Skip to main content

Privacy policy

Your data,
and what we do with it.

This is our operative privacy policy. It describes what we actually process, exactly as the service is implemented today, without adding claims beyond it. The Education Library, the GEX Levels Indicator and the Terminal are separate products.

What we process

Your data, point by point.

Data controller

Marc Lalanne EI, trading as GEX Levels, SIREN 106341936, 70 rue d’Ornay, 76000 Rouen, France, determines processing for the GEX Levels service. Contact support@gex-levels.com or +33 (0)6 13 03 82 78 for privacy requests. Whop and certain third-party platforms have independent responsibilities described below.

Account & sign-in data

If you create an account, we process your email address, a securely hashed password, an opaque session reference, and a device hash used to bind an Indicator license to your device. This data exists to sign you in, protect your session, and verify access. We do not sell it.

Manual access requests

If you request access manually, basic contact information such as email address and request context may be collected to respond and manage access.

Journal, Workspace and team data

We process the entries, notes, files, research, preferences and messages you submit to the features you use. Journal and Terminal features may synchronise with your website account. Private content is not public by default, but content you explicitly share is visible to the public, team or other audience indicated by that feature. Team administrators may manage membership and team resources. Do not publish sensitive data or protected third-party content. Export and deletion controls vary by feature; contact support for a complete request. Public recipients may retain copies beyond our control.

Payments and purchase evidence

Whop handles card information and payment settlement under its own privacy policy. GEX Levels remains the product supplier. We receive purchase and membership details needed for access, billing support, commissions and disputes, which may include identifiers, name, email, billing country/address, product, price, payment status and limited payment-method metadata. Full card numbers and security codes are not collected by our service. Relevant payment, acceptance, notice and access evidence may be disclosed to Whop, payment providers or competent authorities to resolve an actual dispute; we do not infer that a sent email was read.

Access and security logs

Authentication, licence verification and protected-resource requests can produce timestamps, account/resource identifiers, device or network information and security logs. Device and network hashes can still be personal data; pseudonymisation is not anonymity. Access restrictions reduce unauthorised disclosure but no system can promise absolute security. Staff access is limited to support, operations, security and other legitimate needs.

Storage and privacy choices

Essential cookies and storage support sign-in, CSRF protection, licence/session state, security and the checkout you request. Turnstile may use anti-abuse storage. Separately, Privacy choices lets you accept or reject audience measurement, marketing pixels and affiliate attribution independently; optional purposes are off without a current affirmative choice. Refusal does not block account creation or purchase. Reopen the control in the footer to change your choice. The preference is stored locally for up to 180 days; it is not advertising consent for emails.

With analytics enabled, first-party pseudonymous visitor/session identifiers count normalised page paths, bounded campaign tags and referrer hosts. Browser sessions expire after 30 minutes of inactivity; the visitor identifier lasts until consent expiry or deletion. The analytics table uses salted identifiers rather than raw email, IP or full user-agent values, but pseudonymous records can still be personal data. Analytics respects Do Not Track.

Marketing consent permits the Whop attribution pixel and Meta only if configured. Referral consent permits a referral cookie and local code for up to 30 days. Withdrawal stops new optional browser tracking and clears the local identifiers under our control; previously recorded transactions/commissions or server-side referral records may remain where required for payment evidence or valid retention purposes. Contact support to object to associated server-side processing. Third-party checkout/payment processing needed for the requested purchase is distinct from optional marketing.

Purposes and legal bases

Contract performance supports account access, licences, requested synchronisation, billing and support. Legitimate interests support proportionate security, abuse prevention and defence of legal claims, balanced against your rights. Legal obligations support invoicing, accounting and legally required records. Optional tracking or marketing uses consent where required; eligible existing-customer communications about similar own products require an available opt-out. You can object to legitimate-interest processing and marketing at support@gex-levels.com. Essential service notices are distinct from promotions; buying a product is not blanket marketing consent.

