1. TL;DR
We collect the minimum data needed to run your trading journal, AI coach, and broker connections. We do not sell your data. We do not train anyone's AI model on your trades, journal entries, or personal information. You can export your account data or delete your account on demand. We keep only the limited records described below when billing, accounting, fraud-prevention, or legal obligations require it.
2. Who we are
TradeDNA is operated by TradeDNA LLC ("TradeDNA," "we," "us"). Our product is a trading journal, AI coaching tool, and market intelligence platform for self-directed retail and prop-firm traders.
3. What we collect
Account data (you give us)
- Email address
- Password (hashed, never stored in clear text)
- Username (your public handle)
- Display name (optional)
- Trading experience + attribution (onboarding)
Trading data (you give us or your broker gives us via your connection)
- Trades, fills, orders, and account balances
- Broker account credentials, encrypted at rest with a key we manage
- Journal entries (sleep, stress, focus, pre/post-session notes, mood tags)
- Trading plan rules and risk limits
Health and wearable data (optional, only if you connect one)
- Daily sleep and stress scores from a wearable you choose to connect, such as Whoop or Oura
- If you connect Apple Health or Health Connect, bounded daily aggregates can include sleep duration, a daily median heart-rate-variability value, and a daily resting-heart-rate value. Individual samples stay on your device
- We use normalized sleep and stress context in your Journal, daily risk score, performance analysis, and Helix. Raw health values are not sent to Helix or used for advertising
- While connected, Apple Health or Health Connect refreshes during setup, app launch, and foreground return. Disconnect stops future syncing and keeps that provider's imported history in your Journal. System health permissions remain under your control in device settings. Prior Helix conversation text remains until you delete the conversation or your account
Product usage data (we measure)
- Pageviews, feature clicks, session duration
- Device, browser, and coarse geographic location (country + region only)
- Before Registration, first-touch and latest non-direct acquisition context: source, medium, campaign fields, recognized advertising click identifiers, local landing path, referrer host, anonymous analytics identifier, and timestamps
- After account creation, lifecycle events tied to your internal account identifier, such as Registration, onboarding, checkout, access, first product value, and trial conversion. These events do not include your email, a full referrer URL, or arbitrary query strings
- Error reports when the app crashes
Affiliate and ambassador program data
- A protected digest and masked hint of an invited partner's email, invitation status, and expiry
- Affiliate application and partner identifiers used to verify the invitation and prevent duplicate ownership
- Ambassador appointment, managed-partner relationship, customer-count totals, compensation records, disclosure training, and promotion evidence
Purchase and subscription data
- The channel where you purchased, the plan and billing period, subscription status, renewal dates, and cancellation status
- Purchase and subscription identifiers, gross amount, currency, refund or revocation status, and a pseudonymous account token used to match an App Store purchase to your TradeDNA account
- We use this information to grant access, restore purchases, prevent duplicate subscriptions, handle refunds, and keep required financial records
What we do NOT collect
- Your broker password in plain text; we use read-only or token-based connections wherever the broker supports it
- Credit card numbers; payment credentials stay with the channel that processes your purchase
- Full-session replay inside the authenticated TradeDNA product. On the TXD acquisition site, we record a bounded, masked journey from the landing page through qualification and stop before product use
- Individual health samples, workouts, steps, activity, continuous heart-rate series, health-record data, or health data for advertising
- Microphone, camera, or location beyond country/region
4. How we use your data
- To run the product. Display your trades, compute P&L, score your rule compliance, overlay your data on market replays, and keep your paid access in sync across the app and website.
- To power the AI coach. Your trades and journal are sent to our AI provider at inference time so the coach can give grounded feedback. Our agreement with them does not allow training models on this data. Your data is not used to improve any foundation model.
- To improve the product. Product usage, acquisition context, account lifecycle events, and the bounded TXD acquisition replay help us understand which site paths and features lead to successful onboarding and sustained use. The replay masks form and payment regions and stops before authenticated product activity.
- To run the affiliate and ambassador programs. Verify invitations, match approved applications, prevent conflicting ownership, calculate customer-based compensation, review disclosures, and keep required financial and compliance records.
- To communicate with you. Transactional emails (confirmations, password resets), product announcements (you can opt out), and coaching summaries you've opted into.
- To comply with law. If we get a valid subpoena, we'll comply and notify you unless legally prohibited.
5. Who we share data with
We share data only with the third-party processors we need to run the service. These cover cloud hosting and database storage, website and App Store payment processing, AI inference, transactional email, product analytics, error monitoring, and licensed market-data providers. Each is contractually bound to protect your data and to use it only to provide their service to us.
