Privacy Policy

Version 2.0.0

Effective Date: 19 February 2026

Trading Journal Pro ("we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Trading Journal Pro mobile application ("App") and related services ("Services").

This policy complies with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws.

By using the App, you acknowledge that you have read and understood this Privacy Policy. Where we rely on consent as a lawful basis for processing, we will seek your explicit consent separately.

1. Data Controller

The data controller responsible for your personal data is:

If you have any questions about how we handle your personal data, please contact us at Support@insight-flowai.com.


2. What Data We Collect

We collect and process the following categories of personal data:

Category Data Collected Purpose
Account Information Email address, display name, authentication credentials Account creation, login, identity verification
Trading Data Trade records, P&L, notes, strategies, tags, account balances Core journaling and analytics functionality
Trade Images Screenshots and chart images you upload Visual trade documentation
User Preferences Theme, settings, base currency, timezone, notification preferences Personalising your App experience
Device Information Device model, OS version, unique device identifiers Crash reporting, compatibility, security
Usage Data Feature usage counts, session data, subscription status App improvement and usage limit enforcement
IP Addresses IP address at authentication, consent events, and server requests Security, fraud prevention, audit logging
Crash and Error Data Error logs, crash reports, performance diagnostics Bug fixing and App stability
Subscription and Billing Data Subscription status, purchase verification, transaction IDs Subscription management and entitlement verification
AI Chat History Conversation history with AI analysis features Providing AI-powered trade analysis and coaching
Communications Messages and feedback sent through the App or email Customer support and service improvement

We do not collect or store your payment card details. All payment processing is handled by Google Play or the Apple App Store.


3. Lawful Basis for Processing

Under Article 6 of the UK GDPR and EU GDPR, we process your personal data on the following lawful bases:

Data Category Lawful Basis GDPR Article Explanation
Account information Performance of contract Art. 6(1)(b) Necessary to create and maintain your account
Trading data Performance of contract Art. 6(1)(b) Core service: storing and analysing your trades
Trade images Performance of contract Art. 6(1)(b) Core service: visual trade documentation
User preferences Performance of contract Art. 6(1)(b) Necessary to deliver a personalised experience
Subscription and billing data Performance of contract Art. 6(1)(b) Necessary to manage your subscription and verify entitlements
Device information Legitimate interest Art. 6(1)(f) Ensuring App stability, security, and compatibility
Usage data Legitimate interest Art. 6(1)(f) Improving the App and enforcing fair usage limits
IP addresses Legitimate interest Art. 6(1)(f) Security, fraud prevention, and audit compliance
Crash and error data Legitimate interest Art. 6(1)(f) Maintaining App reliability and fixing bugs
AI chat history Consent Art. 6(1)(a) You explicitly opt in to AI analysis features
Marketing communications Consent Art. 6(1)(a) Only sent with your explicit opt-in consent
Consent records Legal obligation Art. 6(1)(c) Required to demonstrate compliance with data protection law
Billing records (retention) Legal obligation Art. 6(1)(c) Tax and accounting legal requirements

Legitimate interest assessments: We have conducted balancing tests for each legitimate interest purpose. The processing is necessary for our business operations, is minimally intrusive, and does not override your fundamental rights and freedoms. You can request details of these assessments by contacting Support@insight-flowai.com.


4. How We Use Your Data

We use the personal data we collect for the following purposes:


5. Data Sharing and Third Parties

We do not sell your personal data. We share data with third parties only as necessary to provide the Services:

Third Party Data Shared Purpose Location
Supabase All user data (encrypted) Database hosting, authentication, cloud storage EU (European region)
Google Email, profile info, subscription status Google Sign-In authentication, Google Play billing and subscription verification US and global
Sentry Device info, crash data, error logs Crash reporting and performance monitoring EU data hosting option selected
OpenAI Trading data, AI chat history (only with consent) AI-powered trade analysis and coaching features See OpenAI's privacy policy
Apple Subscription status (iOS users) App Store billing and subscription verification US and global

All third-party service providers are bound by Data Processing Agreements (DPAs) that ensure they process your data only on our instructions and in compliance with applicable data protection laws.

