Privacy Policy
Last updated: February 2026
1. Information We Collect
We collect the following categories of information:
- Account data: Email address, name, and authentication credentials (managed by Clerk).
- Trade data: Risk calculations, trade plans, executions, journal entries, and strategy metadata that you create within StratPilot.
- Usage data: Feature usage patterns, page views, and interaction data to improve the service.
- Payment data: Billing information processed by Stripe. We do not store credit card numbers.
2. How We Use Information
- Provide, maintain, and improve the service
- Process subscriptions and payments
- Generate analytics and behavioral insights from your trade data (visible only to you)
- Send essential service communications
- Comply with legal obligations
We do not sell your personal data. We do not use your trade data for any purpose other than providing the service to you.
3. Third-Party Services
We use the following third-party services to operate:
Clerk
User authentication and account management. Data shared: Email, name, OAuth tokens. Location: USA (Privacy Shield certified).
Privacy policySupabase
Data storage and processing. Data shared: All user content (trades, risk profiles, analytics). Location: USA (AWS regions).
Privacy policyStripe
Subscription billing and payment processing. Data shared: Email, payment information. Location: USA.
Privacy policy4. Data Storage & Security
Your data is stored securely on Supabase (USA (AWS regions)). We use row-level security policies to ensure you can only access your own data. All data is transmitted over encrypted connections (TLS).
5. Data Retention
- Active accounts: Indefinitely (until account deletion)
- Deleted accounts: 30 days (soft delete), then permanent deletion
- Server logs: 30 days
6. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Delete your account and all associated data
- Export your data in a portable format
- Object to processing of your data
We respond to all data requests within 30 days. Contact getstratpilot.app@gmail.com to exercise your rights.
7. Cookies
StratPilot uses only essential cookies required for authentication and session management. We do not use tracking cookies or third-party advertising cookies. You can manage cookie preferences via the consent mechanism on the site.
8. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "last updated" date. Continued use of the service after changes constitutes acceptance.
9. Contact
For privacy-related questions or data requests, contact us at getstratpilot.app@gmail.com.