Home  /  Legal  /  Privacy
Stedwatch · Legal

Privacy Policy

A tomventures GmbH product · Last updated 2026-09-08

This Privacy Policy explains how Stedwatch handles data. The short version: your monitoring data stays on your own machine. There is no cloud that collects your system metrics or trading activity, and no monitoring or trading telemetry. If you buy Pro, or if you register a machine for Outside Watch, you also get a customer account at my.stedwatch.com; that account holds your email, your licence key and your purchase record, plus the sign-in and licence-activation details listed in section 5, and is entirely separate from your local monitoring data.

Two optional features are different, and they are named here rather than hidden in a list. The first is Outside Watch. If you switch it on, your server sends a short heartbeat to a server we run, so that we can tell you when your server goes quiet. It is off unless you turn it on, it carries no monitoring data, and section 5a says word for word what it sends and what we keep. The second is the app route: if you switch that on, the Stedwatch app reaches your server through a server we run instead of directly. What travels is sealed on your machine and we hold no key for it, so we cannot read it; section 5b says what we can see anyway.

Local by design. The Stedwatch desktop software runs on your Windows machine. Your monitoring data, system metrics, history, and per-terminal MT5 status, is stored locally on that machine. tomventures does not operate a cloud that collects it, and the Software does not phone your trading data home. The personal data we hold on a server is what's needed to sell and licence Pro, described in section 5, and, only if you switch it on, the Outside Watch heartbeat record described in section 5a.

1. Who is responsible

The controller for any personal data described here is tomventures GmbH (Switzerland). Contact: hello@stedwatch.com. Provider details are in the Impressum.

The relevant supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC). If you are in the EU/EEA, you also have the rights described in section 10 and may lodge a complaint with your local data-protection authority.

EU representative (GDPR Art. 27). tomventures GmbH is a Swiss-based controller. Where Art. 27 GDPR applies, we will designate a representative in the EU; until that representative is published here, EU data subjects can reach us for any data-protection matter at hello@stedwatch.com.

2. Data the desktop software handles (locally)

To do its job, the Software reads and stores the following on your machine:

This data is not sent to tomventures. It stays in the Software's local data folder on the machine where it runs.

Connections the Software opens by itself. To tell “this server lost the internet” apart from “this server is fine”, the Software opens, about every two minutes, up to ten short connections that carry no data at all: first one to each of up to three broker endpoints your own MetaTrader 5 terminals are already connected to, and only if those all stay silent, one to each of seven public endpoints such as 1.1.1.1, 8.8.8.8, 9.9.9.9 or 223.5.5.5, operated by neither you nor us. The leading endpoint of a list is tried on its own; the rest are tried, all at once, only if it stays silent, so ten is the worst case of one check and not its usual cost. The same broker address is used for the round-trip latency reading shown per terminal. Nothing about your machine, your terminals or your trading is sent on those connections, and none of those addresses is a tomventures server, so we receive nothing from them; what the operator at the other end can see is that a connection arrived from your server’s network address, as it can for any connection your server makes.

3. Notifications you choose to enable

If you enable alerts, the Software sends them directly from your machine to the channel you configured. Today there is exactly one channel that works, Telegram. The Stedwatch mobile app (native push) is described below because it is built and because we would rather you read it before it exists than after, but it is not yet in service: the app has not been released, no device can be paired, and the Software sends nothing to any push provider. Those messages travel from your machine to that provider, not through tomventures. The one exception is the Outside Watch alarm in section 5a, which by its nature is sent by our server, because it is about your server having gone quiet. Your use of those services is subject to their own privacy policies. If you don't enable a channel, no alerts are sent anywhere. The two channels do not carry the same thing, so they are described separately below.

Telegram carries the full alert text, for example "EA trade request refused (AutoTrading)", and it carries more than alerts: the same chat also receives the daily summary and the weekly summary, and the weekly one arrives as a chart image of your server’s CPU, memory and disk activity. If you give the Software a bot token, it also answers the commands you send that bot, which means it holds a long-poll connection open to Telegram for as long as it runs, in weeks with no alert too. You supply your own bot token and your own chat, so all of that goes from your machine to your chat.