Additional Disclosure Circumstances

We may also disclose your personal data:


6. International Data Transfers

Your personal data may be transferred outside the United Kingdom and European Economic Area (EEA). We ensure all international transfers are protected by appropriate safeguards:

Where data is transferred to countries that have received an adequacy decision from the UK Secretary of State or the European Commission, no additional safeguards are required.

You may request a copy of the safeguards we have in place by contacting Support@insight-flowai.com.


7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

Data Category Retention Period Reason
Active account data (trading data, preferences, images) For as long as your account is active Necessary to provide the Services
Account data after deletion Deleted within 30 days of account deletion Data minimisation principle
Backup data Removed from backups within 90 days of deletion Technical backup cycle
Consent records 7 years after creation Legal obligation to demonstrate compliance
Billing and transaction records 7 years Tax and accounting legal requirements
Crash and error data 2 years App improvement and stability monitoring
Usage analytics data 2 years App improvement and trend analysis
AI chat history Deleted with account, or upon consent withdrawal Retained only while AI consent is active
Marketing consent records 7 years after last interaction Demonstrating consent compliance

After the retention period expires, data is securely deleted or irreversibly anonymised.


8. Your Rights

Under the UK GDPR and EU GDPR, you have the following rights regarding your personal data:

8.1 Right of Access (Article 15)

You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. You can access all your trading data directly through the App at any time.

8.2 Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data. You can update your profile information and edit trade records directly in the App.

8.3 Right to Erasure (Article 17)

You have the right to request deletion of your personal data. You can delete your account through the App at Settings → Delete Account, and we will erase your data within 30 days, except where retention is required by law (e.g., consent records, billing records).

8.4 Right to Restriction of Processing (Article 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

8.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You can export your trading data at any time using the App's export functionality.

8.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

8.7 Rights Related to Automated Decision-Making (Article 22)

We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Our AI features provide informational analysis only and do not make automated decisions about you.

8.8 Right to Withdraw Consent

Where processing is based on consent (AI analysis, marketing communications), you may withdraw your consent at any time through the App settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

How to Exercise Your Rights

You can exercise most of these rights directly through the App. For any requests you cannot fulfil through the App, or for any questions about your rights, contact us at Support@insight-flowai.com.

We will respond to your request within one month of receipt. If your request is complex or we receive a high volume of requests, we may extend this by a further two months, and we will inform you of any extension within the first month.

There is no fee for exercising your rights. However, if a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse the request.


9. Right to Complain

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with a supervisory authority:

United Kingdom

Information Commissioner's Office (ICO)

Website: https://ico.org.uk

Telephone: 0303 123 1113

Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

European Union

If you are located in the EU, you may also complain to your local Data Protection Authority (DPA). A list of EU DPAs is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

We encourage you to contact us first at Support@insight-flowai.com so we can try to resolve your concern directly.


10. Children's Privacy

The App is not directed at and is not intended for use by children under the age of 18. We do not knowingly collect personal data from children under 18. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at Support@insight-flowai.com and we will take steps to delete such information promptly.


11. Cookies and Tracking Technologies

The App is a mobile application and does not use cookies.

We may use the following technologies on your device:


12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

To exercise your CCPA/CPRA rights, contact us at Support@insight-flowai.com.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

The effective date at the top of this policy indicates when the current version took effect.


14. Financial Disclaimer

Trading Journal Pro is a journaling and analytics tool. It does not provide financial advice, investment advice, trading advice, or any other form of regulated financial service. The App is not regulated by the Financial Conduct Authority (FCA) or any other financial regulatory body.

AI-powered analysis features are for informational and educational purposes only. AI outputs may contain errors or inaccuracies. Past performance analysis does not predict future results. You should not rely on the App or its AI features for making investment or trading decisions. Always consult a qualified, regulated financial professional before making financial decisions.

Trading in financial markets involves substantial risk of loss. We accept no liability for any trading losses you may incur.


15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

For data protection specific inquiries, please include "Data Protection" in the subject line of your email.