How we store your data and, if you use copy trading, your trading key — including the parts that are a trade-off rather than a guarantee. It describes what the software actually does. If anything here does not match what you see, email hello@lockstepmarkets.com.
Last updated 26 September 2026
The short version Analysing wallets needs only public addresses, and most people never give us a key. If you switch on copy trading, you give us the private key of a trading wallet. We encrypt it and store it, and the bot decrypts it to sign your orders. The encryption key is on the same server as the database, so someone who took full control of that server could decrypt stored keys.
A private key is complete control of its wallet: whoever has it can move everything in it. So use a separate wallet, keep a small balance in it, and delete the key when you stop copying.
| Everyone | Your email address; your password, stored only as a scrypt hash; whether your email is verified, when you joined and which version of the Terms you accepted; a referral code; a username if you set one; the wallet addresses you track, your settings and your simulated trading history. Your login cookie is stored on our side only as a hash. |
| Two-step verification | If you turn it on: the authenticator secret, encrypted the same way as trading keys, and your backup codes, stored only as hashes. |
| If you pay | Your subscription state from Stripe, and the record of the confirmation you gave at checkout, with the IP address and browser it came from. Never your card details — Stripe handles those and they never reach us. |
| If you copy trade | The private key of your trading wallet, encrypted. Stored beside it, not encrypted: the wallet’s public address, your Polymarket proxy address if you gave one, and which kind of Polymarket account it is. |
| To keep the site running | Your IP address while you sign up, sign in or reset a password, to limit repeated attempts; and server logs. |
The Privacy Policy has the full list, why we hold each item and how long we keep it.
[redacted], before it is
sent.The key that encrypts stored trading keys is kept in a configuration file on the same server, readable only by the server’s administrator account, and handed to the application when it starts. It is not in the database, not in the backups and not in our code repository, and we keep no other copy of it.
That cuts both ways, and you should know which way:
Card payments are handled by Stripe. Cloudflare registers our domain name and runs its DNS; your traffic does not pass through Cloudflare.
Settings → Copying for real → Delete key, then confirm. It removes the encrypted key from the database, switches copy trading off and discards the decrypted copy held in memory. You can do this at any time without closing your account.
The key is erased from the database file itself at once — overwritten, not just marked as free space. The one place encrypted copies remain is our nightly database backups, for up to 14 days, after which they are deleted.
Deleting a key stops us using it. It cannot make safe a key that may already have been exposed. If you think yours has been, move your funds to a new wallet.
Settings → Delete this account, with your password. Your trading key is deleted first, before anything else, and the decrypted copy in memory with it. Then any subscription is cancelled with Stripe, then your account and its data are removed — except the payment records the law requires us to keep, which the Privacy Policy lists. The same 14-day backup window applies.
If our server were ever compromised, we would:
If you find a security problem, email hello@lockstepmarkets.com. It reaches the person who wrote the software.
More: About Lockstep Markets · FAQ · Getting started · Terms of Service · Privacy Policy
← Back to the app