Tradeus

Cookies and local storage

Last updated 14 September 2026

One script, only if you allow it

Tradeus sets no cookies of its own. There is no analytics, no session replay and no cross-site tracking. There is one advertising pixel — Whop's, who sell the subscription — and it does not load unless you accept it, which is why this site asks. Nothing is loaded while the question is unanswered, and nothing is loaded if the answer is no.

What the site does keep is 7 entries in your browser's own storage, which never leave your device except as the requests you would expect — your sign-in token going to our API. They are listed individually below, and you can delete all of them with one button at the bottom of this page.

What we store

Your sign-inLocal storageRequired

tradeus_token

The sign-in token. Without it every page reload would ask you to sign in with Discord again.

Until you sign out or clear it below.

A copy of your own accountLocal storageRequired

tradeus_user

A copy of your own account record — name, avatar, plan — so the app opens on your dashboard instead of a splash screen while it re-checks with the server.

Until you sign out or clear it below.

Scenarios you saved in the calculatorLocal storage

tradeus.calc.scenarios

Scenarios you saved yourself in the prop-firm calculator. It never leaves your browser — these are not stored on our servers.

Until you delete them in the calculator, or clear them below.

What your broker said as it sent you backSession storageRequired

tradeus_oauth_note

The outcome of a broker login — connected, or the error the broker gave — carried across the redirect back from that broker so the page can tell you what happened. Read once and deleted.

Until the tab is closed, and in practice until the message has been shown to you once.

Who referred you, if you arrived through someone's linkSession storage

tradeus_affiliate

If you came here through a referral link, the code identifying the person who referred you — so they are credited if you subscribe, even after you have looked around the site and signed in. It records who sent you, not who you are, and it is sent to Whop only as part of a purchase you make.

Until the tab is closed.

A discount code, if the link you arrived on carried oneSession storage

tradeus_promo

If the link you followed included a discount code, the code itself — so the price is already reduced when the payment form opens, instead of you having to type it. It is sent to Whop as part of a purchase you make, and nothing else.

Until the tab is closed.

Your answer about the advertising pixelLocal storageRequired

tradeus_consent

Whether you accepted or declined the advertising pixel, so you are asked once instead of on every page. It holds that one word and nothing else — no identifier, nothing about you — and it is never sent anywhere.

Until you clear it below, after which you will be asked again.

Marked Required where the service cannot work without it. The ones without that mark are there because of something you did — you pressed Save in the calculator, or you followed a link that carried a referral or a discount code with it. They are stored in your browser rather than on our servers, which means clearing them here loses them for good.

Not marked required: scenarios you saved in the calculator; who referred you, if you arrived through someone's link; a discount code, if the link you arrived on carried one.

What the checkout brings with it

Paying is where most of the code that is not ours runs. We do not sell the subscription ourselves — Whop does, as merchant of record — and their checkout appears inside the pricing page rather than sending you away. That has consequences worth naming rather than burying:

Whop's own visitor cookie, if you already carry oneCookie

_wuid

Whop's visitor identifier — a random string, generated in your browser, that means nothing outside Whop's own records. Our checkout reads it if you already carry one from whop.com. It is also what Whop's advertising pixel sets, on this domain, if you accept it — that is the one way this site causes it to exist rather than merely finding it, and it is how a page view here and a purchase on Whop are recognised as the same visit.

Two years from the last visit, when the pixel sets it. Removed when you clear cookies for this site in your browser's settings.

The card form, which is Whop's page inside oursThird party

whop.com/embedded/checkout

The card form itself is Whop's page inside a frame on ours, and it only loads after you tick the box above it. Anything you type into it is stored by Whop under whop.com, under Whop's privacy policy — card details never reach Tradeus.

Governed by Whop.

Plaid's bank login, only if you pay by bank transferThird party

Plaid Link (link-initialize.js)

If you choose to pay by bank transfer, Whop's checkout loads Plaid's bank-linking script into this page to run the bank login. Choosing card payment never loads it.

Governed by Plaid.

The same visitor identifier, kept a second timeLocal storage

_wuid

The identical random string from the _wuid cookie on this list, stored a second time in your browser's own storage so that clearing cookies alone does not lose it. There is nothing in it that is not in the cookie — it is the same value written twice — and the clear button at the bottom of this page does remove this copy.

Until you clear it below, or clear site data in your browser.

The same identifier again, shared with any subdomainCookie

_wuid_link

A third copy of that same string, written one level up so that anything at a subdomain of this site would read the same visitor rather than a new one. Finding out whether that is possible is done by writing a throwaway cookie named _wpd and immediately deleting it, which you may catch in developer tools. It carries no more than the cookie above does.

Two years from the last visit.

Which domain that worked on, so it is not tried againLocal storage

_wuid_link_domain

The result of the test described above: the domain name the shared cookie turned out to be writable on. Bookkeeping for the entry above, with no identifier of its own.

Until you clear it below, or clear site data in your browser.

That an identifier from elsewhere has already been joined upLocal storage

_wuid_link_seen

Written only if you arrived already carrying one of these identifiers from another site of Whop's, to record that the two have been connected once so it is not done again on every page. It holds that identifier and nothing further.

Until you clear it below, or clear site data in your browser.

Whop's own installation check, if Whop sends you here to run itSession storage

whop_verify

Written only when a link carries ?whop_verify= in it, which is how Whop's dashboard tests that a pixel is installed at all. It holds the id of that test. A visitor who has not been handed such a link never has it.

