theta journal is operated by A Street Ventures LLC, a Colorado limited liability company (“we,” “us,” or “our”). This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data when you use thetajournal.app (the “Service”).
We are committed to a simple principle: your trading data is yours. We do not sell it, share it with advertisers, or use it to train models. It exists solely to power your personal journal.
1. Information We Collect
Information you provide directly
- Account credentials — email address and password (hashed by Supabase Auth; we never store plaintext passwords).
- Brokerage transaction data — the CSV files you upload (trade fills, money movements, assignments, etc.). This data is parsed, stored in our database, and used solely to power your dashboard.
- Journal content — position notes, custom tags, strategy labels, and any other annotations you add to positions.
- Account names — the brokerage account labels you create within the app (e.g., “Tastytrade IRA”).
- Preferences — display settings such as theme, density, and alert thresholds.
Information collected automatically
- Authentication tokens — session cookies managed by Supabase Auth to keep you signed in.
- Server logs — standard web-server request logs (IP address, browser user-agent, pages visited, timestamps). These are used for debugging and security monitoring and are retained for 30 days.
Information we do not collect
We do not collect payment information (the Service is currently free). We do not run third-party analytics (no Google Analytics, Mixpanel, or similar). We do not use advertising cookies or tracking pixels.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Authenticating your account and maintaining your session.
- Storing, organizing, and displaying your trade data, positions, and journal entries as part of the Service.
- Computing analytics shown in your dashboard (P&L, win rate, equity curve, etc.).
- Sending transactional emails (password reset, email verification) via Supabase’s built-in auth flows.
- Investigating security incidents or abuse using server logs.
- Improving the Service based on how it is used, using aggregated and anonymized data only.
We do not use your trading data to train machine-learning models, benchmark products, or produce aggregate market-intelligence reports.
3. Data Storage and Security
All data is stored in a Supabase-managed PostgreSQL database hosted on AWS in the United States (us-east-1 region). Supabase encrypts data at rest (AES-256) and in transit (TLS 1.2+).
Row-Level Security (RLS) policies are enabled on every database table, ensuring that authenticated queries can only access rows belonging to the signed-in user. Even in the event of an application bug, no user can read another user’s data.
Despite these measures, no system is perfectly secure. We encourage you to use a strong, unique password and to sign out of shared devices.
4. Data Retention
Your account data is retained for as long as your account exists. If you delete your account (see “Your Rights” below), we will delete all associated records — trades, positions, imports, preferences, and account rows — within 30 days.
Server logs are automatically purged after 30 days. Supabase Auth logs follow Supabase’s own retention policy (currently 60 days).
5. Sharing Your Data
We do not sell, rent, or trade your personal information to third parties. We share data only in the following limited circumstances:
- Supabase — our database and auth provider. Supabase processes your data as a sub-processor under their Privacy Policy.
- Legal requirements — if required by law, court order, or to protect the rights, property, or safety of users or the public.
If the Service is ever acquired or merged, we will notify you by email and post a notice on the site at least 30 days before your data is transferred to or governed by a different privacy policy.
6. Cookies
We use only functional cookies — specifically the Supabase session cookie that keeps you signed in. We do not use advertising or analytics cookies. You can configure your browser to block or delete cookies, but doing so will sign you out and prevent you from using the Service.
7. Your Rights
You have the following rights regarding your data:
- Access — you can export all your trade data at any time from within the app.
- Correction — you can edit position notes, tags, and strategy labels directly in the app.
- Deletion — you can delete individual imports (and their associated trades) from the Import page. To delete your entire account and all associated data, email us at hello@thetajournal.app.
- Portability — your original CSV files are yours. Imported data can be viewed and referenced at any time within the app.
If you are located in the European Economic Area, you may have additional rights under the GDPR. Contact us to exercise those rights.
8. Children's Privacy
The Service is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the “Last updated” date at the top of this page and, for significant changes, by sending an email to the address on your account. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
10. Contact
Questions, requests, or concerns about this Privacy Policy should be sent to hello@thetajournal.app. We aim to respond within 5 business days.