Privacy Policy

Last updated: August 30, 2026

1. Introduction

ProofTrade (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the ProofTrade platform (“the Service”).

By using the Service, you consent to the data practices described in this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you create an account through our authentication provider (Clerk), we may receive:

  • Email address
  • Display name and username
  • Profile avatar (if provided)
  • Authentication identifiers

2.2 Exchange API Credentials

When you connect an exchange account, we collect:

  • Read-only API key and secret
  • Exchange account identifiers

API credentials are encrypted at rest using 256-bit encryption (libsodium) and are only decrypted in memory during active sync operations. We never store credentials in plaintext.

2.3 Trading Data

Through your connected exchange API, we automatically sync and store:

  • Trade history (entries, exits, symbols, sides, quantities, prices)
  • Open and closed positions
  • Order history
  • Calculated performance metrics (PnL, win rate, realized drawdown, return percentages)
  • Realized equity curve data

2.4 User-Generated Content

  • Trade annotations and commentary
  • Profile settings and visibility preferences
  • Share card configurations

2.5 Automatically Collected Data

  • IP address and approximate geolocation
  • Browser type, device type, and operating system
  • Pages visited and features used
  • Referring URLs
  • Timestamps of access

3. How We Use Your Information

We use collected information to:

  • Provide the Service — sync trading data, calculate metrics, display profiles and leaderboards
  • Authenticate users — verify your identity and manage account access
  • Improve the Service — analyze usage patterns, diagnose issues, and develop new features
  • Communicate with you — send account notifications, security alerts, and service updates
  • Ensure security — detect and prevent fraud, abuse, and unauthorized access
  • Comply with legal obligations — respond to lawful requests from authorities

We do not sell your personal information. We do not use your trading data to make trading decisions or provide financial advice.

4. Public Information

ProofTrade is a public track record by design. A new profile, and every exchange account you connect to it, is public by default. Before any of your trading data is published we ask you to confirm that you have read a summary of what publication means, and we record which version of that summary you confirmed and when. Until that confirmation is on file, your trading data is not served on any public surface.

Once it is, the following information becomes publicly accessible based on your visibility settings:

  • Username and display name
  • Profile avatar
  • Aggregate performance metrics (returns, win rate, realized drawdown)
  • Published trade history (if you choose to share individual trades)
  • Live positions (if you enable live position sharing)
  • Leaderboard ranking
  • Trade and performance annotations
  • Your follower and following relationships with other public profiles

While your profile is public, visitors can open your follower and following lists from your profile. These lists show only other public profiles: private profiles are excluded from both the lists and the counts shown alongside them, and no follow date, follower tier, or invite information is ever included. If you make your profile private, you are removed from other people's public lists and counts, and your own lists stop being available; the underlying relationships are kept so they return if you make your profile public again.

You control your visibility level through your account settings. You can restrict what data is publicly visible at any time, and narrowing or withdrawing publication never requires you to confirm anything first. Note that data previously accessed by third parties when it was public cannot be recalled.

Share cards are a separate case. A card you create has its own link that works for anyone holding it, whether or not they have a ProofTrade account and regardless of whether your profile is public. Revoking a card stops us serving it, but copies already cached by the sites and apps the link was pasted into are outside our control.

5. Data Sharing

We may share your information with:

5.1 Service Providers

  • Clerk — authentication and user management
  • Database hosting provider — encrypted data storage
  • Hosting provider — application deployment and serving, including aggregate traffic and performance measurement
  • PostHog — anonymous product analytics, optional (see section 9)
  • Sentry — error monitoring, plus optional performance measurement and session replay (see section 9)

These providers are contractually bound to handle your data securely and only as needed to provide their services.

5.2 Exchange APIs

We send your encrypted API credentials to the relevant exchange (e.g., Bybit) solely for the purpose of reading your trading data. We only make read-only API calls and do not transmit any additional personal information to exchanges.

5.3 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of ProofTrade, our users, or the public.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such transfer and any changes to this Privacy Policy.

6. Data Security

We implement multiple security measures to protect your data:

  • Encryption at rest — API credentials are encrypted using libsodium (256-bit)
  • Encryption in transit — all data transmitted over HTTPS/TLS
  • Access controls — role-based access to internal systems
  • Audit logging — security-sensitive operations are logged
  • Read-only API access — we never request permissions to trade or withdraw funds

Despite these measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security and are not responsible for unauthorized access resulting from factors outside our reasonable control.

7. Data Retention

We retain your data as follows:

  • Account data — retained while your account is active
  • Trading data — retained while your account is active. Disconnecting an exchange does not delete the trade history and performance metrics already synced from it: they are kept so your track record stays intact if you reconnect, and so your existing results do not silently disappear from your profile. Disconnecting stops new data being collected from that exchange.
  • API credentials — deleted immediately upon disconnection or account deletion
  • Audit logs — retained for up to 12 months for security purposes
  • Automatically collected data — retained for up to 12 months

Deleting your account is what removes trading data. When you delete your account, we delete your personal data, encrypted API credentials, and trading data, including the history retained from exchanges you had previously disconnected. Some anonymized or aggregated data may be retained for analytical purposes. Data that has been made public and cached by third parties is beyond our control to delete.

