Privacy Policy
Last updated: August 26, 2026
1. Introduction
TradeGuardX ("we", "our", or "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, web application, server-side risk engine, and browser extension. Please read this policy carefully.
2. Information We Collect
We collect the following types of information:
- Account information: Email address and authentication credentials when you create an account. Authentication is handled by Supabase; we do not store your password directly. If you sign in with Google, we receive your basic Google profile (name and email) via that sign-in.
- Trading account metadata: Display name, exchange or prop firm identifier, equity mode, starting balance, current balance, account currency, and timezone for the trading accounts you add.
- Exchange API credentials: For crypto exchange accounts (e.g. Delta Exchange), the API key and secret you provide so the kill switch can cancel orders and close positions on your behalf. These are encrypted at rest using AWS KMS and used only to enforce your rules. Delta API keys carry Read and Trade permissions only and can never withdraw funds; we never receive your exchange login password or 2FA codes.
- Trade events: Open, modify, and close events for your trades — symbol, side, quantity, entry/exit prices, stop loss, take profit, P&L, and timestamps. For crypto exchange accounts these are received server-side via your exchange API connection; for prop-firm accounts they are captured by the browser extension on supported broker tabs.
- Risk rule configuration: The risk rules you configure (daily loss limits, per-trade risk, hedging prevention, max trades per day, cooldowns, etc.) and their parameters.
- Pairing and session tokens: When you pair the browser extension with your account, we issue a session token that the extension stores in your browser's local storage and sends to our API as proof of authorization.
- Subscription and payment information: Subscription tier and billing identifiers. Payment card details are processed by Dodo Payments and never stored on our servers.
- Notification preferences: If you enable alerts, the email address or Telegram chat you connect so we can send trade and breach notifications.
- Technical and usage data: Browser type, device type, extension version, and website usage analytics described in the next section.
3. Analytics, Cookies & Marketing Attribution
When you visit our website we collect usage analytics to understand traffic and improve the product. This includes:
- The pages you view and the order you view them in, the website that referred you, your device type, and approximate country.
- A first-party visitor identifier and marketing attribution (including UTM campaign tags such as utm_source and utm_campaign) stored in your browser's local storage. If you create an account, the marketing source that first brought you is saved to your profile so we can measure which channels bring users.
- Your IP address is used only to derive an approximate country and a salted, one-way hash that lets us count distinct networks. We do not store your raw IP address.
- For signed-in users, product events such as sign-up, login, adding an account, and starting checkout — so we can see where new users get stuck.
We use Vercel Web Analytics (a privacy-focused, cookie-free provider) and our own first-party analytics service hosted on AWS. We use browser local storage rather than advertising cookies for these identifiers and for essential functions such as keeping you signed in and remembering dismissed banners. Raw analytics events are retained for up to 120 days; aggregated, non-identifying counts are kept longer. We do not use third-party advertising or cross-site tracking cookies.
4. Browser Extension — Data Practices
The TradeGuardX Chrome extension is scoped to a defined list of supported broker domains declared in its manifest. On other websites it does not load its monitoring scripts. On supported broker tabs:
- It reads the page DOM to detect Buy/Sell buttons, open positions, and order parameters needed to evaluate your configured risk rules.
- It does not read or transmit page content unrelated to trading (account numbers, personal messages on the broker site, etc.).
- It only activates on the broker hostname your trading account is currently paired to. On other supported brokers, the extension stays dormant until you pair an account on that broker.
- It stores configuration, the pairing session token, broker selectors, and a small ring-buffer of recent trades in chrome.storage.local. This data lives only in your browser unless you sync it to our backend by trading.
- When you trade, it sends trade events and account snapshots to our API so they appear in your journal and so server-side rules can be evaluated across devices.
5. What the Extension Does and Does Not Do
To set clear expectations about the scope of the browser extension:
- The extension does not execute trades, modify orders, or interact with broker APIs. It only observes trading activity and enforces user-defined rules within the browser interface.
- All executable code used by the extension is bundled within the extension package. No external scripts are dynamically loaded or executed at runtime.
- The extension only runs on explicitly supported broker domains listed in the extension manifest. It does not access all websites or any site outside that list.
6. Error Reporting
To diagnose crashes and bugs, the extension and web application send error reports to Sentry (sentry.io). Reports are stored in Sentry's EU region (ingest.de.sentry.io). Each report includes:
- A JavaScript stack trace of the error.
- The extension version and surface (popup or content script).
- The broker hostname the error occurred on (e.g., my.exness.com), so we can isolate broker-specific regressions.
- Click and navigation breadcrumbs leading up to the error.
We do not send console log breadcrumbs (which can include account IDs, P&L, or session tokens that brokers log to console), and we strip query strings from any URLs in the report. Error reporting only initializes on broker tabs the user has paired; the SDK is loaded but stays inactive on unpaired sites.
7. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve our services
- Evaluate your risk rules against your trades and notify you of violations
- Generate AI insights, narratives, and behavior tags for trades you save to your journal (uses the Anthropic API)
- Process subscription payments and send related communications
- Send you updates, security alerts, and support messages
- Respond to your requests and comply with legal obligations
- Diagnose bugs and crashes via aggregated error reports
- Understand website traffic and measure which marketing channels bring users, using the analytics described in section 3
8. Data Storage, Security & Retention
We implement appropriate technical and organizational measures to protect your data. Account and trade data is stored in our PostgreSQL database hosted on AWS. Exchange API credentials are encrypted at rest using AWS KMS. Website analytics events are stored in AWS DynamoDB and automatically deleted after 120 days; aggregated counts are retained longer. Extension-only data (session token, selector cache, recent-trade buffer) stays in your browser via chrome.storage.local. We do not sell your personal information to third parties.
9. Third-Party Services
TradeGuardX integrates with the following third parties. Their handling of your information is governed by their respective privacy policies:
- Supabase: Authentication and user identity.
- Google: Optional "Sign in with Google" authentication — used only if you choose that sign-in method.
- AWS: Application hosting, database, encrypted credential storage (KMS), and our first-party analytics.
- Vercel: Website hosting and privacy-focused, cookie-free web analytics.
- Dodo Payments: Subscription checkout and payment processing.
- Telegram: Optional trade and breach notifications, if you connect a Telegram account for alerts.
- Sentry (EU region): Crash and error reporting (see section 6).
- Anthropic: AI generation for trade narratives, behavior tags, and journal insights. Only the trade context you choose to analyze is sent.
10. Your Rights
Depending on your location, you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. You can remove an exchange API connection or disconnect the browser extension from your account at any time, which stops further data collection from that source. To delete your account or exercise other rights, contact us using the details below.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance.
12. Contact Us
For questions about this Privacy Policy or our data practices, contact us at:
privacy@tradeguardx.com