Privacy Policy
Effective Date: June 5th, 2025
Last Updated: October 14, 2025
Scathefire Media Inc. ("we," "our," or "us") operates OptionsAware, a software tool for options data analysis and monitoring that includes both a Telegram bot and web application (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Disclaimer: Not Investment Advice
OptionsAware is a financial data and software tool, not a registered investment advisor, broker-dealer, or financial service. The Service is for educational and informational purposes only. All information, data, analysis, and scoring provided through the Service are impersonal and not tailored to any specific user's investment needs or financial situation.
You are solely responsible for all trading and investment decisions you make. The Service does not provide investment advice, recommendations, or endorsements of any kind. You must rely on your own judgment and perform your own due diligence before entering into any trades. By using the Service, you acknowledge that all trading involves risk and that you are responsible for any and all consequences of your actions.
Table of Contents
1. Information We Collect
1.1 Personal Information
When you use our Service, we collect the following types of personal information:
Website Account Information (Email + Password):
- Email address
- First name and last name (last name optional)
- Password hash (Argon2id; never stored in plaintext)
- Email verification timestamp
- Last login timestamp
Telegram Account Information (Linking Optional):
- Telegram User ID (primary identifier)
- First name and last name
- Telegram username
- Display name
- Link timestamp
Schwab Account Information (Optional):
- Account numbers and account hash identifiers
- Authentication tokens (encrypted)
- Account balances and buying power
- Investment positions and holdings
- Trading history and transaction data
1.2 User-Defined Trading Parameters
- Strategy preferences (Cash-Secured Puts, Covered Calls, Wheel Strategy)
- User-defined target parameters (delta ranges, days to expiration, IV thresholds)
- User-configured profit targets and stop-loss settings
- Watchlist symbols
- User-defined settings from setup wizards and preference commands
1.3 Usage Data
- Bot commands and interactions
- Website page visits and feature usage
- API endpoint usage patterns
- Error logs and system diagnostics
- Session data and authentication timestamps
1.4 Market Data Processing
- Options chain analysis and calculations
- Implied volatility metrics and rankings
- Historical volatility calculations
- Impersonal trade opportunity scoring and data analysis
1.5 Waitlist Data
- Contact information (email)
- Application information you choose to provide (short questionnaire)
- UTM parameters (source, medium, campaign) when provided
- Device and log data used for security and rate limiting (IP address in packed form, user agent)
- Captcha responses (Cloudflare Turnstile) to prevent automated abuse
- Verification/invite tokens stored only as one‑way hashes with expiration timestamps
2. How We Use Your Information
We use the collected information for the following purposes:
2.1 Core Service Functionality
- Account Management: Authenticate users and manage account access
- Trading Analysis: Provide options strategy analysis and data
- Market Data: Deliver real-time quotes, option chains, and market information
- Trade Execution: Process and monitor trading orders through integrated brokers at your explicit direction
- Portfolio Monitoring: Track positions, P&L, and trade lifecycle management
2.2 Data Filtering and User Experience
- Data Filtering: Filter and display market data based on user-defined parameters and criteria that you explicitly set.
- Opportunity Discovery: Screen for trading opportunities that match criteria you have explicitly configured in your settings.
- Performance Analytics: Calculate and display trading metrics and historical performance based on your activity.
- User Experience: Remember preferences and provide customized dashboard views.
2.3 System Operations
- Security: Protect against unauthorized access and fraudulent activity
- Performance: Cache frequently requested data for faster response times
- Reliability: Monitor system health and troubleshoot technical issues
- Compliance: Maintain audit trails and system logs as required
- Form Protection: CSRF protection on website forms (login, signup, settings)
- Rate Limiting: Redis-backed rate limits keyed by IP and/or email; generic responses to prevent email enumeration
- Logging Hygiene: Avoid logging PII or raw tokens; never log Telegram login payloads or hashes
2.4 Beta Waitlist Processing
- Send transactional emails to verify your email and deliver single‑use invites
- Evaluate waitlist entries and questionnaire responses for invite decisions
- Prevent abuse via rate limiting and captcha validation
- Invite acceptance is bound to the verified email and is single‑use/time‑limited
- Transactional emails include verification, invite, and welcome (after signup)
3. Information Sharing and Disclosure
3.1 Third-Party Service Providers
We integrate with the following third-party services to provide our functionality:
Charles Schwab & Co., Inc.
