1. Who is responsible for your information
Trade Clinic is a trading-record review and educational analysis service at tradeclinic.io, operated by Nathan Black in Missouri, United States. In this policy, “we,” “us” and “our” mean that operator. This policy covers the website, account features, trading workspace and support interactions related to the service.
Trade Clinic is currently a private alpha. Public registration may be closed or limited to invited testers. The same privacy principles apply to alpha accounts. If the operating business changes, we will identify the new operator and update this notice rather than represent an unformed company as the current operator.
For privacy, access, correction or deletion requests, contact [email protected]. This is our temporary privacy contact while domain email is being established. Use the subject “Trade Clinic privacy request” and, when possible, write from the email associated with your account. Do not send your password, reset token, full bank details or identity documents in an initial request.
2. Information we collect
Account information: your email address, authentication identifiers, confirmation status, access role, invitation eligibility and account/session records. Our authentication provider processes your password to verify your identity. We do not include passwords or private confirmation/reset tokens in application diagnostic events. Password-strength scoring happens in your browser; the password is submitted securely when you create, sign into or recover an account.
Trading records: the statement text you select and submit for parsing, its filename and any broker name you supply; execution dates and times, symbols, quantities, prices, sides, currencies, fees, order/execution identifiers and account identifiers present in supported records. We calculate reconstructed trades, performance measures, warnings and reports from those records. Saved executions can include their original source-row text and supporting metadata. A broker export may therefore contain personal information beyond the fields needed for a calculation.
Workspace content: saved imports, selected analysis sessions, trade reviews, notes and generated report snapshots. We also receive feedback and information you choose to send when asking for support or reporting an import problem.
Technical information: requests to the site can produce IP addresses, request paths, timestamps, device/browser information, response codes and security or operational logs at our hosting and network providers. Our import event ledger records account/session identifiers, request identifiers, processing stage, outcome, timing, counts, fingerprint identifiers and general error categories. Its dedicated event fields exclude statement contents, filenames, raw headers, supplied broker labels, prices and credentials. These events can still be linked to an account and are treated as private operational information.
We collect information directly from you, through your use of the service, and from providers operating the service for us. Broker files come from your submission; we do not currently connect to your brokerage account to retrieve records or place trades. Please upload only records you are entitled to use, and remove unnecessary identifiers or unrelated personal material without changing fields needed to interpret your trades.
3. Why we use information
We use customer information only as needed to provide, secure, administer, support and improve Trade Clinic’s trading-review service. This includes creating and verifying accounts, controlling invited access, parsing statements, identifying formats, reconstructing trades, calculating analyses, saving requested records, presenting reports, restoring account access, investigating problems and preventing misuse.
Service improvement includes understanding import failures and improving compatibility, accuracy, usability and reliability. We prefer structural fingerprints, counts, redacted examples and fictional test records where these are sufficient. Access to identifiable records for troubleshooting is limited to an operational need. Customer records are not a resource for unrelated research, advertising or a separate data business.
We do not sell or rent customer personal information, share it for targeted advertising, use trading records to advertise financial products, or publish a customer’s trades. We do not use private customer statements to train general-purpose AI models. The current analysis pipeline performs server-side calculations; it does not send statements to an external AI inference service. A future AI feature or broader data use would need a specific disclosure and any required choice or consent before it begins.
We may also use limited information when necessary to comply with a legal obligation, address a security incident or establish, exercise or defend legal claims. These exceptions do not authorize an unrelated commercial use of trading records.
4. Providers and other disclosures
Supabase provides account authentication and database infrastructure for saved records. Vercel hosts the application and runs server-side processing. Cloudflare provides domain/network routing and security services. These providers necessarily process the information involved in the functions they perform; for example, hosting receives submitted requests and the database stores saved executions. Our use of infrastructure does not mean customer information is public.
