Privacy Policy

What is stored, why it is allowed to be stored, who else can touch it, and exactly how to get it back or have it deleted.

Last updated 24 September 2026

The short version
Your trades are yours. They are stored so the app can show them back to you and are used for nothing else: not training, not analytics, not resale. There is no tracking of any kind on this site, which is why you are not being asked to accept cookies. Everything you have logged can be exported or deleted by you, from Settings, without asking anyone.

01Who is responsible for your data

The controller (the party that decides what is stored and why) is NQ Journal, operating as NQ Journal from the Netherlands. Full contact and registration details are at the bottom of this page.

For anything about your data, write to nqtradingjournal@gmail.com. That address reaches a person, not a ticketing system.

02What is stored

Account
Your email address, a hash of your password (the password itself is never stored or visible), the time you signed up, when you accepted the terms and which version, and whether your subscription is active.
Your journal
Everything you type into it: trades, entry and exit prices, sizes, sessions, confluences, setup grades, your written notes, your psychology answers and your trading plan.
Screenshots
Chart images you attach to a trade. Stored in a private bucket and only ever served to you through a short-lived signed link.
Preferences
Theme, time format, your custom dropdown lists and which account filter you last used.
Payment
Stripe holds your card. This app never receives or stores card details. What it keeps is a Stripe customer reference and whether the subscription is active.
Support
If you send feedback or a bug report: the message, any screenshots you attach, your email address so a reply can reach you, and the page, window size, browser, theme, language and time zone the report was sent from, so the problem can be reproduced. That list is the whole of it: no IP address, no location, nothing that was not already in the request headers of every page you load.
Account notices
If we ever have to write to you about how the account is being used, the date and the reason are kept on the account, so a second notice can refer to the first.
Server logs
Vercel records requests for a short window for security and debugging, and Supabase keeps a record of each sign-in for account security. Both include an IP address. They are not linked to your journal and are not read unless something is being investigated.

There is no analytics package, no advertising pixel, no session recorder and no third-party script of any kind on this site. Nothing measures which pages you visit or how long you stay.

03Why it is stored, and on what legal basis

Under the AVG every purpose needs a legal ground. These are the only purposes:

Running the journal
Storing your trades and computing your statistics is the service you are paying for. Basis: performance of a contract (art. 6(1)(b)).
Your account & billing
Signing you in, taking payment, telling you when a payment fails. Basis: performance of a contract.
Invoices & accounts
Dutch tax law requires business records to be kept for seven years. Basis: legal obligation (art. 6(1)(c)).
Keeping the service up
Rate limiting, a bot check on the sign-in forms, error logs, and automated checks on how an account uses the service: how many entries it logs and how fast, how much storage it holds, whether it still signs in. These checks count; they never read what you wrote. A person looks at what is in a journal only if you ask for help with it yourself, or if a report points to something unlawful. Basis: legitimate interest (art. 6(1)(f)), the interest being a service that stays online, is not broken into, and is not used as free storage or shared between people who did not pay for it.
Answering you
Replying to a support message you sent. Basis: legitimate interest.

Your journal is never used for anything else. It is not analysed in aggregate, not used to train any model, not sold, and not shared with any other user. The statistics you see are computed on demand, from your rows, for your screen.

04Who else touches it

Running a web application means a handful of suppliers process data on this service’s instructions. These are all of them:

Supabase
Database, login and file storage. Your journal lives here. Hosted in the EU.
Vercel
Hosting and the CDN that serves the pages. Vercel Inc. is US-based; transfers rely on the EU–US Data Privacy Framework and standard contractual clauses.
Stripe
Payments and invoicing, contracted through Stripe Payments Europe Ltd. in Ireland. They receive your email and billing country; this service never receives your card number.
Resend / Google
Outbound email: confirmation links, password resets, billing notices. Whichever is configured receives your email address and the message.
Cloudflare
The bot check (Turnstile) on the sign-in, sign-up and password-reset forms. For that check only, it sees your IP address and technical details of your browser, never your password or your journal. Cloudflare Inc. is US-based; transfers rely on the EU–US Data Privacy Framework and standard contractual clauses.

Each of these is a processor under a data processing agreement, meaning they may only do what this service asks and may not use your data for their own purposes. Nobody else receives anything, and nothing is ever sold.

05Cookies

This site uses cookies for two things and no third thing:

  • Staying signed in. A session cookie set by Supabase when you log in. Without it there is no way to know it is you.
  • Remembering a preference. Which account filter you last chose, plus your theme and dropdown lists, held in your browser’s local storage.

