Draft document notice These documents were drafted in house and have NOT been reviewed by a lawyer. They are published so they can be read and corrected, not because they are final.

Version 2026-09-18. Operated by Malloy Labs LLC, Milwaukee, Wisconsin, USA.

What changed in v5, in plain English

Effective September 16, 2026. This is a full replacement of both documents, not an amendment, so both the Terms of Service and the Privacy Policy require fresh acceptance. You will see the acceptance panel once.

Why a full replacement. Coherent changed products. The old documents described a public feed, credential checkmarks earned by connecting a brokerage, a paid streak-protection item, and a group feature. None of that exists any more. The old Terms also said reading and writing on Coherent were free, and described recurring charges as something we might introduce one day, while the subscription was already live at $9 a month. That gap is the single biggest reason these documents are being rewritten rather than patched.

What Coherent is now, stated plainly in both documents:
- Coherent watches your own trading, through read-only exchange API keys and public wallet addresses you connect, and warns you before you break a rule you wrote yourself.
- Warnings are warnings. No part of Coherent can stop you from placing a trade. That is now a written promise in Section 3 of the Terms, not just an engineering convention.
- Coherent never places, changes, or cancels an order, and never moves money or assets.

Terms of Service:
- New: Section 3, "Warnings never block." The hard promise, in one place: no code path in Coherent prevents a user action, and none is permitted to be added.
- New: Section 5, read-only connections. An exchange API key that carries trade or withdrawal permission is refused at the point you submit it and is never stored. Wallet addresses are public identifiers that authorise nothing.
- Rewritten: Section 7, payments. The real price, $9 a month with a seven-day free trial, cancel any time, billed through Stripe. Promotional codes, price changes, renewals, refunds, and the EU right of withdrawal are all stated at the point they apply. The old "if we introduce recurring charges" language is gone.
- New: the free journal, available to anyone who confirms an email address, and the optional paid add-on at $2.37 a month that keeps that journal updated automatically from a connection you have already made.
- New: the browser extension, which displays Coherent's own warnings over an exchange page and never touches a trading control, and the mobile apps.
- Removed: the public feed, public replies and their permanence rule, moderation, identity checks through a verification vendor, funded-account credential checkmarks and medallions, the paid streak-protection item, the group feature, and the accountability-partner feature.
- Carried forward deliberately: the publisher posture (no investment advice, no order handling, no custody), Wisconsin law, the arbitration and class-action-waiver section for US users, and the EU consumer carve-outs.

Privacy Policy:
- Rewritten around the data we actually hold. The structure you already knew, collection by source, the lawful-basis table, the recipients table and the retention table, all survive; the contents are now about exchange connections and wallet addresses instead of a social feed.
- Kept and stated harder: normalize-and-drop. Coherent never stores a raw price, a quantity, a notional value, or a balance. What is kept from a fill is a win or loss flag, a banded return, a size band, a duration, and a ticker symbol. The raw numbers exist only in memory while the derived values are computed, then they are gone.
- New: the one stored credential. Your read-only exchange API key is encrypted at rest, is excluded from data export and from every log, and is deleted when you disconnect that exchange.
- New: what a wallet address is. A public address on a public chain, which lets anyone read that address's history and authorises nothing.
- New: retention, deletion and pause are separate actions, and each one says exactly what it does: delete your account, delete synced data, delete imported monitoring history, delete readiness data, disconnect an exchange, or simply pause.
- Removed: the sections about public content, public-reply de-identification, biometric processing by a verification vendor, and funded-status verification.
- Unchanged: Malloy Labs LLC is the controller for EU, EEA and UK users; the international-transfer disclosure; the breach-notification commitment; and the founding-member marker, which is still a one-way hash of an email address and nothing else.

Revision of September 16, 2026, after an outside legal review. An outside legal analyst reviewed the v5 drafts before they went to counsel, and both documents were revised in response. The version date did not change, because nothing here was ever accepted by a user in its earlier form. What changed:

The governing principle. The old drafts stated legal conclusions: that Coherent "is not a money transmitter," "is not an investment adviser," "is not a broker-dealer." Those are claims that whole bodies of law cannot apply to us, and they are not ours to make. Every one of them is now a factual description of what the software does and does not do instead. Coherent does not receive, hold, custody, control, transmit, exchange, purchase, or sell funds or digital assets. Coherent has no technical ability to place, modify, delay, cancel, or block an order. Those facts are stronger than the labels they replaced, and unlike the labels they are things we can prove.