Purpose: Account authentication, real-time market data, trade execution
Data Shared: OAuth tokens, account identifiers, trade orders
Telegram
Purpose: Bot messaging and user authentication
Data Shared: Telegram user IDs, message content related to trading commands
3.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, government agencies).
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will provide notice of any such change in ownership or control.
3.4 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Data Security
Encryption and Protection
- All authentication tokens are encrypted using industry-standard encryption before storage
- All data transmission uses HTTPS/TLS encryption
- Database access is restricted and monitored
- Web sessions expire automatically and use secure session management
Infrastructure Security
- User data is stored in secure, access-controlled databases
- Temporary data caching with automatic expiration
- Regular security updates and monitoring
- Encrypted backups with secure storage
Authentication
- Website Authentication: Email + password (Argon2id). Password reset tokens are one‑way hashes with short TTL (default 2 hours).
- Telegram Linking (Optional): Telegram can be linked to enable chat features and secondary sign‑in; Telegram does not create website accounts.
- OAuth 2.0: Secure token-based authentication with Schwab.
- Session Management: Automatic session expiration and secure logout; website session stores user_id in a secure cookie.
5. Data Retention
5.1 Account Data
- Active Accounts: Data is retained while your account remains active
- Inactive Accounts: Accounts inactive for more than 2 years may be subject to data deletion
- Legal Requirements: Some data may be retained longer to comply with regulatory requirements
- Password Reset Tokens: Stored only as 32‑byte hashes; expire by default after 2 hours and are purged after use or expiry
5.2 Trading Data
- Transaction History: Maintained for regulatory compliance and tax reporting purposes
- Market Data Cache: Automatically expires based on market conditions (1-30 minutes)
- System Logs: Retained for 90 days for troubleshooting and security purposes
5.3 Data Deletion
You may request deletion of your account and associated data at any time. Upon deletion:
- Personal information and preferences are permanently removed
- Schwab tokens and account associations are cleared
- Trading history may be retained in anonymized form for regulatory compliance
5.4 Waitlist Retention
- Verification/invite tokens retained until expiration, then purged
- Waitlist records retained while the beta program is active or as required by law
- You may request deletion of your waitlist data at any time
6. Your Rights and Choices
6.1 Access and Control
- Data Access: Request a copy of your personal data
- Data Correction: Update or correct inaccurate information
- Data Deletion: Request deletion of your account and data
- Data Portability: Request your data in a machine-readable format
6.2 Communication Preferences
- Bot Notifications: Control notification frequency and types through bot settings
- Strategy Preferences: Modify or disable trading strategies at any time
- Watchlist Management: Add or remove symbols from your watchlist
6.3 Account Management
- Account Disconnection: Disconnect Schwab account integration at any time
- Service Termination: Close your account and request data deletion
- Preference Updates: Modify trading preferences and risk parameters
7. International Data Transfers
Our Service is hosted in the United States. If you are accessing our Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located and our central database is operated.
8. Children's Privacy
Our Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
9. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request information about the personal information we collect and how it's used
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
10. European Union Privacy Rights
If you are located in the European Union, you have rights under the General Data Protection Regulation (GDPR):
- Legal Basis: We process your data based on legitimate interests and consent
- Supervisory Authority: Right to lodge complaints with your local data protection authority
- Data Portability: Right to receive your data in a structured, commonly used format
11. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending a notification through the Telegram bot
- Updating the "Last Updated" date at the top of this policy
Your continued use of the Service after any modifications indicates your acceptance of the updated Privacy Policy.
12. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: [email protected]
For data protection inquiries from EU residents, please use the same contact information above.
13. Definitions
This Privacy Policy is designed to be transparent about our data practices while protecting your privacy and enabling the full functionality of our Service.