Privacy Policy
Effective date: April 5, 2026 · Last updated: April 5, 2026
Privacy questions: contact@traderjack.ai
1. Who we are
TraderJack is an AI-powered trade journal. We help traders log trades, analyze chart setups, and spot patterns in their own trading history. Our service is available at traderjack.ai and via the Telegram bot @Trader_JackBot.
The data controller for your personal data is:
Pip4x LLC d/b/a TraderJack
5900 Balcones Drive, Suite 22050
Austin, TX 78731, United States
2. What we collect and why
2.1 Account and identity data
- Email address - used for account creation, login, and transactional emails (receipts, security notices). We do not use your email for marketing without separate consent.
- Password - stored as a one-way hash. We cannot see your password.
- Telegram user ID and username - collected when you link your Telegram account to use the bot. Used to route bot messages to your account.
- Display name and account preferences - set by you, used to personalize the experience.
2.2 Trade journal data
- Trade entries: instrument, direction, entry and exit prices, dates, P&L, lot size, session labels, tags, and notes
- Conversation history with Jack (your messages and Jack's responses)
- Journal statistics and computed analytics derived from your entries
This data is stored on our servers in the EU (Germany) and is used to provide the core journaling and analysis service.
2.3 Chart screenshots and vision data
- Chart images you submit are sent to OpenAI's API (for Jack's conversational responses) and/or Anthropic's API (for The Read - deep chart analysis via Claude Sonnet)
- Images may contain price data, chart annotations, and any other information visible on-screen at the time of capture
- With your consent, anonymized versions of chart data may be used to improve Jack's pattern recognition over time (see Section 6)
2.4 Payment data
Payments are processed by Stripe, Inc. We do not store your card number, expiry, or CVV. We receive from Stripe: your subscription tier, billing status, and the last 4 digits of your card (for display purposes only). Stripe's privacy policy governs their handling of your payment data.
2.5 Broker API credentials (coming soon)
When broker auto-sync launches, you will be able to connect accounts from OANDA, Interactive Brokers, MetaApi, and cTrader. If you do, we will store your API credentials or OAuth tokens encrypted at rest using AES-256. You can disconnect and permanently delete broker credentials at any time from Settings. We do not share broker credentials with any third party other than the broker itself.
2.6 Analytics
We use Plausible Analytics for page view statistics. Plausible is cookieless, collects no personal data, and is hosted in the EU. The data we see is aggregate only: page views, referrer sources, and country-level traffic. No individual is tracked. No data is shared with advertising networks.
2.7 Technical and session data
- IP address, browser type, device type, operating system
- Timestamps of logins and key actions
- Error logs for debugging (retained 90 days)
3. Legal basis for processing (GDPR)
| Processing activity | Legal basis |
|---|---|
| Providing the TraderJack service (journal, analysis, bot) | Performance of contract (Art. 6(1)(b)) |
| Processing payments, managing subscriptions | Performance of contract (Art. 6(1)(b)) |
| Transactional emails (receipts, security alerts) | Performance of contract (Art. 6(1)(b)) |
| Product update / marketing emails | Consent (Art. 6(1)(a)) - unsubscribe any time |
| Security monitoring, fraud prevention, debugging | Legitimate interest (Art. 6(1)(f)) |
| AI model training using your data (vision consent) | Consent (Art. 6(1)(a)) - see Section 6 |
| Legal compliance and record-keeping | Legal obligation (Art. 6(1)(c)) |
4. Who we share data with
We do not sell your data. We share data only with the following service providers under data processing agreements:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| OpenAI, Inc. | Jack's conversational AI responses; chart screenshot analysis | Your messages to Jack; chart images you submit | United States |
| Anthropic, PBC | The Read - deep chart analysis via Claude Sonnet | Chart images and associated trade context you submit for The Read | United States |
| Stripe, Inc. | Payment processing | Payment details (handled entirely by Stripe) | United States |
| Namecheap / Private Email | Transactional email delivery (SMTP) | Your email address and email content | United States |
| Contabo GmbH | VPS hosting and data storage | All data stored in our database | EU (Germany) |
| Plausible Analytics | Aggregate page view analytics | No personal data - cookieless, aggregate only | EU (Germany) |
| Telegram | Bot messaging platform | Messages you send to @Trader_JackBot | Global (see Telegram's privacy policy) |
We may also disclose data if required by law, court order, or to protect the safety of our users or others.