If you want to stop new data being collected but keep your existing record, disconnect the exchange. If you want the record itself removed, delete your account.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate personal data
  • Deletion — request deletion of your personal data
  • Portability — request your data in a portable format
  • Object — object to certain processing of your data
  • Restrict processing — request that we limit how we use your data

To exercise any of these rights, contact us at the email address listed below. We will respond within 30 days.

9. Cookies, Analytics and Error Monitoring

We use essential cookies for authentication and session management (provided by Clerk). Without them you cannot stay signed in, so they are not optional. Alongside those we use a small number of measurement and diagnostics services, split into what is necessary to run the Service safely and what is entirely up to you.

9.1 Error monitoring (not optional)

Sentry — when something breaks, we send the error, the stack trace and technical request context so we can fix it. Authentication cookies, authorization headers, API credentials and email addresses are removed before an error report leaves our systems, and if that removal step ever fails the report is discarded rather than sent. These reports carry no recording of your screen and no profile of how you use the Service.

We keep this running for everyone, including people who decline everything in section 9.2, because an unreported fault in a service that stores exchange API credentials is a security problem. We also collect performance traces from our own servers and background workers. Those are per-process diagnostics that are not tied to an individual account, and we do not offer a per-user switch for them because we could not honestly enforce one.

9.2 Optional measurement — your choice

Nothing in this section runs until you allow it. You are asked once when you set up your account, and you can change or withdraw any of it at any time under Settings → Privacy. Declining all of it is a complete answer and changes nothing about the Service. Until you make a choice, and after you withdraw one, none of it runs.

  • Product analytics (PostHog, Vercel Web Analytics) — which pages get used, and the technical details your browser sends with a page view, such as the page address, referring page, device type and browser. This is anonymous: we send PostHog no email address, no username and no account identifier, we do not create a personal profile for you there, and page addresses that contain a username, an invitation token or a share-card identifier are stripped before they are sent.
  • Performance measurement (Vercel Speed Insights, Sentry browser traces) — how long pages take to load and become interactive, and timing traces for the requests your browser makes to us.
  • Session replay (Sentry) — a masked recording of how a page behaved for you, with text and media blanked out, so a fault that only appears on your screen can be reproduced. Session replay recording is not enabled today, by this service or by our analytics provider, and your answer here records what should happen if we ever switch it on. Recording would begin only for people who had allowed it, and never before.

We record which version of this summary you answered, along with your answer and when you gave it. If we materially change what these categories cover, we ask you again rather than carrying your previous answer over to something you were not shown.

If you are not signed in, none of the optional measurement above runs at all, because there is no account for a choice to be recorded against.

9.3 What we do not do

We do not use advertising cookies or sell data to advertisers. We do not engage in cross-site tracking for advertising purposes. Declining optional measurement does not restrict any feature of the Service.

Our hosting, database and queue providers keep their own records of the requests they serve, as any hosting provider does. That is part of operating the Service rather than something our application starts, and it is not covered by the choices above.

10. Children's Privacy

ProofTrade is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors. If we learn that we have collected data from a minor, we will delete it promptly.

11. International Data Transfers

Your data may be stored and processed in countries other than your own. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.

12. European Users (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:

12.1 Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance — processing necessary to provide the Service you requested (account management, data syncing, profile display)
  • Legitimate interests — improving the Service, ensuring security, preventing fraud, and analyzing usage patterns, where these interests are not overridden by your rights
  • Consent — where you have given explicit consent. Publishing your trading data is public by default rather than opt-in, and we record your confirmation of the publication summary described in Section 4, along with its version and date, before any of it is published. You can withdraw publication at any time from your account settings, without needing to confirm anything first.
  • Legal obligation — processing required to comply with applicable laws

12.2 Your GDPR Rights

In addition to the rights listed in Section 8, you have the right to:

  • Data portability — receive your personal data in a structured, commonly used, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Withdraw consent — withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing
  • Lodge a complaint — file a complaint with your local data protection supervisory authority

To exercise these rights, contact us at the email address listed below. We will respond within 30 days, or sooner as required by applicable law.

13. California Users (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to know — you may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it
  • Right to delete — you may request deletion of personal information we have collected, subject to certain exceptions
  • Right to opt-out of sale — we do not sell your personal information. If this changes, we will provide a “Do Not Sell My Personal Information” link
  • Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA rights

To submit a verifiable consumer request, contact us at the email address listed below. We will verify your identity before fulfilling any request.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notification. The “Last updated” date at the top reflects the most recent revision.

15. Contact Us

For questions, concerns, or requests regarding your privacy or this policy, contact us at: privacy@prooftrade.io