Privacy Policy

What this trading journal stores about you, why it stores it, and how to get it back or get rid of it.

Last updated 3 September 2026

This document is in force and applies to your use of Traquil. If we change it, we will ask you to accept the new version before it applies to you.

Who is responsible for your data

This app is operated from Sweden by Susanne Zabst, who is the data controller for the purposes of the General Data Protection Regulation (GDPR). You can reach us at privacy@traquil.app about anything in this policy.

Because the app is operated from Sweden and is offered to people in the EU, the GDPR and the Swedish Data Protection Act apply to it.

What we collect

Almost everything the app holds is something you typed into it yourself. There is no hidden collection, no tracking pixels and no advertising network.

Account details, needed to give you a login:

  • Your email address.
  • Your password, stored only as a salted hash by Supabase Auth. Nobody, including us, can read your password.
  • A display name, used to greet you in the app. You choose it at signup and can change it in Settings.

Trading accounts you create inside the app:

  • The account name, its type (live, paper or prop challenge), its starting balance and its currency.

Trade records, which is the bulk of what the app stores:

  • Date, session, market, instrument, direction, setup and higher timeframe bias.
  • Entry time and price, exit time and price, quantity, point value, stop loss, take profit, planned risk in currency and planned risk to reward ratio.
  • Result in R, realised profit and loss, and commission and fees.
  • A trade number and the time the record was created.

Psychology and review entries, which are the reason this app exists and are often the most personal thing in it:

  • Confidence, execution quality and focus, each scored from 1 to 10.
  • The emotions you tag on a trade, whether you followed your plan, the mistakes you tag, and whether your checklist was clean.
  • A grade for the trade, plus free text notes and lessons.
  • Weekly reviews: your best and worst trade of the week, your biggest lesson, your most common mistake, your biggest improvement and your focus for next week.
  • Monthly reviews: your best and worst setup, your most common mistake and your lesson for the month.
  • Daily recaps: how a day went and one thing for the next one, written for any day including the ones you did not trade.
  • Session Prep: the rules and focus you write for a trading day, and what you write about how you are arriving that day. This is your own writing about your state of mind, which makes it the most personal text in the app.
  • Your trading plan, if you write one, and which day you completed a pre-session checklist on.

Your written plan, checklists and setups:

  • Your trading plans and pre-market checklists, including the names you give them.
  • Which setup and confluences you tag on a trade, whether you followed the plan, and your notes on it.
  • A description you write for any of your setups: what it is, when you take it, and the confluences that make it valid, along with which of your checklists and trading plans you attach to it.

Screenshots you choose to upload:

  • Chart images attached to a trade, held in a private storage bucket. They are not public, they are not indexed by search engines, and they are reachable only through short lived signed links issued to you.

Feedback, if you choose to send any:

  • The text of any bug report or problem you submit through Settings, and the page you were on when you sent it. This is a one-way report. We do not reply through the app.

Preferences, so the app behaves the way you expect:

  • Your timezone, used to work out which trading session a trade falls into.
  • Your custom dropdown options for setups, mistakes, emotions, sessions, markets, higher timeframe bias and grades. A default set is created for you at signup and you can add your own.

Technical records created automatically:

  • A session cookie that keeps you logged in. It is required for the app to work and is not used to track you anywhere else.
  • Standard server logs kept by our hosting and database providers, which include IP addresses and request times and exist for security and reliability.
  • If you say yes to the analytics prompt, product-usage events: which pages you visit, and actions like logging a trade. Never trade content, notes or screenshots. These are tied to a random identifier for your browser, never to your account, your name or your email, so we cannot look up what any particular person did. It is optional, off by default until you accept, and you can turn it off again anytime in Settings. See "Who else touches your data" below.

What we do not collect

  • No payment details. The app takes no payments.
  • No broker credentials, API keys or connections to any brokerage account.
  • No advertising, and no third party trackers beyond the optional analytics described below.
  • No contacts, location or device identifiers beyond what is in a normal web server log.

Why we collect it, and our legal basis

We use your data to run the journal for you and for nothing else. We do not sell it, rent it, share it for marketing, or use it to train machine learning models.