Both are strictly necessary or purely functional, which is precisely the category the ePrivacy rules exempt from consent, so there is no cookie banner here, and that is not an oversight. Nothing on this site tracks you, profiles you, or follows you anywhere else. If tracking is ever added, you will be asked first, properly, with a real refuse button.

06How long it is kept

Your journal
For as long as your account exists. Delete it yourself from Settings at any moment and it is gone immediately, safety copies included, not queued or archived.
Safety copies
So a mistake can be undone, whether yours or the site’s: a trade you delete or edit is kept as it was for 30 days, and you can put it back from Settings. A copy of every journal and its settings is also made each night and kept for 7 days. Both stay in the same EU storage as the journal itself, readable only by the server, and both are removed the moment you delete everything or your account is closed.
Your account
Until you ask for it to be closed. Ask by email and it is removed within 30 days: journal, screenshots, settings, safety copies and support messages together. A running subscription is cancelled first, so nothing is charged after.
Cancelled subscription
Your data stays where it is after you cancel, so returning does not mean starting over. If you would rather it did not, delete it before you go.
Inactive account
An account with no subscription that nobody has signed into for two years is closed and deleted. You are emailed a month before; signing in once keeps it.
Invoices
Seven years. This is not a choice: the Belastingdienst requires it, and it overrides a deletion request for those specific records.
Support messages
Up to two years after the last message in the conversation, so a follow-up has context, then deleted automatically. Sooner if your account is closed.
Changes made to your account
Twelve months. When access is given or taken away, a notice is sent or two-step verification is reset from the admin console, a record says what was done and when, never what you wrote. It is how every such change can be accounted for.
Server logs
Kept briefly by Vercel, then rotated out.
Rate-limit counters
A day at most. They count requests per IP address or account to stop abuse, and hold a one-way hash of either, never the address itself.

07What you can demand, and how

The AVG gives you the following rights over your own data. All of them are free.

  • Access: a copy of everything held about you.
  • Rectification: anything wrong corrected.
  • Erasure: your account and its contents deleted.
  • Portability: your journal in a machine-readable file you can take elsewhere.
  • Restriction and objection: processing paused, or an objection to anything relying on legitimate interest.

Two of these need nobody’s cooperation: Settings exports your journal to CSV and deletes everything you have logged, on the spot. For the rest, email nqtradingjournal@gmail.com. The law allows one month to answer; the aim here is a couple of working days.

If the answer is unsatisfactory, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in your own EU country.

08Security

What is actually in place, rather than a promise of “industry standards”:

  • Everything travels over HTTPS, forced by HSTS, and is encrypted at rest by the database provider.
  • Every database query is scoped to your user id, and row-level security enforces that at the database, not just in application code.
  • Chart screenshots sit in a private bucket. They are never publicly addressable; the app mints a signed link that expires.
  • Passwords are hashed by Supabase Auth. Nobody, including the operator, can read yours.
  • Two-step verification with an authenticator app is there for you to switch on, and the operator’s own account cannot reach the admin tools without it.
  • You get an email whenever your password changes or an authenticator is added to or removed from your account, whoever made the change and however.
  • A strict Content Security Policy blocks third-party scripts (the one exception is Cloudflare’s bot check on the sign-in forms), and the site refuses to be embedded in a frame.
  • Sign-up, sign-in and password-reset are rate limited and sit behind a bot check, to blunt credential stuffing.

No system is perfect. If you find a hole, mail nqtradingjournal@gmail.com and describe it. Reports are welcomed, not prosecuted, as long as you do not use it against another user’s data.

09If something leaks

A data breach that puts your rights at risk is reported to the Autoriteit Persoonsgegevens within 72 hours of discovery, as the law requires. If the risk to you is high, you get told directly, by email, in plain language: what happened, what was exposed and what to do about it. You will not learn about it from a footnote.

10Automated decisions and profiling

The app scores your trades, ranks your setups and flags behavioural patterns. That is statistics on your own history, shown only to you, and it produces no decision with a legal or similarly significant effect. Nothing about you is profiled for anyone else, and no model is trained on your journal.

11Age

This service is for adults. You must be 18 or older to hold an account. No data is knowingly collected from children; if a child’s account is discovered it is deleted.

12Changes to this policy

When this changes materially (a new supplier, a new purpose) you will be emailed before it takes effect, and the date at the top will move. Small corrections are made quietly. Old versions are available on request.

This policy sits alongside the Terms and the 14-day right of withdrawal.

Seller
NQ Journal
Netherlands