The bounded acquisition context, lifecycle events, and masked TXD acquisition replay described above may be processed by our analytics processors solely to provide measurement services to us. Only authorized team members can access the TXD acquisition recordings, and they do not receive access to authenticated product analytics.
We do not sell your data or share it with data brokers. The TXD acquisition site uses advertising measurement tags that can send page and conversion signals to the advertising platforms running our campaigns. We do not send those platforms your TradeDNA product activity, trades, journal, payment credentials, qualification answers, or customer identity through the replay system.
If you sign up through a referral link, the partner who referred you can see your name and subscription status (for example, on trial or subscribed) so they can track their referrals. They never see your email, trades, journal, or any other data.
6. Data retention
- Active account data: retained while your account is active.
- After deletion: we wipe your trades, journal, plan, and account within 30 days of your deletion request. Backups roll off within 60 days.
- Purchase records after deletion: if an App Store subscription is still active, we retain a pseudonymous ownership and lifecycle record so billing events and Restore Purchases continue to reach the right subscription. We retain minimum purchase and transaction records while the subscription remains active and generally for up to seven years after the last related transaction for accounting, refunds, fraud prevention, and legal obligations. These retained records do not include your email, trades, journal, or broker connections.
- Partner invitations: the raw email is used only to deliver the invitation. Unmatched invitation records keep only the protected digest and masked hint and are removed after the documented invitation-retention window. Accepted appointments, relationship history, and compensation records are retained as needed for contracts, accounting, fraud prevention, disputes, and legal obligations.
- Pre-registration acquisition cookie: expires no later than 30 days after your first qualifying main-site visit. We clear it after its bounded fields are attached to your account or when you sign out.
- Account-bound acquisition record: retained while your account is active and deleted with your account. It is available when you request a complete copy of your account data and is separate from the standard trading CSV + JSON export.
- Native-health imports: retained while your TradeDNA account is active and deleted with your account. Disconnect stops future syncing and keeps that provider's imported sleep and stress history in your Journal.
- TXD acquisition recordings: retained by the replay processor for 30 days. Masked content is not uploaded, and authenticated TradeDNA product activity is outside this recording boundary.
- Aggregate analytics: retained indefinitely in de-identified form.
- Legal holds: if we're under subpoena, retention may extend as required.
7. Your rights
Regardless of where you live, you can:
- Access everything we have on you - request an export anytime from Settings → Data & Privacy.
- Delete your account - one-click from Settings. Account content is removed within 30 days, subject only to the limited retention described above. Deleting your TradeDNA account does not cancel an App Store subscription.
- Disconnect native health to stop future syncing while keeping that provider's imported sleep and stress history in your Journal. System health permissions remain under your control in device settings.
- Correct inaccurate data - edit in-app or email us.
- Port your data - CSV + JSON export of every trade, journal entry, and plan rule.
- Opt out of non-essential emails - every marketing email has an unsubscribe link.
If you're in the EEA, UK, or California, you additionally have the rights granted by GDPR, UK-GDPR, and CCPA. Our US entity acts as the controller of your data.
8. Security
Broker credentials are encrypted at rest with a key held separately from the database. Passwords are hashed. Data in transit is encrypted with TLS. Our production environment enforces least-privilege access and short-lived credentials, and we monitor for errors so we can see and respond to incidents fast.
We'll tell you about a breach affecting your account data within 72 hours of confirming it, and sooner where we can.
Where GDPR applies, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to create a risk to people's rights and freedoms.
We will notify affected people without undue delay when the breach is likely to create a high risk to their rights and freedoms, subject to the exceptions allowed by law.
9. Cookies & tracking
We use first-party cookies (your session and CSRF tokens) to run the product. Our analytics sets a first-party cookie to recognize your anonymous device across pageviews. A separate first-party acquisition handoff cookie keeps only the bounded fields listed above for no more than 30 days from your first qualifying main-site visit, so we can connect that visit to Registration and measure the customer journey. We clear that handoff after it is attached to your account or when you sign out. On the TXD acquisition site, a replay processor may use its measurement cookie where permitted, and we keep approved campaign labels in browser session storage for up to 24 hours. The TXD site also uses advertising measurement tags for page and conversion signals. Form values, payment regions, qualification answers, checkout credentials, and authenticated product activity are excluded or masked as described above.
10. Kids
TradeDNA is not intended for users under 18. If we learn we've collected data from a minor, we'll delete it.
11. Changes to this policy
If we make material changes, we'll email all active users at least 14 days before the changes take effect. Minor wording fixes will be rolled out silently, but the "last updated" date at the top will always be current.