Tradeus

Privacy Policy

Last updated 14 September 2026

1.Who is responsible

The controller for the personal data described here is the operator of Tradeus, who can be reached at support@tradeus.app. Use that address for any request under this policy; it goes to a person, not an autoresponder.

We have not appointed a data protection officer. We are not required to: we do not process personal data on a large scale as our core activity, and we do not monitor anyone systematically. The address above reaches the person who decides how this data is handled, which in a company this size is the more useful answer.

2.What this policy covers, and what it does not

This policy covers what we do with personal data in the Tradeus application, its API and this website. Three things happen around it that are not ours, and being vague about the boundary would be the most misleading part of the document:

  • The checkout. Whop sells the subscription in its own name. Your card details, billing address and tax data are entered into Whop's form and stay with Whop, which decides what happens to them and answers for them under its own privacy policy. They never reach us.
  • Your broker. The account, the money and the orders are yours and your broker's. What we hold is the credential you gave us to reach it and the trading data it returns; the broker keeps its own records under its own terms, and closing your Tradeus account does not close anything there.
  • Discord. Sign-in happens on Discord. We never see a Discord password, and what Discord does with your account is between you and Discord.

3.What we collect

  • Account data. When you sign in with Discord we receive your Discord user ID, email address, display name and avatar URL. Those four fields are the whole of the scope we request — we do not read your servers, your messages or your friends.
  • Profile data you choose to add. Handle, bio, region, tier, traded instruments and TradingView username. Parts of this are public where you switch them to public — you control each of these in your profile settings.
  • Broker connection data. The access tokens or credentials needed to reach the broker you connect. These are encrypted before they are written to disk (AES-256-GCM) and are never displayed back to you or to anyone else. See section 8.
  • Trading data. Accounts, balances, positions, orders, fills, risk settings and the event log produced while the service runs on your behalf.
  • Billing reference. A membership identifier from Whop, and which plan it is for. Your name, billing address, card details and tax data are given to Whop at the checkout and stay with Whop — they never reach us, so we cannot see or store them.
  • Server logs and technical data. Like any server, ours records the requests it answers: the time, the method and path, the response, the browser's user-agent string and the IP address the request came from. The same address is counted, briefly and in memory, by the brake that stops password and token guessing. Logs are scrubbed before they are written — the session token, any authorisation header and any secret in a query string are replaced with a marker, and request bodies are not logged at all, which is where broker credentials travel.
  • What you send to the AI assistant. The question you type and the context the feature attaches to it. See section 7.
  • Support correspondence. If you write to us, we keep the message and our reply so the next person to read the thread knows what was already said.

4.Why we may process it

Every category above has a ground under Art. 6(1) GDPR, and they are not all the same one. Where the ground is legitimate interest, the interest is named, because an unnamed one cannot be objected to.

  • Account, trading and broker connection data — Art. 6(1)(b). Necessary to perform the contract you entered into. Without it there is no copier, no risk manager and no dashboard.
  • Billing reference — Art. 6(1)(b) and Art. 6(1)(c). Necessary to know which plan you hold, and to keep records the law requires us to keep.
  • Server logs, rate limiting and security — Art. 6(1)(f). Our legitimate interest in keeping the service available, diagnosing faults, and stopping brute-force and abuse. This one protects your account as much as our server, which is the balance we have struck.
  • Public profile fields and leaderboard entries — Art. 6(1)(a). Your consent, given by switching a field to public, withdrawable at any time by switching it back. Withdrawing does not affect what was lawful before.
  • Support correspondence — Art. 6(1)(b) and (f). To answer you, and to keep a record of what was answered.
  • Product emails about changes and outages — Art. 6(1)(b) and (f). These are service messages, not marketing. We do not run a marketing mailing list; if we ever do, it will be opt-in and separate from this.

5.What we never do

Negative statements are worth more than positive ones in a document like this, because they are the ones a supervisory authority can check against the product in an afternoon.

  • We do not sell personal data, and we have no advertising business to sell it to.
  • We run no analytics and no session replay, and we build no cross-site profile of you. There is one advertising pixel — Whop's, so they can tell whether an advertisement we paid for led to a sale — and it runs only where you have accepted it, never on the pages behind your sign-in. It does take a fingerprint of your browser, and we would rather name that than let the sentence above imply otherwise. Whop's script can also read form fields, take an identity out of a link, decorate outbound links and measure your graphics hardware; we start it with every one of those switched off, and the itemised list sets out both what is left and how we know.
  • We do not train models on your trading data, and we do not give it to anyone else to train on.
  • We do not publish your trading results. A profile field is public only if you set it to public.
  • No automated decision with legal effect. Nothing here profiles you or decides anything about you within the meaning of Art. 22 GDPR. The software acts on rules you configured — that is automation of your own instruction, not a decision taken about you by us.

