Legal · privacy
Privacy policy
Last updated · 6 May 2026
Plain English: we collect the minimum needed to run the journal, we encrypt the entries you create, we never sell anything, and you can take your data out at any time.
What we collect
Account data. Email address, hashed password, account creation date, and Pro subscription status if applicable.
Journal data. The entries, tags, screenshots, R-multiples and notes you log into ProTrader. Encrypted at rest. Visible only to you (and to spotlight readers if you publish a spotlight).
Usage data. Page views, feature usage events (anonymised), and error reports. We use this to find bugs and decide what to ship next.
Payment data. If you subscribe to Pro, our payment processor (Stripe) handles your card details. ProTrader does not store card numbers.
What we never do
- We do not sell your data to anyone.
- We do not use your journal entries to train any third-party AI model.
- We do not share your entries with prop firms, brokers, or other third parties without your explicit consent.
- We do not run third-party advertising trackers on this site.
How we store it
All journal data is encrypted at rest with AES-256. Production databases run in the EU (London region) and are backed up daily. Backups are also encrypted and rotated on a 30-day window.
Who we share with
We use a small set of well-known sub-processors: Netlify (hosting), Supabase (database), Stripe (payments), Plausible (privacy-preserving analytics). Each is contractually bound to GDPR-equivalent data handling. A current list is available on request.
Your rights
Under UK GDPR you have the right to access, correct, delete, export, or restrict the processing of your personal data. Email privacy@protrader.app and we will respond within 30 days.
Cookies
We use the smallest possible cookie set: a session cookie for authentication and a theme cookie to remember light vs dark mode. We don't run third-party advertising cookies. See the cookie policy.
Data retention
Active accounts: kept indefinitely while you use the Service. Closed accounts: journal data deleted within 30 days; account record retained for 7 years for accounting purposes (UK Companies Act).
Changes to this policy
We will email Pro subscribers and post a notice on the homepage at least 14 days before any material change.
Contact
privacy@protrader.app · Data Protection Officer: ProTrader Limited, London, United Kingdom.