The Stedwatch mobile app channel is not yet in service, and until it is, nothing in the rest of this paragraph happens. The app has not been released, so no device can be paired and no push token exists; the switch that would turn the channel on is off in the build you are running, and with it off the Software does not even look for a paired device, let alone contact a push provider. Expo, Apple and Google therefore receive nothing from Stedwatch today. We describe the channel here in advance so that the day it is switched on is not the day you first read what it carries. When the app ships, it will deliver push notifications through Expo's push service and the platform push infrastructure operated by Apple (APNs) and Google (FCM). Those notifications are not end-to-end encrypted and cannot be, because your phone has to display them without the app running, so we keep out of them everything that is not needed to deliver them. The push will carry a fixed title ("Stedwatch"), one of four fixed severity lines ("Critical alert", "Warning", "Notice" or "New alert", each followed by "open the app for the detail"), and your device's push token. It will carry no server name, no terminal or EA name, no measurement, no account number and no description of the fault. Expo, Apple and Google would therefore see that an alert reached your phone, when it did, and its severity; the detail is fetched by the app from the read-only API on your own machine when you open it. Expo would additionally see the network address your server sends from, because it receives the request. Your use of those services is subject to their respective privacy policies. This notice will be re-dated on the day the channel goes live.

4. The mobile app and local API

The optional mobile app is not on the App Store; today a tester installs it through Expo. It shows your dashboard by reading the read-only API on your own machine, and there are two ways it can reach that API.

Directly, when your phone can already reach the machine over your own network or a VPN. That connection is between your own devices, and nothing of ours is in it.

Or through a server we run, if you switch that on. A trading server usually sits behind a firewall that should not be opened, so rather than accept an incoming connection the machine dials out to relay.stedwatch.com and holds that line open, and the app asks its questions through it. It is off until you switch it on, it requires a Beta, Trial or Pro licence, and switching it on has its own consent screen. What travels is sealed on your machine before it leaves, and we hold no key for it. Section 5b says what that server can and cannot see.

5. Your Stedwatch account & purchases (my.stedwatch.com)

If you buy Pro, or if you register a machine for Outside Watch, we operate a customer account for you at my.stedwatch.com. Together with the Outside Watch record in section 5a and the app route in section 5b, each of which exists only if you switch that feature on, this is the only personal data we hold on a server. We keep it deliberately small:

We use the following processors for this account:

For the full register of the sub-processors we use, including their roles, the data they receive and the applicable transfer mechanisms, see our sub-processor register.

Licence activation (paid keys and trials). A paid licence (and the time-limited trial) covers the number of machines the plan you bought states; that number is minted into the key. To enforce it fairly, each machine on which you install the Software contacts our activation endpoint when you enter the key and keeps contacting it on a repeating schedule for as long as the Software runs: every 15 minutes until the key is accepted, and every 12 hours after that. It is a recurring licence check, not a one-time event. The body of that request carries exactly three values: your licence key, a one-way, salted machine hash (a SHA-256 derived from stable machine identifiers - not reversible to your hardware and not usable to identify you), and the version of Stedwatch running on that machine. The request's User-Agent header identifies that same version a second time. Because a request is an ordinary HTTPS call, our server additionally records, per activation, the IP address and browser user-agent of the request and first-seen and last-seen timestamps, as proof of the seat and for anti-sharing (legal basis: Art. 6(1)(f), our legitimate interest in enforcing the machine limit of the plan). We never receive your monitoring or trading data, or any other hardware detail, through activation. A seat auto-releases after thirty days of no re-check; you can also free a machine yourself in your account, and when you do we clear that seat's IP and user-agent right away. The free tier performs no activation at all and sends us nothing about your licence. (Independently of licensing, every tier asks stedwatch.com a few times a day for a public file naming the current version. That request asks for nothing about your machine and its body carries nothing, but it is not anonymous either: its User-Agent header identifies the version of Stedwatch running there.) Activation records are deleted when you delete your account.