6.Who else sees it

These are everyone who receives personal data, in what role, from where, and on what basis it may leave the EEA. “Processor” means they act only on our instructions; controller means they decide for themselves and answer to you directly for that part.

RecipientRoleSeatTransfer basis
VercelProcessor — hosting of the website and app frontendUnited StatesArt. 28 contract; DPF certification or SCCs (section 9)
RailwayProcessor — hosting of the backend and its databaseUnited StatesArt. 28 contract; DPF certification or SCCs
DiscordController for your Discord account; receives only the sign-in requestUnited StatesYour own use of Discord; DPF certification or SCCs
WhopIndependent controller — sells and bills the subscription as merchant of recordUnited StatesIts own privacy policy; we receive back only the membership id, plan and status
Whop (advertising pixel)Independent controller — told that a sales page was opened, so it can attribute an advertisement we paid forUnited StatesArt. 6(1)(a): your consent, given on the banner and withdrawable on the cookies page
AnthropicProcessor — runs the AI assistant on what you send itUnited StatesArt. 28 contract; DPF certification or SCCs (section 7)
Your brokersIndependent controllers — Rithmic, Tradovate, TradeLocker, contacted only with the credential you suppliedUnited States, or wherever the broker you chose is establishedArt. 49(1)(b): necessary to perform the contract you asked for

That is the whole list. There is no analytics vendor, no data broker and no email marketing platform on it, because we do not use any. The previous version of this page promised that if anything of that kind were ever added, the table would change before the feature shipped. Something was — the advertising pixel in the row above — and this table changed before the feature shipped, in the same commit that built it.

7.The AI assistant, in detail

When you ask the assistant something, the question and the context the feature attaches to it — which can include your accounts, positions and settings, because that is what makes an answer useful — are sent to Anthropic's API, which generates the reply and returns it. We send what the answer needs and not the whole account.

Under the commercial terms we use, inputs and outputs sent through that API are not used to train models, and are retained only briefly for abuse detection before being discarded. We do not train anything on them either, and we do not read your conversations except where you send one to us in a support request.

The assistant is a text generator. It does not place orders, it can be confidently wrong, and nothing it writes is advice — the same as everything else in the product, and worth repeating precisely because it answers in sentences.

8.Broker credentials, in detail

A broker connection is the most sensitive thing we hold, because it is what lets software act on an account with money in it. It is handled accordingly:

  • Credentials are encrypted with AES-256-GCM before they are written to disk, under a key held in the server environment and not in the database.
  • They are never displayed back — not to you, not in support, not in a log. Request bodies are not logged, which is the route by which they arrive.
  • They are used only to reach the broker you connected, for the account you connected, to do the things you configured.
  • Disconnecting deletes them. Not marked inactive — deleted. Deleting your account deletes all of them.
  • Where the broker supports OAuth, we hold a token you can revoke at the broker as well as here, which is the better arrangement and the one we prefer where there is a choice.

9.International transfers

Most of the providers in section 6 are established in the United States, so personal data is transferred outside the EEA. Each transfer rests on one of the following: an adequacy decision, where the recipient is certified under the EU–US Data Privacy Framework; the European Commission's Standard Contractual Clauses, where it is not; or, for your broker, Art. 49(1)(b) — the transfer is necessary to perform the contract you yourself asked for by connecting that account.

The United States does not offer protection identical to the EEA, and a transfer there cannot be made perfectly equivalent by contract. We reduce what is exposed rather than claim otherwise: payment data never reaches us at all, broker credentials are encrypted before storage, and the assistant is sent the context an answer needs rather than an account export.

10.How long we keep it

“As long as necessary” is not an answer, so here are the actual periods.

DataKept for
Account and profile dataWhile the account exists. Deleted when you delete the account.
Broker credentialsDeleted the moment you disconnect the broker, or delete the account — whichever comes first.
Trading data (accounts, positions, orders, fills, event log)While the account exists, so that your own history stays available to you. Deleted with the account.
Billing reference and recordsSeven years, where a record forms part of accounting documentation (§132 BAO). The invoice itself is issued and kept by Whop, not by us.
Server logsA rolling operational window of at most 30 days, except where a specific entry is held longer because it is part of an active security investigation.
Rate-limit countersMinutes, in memory. Never written to the database.
Support correspondenceUp to three years after the matter is closed, so that a later question about the same issue can be answered.
AI conversationsHeld with your account so you can re-read them, and deleted with it. Anthropic's own brief retention is described in section 7.

