This policy explains what AF OPTIONS collects, why, and who it is shared with. We collect only what the service needs to work.
| Data | Why |
|---|---|
| Name and email address | To create and identify your account |
| Password | Stored only as a salted hash by our auth provider — we never see it |
| Deriv API token | Encrypted (AES-256-GCM) and used solely to place mirrored trades and read your balance and trade history |
| Deriv account ID, account type, balance | To size trades proportionally and show your dashboard |
| Trade records (stake, result, timestamps) | To show your history and calculate profit share |
| USDT wallet address | To assign and verify profit-share payments |
| Settlement records | To track what is owed and paid |
| Internal admin notes | Support and account management (visible only to administrators) |
| Technical logs | Security, debugging, and service reliability |
Your token is encrypted with AES-256-GCM before storage. The encryption key is held only in our server environment and is never present in the website or in your browser. The token is decrypted transiently, server-side, only to place a trade or read your balance. It carries Trade permission only, so it cannot be used to move your money.
We do not sell your data. We share it only with the infrastructure providers needed to run the service:
| Provider | Purpose |
|---|---|
| Deriv | Trade execution and account data (your broker) |
| Supabase | Database, authentication, server functions |
| Vercel | Website hosting |
| Fly.io | Hosting the trade-mirroring service |
| TRON network / public block explorers | Verifying USDT payments (public blockchain data) |
We may also disclose data where required by law.
We use browser local storage to keep you signed in. We do not use advertising or third-party tracking cookies.
We keep account, trade, and settlement records for as long as your account is active and afterwards where needed for legal, accounting, or dispute purposes. When you delete your account, your stored Deriv token is destroyed immediately.
To exercise any of these, contact us using the details below.
We use encryption in transit and at rest for sensitive fields, row-level database access controls so users can only read their own records, and administrator-only access to management functions. No system is perfectly secure; please use a strong, unique password.
This service is not for anyone under 18, and we do not knowingly collect data from minors.
We will post updates to this policy here and notify you of material changes. Questions: Telegram @afoptions · WhatsApp @AFoptions