Privacy Policy

Last updated: July 27, 2026. Applies to the Syrius Chrome extension and the web platform at syrius.pro.

1. Data controller

Syrius ("we") operates the Syrius extension for TradingView and the web platform at syrius.pro. To exercise any right, contact us at contato@syrius.pro.

2. Single purpose of the extension

The Syrius extension has a single purpose: read the active TradingView chart and deliver AI-assisted analysis and contextual chat in the same tab. All data below is collected only for that purpose.

3. Data we collect

  • Personal identification: display name and email from sign-up.
  • Authentication: encrypted password, session tokens issued by the backend, and device identifiers linked to your account.
  • Personal communications: messages you send to the Copilot and chat, stored to show your history and improve answers.
  • Site content: ticker, timeframe and legend of the active TradingView chart, read only when you trigger an analysis or a question. We do not read orders, balances, wallets or positions.
  • Payments (via NOWPayments): crypto wallet address, order ID and confirmation status. We never store private keys or card data.
  • Demo-mode anonymous identifier: syr_did cookie and IP used only for the 5-free-analysis limit per device.

4. How we use data

We use data to authenticate, run AI analyses, show history, count credits, process payments, calculate Referral commissions and send essential account communications. We don't use your data for credit, lending or anything outside the extension's purpose.

5. Sharing and subprocessors

We don't sell, rent or transfer your data to third parties for marketing. We share the minimum with these subprocessors, under confidentiality contracts:

  • Lovable Cloud / Supabase — hosting, database and authentication.
  • Google AI (Gemini) and Lovable AI Gateway — generating Copilot answers.
  • NOWPayments — crypto payment processing.
  • Resend — transactional email delivery.

6. Retention and deletion

We keep the data while your account is active. On deletion request via contato@syrius.pro, we remove personal data within 30 days, keeping only minimum records required by law or anti-fraud audit.

7. Security

We apply TLS in transit, Row Level Security in the database, minimum-scope session tokens, device limits per account, payment audit and admin access restricted to the CEO role.

8. Remote code use

The Syrius extension does not execute remote code. All JS, CSS and the manifest are packed locally in the package published on the Chrome Web Store. Network calls only hit REST APIs of the Syrius backend and Supabase, exchanging JSON only. We don't use eval, new Function, importScripts or dynamic <script src> injection, per Manifest V3.

9. Cookies and local storage

The extension uses chrome.storage.local for session, preferences and the last chart. The site uses essential auth cookies and the syr_did cookie to limit demo mode. We don't use ad-tracking cookies.

10. Your rights (LGPD/GDPR)

You have the right to access, correct, export, restrict processing and delete your data, and to withdraw consent at any time. Write to contato@syrius.pro.

11. Statements required by Chrome Web Store

  • We don't sell or transfer user data to third parties outside the cases approved in this policy.
  • We don't use or transfer user data for purposes unrelated to the extension's single purpose.
  • We don't use or transfer user data to determine creditworthiness or for lending.

12. Changes to this policy

We may update this policy. Material changes will be announced by email or a prominent notice before taking effect.

13. Contact

Data Protection Officer / DPO: .contato@syrius.pro