Last updated: September 2026

Privacy Policy

Your trading data says more about you than most things you put online. This policy says exactly what is collected, where it goes, and what you can take back.

What we collect

  • Account: your email address, and the name and profile picture Google returns if you sign in with Google.
  • What you enter: trades, notes, mistakes, missed setups, goals, your written trading plan, your personal rules, and the screenshots you upload.
  • What the app derives from it: statistics, behavioural signals and your Edge Score. These are computed, not collected.
  • Operational data: the technical minimum needed to serve the app and keep it secure.

What we do not collect

  • No broker credentials, no API key to a broker - TradeVault has no broker connection at all.
  • No card number. Stripe and Coinbase Commerce handle payment; the card never reaches our servers.
  • No advertising identifier, no third-party tracking pixel, no behavioural advertising profile.

Google Sign-In

If you sign in with Google, we request your email address and basic profile only, to create and authenticate your account. We never access your Gmail, your contacts, your files or any other Google data. Google is set to always show the account chooser, so you decide which account is used each time.

Where your data lives

Your data is stored in a Supabase (PostgreSQL) project hosted in the European Union, and your uploaded screenshots in the storage of that same project. Every table is protected by row-level security: a query can only ever return rows belonging to the signed-in account. The application is served by Vercel. The site is reachable at tradevault.be.

Jarvis and the AI provider

When you ask Jarvis a question, the data needed to answer it is sent to an AI provider for processing: trade dates, symbols, P&L, strategies, mistake tags, your behavioural signals, your rules and your trade notes. Your screenshots and your credentials are never sent.

  • This only happens when you actively ask. Nothing is sent in the background.
  • The provider is set by configuration; Gemini is the default. If it is unavailable, the request falls back to the next configured provider, which may be Anthropic, Groq, OpenRouter or another OpenAI-compatible service. The provider processes the request to produce the answer.
  • Jarvis also has a fully local mode that uses no provider at all: when none is configured, or when the call fails, the answer is built on this server from the same data.
  • If you would rather share none of it, do not use Jarvis. Every other feature keeps working.

Emails and notifications

We send account emails (welcome, end of trial, and a reminder if you leave mid-trial) and, if you generate them, your monthly reports. Push notifications are strictly opt-in, asked for during onboarding, and can be revoked in your browser at any time; refusing them changes nothing else in the app.

Who else sees it

We do not sell your data and we do not share it for advertising. It is processed only by the providers the service needs to run: Supabase for storage and authentication, Vercel for hosting, the AI provider above when you use Jarvis, Stripe or Coinbase Commerce when you pay, and the email provider for the messages listed above.

What you can do about it

  • Export: your trades can be downloaded as CSV at any time, from the app.
  • Delete a part: any trade, missed setup, note or screenshot can be deleted individually.
  • Delete everything: deleting your account removes your data, your uploaded files and your authentication record.
  • Ask: write to us at the address below for anything the app does not let you do yourself.

Changes

If this policy changes in a way that affects what is collected or where it goes, we will say so before the change takes effect.

Contact

Questions about this policy: tradevault@outlook.fr