Terms of Service:
- Section 2 rebuilt around facts rather than labels, on funds and digital assets, on advice, and on order handling.
- A plain-language notice at the top of the document that Section 20 contains binding arbitration and a class-action waiver, and the automatic-renewal disclosure in the same place: 7 days free, then $9.00/month until cancelled.
- Section 7 now carries the full automatic-renewal disclosure, a price-change clause that applies only prospectively and with advance notice, and a refunds clause with a savings clause for rights that cannot lawfully be excluded.
- Section 7's EU right of withdrawal no longer implies you waive the right by signing up. The right is described accurately, and immediate supply inside the 14-day window requires your prior express request and acknowledgment, asked for separately.
- Section 9 no longer describes the iPhone app as available. It is built and not released.
- Section 18's liability cap now says expressly that it does not apply to liability that cannot lawfully be limited or excluded.
- Section 19, indemnity, narrowed hard. It now reaches only third-party claims arising from your unlawful conduct, your infringement, your misuse of another person's account or credentials, or your material breach, and it expressly does not cover claims arising from our own acts or omissions.
- Section 20, arbitration, rewritten in full: the Federal Arbitration Act, the administrator and its rules, who pays consumer fees, how an arbitration is started, the small-claims carve-out, individual-only proceedings, the jury-trial waiver, the class waiver, a 30-day opt-out with mechanics, severability, what happens if no arbitration provider will take the case, and a California public-injunctive-relief carve-out reflecting McGill v. Citibank.
- Section 22 no longer lets us change binding terms without notice. Material changes, including to arbitration, price, and privacy, apply only going forward, with notice and with renewed acceptance where required.

Privacy Policy:
- New Section 14, consumer health data. The optional wellness check-in plausibly falls under Washington's My Health My Data Act and Connecticut's consumer health data rules, which can apply regardless of a company's size or processing volume. The section covers what is collected, that it is optional and off by default, the separate explicit consent and its exact wording, that we do not sell it and do not share it without consent, and how to withdraw and delete.
- The wellness consent is now stated to be a distinct, optional, withdrawable consent that is never bundled into accepting the Privacy Policy, with the consent text printed in the document.
- New Section 2.7, the browser extension, describing exactly what the published manifest lets it reach and what it cannot see.
- Section 2.2 now treats the exchange API credential as its own category, with the facts checked against the code that handles it, and states the normalize-and-drop architecture in the terms an outside reader needs.
- Linked wallet addresses are now stated to be personal data. Public does not mean outside privacy law.
- Section 3 now distinguishes service messages from marketing.
- Section 7's retention table is now object by object, and a new paragraph says plainly that production deletion is immediate while backup snapshots age out on their own schedule. We do not claim deletion is instant everywhere.
- Section 2.5 now separates empty legacy tables, which hold nothing about anyone, from legacy tables that still hold real rows, which are personal data and are deleted with your account.
- Section 8 adds how to make a request, authorised agents, the US state appeal right, and supervisory-authority complaints.
- Section 16 states plainly that EU Article 27 and UK representative requirements are under assessment. We do not claim a representative is appointed, because none is.
- Section 17 now describes the automated processing factually and then says the part that was missing: profiling remains subject to the rest of the GDPR even where the Article 22 restriction does not apply. Nothing here implies the GDPR stops applying.
- Section 18 no longer reserves an unrestricted right to change this Policy.

Draft status. These documents were drafted in-house and reviewed by an outside legal analyst who is not our counsel. They have not been reviewed by the company's lawyer. Both pages say so at the top until that review happens.

