Privacy Policy
Last updated: July 2026
Describes how TradaxLab currently processes personal data. It is not legal advice.
Who we are
TradaxLab ("we", "us") is operated as a Belgian company providing educational trading software. For GDPR purposes we are the data controller. Contact: support@tradaxlab.com. Supervisory authority in Belgium: Gegevensbeschermingsautoriteit / Autorité de protection des données.
What we collect
- Account: email, display name (Firebase Authentication)
- Workspace: journal trades, playbooks, analyst usage, settings (Firestore + local browser mirror)
- Billing: subscription tier and Stripe customer ids (we do not store full card numbers)
- Exchange connections: read-only API credentials, encrypted server-side when you connect
- AI inputs: text prompts and optional chart screenshots sent to AI providers via our servers (Gemini by default; OpenAI/Anthropic when you select those models). Signed-in AI support chat also sends message text to Gemini. Server logs omit prompt/image bodies (metadata only).
- Friends / shared journals: display names, invite codes, shared trade notes you choose to publish
- Referrals: invite codes, redeem IP/device fraud signals, bonus credit balances
- Creator Program: profile, platform handles, encrypted payout destinations (PayPal/IBAN/wallet), audit of payout changes, payout requests
- Support tickets: name, email, message, optional chat transcript, page URL, and account id when signed in
- Transactional email: welcome message on signup (when Resend is configured)
- Price alerts: symbols, thresholds, optional alert email and webhook URL (HMAC secret stored server-side; webhooks allowlisted to Discord/Slack HTTPS only)
- Optional analytics (with server-stored consent): page/feature usage, coarse device/browser hints
- Security: signup IP quotas, session revocation metadata, rate-limit counters
Why we process data
- Contract: provide the service you signed up for
- Legitimate interests: security, abuse prevention, product improvement (with analytics consent where required)
- Legal obligations: tax/accounting where applicable
Processors & sharing
We use trusted providers who process data on our instructions. A living inventory of categories, purposes, and retention notes lives in the repository at docs/PROCESSOR_AND_RETENTION_INVENTORY.md (for operators/counsel). Summary:
- Google Firebase / Firestore / App Hosting (auth, database, hosting) — EU region where configured
- Stripe (subscription billing and one-time AI credit packs)
- Google Gemini (default AI chart analysis + authenticated support chat)
- OpenAI (optional Apex chart models when you select them)
- Anthropic (optional Quantum chart models when you select them)
- Resend (transactional email, including price-alert delivery when configured)
- Sentry (error monitoring, when configured)
- Financial Modeling Prep and public market/exchange APIs (quotes, calendars, symbol search)
We do not sell your personal data.
International transfers
Some providers may process data in the United States or other countries. Where required, we rely on appropriate safeguards (e.g. Standard Contractual Clauses offered by vendors).
Retention
- Account / workspace / creator profile: while the account is active
- Analytics: day aggregates trimmed to about 90 days; raw event documents are deleted after 90 days when new events are ingested
- Referral fraud / device signals: deleted with the account when linked by user id; device fingerprint aggregates carry a ~90-day expiry hint when updated
- Rate-limit counters: short-lived hashed keys with a window expiry hint (not keyed by account id)
- Stripe invoices / tax records: as required by law (often 7+ years via Stripe)
- After deletion (Settings → Delete account): we require a recent sign-in and an explicit confirmation phrase. We remove Firebase Auth, workspace (trades, chart analyses), entitlements, alerts, referral mappings, support tickets linked to your uid, exchange connections/fills, analytics we control, social/friend data scoped to your uid, and session-revocation metadata, and we cancel identifiable Stripe subscriptions. Creator payout ledgers are redacted (destinations and profile PII cleared) but amount/status records may be retained for bookkeeping pending a documented retention policy. Stripe Customer objects and invoices remain at Stripe for tax/accounting. Provider backups and third-party copies (email, AI vendors, error monitoring) may persist briefly per those providers' policies.
Security
We use HTTPS, httpOnly session cookies, server-side subscription checks, Firestore security rules that block client plan upgrades, encrypted exchange secrets, and Stripe webhook signature verification. No system is perfectly secure — use strong passwords and read-only exchange keys.
Your rights (GDPR / UK GDPR)
Depending on your location you may have rights to access, rectify, erase, restrict, object, or port your data, and to withdraw consent for optional analytics. In-app: Settings → Data & privacy → Download my data (account metadata package; excludes encrypted secrets and full journal) and Export journal (CSV). Full chat transcripts are not included in the automated package — email support@tradaxlab.com from your account email for assistance. You may lodge a complaint with your supervisory authority.
Account deletion
Delete your account in Settings. This is the primary way to request erasure. You can also email us if you cannot access your account.
Cookies
See our Cookie Policy for details and consent choices.
Children
TradaxLab is for users 18 and older. We do not knowingly collect data from children. If you believe a minor created an account, contact us and we will delete it.
Educational and journaling software—not personalized investment, tax, or legal advice. Past performance does not guarantee future results.