Retention. We keep your account data for as long as you have an account. You can delete your account and its data at any time from my.stedwatch.com → Account → Delete account, or by emailing us. Payment and invoice records held by Lemon Squeezy (and its underlying payment processor) are retained as required by accounting and tax law (in Switzerland, up to ten years) and are not deleted by an account deletion.

5a. Outside Watch (optional, and off unless you switch it on)

Apart from the licence and version checks in section 5 and the optional app route in section 5b, Outside Watch is the feature where your server talks to a server we run, and it exists because a machine that has stopped cannot tell you so itself. It is available on every plan, including Free, and it is off until you switch it on in the Software’s settings. Registering a machine needs a one-time code from your account at my.stedwatch.com, which is why an account exists for it.

What you agree to when you switch it on

This is the text the Software shows you at that moment, word for word (exe-poc/Consent.cs, OutsideWatchGrantText):

Outside Watch

Everything Stedwatch does runs on this server, so it cannot tell you when this server itself stops. Outside Watch is a second, much smaller thing: this server sends a short signed message to a Stedwatch server at a steady interval, so that its silence is observable from somewhere other than this machine.

What leaves this machine, exactly: 83 bytes, to ping.stedwatch.com, which we run. They are the registration number Stedwatch gives this machine, one byte saying whether this is an ordinary heartbeat or the agent stopping, updating or being removed or a Windows restart being queued, a counter, and a signature over those three. There is no hostname in it, no metrics, no list of terminals, no broker, no account, no licence key, no version and no log line. You can print the exact bytes of the next one at any time.

Registering this machine is one more message, sent once: 163 bytes, made of the code from your Stedwatch account, this machine's own public key and a signature over both. That key is made when Stedwatch is installed and kept for the lifetime of the installation, so it identifies this machine to Stedwatch for as long as Outside Watch is registered.

How often: once a minute, or once every ten minutes on the Free plan. Like any connection, it shows the Stedwatch server the internet address it comes from and the moment it arrives.

Being told is a separate step, and it happens in your Stedwatch account rather than here. You connect a Telegram chat there, that is where an alarm goes when these messages stop, and this machine cannot see whether that has been done. If you switch Outside Watch on without connecting that chat, this server will send its heartbeats and no alarm will reach anyone.

What does not change: this server goes on monitoring exactly as it does now, and your alerts go on leaving from here through your own Telegram bot. That bot is a separate setup from the Telegram chat above, and the two do different jobs: your bot carries the alerts this server sends while it is running, and the chat in your account carries the alarm for when it stops. Switching Outside Watch off again stops the messages, and nothing else on this server depends on it.

What changed, and when. Until 8 September 2026 the Free heartbeat left the machine once every five minutes. On that date the Free interval became ten minutes (600 seconds); every paid plan stays at once a minute. Sender and receiver were moved in the same step, so no machine is judged against an interval it is not sending: exe-poc/OutsideBeat.cs (PeriodSecFor: Free 600 s, paid 60 s) and ping/src/budget.mjs (NOMINAL_PERIOD_SEC: free: 600). The consent screen quoted above carries the corrected sentence. Nothing else in that text changed: the bytes, their contents and the opt-in are as described.

That text deliberately says nothing about what our server keeps, because the Software can only vouch for what it sends. What our server keeps is a fact about us, and it belongs here. To print the next heartbeat yourself, run Stedwatch.exe --watch-preview. When you register, one extra message of 163 bytes carries the registration code and the public half of a key your machine generates for itself; the private half is kept on your machine only and is never sent to us; it is what signs every heartbeat.

What our server at ping.stedwatch.com keeps

The receiver runs on the same dedicated server as my.stedwatch.com (Hetzner Online GmbH, Germany, EU/EEA), in a database of its own. For every machine you register it holds:

What our server does not keep. The heartbeat is 83 fixed bytes, and the receiver refuses any other length, so nothing beyond the fields above can arrive. Your IP address reaches the receiver, as it does for any connection; the receiver holds it in memory only to rate-limit abuse and writes it neither to the database nor to its own log. Our hosting provider may keep standard server access logs, as described in sections 5 and 7. No hostname, no metric, no terminal, no broker, no account number and no licence key is ever sent, so none is stored.