Ten minutes, and in any case until the tab is closed.

When that check stops being validSession storage

whop_verify_expires_at

The moment the test above expires. A timestamp, and nothing else.

Ten minutes, and in any case until the tab is closed.

Where the panel of that check was dragged toSession storage

whop_verify_hud_position

Whop's test draws a small panel over the page; this is the corner it was last moved to. Two numbers.

Until the tab is closed.

A fingerprint of your browser, sent with every page viewSent, not stored

fp

The script computes a short hash out of things your browser reveals by being asked politely — screen size, time zone, language, installed fonts, how text and graphics are drawn — and sends it with every event, along with a confidence score for it. It is not stored on your device and it is not a name; it is a value that is likely to be the same for you tomorrow, which is what makes it a fingerprint, and it is how Whop still recognises a visit when cookies are refused. It cannot be switched off from our side: unlike the other five things this script can do, there is no option for it, so the honest thing is to say it is there rather than to imply it is not.

Not stored in your browser. What Whop keeps of it is governed by Whop's privacy policy.

Whop's advertising pixel, if you accepted itSent, not stored

t.whop.tw/s.js

A script from Whop that records that a sales page was opened, so Whop can tell whether an advertisement we paid for led to a sale. It does not load unless you accept it, and it never loads on the pages behind your sign-in. With each page view it sends the address of the page, its title, the page you came from, your browser's user-agent string, screen size, language, time zone, the fingerprint described above, and any campaign or click parameters that were in the link you followed. It does not report what you looked at, typed or traded — Whop's script can do all four of those things, and this site starts it with each of them switched off.

Runs for as long as the page is open; what it leaves behind is the list above.

The pixel is the exception, and it is the only one: everything else on that list waits until you open the checkout and tick the box above the card form, and if you never buy anything none of it ever runs. Card numbers are entered into Whop's frame, stored by Whop under Whop's domain, and never reach Tradeus — see the Privacy Policy for who is responsible for what.

Why there is a consent banner

Consent is not owed for everything a site puts in your browser. Article 5(3) of the ePrivacy Directive — in Austria, §165 TKG 2021 — requires it for storing or reading anything on your device, and then carves out storage that is strictly necessary for a service the user has explicitly asked for. A banner is what a site shows when it wants something outside that carve-out. We have exactly one thing outside it, and that is what the banner is for.

Each entry above is marked against that test, and the marks are not decorative. The sign-in token and the copy of your own account are what “keep me signed in” means; without them every page load would send you back to Discord. The note carried back from a broker login exists for one page view and is deleted as it is read. The entries without the mark are not tracking either: a saved scenario exists because you pressed Save, a referral or discount code exists because you followed a link that carried one, none of them outlives the tab or the browser you are reading this in, and all of them are gone the moment you clear them below. Storage a user created on purpose is not storage a user needs to be asked about.

The pixel is the one thing here that is none of those. It exists so Whop can tell whether an advertisement we paid for led to a sale, which is our interest and not yours, so it is asked about rather than assumed — and declining is a button of exactly the same size as accepting, in the same colour, because a choice presented as one obvious action and one afterthought is not a choice. The page behaves identically either way. Ignoring the question entirely also counts as no.

You can change your mind at the bottom of this page: clearing removes the record of your answer along with everything else, and the banner asks again on the next page you open. It also removes the copies of Whop's identifier that live in this site's own storage, because storage belongs to the site and not to whichever script filled it. The one thing that button honestly cannot do is take back the two cookies Whop's script has already set — this site writes no cookies and therefore cannot delete one, which is a restriction we keep on purpose because it is what makes the sentence at the top of this page checkable. Those go when you clear site data in your browser's own settings. We would rather say that than offer a button whose label promises more than it does.

What the pixel does more than count page views is worth saying plainly, because it is the part a reader cannot check for himself. Alongside the visit it computes a fingerprint of your browser: a short hash of the things any page can ask for — screen size, time zone, language, installed fonts, the way text and graphics come out — which is likely to be the same for you tomorrow, and which is how Whop recognises a visit even where cookies are refused. It is sent, not stored, and there is no setting in the script that turns it off. We are telling you because we would rather you knew than that you found out.

There are five further things that script is capable of by default, and this site starts it with all five switched off: reading the fields of any form on the page — the contact form included — lifting a name or an email address out of the link you followed, rewriting outbound links to carry your identifier onward, timing how long you stay on a page, and drawing a hidden graphic to derive a hash of your graphics hardware. None of them happens here, and the list above is what is left when they are gone. Beyond the pixel there is still no analytics, no session replay, and no profile built out of any of it; the checkout code named above loads only inside checkout, only after you choose to pay, and its own consent is Whop's and Plaid's to collect under their policies.

One thing that is not storage

The live dashboard holds a WebSocket open to our API so positions and fills arrive without polling. Your sign-in token is sent once, when that connection opens, as part of the handshake and not as part of its address. The address is the part that servers and the networks in between routinely write into their logs, which is no place for a token that stays valid for months. Nothing is stored by the connection, and it closes when you close the tab.

Clearing it

This removes every entry listed above from this browser. It does not delete your account or anything on our servers — for that, see Your rights in the privacy policy.

This signs you out, deletes your saved calculator scenarios, which are not stored anywhere else, and forgets your answer about the advertising pixel.