not live or client returns; past performance does not predict future results.