Account and support emails are also processed by the mail services involved in delivery and by your own email provider. During the alpha, individually approved account setup or support messages may be handled through our Gmail inbox. A dedicated transactional sender is not yet operational. We will update the provider information when domain mail is established. Never send a full statement or password by email merely to request a reset.
Authorized administrators may access customer records when necessary for account administration, security, requested support or a specific service problem. Access is limited by role and operational need. Hosting, database and email providers can also have authorized infrastructure/support access under their service arrangements. We do not claim that only you can decrypt or access all data.
We may disclose information if required by law or a valid legal process, or when reasonably necessary to investigate abuse, protect safety or defend our rights. We assess the request and limit disclosure to the relevant information where permitted. We may share information at your direction, such as when you send a downloaded report to someone else.
If Trade Clinic undergoes a business transfer, customer information may be transferred only as necessary to continue the service, subject to applicable law, confidentiality protections and the existing privacy commitments. We will give notice of a change of operator or a material change in handling. This clause is not permission to sell statements for unrelated purposes or expose identifiable records to prospective buyers without appropriate safeguards.
External broker links and services have their own privacy notices. Broker names and logos do not imply an affiliation or that a broker receives your Trade Clinic records. GitHub is used for application source and version history; customer statements are not intended to be committed to that repository.
5. Cookies and browser storage
We use necessary session cookies for sign-in and access control. A legacy private-build access cookie may exist on browsers that used earlier alpha access. Account/session cookies are cleared by our logout flow; logging out does not delete saved database records.
The workspace uses browser local storage to remember selected import and analysis session identifiers, scoped to the account. Developer diagnostics can also cache diagnostic results on the device. File previews and password-strength calculations use browser memory. Local storage can remain until cleared by the application or your browser and should be considered when using a shared device.
The current application has no advertising trackers, third-party session-replay integration or customer behavioral-advertising analytics. Necessary provider security and operational logging still occurs. An analytics opt-out marker in our HTML preserves a browser privacy setting; it is not evidence that Google Analytics is installed. If optional tracking is added, we will explain it and provide any legally required consent controls before activation.
You can block cookies or clear browser storage using your browser settings, but sign-in or remembered selections may stop working. Do not rely on a Do Not Track header alone to make an account deletion request. We do not sell or share information for cross-context behavioral advertising, including when a Global Privacy Control signal is present.
6. Retention and deletion
We retain saved trading records, notes, reports and account information while they are needed to provide your account and requested trading history. We retain operational/security records only for service troubleshooting, abuse prevention, accountability or legal needs. Retention depends on the record’s purpose, whether your account is active, outstanding support/security issues and applicable obligations; the alpha does not currently apply one automatic deletion period to every category.
Choosing a file sends its text for processing before you click Save. A preview may create or update an import-session record and its filename. Clicking Save persists execution rows, source-row text and derived records. We do not intentionally keep a separate permanent copy of the complete original uploaded file through the current import pipeline, but saved rows can reproduce substantial parts of that file. Request/network processing and provider logging are distinct from saved trade records.
You may request deletion of an account, an import or associated records by contacting us. Deletion is currently handled through a verified manual request rather than a self-service account-delete button. We will explain the request’s scope, verify the account without asking for its password, and address it under the applicable deadlines. Some records may need to remain for a legal duty, security investigation or claim; we will explain a permitted exception rather than silently treating the request as complete.
Deleted live records may remain in restricted provider backups until the applicable backup cycle expires. We do not promise instant erasure from every backup. If a backup is restored, applicable completed deletion requests must be reapplied. Downloads, emails or copies you share outside Trade Clinic are controlled by you or the recipient and cannot be deleted by us from their systems.
7. How we protect information
We use HTTPS for transmission, verified account sessions, server-side authorization, account ownership rules for trading records and restricted developer/administration access. Privileged database credentials and private processing logic stay on the server. Public visitors do not receive access to trading workspaces simply because they can view the landing page.
