Privacy policy
All times UTC. This policy applies to tradediscuss.com.
Before launch: this policy must be reviewed by counsel for the jurisdictions you operate in and must name the data controller, its address, a data protection contact and, where required, an EU/UK representative. The substance below describes what the software actually does — that part is accurate — but it is not a substitute for legal review. See docs/LAUNCH-RUNBOOK.md.
What is permanently public
The core of this product is a public record, so it is worth being blunt about what that means before anything else. If you publish a call, the following is public and permanent:
- Your username and profile.
- Every call you publish: levels, timeframe, stated conviction and thesis.
- The timestamp, the price we recorded, and the outcome.
- The statistics computed from those calls, including the unflattering ones.
- Your comments and the reactions your calls receive.
Published calls cannot be edited or deleted, including by you. That is the entire point of the platform, and it is the one thing an account deletion request cannot undo — see below.
What we collect
| Data | Why | Retention |
|---|---|---|
| Email address | Sign-in, email verification, outcome alerts you opt into | While the account exists |
| Password hash (argon2id) | Authentication. The password itself is never stored or logged | While the account exists |
| Session records (IP, user agent) | Keeping you signed in, and letting sessions be revoked | 30 days after expiry |
| Calls, comments, reactions | The public record itself | Permanent |
| First-party analytics events | Understanding which parts of the product work | 13 months |
| Follow-a-call email (non-account) | Sending the single outcome alert you asked for | Until the alert is sent or you unsubscribe |
What we do not do
- No third-party advertising or advertising networks.
- No selling, renting or sharing personal data with data brokers.
- No cross-site tracking pixels or third-party analytics scripts.
- No marketing email you did not explicitly opt into.
Analytics are first-party and stored in our own database. We record which pages are visited and which product actions occur — not a profile of you across the internet.
Cookies
One essential cookie holds your session. It is HttpOnly, SameSite=Lax and, in production, Secure. There are no advertising or third-party cookies. Some interface preferences may be stored in your browser's local storage; those never leave your device.
Transactional email is sent through Resend. Following a call without an account requires double opt-in: an unconfirmed address is never emailed anything except the confirmation request itself. Every alert carries an unsubscribe link.
Your rights
Depending on where you live you may have rights to access, correct, export, restrict or delete your personal data. We honour these requests. But one limit needs stating plainly:
Deleting your account does not delete your published calls. A public record that can be withdrawn once it looks bad is not a record. On account deletion we remove your email address, password hash and sessions, and we can pseudonymise your username on request — but the calls, their timestamps and their outcomes remain, because other people relied on them being permanent when they read them.
This is disclosed at signup, not buried here.
Security
Passwords are hashed with argon2id. Sessions are server-side records referenced by a signed HttpOnly cookie, so they can be revoked immediately. Traffic is served over TLS. Database backups are encrypted and stored off-host. We do not claim to be unbreachable; if a breach affecting personal data occurs, we will notify affected users and the relevant authority within the required timeframe.
Children
TradeDiscuss is not intended for anyone under 18 and we do not knowingly collect data from them.
Changes
Material changes to this policy will be announced on the site before they take effect. The date of the last change is shown at the top.
Contact
Privacy requests and questions go to the address on the about page.