Privacy Policy.
1. Who we are
"Trade Journal AI" (the "Service," "we," "us," "our") is operated by Adam Hardegree, doing business as Trade Journal AI, located in Florida, United States. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and your rights. By using the Service you agree to this Policy.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account info | Email address, password (stored only as a one-way bcrypt hash, never plain text) | You provide at signup |
| Trading data | Trades you log, notes, screenshots, rules, playbook setups, weekly reviews, custom dashboards, AI Coach conversations | You enter; or auto-imported from a broker if you connect one |
| Broker API keys | Bitunix (and future broker) API keys, encrypted at rest with AES-256 | You provide if you connect a broker |
| Billing info | Plan, subscription status, payment method token (we never see or store full card numbers) | Stripe — when you subscribe |
| Technical data | IP address, user-agent, login timestamps, request logs | Automatic, when you use the Service |
| Communications | Emails you send to support, feedback you submit in-app | You send them |
3. What we DON'T collect
To set expectations clearly:
- We don't run third-party analytics scripts (Google Analytics, Facebook Pixel, etc.).
- We don't fingerprint your device.
- We don't sell your data to anyone, ever.
- We don't access your broker account beyond what your read-only API key permits.
- We never store your full credit card number — Stripe handles that.
4. How we use your information
We use the information we collect for these purposes only:
- Operate the Service. Authenticate you, store your trades, sync from your broker, render the dashboard.
- AI Coach. When you ask the AI Coach a question, we send the relevant trade history + your question to Anthropic's Claude API. See Section 6.
- Transactional email. Password resets, welcome emails, billing receipts, account-security alerts. Sent via Postmark.
- Billing. Charge you, send invoices, prevent fraud, comply with tax obligations.
- Security. Detect and prevent unauthorized access, abuse, and security incidents. Includes rate-limiting and login-attempt tracking by IP.
- Improve the Service. Understand which features are used, find bugs, fix problems. We do this from server-side logs — not from third-party tracking scripts.
- Comply with law. Respond to legal process, enforce our Terms, defend against legal claims.
5. Legal basis (for users in the EEA, UK, and similar jurisdictions)
Where the GDPR or similar laws apply, we process personal data on these legal bases:
- Contract — to provide the Service you signed up for.
- Legitimate interest — to keep the Service secure, improve it, and communicate with you about it.
- Consent — for any optional features that require it (e.g., sending data to AI providers if you choose to use AI Coach).
- Legal obligation — to comply with tax, accounting, and law-enforcement requirements.
6. Third parties we share data with
We share the minimum data necessary with these service providers, who are contractually bound to use it only to provide their service to us:
6.1 Anthropic (AI Coach)
When you use the AI Coach feature, we send your trade history (or the subset relevant to your question), your question text, and your trader profile to Anthropic's Claude API. Anthropic processes this to generate a coaching response, then returns it to us. Anthropic does not use your data to train their models per their commercial terms. Data is retained by Anthropic for up to 30 days for abuse monitoring.
If you don't use AI Coach features, no data is sent to Anthropic.
6.2 Postmark (transactional email)
We send password-reset, welcome, and billing emails via Postmark. Postmark sees your email address, the email content, and delivery metadata.
6.3 Stripe (payments)
Subscription billing is handled by Stripe. Stripe collects and processes your payment method directly. We see only a token reference and high-level subscription status — not your full card.
6.4 Bitunix (and other brokers, when you connect them)
If you connect Bitunix, we use your read-only API key to call Bitunix's servers and pull your trades. Bitunix is a separate company; their handling of your data is governed by Bitunix's own privacy policy.
6.5 SiteGround (hosting)
The Service is hosted on SiteGround. Their infrastructure handles request routing, file storage, and our MySQL database. SiteGround does not access your data except as required to deliver hosting.
6.6 Compelled disclosure
We may disclose data if required by valid legal process (subpoena, court order) or to prevent fraud or protect the rights and safety of users or the public. We'll notify you of such requests when allowed by law.
7. Data security
We take security seriously. Specifically:
- All traffic to the Service is encrypted with TLS (HTTPS).
- Passwords are stored as bcrypt hashes — we cannot read or recover them.
- Bitunix API keys are encrypted at rest with AES-256-GCM using a server-held master key.
- Access to production servers is restricted to a small number of authorized administrators.
- We use rate-limiting and brute-force protection on login endpoints.
No system is 100% secure. If we ever suffer a data breach affecting your personal information, we'll notify you and the appropriate authorities as required by law.
8. Data retention
We keep your data for as long as your account is active.
- If you delete your account, we permanently delete your trades, notes, screenshots, rules, and Bitunix keys within 30 days.
- Billing records may be retained for up to 7 years to comply with tax law.
- Server logs (IPs, request metadata) are retained for up to 90 days, then rotated.
- Anonymized aggregates (e.g., "X% of users connect Bitunix") may be retained indefinitely; these can't be linked back to you.
9. Your rights
Depending on where you live, you have some or all of these rights:
- Access — see what personal data we hold about you. (Most of it is already visible in-app; for the rest, email us.)
- Correction — fix data that's wrong. You can edit most fields directly in Settings.
- Deletion — delete your account and everything in it. Settings → Account → Delete account.
- Portability — export your trades as CSV from the Trades page.
- Object / restrict processing — object to specific uses (e.g., AI Coach) by not using those features. For other objections, email us.
- Withdraw consent — where we rely on consent, you can withdraw it at any time without affecting prior processing.
- Complain to a regulator — if you're in the EEA/UK and unhappy with how we handle your data, you can complain to your local data protection authority. We hope you'll talk to us first.
To exercise any of these rights, email support@tradejournal.ai.
10. California residents (CCPA / CPRA)
If you're a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- The right to know what personal information we collect, use, and disclose.
- The right to delete personal information we collect from you.
- The right to correct inaccurate personal information.
- The right to opt out of the "sale" or "sharing" of personal information. We don't sell or share personal information for cross-context behavioral advertising.
- The right to non-discrimination for exercising these rights.
11. Cookies and similar technologies
We use a single first-party session cookie to keep you logged in. We don't use tracking cookies, advertising cookies, or third-party cookies. We don't run "essential" third-party scripts that set cookies.
The Service uses localStorage in your browser to cache preferences (theme, dashboard layouts, etc.) — these stay on your device and aren't transmitted to us.
12. Children
The Service is not directed to children under 18 and we don't knowingly collect personal information from children. If you believe a child has given us their information, email support@tradejournal.ai and we'll delete it.
13. International data transfers
Our servers are located in the United States (SiteGround US-East). If you access the Service from outside that region, your data is transferred and processed there. Where required, we rely on standard contractual clauses or other lawful transfer mechanisms.
14. Changes to this Policy
We may update this Privacy Policy from time to time. If a change is material, we'll notify you by email or in-app notice at least 14 days before it takes effect. The "Last updated" date at the top reflects the current version.
15. Contact
Privacy questions, data-rights requests, or anything else: support@tradejournal.ai.