We limit diagnostic fields and avoid logging passwords, reset links and complete statements in the import event ledger. Provider operational logs and support material have their own scope, so the reduced event ledger should not be understood as a promise that no other operational records exist. We use service-provider storage/security controls; this is not an end-to-end encrypted vault, and no internet service can guarantee absolute security.
Use a unique password or passphrase and protect your email account. Do not share invitation or recovery links. Report suspected unauthorized access to our privacy contact. We will investigate security incidents and provide notices when required by applicable law.
8. Your choices and privacy requests
You decide whether to create an account, submit a file, save an import or send optional support information. Required account and trade fields are necessary for the corresponding feature; withholding them can prevent that feature from operating. Public landing content can be viewed without uploading trades.
Depending on your location and applicable law, you may have rights to access, correct, delete or receive a portable copy of personal information; restrict or object to certain processing; withdraw consent where processing relies on it; use an authorized agent; and appeal a denied request or complain to a supervisory authority. These rights have legal conditions and exceptions. We will not penalize you for exercising applicable rights, though deleting information necessary for an account can prevent us from continuing that service.
Email [email protected] with the account email and the action you request. We may seek proportionate information to verify ownership or an agent’s authority before disclosing or changing records. We do not ask for your password. We will respond within the deadlines applicable to your request, explain a permitted refusal or extension, and tell you how to challenge it. A request does not need legal terminology to be recognized.
Service and security messages, such as confirmation or recovery messages, are part of administering your account. We do not currently operate a customer marketing-email program. Any future optional marketing will have separate choice/unsubscribe controls and will not change how we use your private trading records.
9. Location and international processing
Trade Clinic is operated from the United States. Our application, database, network and email providers may process information in the United States and other countries where their infrastructure or authorized support operates. A selected database region does not necessarily describe every processing location. Laws and access rights may differ by country.
Where a privacy law applies to our processing, we must satisfy its requirements, including any required safeguards for international transfers. This notice does not claim that a specific certification, transfer agreement or EU/UK representative has already been established. We will verify the applicable arrangements before expanding access where additional requirements apply.
Where the GDPR or a comparable law applies, processing necessary to provide your requested account/analysis is based on performance of that service; security, troubleshooting and limited service improvement are based on our legitimate interests, subject to your rights and interests; legal compliance is based on an applicable obligation; and genuinely optional uses requiring consent will rely on that consent. We do not use a general acceptance of this policy as blanket consent for every use.
10. Automated analysis and sensitive records
Broker detection, import checks, reconstruction and performance calculations are automated. Outputs can be incomplete or inaccurate when a statement is unsupported, inconsistent or missing context. Review the preview and compare findings with your broker records. Trade Clinic does not use these outputs to make employment, credit, insurance or other legally significant eligibility decisions about you.
Trading information can reveal financial activity and is treated as private. We do not request government identifiers, full payment-card details, health records or other unrelated sensitive information for trade analysis. The current alpha does not collect payment-card details or operate a checkout. If paid features are introduced, we will identify the payment processing and additional information before collection.
11. Adults and children
Trade Clinic is intended for adults aged 18 or older and is not directed to children. We do not knowingly solicit children’s personal information. If you believe a child has submitted information, contact us so we can investigate and take appropriate deletion or other protective action. Describing an adult audience is not a claim that an automated age-verification system exists.
12. Policy changes and new uses
This policy is effective October 7, 2026, version 1.0. We will update its date and retain a version record when practices change. For material changes, we will provide a prominent site notice or direct account communication, as appropriate, before the change takes effect.
A revised policy does not automatically authorize a new use of information already collected under an earlier commitment. Before materially expanding a purpose, introducing a new recipient for a different use or changing a required consent-based practice, we will give the relevant disclosure and obtain consent or provide the choice required by applicable law. Until then, existing information remains subject to the commitments under which it was collected.
Our purpose remains to provide a useful, secure trading-review service. If you have a question about a statement in this policy or believe our handling does not match it, contact [email protected].