Who receives it

Legal basis, switching it off, and how long we keep it

Legal basis: your consent (Art. 6(1)(a) GDPR). The switch is the consent, and you withdraw it by switching Outside Watch off in the same place. Your machine then sends one last signed message asking us to delete its record, and we remove the registration, its current state, its hourly history, its alarms and its audit rows in one transaction, and confirm that to your machine with a signed receipt; the Software says so until it has that receipt. The alarm destination stays as long as you still have another machine registered, because it belongs to the account, and goes with the last one. One audit row saying “consent withdrawn” stays for 90 days; it names your account and deliberately not the machine. Uninstalling the Software without switching Outside Watch off first does not withdraw: the heartbeats simply stop, we treat that silence like any other and may alarm you, and the registration stays until you delete your account. If you delete your account while a machine still has Outside Watch on, that machine keeps sending until you switch it off or uninstall; those messages are refused and not recorded.

Retention. The hourly history, the alarms and the audit trail are kept for 90 days and then deleted by a nightly job. The registration, its current state and the alarm destination are kept for as long as the machine is registered, never trimmed by age, because trimming them is what would silently switch the watch off. We take an encrypted backup of the database each night and keep it for two weeks, so a record deleted from the live database can survive in a backup for up to 16 days after that, and then it is gone. Deleting your account at my.stedwatch.com removes all of the above for all your machines in the same transaction as the rest of your account data. Your alarm destinations can be removed on your account page at any time, and no alarm is sent there afterwards.

5b. The app route through a server we run (optional, and off unless you switch it on)

The Stedwatch app talks to your servers directly wherever it can. On a trading server it usually cannot: the machine sits behind a firewall you should not open, and it has no name a phone can verify. This is the way round that, and it is off until you switch it on in the Software’s settings. It requires a Beta, Trial or Pro licence.

What you agree to when you switch it on

This is the text the Software shows you at that moment, word for word (exe-poc/Consent.cs, AppRelayGrantText):

Let the Stedwatch app reach this server

The Stedwatch app talks to your servers directly. That works when your phone can reach them, and on a trading server it usually cannot: the machine sits behind a firewall you should not open, and it has no name a phone can verify. This route solves that without asking you to run anything extra. This server dials OUT to a Stedwatch server and keeps that line open, and the app asks its questions through the same line. Nothing on your side has to accept an incoming connection.

What the line carries: the readings the app asks for, and nothing else. They are sealed on this machine before they leave it. A key is made here for EACH phone you pair, and the only other place it goes is that phone. A Stedwatch server passes the sealed bytes on; it has no key, so relaying them and reading them are not the same act.

What we can see anyway, because no relay can hide it: that this installation is connected, when it connects, how much it sends, and the internet address it comes from. If that matters to you, this is the switch to leave off.

What does not change: this server goes on monitoring exactly as it does now, and your alerts go on leaving from here through your own Telegram bot - they do not use this line and they keep working when it is down. Switching this off closes the line and the app stops being able to look; nothing else on this server depends on it.

That text says what your machine sends. What the server at the other end keeps is a fact about us, and it belongs here.

What our server at relay.stedwatch.com keeps

Nothing. The relay has no database, writes no file, and holds no key. It is a process that passes bytes between two live connections and forgets them as they pass; when it restarts, everything it knew is gone, because it never wrote anything down. That is not a promise about care, it is the shape of the program: there is no filesystem write and no database client anywhere in it.

Because it holds no key, it cannot read what it carries. The readings your app asks for are sealed on your own machine before they leave it, under a key made there for each phone you pair, and the only other place that key goes is that phone. Passing sealed bytes on and reading them are not the same act.

What it can see anyway

Relaying is not reading, and it is not invisibility either. While the line is open, our server can see that an installation is connected, when it connects and disconnects, and how much it sends. Its own log names the installation by a twenty-character fingerprint of the public key your machine generated for itself, never by your name, your account or your server’s address, together with those instants. Your IP address reaches the relay, as it does for any connection you make. Our hosting provider may keep standard server access logs, as described in sections 5 and 7.

