Last updated: August 30, 2026
ProofTrade (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the ProofTrade platform (“the Service”).
By using the Service, you consent to the data practices described in this policy. If you do not agree, please do not use the Service.
When you create an account through our authentication provider (Clerk), we may receive:
When you connect an exchange account, we collect:
API credentials are encrypted at rest using 256-bit encryption (libsodium) and are only decrypted in memory during active sync operations. We never store credentials in plaintext.
Through your connected exchange API, we automatically sync and store:
We use collected information to:
We do not sell your personal information. We do not use your trading data to make trading decisions or provide financial advice.
ProofTrade is a public track record by design. A new profile, and every exchange account you connect to it, is public by default. Before any of your trading data is published we ask you to confirm that you have read a summary of what publication means, and we record which version of that summary you confirmed and when. Until that confirmation is on file, your trading data is not served on any public surface.
Once it is, the following information becomes publicly accessible based on your visibility settings:
While your profile is public, visitors can open your follower and following lists from your profile. These lists show only other public profiles: private profiles are excluded from both the lists and the counts shown alongside them, and no follow date, follower tier, or invite information is ever included. If you make your profile private, you are removed from other people's public lists and counts, and your own lists stop being available; the underlying relationships are kept so they return if you make your profile public again.
You control your visibility level through your account settings. You can restrict what data is publicly visible at any time, and narrowing or withdrawing publication never requires you to confirm anything first. Note that data previously accessed by third parties when it was public cannot be recalled.
Share cards are a separate case. A card you create has its own link that works for anyone holding it, whether or not they have a ProofTrade account and regardless of whether your profile is public. Revoking a card stops us serving it, but copies already cached by the sites and apps the link was pasted into are outside our control.
We may share your information with:
These providers are contractually bound to handle your data securely and only as needed to provide their services.
We send your encrypted API credentials to the relevant exchange (e.g., Bybit) solely for the purpose of reading your trading data. We only make read-only API calls and do not transmit any additional personal information to exchanges.
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of ProofTrade, our users, or the public.
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such transfer and any changes to this Privacy Policy.
We implement multiple security measures to protect your data:
Despite these measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security and are not responsible for unauthorized access resulting from factors outside our reasonable control.
We retain your data as follows:
Deleting your account is what removes trading data. When you delete your account, we delete your personal data, encrypted API credentials, and trading data, including the history retained from exchanges you had previously disconnected. Some anonymized or aggregated data may be retained for analytical purposes. Data that has been made public and cached by third parties is beyond our control to delete.
If you want to stop new data being collected but keep your existing record, disconnect the exchange. If you want the record itself removed, delete your account.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at the email address listed below. We will respond within 30 days.
We use essential cookies for authentication and session management (provided by Clerk). Without them you cannot stay signed in, so they are not optional. Alongside those we use a small number of measurement and diagnostics services, split into what is necessary to run the Service safely and what is entirely up to you.
Sentry — when something breaks, we send the error, the stack trace and technical request context so we can fix it. Authentication cookies, authorization headers, API credentials and email addresses are removed before an error report leaves our systems, and if that removal step ever fails the report is discarded rather than sent. These reports carry no recording of your screen and no profile of how you use the Service.
We keep this running for everyone, including people who decline everything in section 9.2, because an unreported fault in a service that stores exchange API credentials is a security problem. We also collect performance traces from our own servers and background workers. Those are per-process diagnostics that are not tied to an individual account, and we do not offer a per-user switch for them because we could not honestly enforce one.
Nothing in this section runs until you allow it. You are asked once when you set up your account, and you can change or withdraw any of it at any time under Settings → Privacy. Declining all of it is a complete answer and changes nothing about the Service. Until you make a choice, and after you withdraw one, none of it runs.
We record which version of this summary you answered, along with your answer and when you gave it. If we materially change what these categories cover, we ask you again rather than carrying your previous answer over to something you were not shown.
If you are not signed in, none of the optional measurement above runs at all, because there is no account for a choice to be recorded against.
We do not use advertising cookies or sell data to advertisers. We do not engage in cross-site tracking for advertising purposes. Declining optional measurement does not restrict any feature of the Service.
Our hosting, database and queue providers keep their own records of the requests they serve, as any hosting provider does. That is part of operating the Service rather than something our application starts, and it is not covered by the choices above.
ProofTrade is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors. If we learn that we have collected data from a minor, we will delete it promptly.
Your data may be stored and processed in countries other than your own. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:
We process your personal data on the following legal bases:
In addition to the rights listed in Section 8, you have the right to:
To exercise these rights, contact us at the email address listed below. We will respond within 30 days, or sooner as required by applicable law.
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
To submit a verifiable consumer request, contact us at the email address listed below. We will verify your identity before fulfilling any request.
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notification. The “Last updated” date at the top reflects the most recent revision.
For questions, concerns, or requests regarding your privacy or this policy, contact us at: privacy@prooftrade.io