1. Who we are and what this Policy covers
RAR7 LLC manages and operates the Lotra project and is responsible for the Lotra Cloud information described in this Policy. "Lotra," "we," "us," and "our" refer to RAR7 LLC when it determines how that information is processed.
This Policy applies to:
- the Lotra/RSA Software Windows desktop application;
- the Lotra Discord application, OAuth login, server-role checks, slash commands, and messages;
- the Cloudflare Worker and D1 database that provide login, device binding, signal delivery, and receipt state;
- the Lotra legal website; and
- support, security, and privacy requests submitted to RAR7 LLC.
Independent brokers, Discord, Cloudflare, Microsoft, Google, Auth0, market-data sources, download hosts, and other third parties control their own services and privacy practices. This Policy describes Lotra's interaction with them but does not replace their notices.
2. Privacy summary
- Broker credentials, session state, account identifiers, detailed holdings, balances, and order records are designed to remain on your computer or travel directly to the broker.
- Lotra Cloud receives Discord identity and role data, a device public key, acceptance records, limited signal/preview data, and delivery/completion status.
- The device binding uses a random installation key, not hardware serial numbers or a general hardware fingerprint.
- We do not sell personal information, rent it, or use it for targeted advertising.
- The legal website has no advertising or analytics scripts and sets no first-party cookies.
- Starting the cloud listener can cause eligible orders to be submitted automatically; that processing is described below.
3. Sources of information
We receive or process information from:
- you, when you accept policies, configure the app, connect a broker, use Discord, seek support, or make a request;
- your installation, including its device public key, signed requests, settings, previews, and execution status;
- Discord, including your user ID, username, server membership, roles, and authorized interactions;
- administrators, when they issue buy/sell signals or owner-only device-unbind commands;
- connected brokers and data sources, when the local application requests accounts, positions, quotes, previews, and order status; and
- Cloudflare and network infrastructure, which process request, routing, security, and diagnostic metadata.
4. Information processed by Lotra Cloud
Discord identity and access
- Discord user ID and username;
- server membership, role IDs, Premium status, administrator status, and verification times;
- OAuth request status, denial reason, and timestamps; and
- Discord application, guild, channel, interaction, message, creator, approver, canceller, and owner-command identifiers where relevant.
Discord OAuth requests only basic identity and current-server membership access; it does not request your Discord email. Lotra receives a temporary Discord access token to perform the identity/role lookup and attempts to revoke it immediately afterward. Lotra does not receive your Discord password, 2FA code, or backup codes.
Terms, privacy, and age affirmation
- the Terms and Privacy Policy version accepted;
- acceptance and recording timestamps;
- confirmation that the user affirmed being at least 18, without collecting a birth date; and
- the Discord user ID and device public key associated with acceptance after binding.
The application also stores the current acceptance locally so it can determine whether the same policy version has already been accepted on that installation.
Device binding and session security
- a random per-installation Ed25519 public key and generic device label;
- binding and update timestamps;
- OAuth state, polling secret, and session-token hashes rather than their plaintext values;
- session creation, expiration, revocation, and last-seen times; and
- signed-request timestamp, nonce hash, and replay-protection state.
The Ed25519 private key and plaintext cloud session token remain in your operating- system credential store. Lotra Cloud does not receive the private key. The binding does not collect a MAC address, disk serial number, motherboard ID, TPM ID, or biometric identifier.
Signals, previews, and execution status
- buy/sell action, ticker, whole-share quantity, deadline, expiration, status, and timestamps;
- quote time, reference price, broker display name, broker availability, aggregate eligible-account count, and generic unavailability reason;
- per-user delivery state such as pending, claimed, executing, executed, skipped, or uncertain;
- lease and anti-duplicate hashes, completion times, and optional opaque execution identifiers; and
- Discord administrator and message identifiers connected to a signal.
The preview is intentionally aggregated. Lotra Cloud is not designed to receive full brokerage account numbers, complete positions, balances, account-level buying power, broker passwords, MFA codes, browser cookies, or full broker order history.
Network, rate-limit, and security information
The Worker reads the connecting IP address to enforce rate limits and stores only a peppered hash with the limit scope, time window, and count. Cloudflare can separately process the raw IP address, user agent, request time, request URL, routing, country or region inferred from the connection, error, abuse, and security-event information as part of hosting and protecting the Service.
5. Information processed and retained on your computer
Lotra needs substantial local information to display portfolios, authenticate to brokers, apply safety rules, and submit or reconcile orders. This information is not uploaded to RAR7 LLC merely because it exists locally. It can still be transmitted directly to a broker, Discord, Cloudflare, or another provider when you use the related feature.
Credentials and authentication state
- broker username/email and password, or Webull App Key and App Secret;
- Webull access-token data and other broker tokens where supported;
- the Lotra cloud session token and installation private key;
- broker cookies, browser local storage, cache, session metadata, and request-session snapshots; and
- one-time MFA, email, or app-verification responses while a local prompt is active.
