Privacy Policy
Last updated: September 2026
This policy explains what The Pips Project collects, why we collect it, and what you can do about it. It covers our website and the journalling application behind it.
Information we collect
Account information
Your email address, and a display name if you set one. We use Supabase Auth for sign-in via Google or an emailed link, so we never handle or store a password of yours.
Trading data
The trades you import — by MetaTrader sync, by file, or by typing them in — along with the accounts they belong to and anything you write about them. Typically: instrument, direction, size, entry and exit price and time, commission, swap, and your own notes.
Usage and device information
Which pages and features you use, and standard technical details your browser sends — IP address, browser and operating system. We use these to keep the service working and to detect abuse, not to build an advertising profile.
How we use your information
- To run the service: storing your trades, computing your analytics, syncing your data.
- To generate AI analysis of trades you submit for review.
- To send transactional email — receipts, sign-in links, and service notices.
- To investigate abuse, fraud, and security incidents.
We do not sell your trading data. We do not share your individual trading performance with anyone, and we do not use your trades to train third-party models.
MetaTrader connection and your investor password
Automatic sync uses your investor password, which is read-only by design. It lets us read your trade history. It cannot place, modify or close trades, and it cannot move money. Your broker enforces that restriction on their servers — it is not a promise we are making about our own code.
Stored credentials are encrypted at rest, and they are never returned to the browser or included in any response. You can disconnect an account at any time from Settings, which deletes the stored credential.
Data storage and security
- Encrypted in transit with TLS, and at rest by our hosting provider.
- Row-level security in the database, so a query can only ever return the rows belonging to the signed-in user.
- Privileged keys are held server-side only and are never shipped to the browser.
Data retention
We keep your account and trade data while your account is open. If you delete your account, we delete the associated data within 30 days, except where we are required to keep billing records for tax and accounting purposes.
Your rights
- Export your data at any time.
- Correct anything inaccurate, from your account settings.
- Delete your account and the data attached to it.
- Ask us what we hold about you, and why.
If you are in India, the Digital Personal Data Protection Act, 2023 applies to your personal data, and the rights it grants — access, correction, erasure, and grievance redressal — are available to you through the contact route below. If you are in the EEA or UK, the equivalent GDPR rights apply.
Cookies
We use a small number of cookies, almost all of them essential to keeping you signed in. See the Cookie Policy for the detail.
Third-party services
We rely on a handful of processors to run the service: Supabase for authentication, database and storage; Razorpay for payments; and Anthropic for the AI review features. MetaTrader auto-sync runs through a desktop agent on your own computer, so your broker login is used only on your machine. Each processor receives only the data needed for its function.
Children's privacy
The service is not intended for anyone under 18, and we do not knowingly collect data from them.
Changes to this policy
We will update this page when things change, and email account holders before any material change takes effect.
Contact
Questions, requests, or complaints: email privacy@thepipsproject.com.