  • To provide the service you asked for, which covers storing your trades, computing your statistics and showing you your own history. Legal basis: performance of a contract, GDPR Article 6(1)(b).
  • To keep accounts secure and prevent abuse, which covers server logs and authentication records. Legal basis: legitimate interests, GDPR Article 6(1)(f).
  • To keep the app working, which covers the error reports sent to our monitoring provider when something breaks. Those carry technical detail such as which line of code failed, never your trade content, your notes, your screenshots or your email address. Our interest is a service that stays usable; yours is the same one. Legal basis: legitimate interests, GDPR Article 6(1)(f).
  • To meet legal obligations where one applies. Legal basis: GDPR Article 6(1)(c).
  • For the two things you are asked about separately and can switch off at any time in Settings: product analytics, and the AI features. Neither runs unless you say yes. Legal basis: consent, GDPR Article 6(1)(a).

Only an email address and a password are required, because without them there is no account to log in to. Everything else is yours to give or withhold: every trade, note, review, screenshot and preference is something you choose to add, and the app works with any of it left out. The two consent-based purposes above are optional too, and declining them takes nothing else away.

Your trading and psychology entries are not special category data under GDPR Article 9. What you record here is your own state of mind in the context of your performance, which is not data concerning health, sex life, religion, politics, trade union membership, race or biometrics, and none of those is asked for anywhere in the app. We are aware it can still feel deeply personal, since it records how you felt and where you went wrong, so it is protected the same way as everything else here.

Automated analysis of you and what you write

This app exists to find patterns in your own behaviour, so it is worth being plain about what that means under the GDPR. Two different things happen here, and only one of them is optional.

The journal itself computes things about you automatically, for every account: a Quil Score for whether your edge looks real or looks like luck, a reading of how consistently you followed your own plan, a calibration curve setting your stated confidence against your actual results, and a tally of which mistakes keep recurring. Under Article 4(4) that is profiling, because it evaluates aspects of your performance and your behaviour. We say so rather than leave it unsaid, even though it is the ordinary functioning of a trading journal. It is computed from your own entries, it is shown only to you, it is never shared, and because it is the service you signed up for it runs on our contract with you rather than on consent.

The AI features go further, and they are the optional half. If you turn them on, they read what you have written and characterise it in words: how consistently you followed your plan, which mistakes keep coming back, how your results line up against the emotions you recorded. That is profiling too, and it is the reason these features are consent-based. It happens only when you ask for it, by opening a question or pressing Generate. Nothing is analysed in the background or on a schedule, and nothing is sent for analysis at all if you decline or later withdraw in Settings.

For both of them: no decision is taken about you automatically. The output is a number or a paragraph for you to read and disagree with. It does not change your access to anything, set a price, or produce any other legal or similarly significant effect, so the GDPR's rules on automated decision-making in Article 22 do not apply.

All of it is a description of what you logged, not a judgement of you as a trader, and it is only ever as accurate as what you typed.

Who else touches your data

We use a small number of service providers, each acting as a processor on our instructions under GDPR Article 28. None of them is permitted to use your data for its own purposes.

  • Supabase, which provides the database, authentication and file storage.
  • Vercel, which hosts and serves the application.
  • Sentry, which receives error reports (technical details like a stack trace, never trade content, screenshot URLs or your email address) so we can fix problems. EU-based processing.
  • PostHog, which receives the product-usage events described above, tied to a random per-browser identifier rather than to your account, and only if you say yes to the analytics prompt. EU-based processing. Say no, or change your mind later in Settings, and nothing is sent.
  • Resend, which sends transactional email on our behalf: account confirmation, password reset, and the text of anything you submit through "Report a problem". EU-based processing (eu-west-1).
  • Anthropic, which provides the AI features. It only ever receives data when you personally ask a question or press Generate: nothing is sent in the background, on a schedule, or at all if you never use these features. What it receives depends on which feature you use. A weekly or monthly review sends every trade in that period: their fields, your written notes, lessons and session recaps on them, the emotion and mistake tags, and the reflections you wrote for that period. Asking a question in Ask sends the same for the date range shown on that page, which is the last 180 days unless you change it. It is never sent anything about any other user, and it is never sent your email address.

On the AI provider specifically, because it is the one people ask about: Anthropic's commercial terms state that it may not train its models on data sent through its API, and its published retention policy is that API inputs and outputs are deleted from its systems within 30 days (longer only where it is investigating a policy violation or where the law requires it). Both statements were checked against Anthropic's own published terms and policy on 21 August 2026, and both should be re-checked before this feature is turned on for anyone.

Where your data sits: the database, authentication and file storage are hosted in the European Union (Supabase, eu-central-1). Error reports are processed in Germany (Sentry), and analytics and transactional email in the European Union (PostHog; Resend, eu-west-1).

