Privacy Policy
Effective Date: July 19, 2026
1. Introduction
This Privacy Policy explains how Restored Trading LLC ("we", "us", or "our") collects, uses, and protects information when you use the TradePosture platform and related services (the "Service"). By using the Service, you agree to this Policy.
2. Information We Collect
We collect the following categories of information:
- Account information — the email address and password you use to register (authentication is handled by our infrastructure provider; we do not store your plaintext password). We also store your access code, entitlement tier, and the date you last used the Service.
- Profile information — your preferred/display name and app preferences and settings.
- Journal and trading content — trades, notes, tags, goals, watchlists, playbooks, dated reflections, discipline entries, tracked setups, and other entries you choose to create. This includes financial information you enter, such as position sizes, prices, fees, and realized profit and loss; it is stored to provide the journaling features to you.
- Images you upload — chart screenshots and similar images attached to trades or watchlist entries. These are stored in our cloud storage. Please note that stored images are addressed by a long, randomly generated URL that is not publicly listed or indexed, but is not individually access-controlled; anyone who obtains the exact URL could view that image. Avoid uploading images containing sensitive personal information such as account numbers.
- Broker-connected data — if you choose to link a brokerage account (for example, through Charles Schwab or SnapTrade), we access account, position, and transaction information from that broker in order to display it and import your trade history. The credentials and access tokens for these connections are stored in encrypted form.
- AI coaching profile — if you use the AI coaching features, the Service generates and stores a profile of your trading patterns and habits (for example, recurring behavioral tendencies and areas of improvement) inferred from your journal content, so that coaching can be personalized over time. This is information about you that we derive, rather than information you enter directly. You can review and delete this profile within the Service.
- Your API keys — if you choose to supply your own third-party API keys (for example, for AI providers), the keys you enter are stored, in encrypted form, to enable those features at your request.
- Integration settings — such as a Discord webhook URL you provide in order to share content to a channel you control.
- Support and feedback — the content of any feedback or support message you submit, together with your email address and the page you sent it from.
- Usage and technical data — basic technical information such as device/browser type and interactions with the Service, used to operate and improve it. We also maintain per-account usage counters to enforce fair-use and rate limits; for requests that are not signed in, these counters are keyed to an IP address instead.
3. How We Use Your Information
- To provide, maintain, and improve the Service and its features.
- To authenticate you and secure your account.
- To generate the analyses, journals, screeners, and AI-assisted features you request.
- To communicate with you about access, support, and updates.
- To comply with legal obligations and enforce our Terms.
4. Third-Party Services and Sharing
We do not sell your personal information. We share information only as needed to operate the Service, including with the following providers:
- Infrastructure — Vercel (application hosting and scheduled jobs) and Supabase (database, authentication, and file storage) store and serve your data. We also operate a private server that retrieves and caches market data; it does not store your personal information.
- Market-data providers — ThetaData, Massive, Financial Modeling Prep, Finnhub, the U.S. Securities and Exchange Commission EDGAR system, and Charles Schwab, when the Service retrieves quotes, price history, option chains, fundamentals, news, or calendar data. These requests are for market information and do not include your journal content.
- Brokerage connections — Charles Schwab and SnapTrade, only if you choose to link a brokerage account, in order to retrieve the account and transaction data needed to import your trades.
- AI providers — Google (Gemini) and Anthropic (Claude), when you use AI-assisted features. See Section 5 for detail on what is sent and under which account.
- Discord — only when you choose to share content to a Discord channel using a webhook you supply, and when you submit feedback to us (which delivers your message and email address to our internal channel).
- Payment processing — paid plans are sold through Whop, which hosts the checkout and processes the transaction under its own terms. We do not receive or store your full payment card details.
- Law enforcement or others when required by law or to protect rights and safety.
- Note on images: certain third-party company logos are loaded directly from a market-data provider by your browser, which means your browser makes a request to that provider when such logos are displayed.
5. AI-Assisted Features and What Is Sent
When you use the AI coaching and analysis features, relevant context from your account is sent to the AI provider in order to generate a response. Depending on your request, this can include your trades and their outcomes, your written journal notes and reflections, your goals, watchlists, playbooks, discipline history, the stored AI coaching profile described in Section 2, and any chart images you ask the assistant to review.
There are two ways this can happen. If you supply your own AI provider key, your browser sends this content directly to that provider under your own account and subject to your agreement with them. If you use the built-in assistant included with a paid tier, the request is sent through our servers using our provider account. In both cases the content is processed by a third-party AI provider.
Please do not submit information to AI features that you do not want processed by a third-party AI provider.
6. Content You Choose to Publish
Most of what you create in the Service is private to your account. Some features let you publish content so that other users can see it.
If you are granted an analyst role, you may publish a public profile and trade ideas to the community board, where they can be viewed by other signed-in users (either by all members, or only by users you grant access to, depending on your settings). When you publish one of your own journal trades, the Service removes certain private details before display — including your account and balance information, position sizes, fees, and dollar profit and loss, and any attached screenshots. Published trades show information such as the ticker, direction, strategy, entry, target and stop prices, dates, status, your written notes, and, for closed trades, only whether the result was a win, loss, or flat — never the dollar amount.
You are responsible for what you choose to publish. Do not include personal or sensitive information in content you publish or share. Content you share to Discord through a webhook is delivered to that channel and is governed by Discord's terms and the channel's own audience.
7. Data Storage and Security
Your data is stored with our infrastructure providers and protected in transit using encryption. We use access controls, including database row-level security and per-request authorization, so that your private content is associated with your account and is not accessible to other users.
Particularly sensitive credentials — brokerage access tokens and any AI provider keys you supply — are encrypted at rest using industry-standard authenticated encryption. Uploaded images are stored as described in Section 2. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Cookies and Local Storage
The Service uses cookies and browser local storage to keep you signed in and to remember your preferences and settings. You can control cookies through your browser, but disabling them may affect functionality.
9. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion as described below.
10. Your Rights and Choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at rivethediver@gmail.com. You may also delete most of your content directly within the Service. We will respond to verified requests as required by applicable law.
11. Children’s Privacy
The Service is intended for adults (18+) and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
12. International Users
The Service is operated from the United States. If you access it from outside the United States, you understand your information will be processed in the United States, where data-protection laws may differ from those in your jurisdiction.
13. Changes to This Policy
We may update this Policy from time to time. We will indicate changes by updating the "Effective Date" above. Your continued use of the Service after changes become effective constitutes acceptance of the updated Policy.
14. Contact
For privacy questions or requests, contact us at rivethediver@gmail.com.
© 2026 Restored Trading LLC. All rights reserved. TradePosture™