AI Trade JournalCreate account

Privacy notice

Your journal evidence stays attached to your account

This notice describes the data the beta needs, why it is used, and the controls that exist today.

Effective 18 August 2026 · Free beta

Data the service handles

  • Account details: email address, verification state, and secure session records.
  • Journal evidence: chart links or images, trade fields, timestamps, labels, playbooks, outcomes, reports, and your corrections.
  • Optional AI-review context: only the evidence needed for a review you request.
  • Support requests: the message, contact address, page context, and status history you submit.
  • Operational records: security, delivery, and error events needed to run and protect the service.
  • Private product events: allowlisted workflow milestones used to evaluate activation and evidence completion, without symbols, prices, notes, screenshots, support text, credentials, or OAuth material.

How it is used

Data is used to authenticate you, store and retrieve your private journal, extract editable chart facts, compare evidence with rules you saved, generate reports, recover from failures, and answer support requests. AI Trade Journal does not sell journal data or use it for advertising.

Optional ChatGPT connection

Your journal account and ChatGPT authorisation are separate. Connecting ChatGPT is optional. When you request an AI review, the relevant structured evidence is sent through the connected companion for that request. If the connection is unavailable, deterministic extraction and rules remain available and the interface states the degraded mode.

Storage and access

The production service runs on Cloudflare. Account and journal records are stored in D1; private chart evidence is stored in private R2 buckets. Access is enforced by authenticated, user-scoped application queries and ownership constraints. This is not a claim that D1 provides PostgreSQL row-level security.

Retention and deletion

Journal data is retained while the beta account remains active. Private product events expire after 90 days and can be disabled and deleted from the signed-in export page. Self-service account deletion is not available yet. Request account deletion through the authenticated support form; identity and scope must be verified before removal. Backup and legal-retention details require formal operator policy before this beta notice can become a final legal privacy policy.

Questions and changes

Use the authenticated support form for privacy questions or access requests. Material changes will be published here with a new effective date. This beta notice is an operational disclosure and still requires review against the operator's legal identity, jurisdiction, and user locations.