← Back to MagicMoneyMachine

Privacy Policy

Last Updated: August 2026

Overview

MagicMoneyMachine is offered in two forms, and they have genuinely different privacy profiles. Read the section that applies to you — they are not the same.

Self-Hosted Software

The self-hosted software stores your data on your own machine. Trading records, configuration, credentials, and logs live in local files inside the installation directory (for example managed_positions.json, trade_history.json, auto_trader_config.json, .env, and logs/). They are not transmitted to us.

Your copy connects directly to the third-party services listed below. You can inspect every stored file (most are plain JSON), delete any of them, or remove the whole directory to uninstall. If you also create a cloud account, the cloud section below applies to that account.

Cloud Service — What We Store

If you use the Telegram bot or the hosted dashboard, we store the following on our servers:

CategoryWhat it includes
Exchange API keysThe Coinbase API key and secret you submit, and — if you use DEX features — a Solana wallet key. Stored encrypted (see below).
Trading dataPositions, trade and order history, balances, portfolio value snapshots, per-engine performance metrics, and prediction records.
Account identifiersTelegram ID, Telegram username and first name, your email address if you provide one, subscription tier and account status, and your bot configuration.
Technical and access dataIP address and browser user-agent recorded when credentials are accessed (a security audit trail), and application logs.
Marketing and product dataEmail addresses submitted on our website, the referring page and campaign parameters, a hashed IP, page-view events, and a record of which emails we sent you.
Payment dataYour subscription status and the identifiers Stripe gives us. We never receive or store your card number.

Your exchange API keys

We do store them — encrypted. To trade on your behalf, the cloud service must hold your exchange API credentials. They are encrypted at rest using authenticated symmetric encryption (Fernet: AES-128-CBC with an HMAC-SHA256 authentication tag) under a master key held only in our server environment, and they are decrypted only in memory when placing or reading an order for you. Every access is logged. We do not log the key values themselves.

We never ask for withdrawal permission on your exchange account, and we recommend you never grant it to any third party, including us. You can remove your stored keys at any time with /disconnect in the bot.

What we do not do

Third-Party Services

Depending on which features you use, data is processed by:

Your Rights and How to Use Them

You can exercise these yourself in the Telegram bot, without contacting us:

Depending on where you live, you may also have the right to access, correct, port, or delete your personal data, to object to or restrict certain processing, and to complain to your data protection authority. To make any request — including removing an email address that was submitted on our website but never linked to a bot account — email support@magicmoneymachine.app and we will action it.

Data Retention

Security

No system is perfectly secure. If you believe you have found a vulnerability, please email support@magicmoneymachine.app.

Where Your Data Is Processed

Our application servers are located in the United States, and our third-party processors may store or process data in the United States and elsewhere. If you use the service from outside the United States, you are transferring your data there.

Children

The service is not directed to anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, email us and we will delete it.

Changes

We may update this policy. The "Last Updated" date above always reflects the current version, and material changes will be noted in our release notes.

Contact

Privacy requests and questions: support@magicmoneymachine.app

Website X / Twitter Instagram Reddit