Privacy
Last updated 3 October 2026
We keep as little about you as we can. You don't need to give us your name, email address or a password to use aggr.
What we store
| Account | Your account number and API keys, stored only in a one-way scrambled (hashed) form, so we can check them but not read them back. The names you give your keys, when they were created and last used, and how many requests they made. |
|---|---|
| Sign-ins | When your account last signed in, and its sign-in sessions (also hashed). |
| Payments | For each payment: the plan, term, amount, the coin you paid with, its status, the country (and VAT id, if you give one) you enter at checkout, and the country your connection came from at that moment (not the address itself). Tax law needs this evidence of where a customer is. |
| Only if you add one: used for reminders before your paid time runs out and to help you back in if you lose your account number. Nothing else, never shared, never used for marketing. |
What we don't store
- No access logs of who requested what. Your IP address is used in memory only, to limit abuse (for example how many accounts one address can create, or failed sign-in attempts), and is forgotten within a day.
- No analytics, advertising or tracking of any kind. This site loads nothing from other companies: fonts, scripts and images are all served by us.
- No card details: card payments, when we add them, go directly to the payment provider.
Cookies and browser storage
aggr_s | Keeps you signed in on the odds board and the account page (30 days). Can't be read by scripts. |
|---|---|
aggr_hint | Only your plan's name, so every page's top bar can show whether you're signed in (30 days). Contains nothing secret. |
aggr_theme | Light or dark, if you choose one, so every page of aggr.fi uses it (a year). |
| Local storage | Your choices on the odds board (theme, odds format, time zone, watchlist and the like). Stays in your browser; we never see it. |
All of these are needed for the site to work; there are no others, so there's nothing to consent to.
Who else handles your data
- Hosting: our servers are in the European Union.
- Payments: crypto payments are processed by NOWPayments, which sees what's needed to process the payment (the amount, the coin and the paying wallet), under its own privacy policy. We receive the payment's status and amount.
- Email: if you add an address, the email service we use to send reminders will handle it.
We don't sell or share data with anyone else.
How long we keep it
Account data for as long as the account exists. Payment records for as long as accounting law requires. Sign-in sessions end after 30 days.
Your rights
Under the GDPR you can ask what we hold about you, have it corrected or deleted, or take it with you. Write to hello@aggr.fi from the email on your account, or include your account number's last four characters and one of your API key prefixes so we can find the account. You can also complain to the Finnish Data Protection Ombudsman (tietosuoja.fi).
Changes
If this policy changes in a way that matters, we'll update the date above and, if you've added an email address, tell you.