Privacy Policy
Last updated: 6 October 2026
This policy explains what happens to the data you send when you request access to the Midaro beta on midaro.app.
Who is responsible
The controller of your data is Kirill Vasilev, a private individual who runs Midaro. Contact: [email protected].
What we collect
Only what you enter in the beta access form, plus a few technical fields the form adds:
- your email address (required) and, if you give it, your Telegram username;
- your trading experience, the exchanges you use and, if you write it, what you want to automate;
- the time you gave consent and the language of the page you used;
- the campaign tags (utm_source, utm_medium, utm_campaign) of the link that brought you to the site, if it had any.
What we do not collect
We do not store your IP address: the web server keeps no access log for midaro.app and does not pass your IP address to the service that stores requests.
Visits are counted with a self-hosted Umami instance. Umami sets no cookies and stores no personal data — only aggregated page views and the events of the form (for example, that a request was sent), never your email address.
Why, and on what legal basis
We use your data to decide on beta access, to send you an invite and to talk to you about your feedback during the beta. The legal basis is your consent (Article 6(1)(a) GDPR), which you give with the checkbox in the form.
Who processes it
These providers handle your data on our behalf. Apart from them and the Telegram notifications described below, we do not sell or share your data.
- Hetzner (EU) — hosting of the website and of the database with requests;
- Cloudflare — content delivery network and proxy in front of the website, and routing of email to the contact address.
Transfers outside the EU
Each new request is sent as a notification to the controller in Telegram, a messaging service he uses himself; the notification contains the content of the request. Telegram is not a processor acting on our behalf — it handles messages under its own privacy policy, and its servers are located outside the EU.
Cloudflare, as the content delivery network and proxy in front of the website, may process data in transit outside the EU.
These transfers rely on our legitimate interest in running the beta and answering requests quickly (Article 6(1)(f) GDPR) and, where the provider offers them, on the EU Standard Contractual Clauses in its terms.
How long we keep it
Until the end of the beta plus 6 months, or until you ask us to delete it — whichever comes first.
Your rights
You can ask for a copy of your data, have it corrected or deleted, and withdraw your consent at any time — write to [email protected] from the address you used in the form. On a deletion request we remove your request from our database and delete the Telegram notification about it; copies in database backups expire within 14 days. To correct a request, write to the same address — sending the form again does not change it. You also have the right to lodge a complaint with a data protection supervisory authority.
Age
The beta is not intended for people under 18.
Changes
If this policy changes, the new version is published on this page with a new date.