Privacy Policy
Effective September 25, 2026
This Privacy Policy explains what information DailyTraderOS (the "Service"), provided by [Your Full Legal Name], collects, how it's used, and how it's protected. We built this Service to help traders keep a disciplined journal - not to build an advertising profile - and the data practices below reflect that.
1. Information We Collect
- Account information: your name, email address, and a securely hashed password (we never store your password itself, only a one-way hash of it).
- Trading data you provide or import: trades, positions, account values, and any notes, plans, or reflections you write into the Service, either typed directly, imported from a CSV file you upload, or synced from a brokerage account you connect.
- Broker connection credentials: if you connect a supported broker, the resulting access tokens are encrypted before being stored and are never exposed to your browser or any other user.
- Basic technical data: standard server logs (e.g. IP address, timestamp) generated by normal web traffic, kept only as long as needed for security and troubleshooting.
We do not use advertising trackers, ad pixels, or third-party analytics scripts on the Service.
2. How We Use Your Information
We use your information solely to operate the Service for you: to show your journal, positions, and reports; to sync and import trade data from a broker you've connected; to send you account-related email (such as a password reset link); and to maintain the security and reliability of the Service.
We do not sell your data, and we do not use your trading data to train any model shared with or used by other users.
3. How We Protect Your Information
Connections to the Service are encrypted in transit (HTTPS). Broker access tokens are encrypted at rest, separately from the rest of your data. Your session is stored in an HttpOnly cookie that isn't readable by page scripts. As with any online service, no method of transmission or storage is perfectly secure, but we design the Service to keep your credentials and data protected.
4. Who We Share Data With
We don't sell or rent your personal information. We use a small number of service providers strictly to operate DailyTraderOS on our behalf, under their own confidentiality and security obligations:
- Hosting (Render): runs the application and database.
- Email delivery (Resend): sends account emails, such as password reset links.
- Market pricing data (Alpaca): supplies live prices used to value your open positions - this is a one-way data feed we use to price the market, not a service we send your personal data to.
If you choose to connect a brokerage account (for example, Schwab or Interactive Brokers), you are separately authorizing that broker to share your account data with us, governed by that broker's own authorization flow and terms.
We may also disclose information if required to by law, or to protect the rights, safety, or property of the Service or its users.
5. Data Retention and Deletion
We keep your data for as long as your account is active. You can request deletion of your account and associated data at any time by emailing sumindah@gmail.com; we'll delete it within a reasonable time, except where we need to retain limited records for legal or security purposes.
6. Your Rights
You can access, correct, export, or request deletion of your personal information by contacting sumindah@gmail.com. If you're in a jurisdiction that grants additional statutory rights over your personal data, we'll honor those rights on request.
7. Cookies
The Service uses a single essential cookie to keep you signed in. It isn't used for tracking or advertising, and it's cleared when you log out.
8. Children's Privacy
The Service is not directed to, and is not intended for use by, anyone under 18.
9. Changes to This Policy
We may update this Privacy Policy as the Service evolves. We'll update the effective date above when we do.
10. Contact
Questions about this policy or your data? Reach us at sumindah@gmail.com.