Two providers process outside the European Economic Area. Anthropic, which powers the AI features, is a United States company, so anything those features send is transferred to the United States, and only if you turn them on and use them. That transfer relies on the European Commission's Standard Contractual Clauses, under the data processing agreement built into Anthropic's commercial terms.

Vercel, which serves the application, is the second one, and we would rather be exact about it than tidy. It receives no trade data at all: what reaches it is the IP address and request metadata in an ordinary server log line. It serves each visitor from the edge location nearest to them, so a request from the EU is normally handled inside the EEA. Vercel publishes the same Standard Contractual Clauses, but they apply to accounts on its paid plans and ours is not yet one, so for those log lines we cannot currently claim that safeguard. We are changing the plan. We would rather tell you this than let a sentence stand that sounds better than the truth.

If you want to see the safeguards rather than take our word for them, email us and we will send you a copy of the clauses each provider relies on.

How your data is protected

  • Every table in the database has row level security enabled, with policies that scope every read and write to the account owner. One user cannot read another user's rows even if the application code were wrong.
  • The screenshot bucket is private, and each file lives under a folder keyed to its owner. Access is granted only through signed links with a short lifetime.
  • All traffic is served over HTTPS with HSTS, and the app sets a content security policy along with other protective headers.
  • Passwords are hashed by Supabase Auth and are never stored or transmitted in readable form.
  • A minimum password length is enforced on the server rather than only in the browser.

How long we keep it

Your data stays for as long as your account exists. There is no automatic expiry, because a trading journal is only useful if the history stays intact.

Server logs are the exception, and they are not really yours in the same sense: our hosting and database providers keep short operational logs containing IP addresses and request metadata. Those roll off on the providers' own schedules, measured in days rather than years. We keep no logs of our own, we do not export copies, and we use them only to keep the service running and to investigate abuse.

When you delete your account, everything goes with it: your trading accounts and trades, your daily, weekly and monthly reviews, your Session Prep notes, your trading plans and checklists, what you have written about your setups, your settings and custom options, and your uploaded screenshots. The deletion is immediate and there is no recovery period, no holding queue and no soft-delete.

We keep no backups of our own. Where a provider holds an operational copy as part of running its own infrastructure, it ages out on that provider's schedule and we cannot reach into it or restore from it, which also means we cannot bring a deleted account back.

One thing we cannot make immediate, said plainly because the two sentences above and below it are in tension: anything the AI features already sent to Anthropic is deleted on Anthropic's schedule (within 30 days) and not at the moment you press delete. We have no way to pull it back sooner. If you never used those features, nothing was ever sent.

You can download a complete, machine readable copy of everything this app stores about you at any time, from Settings, and you do not need to ask us or wait for a reply.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct anything inaccurate. Most of it you can edit directly in the app.
  • Erase your data, which you can do yourself from Settings at any time.
  • Restrict or object to processing.
  • Receive your data in a portable, machine readable format.
  • Withdraw consent where processing relies on consent.

Two of these deserve saying separately rather than as one line in a list.

You have the right to object. Where we rely on legitimate interests, which is the security logging and the error monitoring described above, you can object to that processing at any time on grounds relating to your particular situation. Tell us and we will stop unless we have compelling legitimate grounds that override your interests, and we will explain which if we think we do.

Withdrawing consent is not retroactive, and that is not a catch. You can withdraw at any time and everything stops from that moment. What withdrawal cannot do is unmake processing that already lawfully happened while the consent was in place, which is what Article 7(3) means when it says withdrawal does not affect the lawfulness of processing before it. It is also why the record of when you gave consent survives when you take it back.

To exercise a right that the app does not already let you perform yourself, email privacy@traquil.app. We will respond within one month, as the GDPR requires. If a request is unusually complex we may extend that by up to two further months, which Article 12(3) allows, and we will tell you within the first month if that happens and why.

If you think we have handled your data badly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or to the supervisory authority in the EU country where you live.

Age

You need to be at least 16 to hold an account. We do not knowingly collect data from anyone younger. If you believe a child below that age has an account, contact us and we will remove it.

Changes to this policy

If this policy changes in a way that affects you, we will update the date at the top and ask you to accept the new version the next time you open the app. You see the change before it applies to you, not after. Corrections that do not change what we do with your data (a typo, a clearer sentence) do not trigger that prompt.

Contact

Questions about this policy or about your data go to privacy@traquil.app.