Long-term secrets are intended for the operating-system credential store. Some broker session snapshots and managed browser profiles remain in the user's local application-data directories. One-time challenge responses are not intentionally saved by Lotra.
Profiles, accounts, portfolios, and trading records
- broker type, internal login ID, user-created label, enabled account selectors, persistence preference, and timestamps;
- account identifiers or masked identifiers, account type, positions, symbols, quantities, prices, cost basis, and realized profit/loss;
- cash, margin debit, buying power, equity, market value, baselines, and balance history;
- event, client, broker, and account order IDs; ticker, side, quantity, price, gross amount, state, timestamps, and preflight results;
- duplicate/execution guards, uncertain outcomes, unavailable quotes, restrictions, protected tickers, and tracked liquidation/play data; and
- local app settings, including share/cost limits, account selections, cutoff settings, session preferences, and appearance.
The local SQLite database is not separately encrypted by Lotra. It relies on your Windows account, filesystem, device encryption, and physical security. Full account selectors can contain sensitive account identifiers even though cloud previews send only aggregate account counts.
Local diagnostics
A transient network-activity list can include time, adapter, destination host, purpose, and success status. It is designed not to include request or response bodies, headers, cookies, or credentials. Warning/error messages are redacted and stream-only in the current release; Lotra does not intentionally create a persistent application log or take automatic screenshots.
6. Legal website data
These static legal pages contain no account forms, advertising, analytics scripts, pixels, or first-party cookies. Cloudflare processes ordinary web-request and security metadata when it serves the pages. Following a Discord or other external link moves you to that provider, whose privacy practices then apply.
7. How RAR7 LLC uses information
We use the information described above to:
- present and record Terms and Privacy acceptance;
- authenticate Discord users and confirm server membership, Premium access, and administrator authority;
- bind one installation, authenticate signed requests, revoke sessions, and process owner-approved unbinding;
- create, quote, deliver, claim, authorize, expire, complete, and de-duplicate signals;
- connect locally to selected brokers, show portfolios, apply settings, and submit or reconcile user-authorized orders;
- protect accounts, rate-limit abuse, troubleshoot failures, and investigate security incidents;
- provide support, respond to privacy requests, enforce the Terms, and resolve disputes; and
- comply with law, lawful process, provider requirements, and recordkeeping obligations.
We do not use Discord API data, broker data, or device-binding data to build advertising profiles or for an unrelated commercial purpose.
8. Legal bases where required
Where a law requires a legal basis, processing may be based on: performance of our contract with you; steps you request before entering that contract; RAR7 LLC's legitimate interests in operating, securing, improving, and enforcing the Service; compliance with legal obligations; protection of users and legal rights; or consent where the law requires consent. You may withdraw consent for future processing where consent is the basis, but withdrawal does not make earlier processing unlawful and may make the related feature unavailable.
10. No sale, sharing for targeted advertising, or advertising profiles
RAR7 LLC does not sell or rent personal information, exchange it for cross-context behavioral advertising, or share it for targeted advertising. The legal site contains no third-party advertising or analytics trackers. We also do not knowingly sell or share personal information of anyone under 18.
11. Retention and deletion
| Record | Current retention approach |
|---|---|
| OAuth login request | Active for about 10 minutes and normally deleted after an additional cleanup period of about one hour. |
| Cloud session | Configured for about eight hours. Expired records are removed by scheduled cleanup; a revoked record can remain for up to about 24 hours. |
| Used device nonce hash | About five minutes for replay protection. |
| Rate-limit hash | About one hour. |
| Signal and receipt | Through the deadline and normally a short grace period of about five minutes. A failed message-sync reservation may remain longer, up to about one day. |
| Discord interaction ID | About 30 days to prevent replay or duplicate command handling. |
| Discord user and role record | No automatic expiry; retained while needed for access, security, support, legal obligations, or until an appropriate verified deletion request. |
| Device binding | Until owner-approved unbinding, account deletion, or another lawful reason. Unbinding revokes active sessions. |
| Legal acceptance | Retained as needed to document the policy version and consent associated with a Discord account and device, resolve disputes, and meet legal obligations, including after unbinding where reasonably necessary. |
| Local app and broker data | Until you use the relevant delete/reset controls or remove it from Windows app-data, browser-profile, and credential-store locations. Uninstalling the EXE alone may not remove it. |
| Cloudflare/Discord/provider logs and backups | Controlled by the provider, configured plan, security settings, legal obligations, and backup cycles. |
We may retain information longer where reasonably necessary for fraud prevention, security, legal claims, tax/accounting duties, provider disputes, or compliance, and may delete it earlier when no longer needed. Deletion can be delayed in backups until the ordinary backup cycle completes.
Local deletion controls
- Clear Sessions removes supported request-session files, Webull tokens, broker browser profiles/cookies, and certain safety state, but keeps saved credentials and broker/account settings.
- Delete Session & Cookies removes the selected managed browser profile/session while keeping credentials and account settings.