One caveat about backups. The database is backed up, and the backups are encrypted and overwritten on a rolling schedule. Deleting something removes it from the live service immediately; it disappears from the backups as those are overwritten, within a short number of weeks. We do not restore deleted data from a backup to bring it back, and a restore performed for any other reason is followed by re-applying deletions.

11.How we protect it

The measures required by Art. 32, in the form they actually take here rather than as a list of adjectives:

  • Everything travels over TLS; the application is not reachable without it.
  • Broker credentials are encrypted at rest with AES-256-GCM under a key that is not in the database.
  • Sessions are bearer tokens that are redacted out of logs, and the live feed authenticates in the connection handshake rather than in a URL — a URL is the part that gets written into logs by every machine along the way.
  • Sign-in is delegated to Discord, so there is no password of ours to leak, and a brute-force brake counts attempts per address.
  • Access to production is limited to the people who operate it, and the database is not exposed to the public internet.
  • Changes are covered by automated checks that run on every build, including checks that hold this policy and the storage disclosure against what the code actually does.

No system is perfectly secure, and any policy claiming otherwise is describing a hope. If you find a weakness, write to support@tradeus.app; we will not pursue anyone who reports one in good faith.

12.If something goes wrong

If personal data is breached and there is a risk to you, we report it to the Austrian data protection authority within 72 hours of becoming aware of it, as Art. 33 requires. Where the risk to you is high, Art. 34 requires us to tell you as well — and we will, directly, saying what happened, what was affected and what to do about it, rather than publishing a notice and hoping you read it. We keep a record of incidents even where no report is required.

13.Your rights

You can request access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Write to support@tradeus.app. If you believe we have handled your data unlawfully you can complain to the Austrian data protection authority (Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna).

We answer within one month. Where a request is genuinely complex we may extend that by up to two further months and will tell you why inside the first month. There is no charge. We may ask you to confirm you are who you say you are — for a request to delete an account that can place trades, that is protection for you rather than an obstacle.

Two of these you can exercise yourself, immediately, without writing to anyone: switching a public profile field back to private withdraws that consent, and deleting your account from the settings page performs the deletion. Disconnecting a broker deletes its credentials on the spot.

14.Children

The service is not for anyone under 18, and we do not knowingly collect data from anyone under that age — trading a leveraged account is not a minor's activity in any case. If you believe a minor has created an account, write to support@tradeus.app and we will delete it.

15.If you are in the United States

We apply the same standard to everyone rather than running a second, thinner policy for residents of states with their own privacy laws. For California in particular:

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising, as the CCPA/CPRA define those terms. There is therefore nothing for a “Do Not Sell or Share” link to switch off.
  • You may request to know what we hold, to have it corrected, and to have it deleted, and we will not treat you differently for asking. The address is the same: support@tradeus.app.
  • We do not use or disclose sensitive personal information for any purpose beyond running the service you asked for.
  • Do Not Track and Global Privacy Control. There is now one thing to apply them to, and they are applied to it: a browser sending a GPC signal is treated as having declined the advertising pixel. It does not load, and you are not asked. Pressing Allow on the banner anyway still works — a specific answer about this site beats a standing general one — and so does pressing No.

16.Cookies and local storage

We write no cookies of our own, and run no analytics or session replay. What the site keeps is a small number of entries in your browser's own local and session storage — your sign-in token, a cached copy of your own account so the app opens without a splash screen, the result of a broker login while you are redirected back from it, any calculator scenarios you saved yourself, and your answer about the advertising pixel.

Whop's advertising pixel sets a cookie on this domain, and only after you accept it on the banner. It is the one cookie that exists because of something we did, it is set by Whop's script rather than by us, and it identifies the visit so that an advertisement we paid for can be matched to a sale. It never loads on the pages behind your sign-in. The same random identifier is kept in two further places, and the script sends a fingerprint of your browser with each page view — a hash of screen size, time zone, language, fonts and the like, which is how it recognises a visit where cookies are refused. Every one of those is a named row on the cookies page, with what it holds and how long it lasts.

The checkout brings more that is not ours: Whop's payment form runs in a frame from whop.com and carries its own storage, under its own privacy policy. Every one of these is named individually — with its purpose, how long it lasts and a button that deletes all of them — on the cookies and local storage page, which also sets out what the banner asks and what declining does.

17.Changes

If this policy changes materially we will say so in the product before the change takes effect. The date above is when this version was published. Earlier versions are not archived on the site; if you need to know what the policy said on a particular date, ask and we will tell you.