This Privacy Policy explains what information TradeOS (“we”, “our”, “the service”) collects when you use the app, why we collect it, and how it's stored. The short version: we collect the minimum needed to give you a working trading journal, and we don't sell or share your data.
1. Information we collect
Account information
- Email address — used to identify your account and for password resets.
- Password — stored hashed by our auth provider (Supabase). We never see or store plaintext passwords.
Trading data you enter
- Trades you log (date, contract, direction, prices, contract count, commission, planned risk, notes).
- Prop firm configuration (selected preset or custom rules).
- Calculator inputs (stored locally on your device only).
Technical information
- Authentication cookies (essential — required to keep you signed in).
- Server logs from our hosting provider (Vercel) including IP address and request paths, retained briefly for operational diagnostics.
2. How we use your information
- To provide and maintain the service (authenticate you, store your trades, compute analytics).
- To send transactional emails (account verification, password resets).
- To respond to support requests you initiate.
We do not use your data for advertising, sell it to third parties, or share it with partners for marketing purposes.
3. Where your data is stored
- Supabase — database + authentication. Servers hosted in the United States.
- Vercel — application hosting + edge network.
- Forex Factory — public economic calendar feed (we read this; we don't send your data to them).
Your trades and prop firm config are protected by Row Level Security policies — only your account can read or write them, even via direct database access.
4. Your rights
- Access: view all your trades any time in the Journal tab.
- Export: download your trades as CSV from Settings or the Journal.
- Correction: edit or delete any trade individually.
- Deletion: delete your account from Settings → Danger zone. This permanently removes your trades, prop firm config, and login.
If you're in the EU, UK, or California, additional rights may apply under GDPR / UK GDPR / CCPA. Contact us at the email below to exercise them.
5. Cookies
We use only essential cookies required to keep you signed in. We do not use analytics, advertising, or tracking cookies.
6. Security
Your data is encrypted in transit (HTTPS) and at rest. Passwords are hashed using industry-standard algorithms by our auth provider. No system is perfectly secure — please use a strong, unique password.
7. Children
TradeOS is not directed at children under 18. If we discover an account belongs to a minor we will delete it.
8. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date above will reflect any changes. Material changes will be communicated via email when feasible.
9. Contact
Questions about this policy or your data? Reach out at tradeos.support@gmail.com.