Required and optional information

Account and purchase details needed to deliver the chosen service are required; without them we may be unable to provide it. Optional profile fields, research uploads and community posts can be left blank. We do not sell personal data or use private customer content as trading advice. No promise of anonymity follows from removing a name.

Providers and transfers

Cloudflare provides production web hosting, API and storage; Netlify is used for separate web deployments and previews; Resend delivers email. Whop handles payments. Google and Discord operate their own optional services. See the provider list. Processing may occur outside the EEA. Depending on the recipient, service and applicable agreement, transfer safeguards may include an applicable adequacy decision or standard contractual clauses. You may request details and a copy of relevant safeguards, subject to necessary redactions. This notice is not a claim that every provider or every service is covered by the same certification.

Your rights and requests

Where applicable you may request access, rectification, erasure, restriction, portability, or object to legitimate-interest processing. Withdraw optional consent without affecting earlier lawful processing. Account controls provide export/deletion tools, but retained invoices, fraud/dispute evidence or legal obligations may require a separate restricted archive rather than immediate erasure; we explain any exception. Contact support@gex-levels.com. We normally respond within one month, with any lawful extension explained within that month. We request identity evidence only where necessary and proportionate. You may complain to the CNIL or your competent authority. Contact us for human review of a disputed access restriction.

Retention and legal archives

Operational account and synced content are retained while needed to provide the account, then deleted or restricted following closure and applicable requests. Our retention limits are up to 12 months for unsuccessful manual access requests, up to 180 days for pseudonymous page-visit records and ordinarily up to 24 months for support follow-up. Required invoices/accounting records are kept for the applicable statutory period, generally 10 years for accounting records; relevant contractual or dispute evidence may remain in a restricted archive for the applicable limitation period or an active case. Any longer retention needs a documented basis and is not permission to retain every event indefinitely. Local Terminal backups remain on your device until removed. Contact us for the retention applicable to a particular record.

Terminal local state and synchronisation

The desktop application keeps local preferences, saved layouts and working data. Sensitive fields use the operating system’s secure-storage facility where available; this is not encryption of every local file. Protect your device and backups. Authentication, licensing and data requests communicate with our servers. When used, account-linked Journal, Workspace, portfolio or sharing features send the associated content and settings for synchronisation or delivery to the selected audience. Local diagnostics may contain system and application details; review them before voluntarily sharing them with support. External integrations you enable have their own data flows and provider terms.

Truddy profiles, recruitment and private messages

Truddy is an optional directory for signed-in members, not a marketplace for investment advice or managed trading accounts. Your guided trader CV records experience ranges, markets, trading or research style, preferred session, time zone, languages and learning goals. These fields are self-described, not verified qualifications or trading results. Directory visibility, Discord display and receiving private messages each require your explicit choice and are off by default. Directory visibility does not change your separate public profile setting.

Applying to a team explicitly shares your CV snapshot and application note with that team's active owner and administrators. Discord remains hidden unless you separately chose to display it. Teams that publish recruitment listings must be publicly discoverable; their discussions and watchlists keep their own access controls. Deleting your Truddy CV removes its directory entry, clears your submitted CV snapshots and notes, and withdraws pending applications. It does not remove an accepted team membership.

Private messages are stored to provide conversation history and anti-abuse controls, and are readable only by the sender and recipient through the member interface. They are not end-to-end encrypted. Blocking prevents further messages; it does not erase existing conversation evidence. A recipient may report a message, in which case authorised moderators can review that reported message and the participants' handles, not browse the entire private inbox. Messages and relevant report records follow the operational account and dispute-retention rules above. Contact support for an access, export or erasure request concerning your messages or applications. Never send passwords, payment details or sensitive third-party information.

Version 2.1 — 30 September 2026. This policy covers the website, account, Indicator, Terminal, Library, Journal, Workspace and optional Truddy features. Material processing changes are communicated where required; a policy update does not itself provide consent. GEX Levels remains educational and informational, not financial advice.

Related

Terms & policies.