Who receives it

Legal basis, switching it off, and how long we keep it

Legal basis: your consent (Art. 6(1)(a) GDPR). The switch is the consent, and you withdraw it by switching the route off in the same place. This is the text the Software shows you at that moment, word for word (AppRelayWithdrawText):

Close the app route?

This server stops dialling out to Stedwatch for the app, and the app can no longer look at this server from anywhere. The keys made for the seal are discarded here, so anything already relayed stays unreadable.

What stays: this server goes on monitoring exactly as it does now, and your alerts go on leaving from here through your own Telegram bot. Outside Watch, if you have it on, is a separate thing and is not touched by this.

Retention. There is no record of yours on the relay to delete, because it keeps none: closing the line ends it. What remains is the operating-system log line described above, kept for as long as that log is kept on the server. Deleting your account does not need to reach this route, because nothing of yours is stored on it.

6. Marketing emails and newsletter

If you ask to receive product news or our newsletter, we send those emails only after you confirm your subscription. We use double opt-in: you enter your email, we send you a confirmation link, and we add you to the list only once you click it.

For this we store your email address, the IP address and user-agent used to subscribe, the timestamp of your subscription and confirmation, and the source (where you signed up). We keep these consent details so we can prove that you asked to be added. Legal basis: your consent (Art. 6(1)(a) GDPR).

You can withdraw your consent at any time by clicking the unsubscribe link in any marketing email, or by emailing hello@stedwatch.com. Withdrawing consent does not affect the lawfulness of processing before you withdrew it, and it does not stop the essential service emails (such as your sign-in link or licence key) that we send to run your account.

7. This website

This marketing website is intentionally minimal. It self-hosts its web font (no third-party font service) and is served from a dedicated server operated by Hetzner Online GmbH in Germany (EU/EEA), which may keep standard server access logs (which include IP addresses) for security and operation. We do not set advertising or cross-site tracking cookies. If analytics are added later, this policy will be updated to say what, and on what basis.

Cookies. The customer account at my.stedwatch.com sets one strictly-necessary session cookie (our Better Auth sign-in session) so you stay logged in; we set no advertising, analytics, or cross-site tracking cookies.

8. Email support

If you email hello@stedwatch.com, we process the contents of your message and your email address to answer you. A diagnostics export, if you choose to send one, has secrets redacted by the Software before it is created.

9. Legal bases (where GDPR/Swiss FADP applies)

10. Retention

Locally stored monitoring data lives on your machine for as long as you keep it; you control it and can delete it, and uninstalling removes the Software's local data. Your my.stedwatch.com account data is kept until you delete your account (see section 5); deleting it removes your email, licence keys and sign-in data from our systems, while invoice records held by Lemon Squeezy (and its underlying payment processor) are retained as required by law. Outside Watch records follow the periods in section 5a: 90 days for the hourly history, alarms and audit trail, the life of the registration for the rest, and all of it goes when you switch the machine off or delete your account. Support emails are kept only as long as needed to handle your request and any follow-up.

11. Your rights

Subject to applicable law, you may have rights to access, correct, delete, or restrict processing of your personal data, to data portability, and to object or lodge a complaint with a supervisory authority. Where processing is based on your consent (marketing emails, an optional notification channel, Outside Watch), you can withdraw that consent at any time; for Outside Watch, switching it off in the Software is the withdrawal, and it deletes that machine’s record as described in section 5a. Because most data never leaves your machine, you exercise much of this directly by managing or deleting your local data. For your Pro account, you can delete everything we hold yourself from my.stedwatch.com → Account → Delete account. For anything else we hold (e.g. support emails), contact hello@stedwatch.com and we will action your request. If you are in Switzerland you may also contact the Federal Data Protection and Information Commissioner (FDPIC); if you are in the EU/EEA, your local data-protection authority.

12. Children

Stedwatch is a professional tool not directed at children and is not intended for use by anyone under 18.

13. Changes

We may update this policy as the product develops. Material changes will be reflected here with a new "last updated" date.