LockstepMarkets

Security

How we store your data and, if you use copy trading, your trading key — including the parts that are a trade-off rather than a guarantee. It describes what the software actually does. If anything here does not match what you see, email hello@lockstepmarkets.com.

Last updated 26 September 2026

The short version Analysing wallets needs only public addresses, and most people never give us a key. If you switch on copy trading, you give us the private key of a trading wallet. We encrypt it and store it, and the bot decrypts it to sign your orders. The encryption key is on the same server as the database, so someone who took full control of that server could decrypt stored keys.

A private key is complete control of its wallet: whoever has it can move everything in it. So use a separate wallet, keep a small balance in it, and delete the key when you stop copying.

What we store

EveryoneYour email address; your password, stored only as a scrypt hash; whether your email is verified, when you joined and which version of the Terms you accepted; a referral code; a username if you set one; the wallet addresses you track, your settings and your simulated trading history. Your login cookie is stored on our side only as a hash.
Two-step verificationIf you turn it on: the authenticator secret, encrypted the same way as trading keys, and your backup codes, stored only as hashes.
If you payYour subscription state from Stripe, and the record of the confirmation you gave at checkout, with the IP address and browser it came from. Never your card details — Stripe handles those and they never reach us.
If you copy tradeThe private key of your trading wallet, encrypted. Stored beside it, not encrypted: the wallet’s public address, your Polymarket proxy address if you gave one, and which kind of Polymarket account it is.
To keep the site runningYour IP address while you sign up, sign in or reset a password, to limit repeated attempts; and server logs.

The Privacy Policy has the full list, why we hold each item and how long we keep it.

How a trading key is stored

Where the encryption key lives

The key that encrypts stored trading keys is kept in a configuration file on the same server, readable only by the server’s administrator account, and handed to the application when it starts. It is not in the database, not in the backups and not in our code repository, and we keep no other copy of it.

That cuts both ways, and you should know which way:

Who can reach it

Card payments are handled by Stripe. Cloudflare registers our domain name and runs its DNS; your traffic does not pass through Cloudflare.

Deleting your key

Settings → Copying for real → Delete key, then confirm. It removes the encrypted key from the database, switches copy trading off and discards the decrypted copy held in memory. You can do this at any time without closing your account.

The key is erased from the database file itself at once — overwritten, not just marked as free space. The one place encrypted copies remain is our nightly database backups, for up to 14 days, after which they are deleted.

Deleting a key stops us using it. It cannot make safe a key that may already have been exposed. If you think yours has been, move your funds to a new wallet.

Closing your account

Settings → Delete this account, with your password. Your trading key is deleted first, before anything else, and the decrypted copy in memory with it. Then any subscription is cancelled with Stripe, then your account and its data are removed — except the payment records the law requires us to keep, which the Privacy Policy lists. The same 14-day backup window applies.

If there is a breach

If our server were ever compromised, we would:

  1. switch off copy trading for every account straight away, so no stored key is used;
  2. email everyone affected within 24 hours of finding out, saying what happened and telling you to move your funds out of your trading wallet;
  3. delete every stored key and replace the encryption key — to copy again you would set up a new wallet, because the old one should be treated as exposed;
  4. report it to the Information Commissioner’s Office within 72 hours, where the law requires it.

What you can do

Reporting a problem

If you find a security problem, email hello@lockstepmarkets.com. It reaches the person who wrote the software.


More: About Lockstep Markets · FAQ · Getting started · Terms of Service · Privacy Policy

← Back to the app