2026-09-17, second outside review applied. The same outside analyst read the published text section by section and sent a redline. Both documents move to version 2026-09-17 and both ask for acceptance again. What changed, in plain English:
- Terms 1 and 22: you accept the Terms by creating an account and affirmatively accepting them. The Privacy Policy is a notice, not a contract, and is no longer "incorporated by reference" or part of the entire agreement. The free plan builder is governed by the notice on its own page.
- Terms 3: the "warnings never block" promise now says exactly what it covers: nothing in Coherent can prevent, delay, cancel, alter, throttle or interfere with an action at a connected exchange or wallet. Ordinary login, security and billing controls on Coherent itself are not what the promise is about.
- Terms 4: you are not answerable for what happens under your account when it results from our own breach, negligence or security failure.
- Terms 5, Privacy 2.2: every exchange key is now verified by the venue's own API, with no attestation fallback, so the sentences about attesting are gone.
- Terms 6, Privacy 17: rule templates carry no preset number; you type the limit. Coherent may format or restate your choices into a draft rule or plan, but does not select a limit, parameter, asset, strategy or course of action for you.
- Terms 7: the price is $9.00 a month and that is the total, with no tax added at checkout. The trial is 7 days and the first charge is on day 8. For EU and EEA consumers: our position is that Coherent is a digital service under Directive 2019/770, which we ask EU counsel to confirm; checkout shows a separate, un-ticked request to start during the withdrawal period; a valid withdrawal within 14 days refunds any payment taken in those 14 days in full; you withdraw by email in any clear words; and we send the contract information by email after signup. App-store rules apply subject to your mandatory rights.
- Terms 10: no longer calls crypto assets "largely unregulated"; describes the risk factually and cross-references Section 2 instead of restating it.
- Terms 13: aggregate statistics are prepared so they do not reasonably identify you.
- Terms 16: copyright notices go to the contact address; registration of a designated agent with the Copyright Office is pending and is no longer claimed.
- Terms 18: the last paragraph is named for what it is, a savings clause.
- Terms 20: if you reject a change to the arbitration section, the version you most recently accepted governs; the sentence about the EU online dispute resolution platform is deleted because that platform was discontinued in 2025; "coordinated" is removed from the class waiver; an arbitration demand is copied to the physical notice address in Section 22.
- Terms 21: if we end a paid subscription for a reason other than your breach, we refund the unused period pro rata.
- Every postal address now reads "Malloy Labs LLC, 2466 N Oakland Avenue, Milwaukee, Wisconsin 53211, USA". Until 2026-09-18 that line carried a visible placeholder because the company had not settled which address to publish.
- Privacy 1, 14, 15, Terms 9: the separate Consumer Health Data Privacy Policy now covers the live wellness check-in, is linked from the homepage footer at /health-privacy, and is published as plain HTML too. Wearable data is not collected and both documents will be updated before it is.
- Privacy 2.5: the retired public-profile and identity-verification records were deleted on September 16, 2026, and the text now says they no longer exist rather than that they linger until account deletion.
- Privacy 2.6, 7 and 14: withdrawing the wellness consent now erases the stored check-ins and the readiness inference, not only stops collection. Engagement events are deleted with the account and otherwise expire within 90 days. Backups are encrypted and kept no longer than 14 days; consumer health data deletions reach backups no later than six months after the request is authenticated.
- Privacy 3: "explicit" is reserved for the Article 9 wellness consent. Counsel is confirming whether connecting an exchange and automatic detection rest on contract or on consent; until then we collect consent.
- Privacy 4: roles in the recipients table reflect our vendor contracts as we understand them and are being confirmed vendor by vendor.
- Privacy 6 and 16: the transfer section names the Chapter V mechanisms we use and offers a copy of the clauses on request; the two references to an internal compliance matrix are gone.
- Privacy 7: opens with "How long we retain personal data varies by category and purpose"; the acceptance-records row notes that counsel is settling a limited post-deletion retention period.
- Privacy 8: response times follow the law that applies, ordinarily one month under the GDPR and UK GDPR, 45 days under several US state laws. The "we do none of those three" shorthand is replaced with the precise statement.
- Privacy 9: at account deletion you choose whether to keep the founding-member marker so the status can be restored, or erase it. The marker is a hash of your email address and we treat it as personal data, not as anonymous.
- Privacy 10: plan-builder drafts and waitlist emails with no account are deleted automatically after 12 months.
- Privacy 14: the "could fall" hedge is replaced with a statement that we treat wellness data and the readiness inference as consumer health data wherever a state law protects it; the "open question" paragraphs are gone; the consent screen is described; geofencing is disclaimed.
- Privacy 16: "We intentionally offer the service to users in those territories." Appointing EU and UK representatives is a step we are taking with counsel.
- Privacy 17: the output of automated processing is an informational alert, comparison or summary; it does not itself take any action on you or your account.
- Privacy 18: no materially different purpose without the notice, consent or other lawful basis the law requires, and archived versions stay available.
- Later the same day, a third read: the Consumer Health Data Privacy Policy now carries only what Washington's law asks it to carry, says in the statute's own words that we share nothing, and describes the access right in full. Privacy Section 14 now gives the same purpose as that policy and as the consent screen: showing you your readiness and timing your warnings. Same effective date, because all of it shipped on the same day.

2026-09-18, the company address

The one placeholder in these documents is filled: every postal address now reads Malloy Labs LLC, 2466 N Oakland Avenue, Milwaukee, Wisconsin 53211, USA. That is the address for a privacy request, a copyright notice and a copy of an arbitration demand. Nothing else changed. The version moved from 2026-09-17 to 2026-09-18 because a version here identifies an exact text, and the text is not the same one.

Still true after this revision: no lawyer has read these documents, and the draft notice stays until one has.