Privacy Policy
This is an English translation for convenience; if it differs from the Turkish text, the Turkish text prevails. This policy explains which personal data the Demon application at laplace-demon.com collects, how it uses them, with whom it shares them, and your rights.
Last updated: 17 September 2026
1. Data controller
Demon is operated by Anemon Bilişim Hizmetleri Sanayi ve Ticaret Limited Şirketi. For any question or request about your personal data, you can write to [contact e-mail not yet specified].
2. Data we collect
We keep only the data needed to provide the service:
- Account information: your e-mail address (which is your user name), your display name, your account's role and its creation time. Your password is not stored in plain text; only a hash that cannot be reversed (BCrypt) is kept.
- If you sign in with Google, we receive from Google your e-mail address, the information that this address has been verified by Google, and your name. We have no access to your Google password.
- The investment records you enter: stock, amount, purchase date and price, sale details and the notes you add.
- Auto Player: the virtual portfolios you create, their strategies, the stocks you select, and the virtual orders and positions.
- AI settings: whether you use the AI switched off, with your own key (Anthropic Claude, OpenAI or Google Gemini) or with Multi LLM (ConsensusRoom), your budget, the API keys you enter, and your API key obtained from ConsensusRoom for Multi LLM. Keys are stored encrypted with AES-256-GCM; only their last characters are shown on screen.
- AI usage records: the purpose, model, token counts, number of web searches and cost of each call; the daily news reviews prepared for you.
- Your exchange and language choice: the exchange and interface language you choose in the top bar are stored in your account so that they come up the same the next time you sign in.
3. Cookies and what is kept in the browser
We use no advertising, analytics or tracking cookies, and no third-party scripts or fonts are loaded on our pages. Only the following are used:
- Session cookie (JSESSIONID): to remember that you are signed in; it ends when you close the browser or sign out.
- Security cookie (XSRF-TOKEN): to verify that requests come from your page.
- Session refresh cookie (demon_refresh): so that your session does not end even if the server restarts or you are inactive for a while; our pages' scripts cannot read it. It is renewed on each use and deleted if it is not used for 60 days or when you sign out. Only a hash that cannot be reversed is kept on the server.
- Theme preference: your choice of light or dark appearance is kept in your browser's local storage and is not sent to the server.
- Exchange choice (demon.market): the exchange you last chose is kept in your browser's local storage; it is sent to the server with each request to indicate which exchange's data should be shown.
4. How we use data
We use your data only for the following purposes:
- to create your account, verify your sign-in and protect your session,
- to show you your investment records, your virtual portfolios and the analysis screens,
- to prepare the AI reviews you request and calculate their costs; if you chose Multi LLM, to open or link your ConsensusRoom account, obtain your key and open the credit top-up page,
- to determine which exchange and language are selected when you first open the site: your IP address is matched only at country level against the country table on our server (DB-IP) and considered together with your browser's language setting; your IP address and the country found are not recorded and are not sent to anyone,
- to keep the service secure and to fix errors.
5. Parties with whom data are shared
We do not sell your data and do not share it for advertising. For the service to work, limited data are shared with the following parties:
- Anthropic (Claude), OpenAI or Google (Gemini): only if you chose that provider with your own key. For the daily news review, market data, KAP disclosures and news headlines that are common to everyone are sent. In Auto Player, the positions, costs, cash and selected stocks of the virtual portfolio for which you turned on the AI books are sent. Your e-mail address, your name and the real investment records you enter are not sent to these providers. Calls made with your own API key are also subject to the terms of your own account with that provider.
- ConsensusRoom: only if you set up Multi LLM. To open or link your account, your e-mail address and name are sent; for AI calls, the content stated above as sent to providers is sent. ConsensusRoom passes this content on to the providers of the models you choose (Anthropic, OpenAI, Google and the like). Credit top-ups are made on ConsensusRoom's payment page; your card details do not reach the application. This use is also subject to ConsensusRoom's own terms.
- Google: to verify your identity if you sign in with Google.
- Amazon Web Services: the application and the database run on our server in AWS's Frankfurt (Germany) data centre.
- Let's Encrypt: only for the HTTPS certificate; no personal data are shared.
- DB-IP: the IP country table is downloaded monthly from db-ip.com and used on our server; no information about you is sent to DB-IP. IP Geolocation by DB-IP (https://db-ip.com), under the CC BY 4.0 licence.
- Market data sources (Borsa İstanbul, İş Yatırım, Yahoo Finance, Nasdaq, Tencent, Euronext, onvista, Moneycontrol, TMX, Kabutan, KAP and news feeds): data are fetched from these sources only with stock codes; no information about you is sent.
6. Transfer abroad
Our server is located in the European Union (Frankfurt). When you use the AI or Google sign-in, the data stated above may be processed by Anthropic, OpenAI, Google, ConsensusRoom and the providers ConsensusRoom uses in other countries, including the United States of America. By using these services you give your explicit consent to this transfer; you are not obliged to use them.
7. Retention periods
- Your account and usage data are kept for as long as your account remains open.
- When your account is deleted, your data are deleted from the database; they remain in the daily backups for at most 14 more days.
- Application logs are kept for at most 8 weeks. The application does not record your IP address; when you sign in with Google, your e-mail address is written to the log.
8. Security
Connections are encrypted with HTTPS. Passwords are protected with BCrypt, API keys with AES-256-GCM. The database cannot be reached from outside; it is connected to only from within the server. A backup is taken every night. No system is completely secure; if we notice a breach, we will inform you and the relevant authorities within the legal time limit.
9. Your rights
Under Article 11 of the KVKK (Turkish Personal Data Protection Law No. 6698) and the European Union General Data Protection Regulation (GDPR), you have the right to learn whether your data are processed, to access your data, to request their correction, deletion or a copy, and to object to their processing.
You can delete your investment records, your virtual portfolios and your own API key yourself from within the application. For complete deletion of your account or a copy of your data, write to [contact e-mail not yet specified]; we will conclude your request within 30 days at the latest. Your right to lodge a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) is reserved.
10. Children
Demon is not intended for persons under 18, and we do not knowingly collect data of persons under 18.
11. Changes
We may update this policy. The current text is always published on this page with its last updated date.