5. OpenAI and Anthropic: what happens to your chart screenshots
When you use Jack's chat or The Read feature:
- Chart images and message context are sent to OpenAI's API and/or Anthropic's API for processing
- OpenAI retains API inputs for up to 30 days for abuse monitoring; they do not use API inputs to train their models by default
- Anthropic has a similar data handling policy for API customers
- Your data is not used to train OpenAI or Anthropic's general models without a specific data processing agreement
- If your screenshot contains personally identifiable information visible on-screen (e.g., broker usernames, account numbers), that information is included in what is transmitted
For EU/EEA users: data transfers to OpenAI and Anthropic (both US-based) are conducted under Standard Contractual Clauses approved by the European Commission. You can opt out of The Read feature by simply not using it - it is never required to use the core journal.
6. AI training data and vision consent
We may use anonymized versions of your trade data, journal entries, and chart interactions to improve Jack's pattern recognition. Before use: all personal identifiers (name, email, Telegram ID, account number) are stripped. The anonymized data cannot be linked back to you individually.
Your consent choices:
- EU, EEA, and UK users: We will not use your data for AI training unless you explicitly opt in. You can opt in or change your choice at any time in Settings > Privacy > AI Training.
- US users (outside California): Your anonymized data may be used for AI training by default. You can opt out at any time in Settings > Privacy > AI Training.
- California users: See Section 9 for your CPRA rights.
Withdrawing consent stops your data from being used in future training runs. Data already incorporated into trained model weights cannot be retroactively removed - this is technically infeasible and is standard industry practice.
7. Data retention
| Data type | Retention period |
|---|---|
| Active account data and trade journal | For the life of your account |
| Deleted account data | Permanently deleted within 30 days, except where legally required |
| Payment and billing records | 7 years (legal / tax obligation) |
| Security and access logs | 90 days |
| Broker API credentials | Deleted immediately on disconnect or account deletion |
| Chart screenshots (server copy) | Retained for the life of your account; deleted with account |
| Conversation history with Jack | Retained for the life of your account; exportable and deletable in Settings |
8. Your rights (GDPR - EU, EEA, and UK users)
- Access: Request a copy of the personal data we hold about you
- Deletion: Request deletion of your account and associated personal data
- Correction: Request correction of inaccurate or incomplete data
- Portability: Export your trade journal data as CSV or JSON from Settings at any time
- Object: Object to processing based on legitimate interest
- Restrict: Request restriction of processing while a complaint is resolved
- Withdraw consent: At any time, without affecting prior lawful processing
- Lodge a complaint: With your local data protection authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany)
To exercise any right: email contact@traderjack.ai with the subject "Privacy Request". We will respond within 30 days.
9. California users (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of personal information (subject to legal exceptions)
- Opt out of the "sale" or "sharing" of personal information (we do not sell data; analytics use may constitute "sharing" under CPRA)
- Correct inaccurate personal information
- Limit use of sensitive personal information
- Non-discrimination for exercising privacy rights
To opt out of AI training data use or analytics sharing: go to Settings > Privacy, or email contact@traderjack.ai. We will respond within 45 days.
10. Cookies
We use only essential session cookies required for login and security. We do not use advertising, tracking, or third-party analytics cookies. Our analytics provider (Plausible) does not use cookies at all.
11. Children
TraderJack is not intended for users under 18. We do not knowingly collect personal data from minors. If you believe we have collected data from someone under 18, email us immediately and we will delete it.
12. International data transfers
Our primary servers are in the EU (Germany). However, some data is transferred to service providers in the United States (OpenAI, Anthropic, Stripe, Namecheap). All US-bound transfers from the EU/EEA are conducted under Standard Contractual Clauses approved by the European Commission.
13. Changes to this policy
We may update this policy from time to time. For material changes, we will notify you by email at least 14 days before they take effect and post a notice on traderjack.ai. Continued use after the effective date constitutes acceptance of the updated policy.
14. Contact
For any privacy questions, data requests, or complaints:
contact@traderjack.ai
Pip4x LLC d/b/a TraderJack
5900 Balcones Drive, Suite 22050
Austin, TX 78731
Response time: within 30 days for GDPR requests, 45 days for CCPA requests.