Privacy Policy

Last updated: 2026-05-09

1. Data we collect

When you sign up we collect your email, full name and password (stored hashed with bcrypt — we never see your plaintext password). When you connect a broker via OAuth we receive an access token and basic account metadata (account number, currency, leverage). We do not receive your broker password.

2. Trading data

We log every trade Tradiow places on your behalf, including symbol, volume, entry/exit prices and the AI reasoning that produced the signal. This data is associated with your account and is used to display performance metrics and to comply with audit requirements.

3. Storage & security

OAuth access tokens are encrypted at rest with AES-256. Communication with our servers is encrypted via TLS. Production data is hosted on a VPS located in France (Paris).

4. Third parties

We use Stripe (payments), Resend (email), Sentry (error tracking), OpenAI (AI signal validation) and Spotware/cTrader (broker connectivity). Each processes only the minimum data required for their function.

5. Your rights

You can export, correct or delete your data at any time from the Settings page. Account deletion permanently disconnects all brokers and removes your personal information from our database within 30 days.

6. Cookies

We use only strictly necessary cookies for authentication and security. We do not use marketing or analytics cookies that track you across other websites.

7. Contact

Questions: privacy@tradiow.com.