- Delete Login removes the selected profile and associated saved username/password, Webull token, and supported session snapshot, but may not remove all historical portfolio/order/safety records or every browser artifact.
- Reset Portfolio Records removes many portfolio snapshots and Lotra order-history records but intentionally retains certain baseline, protected-ticker, tracked-play, and safety/deduplication records.
- Discord logout attempts remote session revocation and clears the local cloud token. Owner-only unbinding removes the cloud device binding and revokes active sessions.
12. Automated access and order processing
Lotra automatically checks Discord membership, Premium role, administrator status, policy version, session status, signed device proof, replay state, signal deadline, and device binding to allow or deny Service access. An owner unbind command removes a binding and revokes sessions. You can ask for review of an access decision through the contact method below.
If you manually start the cloud listener, the desktop automatically receives eligible administrator signals, requests broker quotes and previews, applies enabled account selectors and safety checks, obtains server authorization, and can submit live buy or sell orders without a per-signal local confirmation. Lotra does not use a financial profile to determine suitability. Stop the listener to prevent new signals; stopping may not interrupt an order already submitting. See the automatic-execution Terms before enabling it.
13. Security
Measures include TLS with certificate and hostname verification, OS-keyring storage for selected secrets, hashed cloud session/state values, short-lived sessions, per-installation request signatures, nonce replay protection, Discord interaction- signature verification, live role checks, restricted administrator/owner commands, limited cloud preview fields, no-cache responses, rate limiting, and credential/error redaction.
No system is perfectly secure. Lotra does not provide certificate pinning, TPM-backed device keys, traffic-analysis-tool detection, or a guarantee that local software, device traffic, browser state, or files cannot be inspected, copied, altered, or reverse engineered. Protect your Windows account, enable device encryption where available, use broker MFA, and do not run Lotra on an untrusted or shared computer.
14. Your choices and privacy rights
Depending on your location and subject to legal exceptions, you may request:
- confirmation of processing and access to personal information;
- correction of inaccurate information;
- deletion of information that is no longer required;
- a portable copy of information you provided;
- restriction of or objection to certain processing;
- withdrawal of consent where consent is the legal basis;
- review of certain automated access decisions; and
- an appeal if a covered U.S. state privacy request is denied.
We may verify a request using Discord identity, the bound device, transaction or purchase information, or other reasonable evidence. We will not ask you to post a password, MFA code, full brokerage account number, or government identifier publicly. An authorized agent may submit a request where law permits, but we may require proof of authority and direct confirmation from the user.
Some information cannot be deleted immediately because it is needed for security, fraud prevention, contract records, legal obligations, protected rights, or completion of a request you made. We do not discriminate against users for exercising applicable privacy rights, although deleting information needed for access can make the Service unavailable.
15. U.S. state privacy notice
The categories collected during the preceding 12 months can include identifiers; internet/network activity; account-access and financial information processed locally; commercial/subscription records if access is purchased; device/security identifiers; and inferences limited to Premium, administrator, access, and signal status. Sources, purposes, recipients, and retention are described above.
If a state privacy law applies to RAR7 LLC and your request, you may have rights to know/access, correct, delete, obtain portability, opt out of sale or targeted advertising, opt out of certain covered profiling, limit certain sensitive-data uses, use an authorized agent, appeal, and receive nondiscriminatory treatment. RAR7 LLC does not sell personal information or share it for targeted advertising, so there is no sale or targeted-advertising opt-out necessary for current practices.
16. Global Privacy Control and Do Not Track
Because the legal site has no advertising trackers and RAR7 LLC does not sell personal information or use it for targeted advertising, Global Privacy Control and legacy browser Do Not Track signals do not change current site behavior. We do not permit third parties to track visitors across unrelated sites through these legal pages. If practices change, we will update this disclosure and honor legally required opt-out signals.
17. Children's privacy
Lotra is intended only for adults age 18 or older. We do not knowingly collect personal information from a child under 13 or knowingly allow a minor to use automated brokerage features. If you believe an underage person submitted information, contact RAR7 LLC so the account and records can be reviewed and deleted where appropriate.
18. International processing
RAR7 LLC and its providers are based in or operate from the United States, and Discord, Cloudflare, brokers, and other providers use infrastructure in multiple countries. Information can therefore be processed outside your home jurisdiction, where laws may differ. Where required, transfers rely on provider contractual safeguards, adequacy decisions, consent, or another lawful mechanism.
19. Changes to this Policy
We may update this Policy when the Service, law, providers, risks, or data practices change. The effective date will be revised. Material changes may be announced in the desktop application or official Discord community and may require you to accept the new Terms and Privacy version before continuing or creating a new device binding.
20. Contact RAR7 LLC
Submit privacy questions or requests through the official Lotra Discord community and ask to continue in a private channel. Do not post passwords, MFA codes, API secrets, session data, full account numbers, government identifiers, or other sensitive information publicly.
Identify the request as a RAR7 LLC privacy request and include your Discord username and a general description of the request. We may ask you to verify the request through Discord OAuth or the bound installation before acting.