Privacy Policy
Last updated: October 2026
1. Data Controller
[FULL NAME]
[STREET ADDRESS]
[POSTAL CODE, CITY], Germany
Email: [EMAIL]
2. Collection and Storage of Personal Data
2.1 When Visiting the Website
When you access our website, your browser automatically sends information to our server. This information is temporarily stored in a log file, including: IP address, date and time of access, name and URL of the retrieved file, referring website, browser used, and operating system.
2.2 Registration and Usage
When registering for Tradoloom, we collect: email address, name (optional), and password (stored as bcrypt hash). During use of the service, we store your trading data, journal entries, voice note transcripts (the recording itself is not stored after conversion to text), and AI-generated analyses.
2.3 Broker Connections
When you connect a broker (e.g., Tradovate), your broker credentials are stored encrypted with AES-256-GCM in our database. Decryption only occurs at the time of synchronization. We have no access to your broker account except to retrieve trade data.
3. Data Sharing
We do not sell your data or share it for advertising purposes. To operate the service, we use the following service providers as processors:
- DigitalOcean, LLC – Hosting of website, app and database (data center in Frankfurt am Main, Germany; company based in the US)
- Cloudflare, Inc. – CDN, DDoS protection and access protection (US-based, EU Standard Contractual Clauses)
- Cloudflare, Inc. (Cloudflare R2) – Storage of uploaded images, e.g. chart screenshots (US-based)
- Mistral AI SAS – Speech recognition of voice notes and automatic journal filling (based in Paris, processing in the EU)
- Anthropic, PBC – AI analyses and AI chat (US-based, EU Standard Contractual Clauses)
- Groq, Inc. – fallback speech recognition only during an outage (US-based, EU Standard Contractual Clauses)
- Brevo SAS – Sending transactional emails, e.g. confirmation codes (based in Paris), once email sending is active
- Stripe – Payment processing once online payment is introduced. Credit card data is processed exclusively by Stripe.
For the AI features, metrics about your trades, journal and emotion fields, notes, transcripts, strategy rules and, where present, chart screenshots are sent to the AI providers listed above – but not your name, email address, account names or broker credentials. According to the providers, the data is not used for training and is only stored briefly for abuse monitoring. You can switch off AI processing in the app settings at any time. Details are in the privacy policy inside the app.
4. Your Rights
Under GDPR, you have the right to:
- Access your stored personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR) – in the app via Settings → Delete account (confirmation by code, deletion after 3 days, cancellable until then)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
To exercise your rights, contact: [EMAIL]
5. Data Security
We use SSL/TLS encryption for all data transfers. Passwords are stored as bcrypt hashes. Broker credentials are encrypted with AES-256-GCM. Regular backups protect your data against loss.
6. Cookies
The app uses a technically necessary session cookie for authentication. If you open the website via a referral link (address with ?ref=CODE), the website stores the referral code for 30 days in the cookie vg_ref in order to pass it on to the app when you register. No analytics or advertising cookies are used.
7. Changes to this Privacy Policy
We reserve the right to update this privacy policy to comply with current legal requirements. The updated policy will apply from your next visit.