Draft — review before launch: fill in company / contact / jurisdiction / effective date. This boilerplate has not been reviewed by a lawyer.

Privacy Policy

Effective date: [Effective date]

This policy explains what Financially Skilled People (“we”, “us”) collects, why, how we protect it, and the choices you have. We collect only what we need to run your trading journal.

1. Information we collect

  • Account information— your email address, display name, and authentication details needed to sign you in.
  • Trades— the trade records you enter manually, import from a CSV file, or sync from a connected broker (symbol, side, size, prices, dates, fees, and similar fields).
  • Journal entries— notes, tags, and reflections you attach to your trades.
  • Strategies— the trading strategies and rules you define and associate with your trades.
  • Broker-connection metadata— which broker you connected, connection status, and the credentials/API secrets required to import your activity. Broker API secrets are stored encrypted with AES-256-GCM, are used only to fetch your data, and are never shared with anyone or shown back to you in full.
  • Limited technical data— basic, security- related request information (such as that needed to maintain your session and protect the Service from abuse).

2. How we use your information

We use your information to:

  • provide the journal, analytics, and other features you use;
  • import and reconcile your trades from connected brokers or uploaded files;
  • authenticate you and keep your account secure;
  • display content (such as a profile, group activity, or leaderboard standing) only where you have explicitly chosen to share it; and
  • operate, maintain, debug, and improve the Service.

We do not sell your personal information, and we do not use your trades or journal entries for advertising.

3. Sharing and disclosure

Your data is private by default. Other users can see only what you explicitly choose to make public (for example, by opting your profile into the leaderboard). We may disclose information if required by law or to protect the rights, safety, and security of our users or the Service. If the Company is involved in a merger or acquisition, we will continue to protect your information and notify you of any change in control or applicable policy.

4. Service providers

We use Supabase as our database, authentication, and hosting processor; your account data, trades, journal entries, and strategies are stored there on our behalf. Supabase processes this data under its own security and privacy commitments and only to provide the infrastructure we run on. We limit the processors we use to those necessary to operate the Service.

5. Cookies and sessions

We use strictly necessary authentication cookies to keep you signed in and to maintain your session securely. We do not use advertising or third-party tracking cookies. Clearing these cookies will sign you out.

6. Data security

We protect your data with measures including encryption in transit, encryption of sensitive secrets at rest (broker API secrets via AES-256-GCM), and per-user data isolation so one user cannot read another’s private data. No method of transmission or storage is perfectly secure, but we work to safeguard your information.

7. Data retention

We keep your information for as long as your account is active or as needed to provide the Service. When you delete your account, we delete your personal data and trading content, except where we must retain limited records to comply with legal obligations, resolve disputes, or enforce our agreements. Backups are purged on a rolling schedule.

8. Your rights and choices

You can access and update most of your information directly in the app. You can also:

  • Export your data— download your trades and related data from your profile settings at any time.
  • Delete your account— permanently delete your account and associated data from your profile settings.

Depending on where you live, you may have additional rights (such as access, correction, portability, deletion, or objection). To exercise any right, use the in-app tools above or contact us at the address below.

9. Children’s privacy

The Service is not directed to children, and we do not knowingly collect personal information from anyone who is not old enough to form a binding contract in their jurisdiction. If you believe a child has provided us information, please contact us so we can remove it.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, notify you. Please review it periodically.

11. Contact us

Questions or requests about your privacy? Email [support email] or visit our Support page. Company: Financially Skilled People, [company address / jurisdiction].