Legal
Privacy Policy
Last updated: 2026-07-21
1. Overview
This Privacy Policy describes how The Journal Inc. (“we,” “us,” or “our”) collects, uses, stores, and protects your personal information when you use The Journal (“the Service”). We are committed to protecting your privacy and being transparent about our data practices.
2. Information We Collect
Information you provide
- Account information: Email address, name (if provided), and authentication credentials. If you sign in with a wallet, we collect your public wallet address.
- Exchange API keys: Read-only API keys and secrets for supported exchanges and brokerages. These are encrypted at rest and never exposed in plaintext after initial submission.
- User content: Trade notes, screenshots, tags, strategies, journal entries, session plans, and any other content you create within the Service.
Information we collect automatically
- Trading data: Trade history, order fills, positions, and balances fetched from connected exchanges and brokerages via your read-only API keys.
- AI chat messages: Content of conversations you have with the AI Coach feature, including prompts and responses.
- Usage data: Feature usage, page views, and interactions within the Service collected via PostHog analytics (see Section 7).
- Device and technical data: Browser type, operating system, IP address, and approximate location derived from IP.
3. How We Use Your Information
We use your information solely for the following purposes:
- To provide, maintain, and improve the Service — including importing your trades, computing analytics, and generating insights.
- To power the AI Coach and other AI features with context from your trading data and journal content.
- To process payments and manage your subscription.
- To communicate with you about your account, product updates, security alerts, and billing matters.
- To detect and prevent fraud, abuse, and security incidents.
- To analyze aggregated, anonymized usage patterns to improve the product and inform feature development.
- To comply with legal obligations and enforce our Terms of Service.
4. Data Storage and Security
All data is stored on infrastructure provided by Amazon Web Services (AWS) in the United States. We implement industry-standard security measures, including:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3.
- Encryption at rest: Exchange API secrets are encrypted at rest using AWS Key Management Service (KMS) with envelope encryption. Each API secret is encrypted with a unique data key.
- Database encryption: Our production databases use AES-256 encryption at rest.
- Access controls: Access to production systems and databases is restricted to authorized personnel on a need-to-know basis, enforced through IAM policies and multi-factor authentication.
- Infrastructure as code: All infrastructure changes are reviewed, version-controlled, and auditable.
While we take reasonable precautions, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
5. How We Share Your Information
We do not sell your personal information. We do not sell, rent, or trade your personal data, trading data, or any user content to third parties for their marketing purposes.
We may share your information in these limited circumstances:
- Service providers: We engage trusted third-party service providers who process data on our behalf to provide the Service. These include:
- AWS (cloud infrastructure and hosting)
- PostHog EU Cloud (product analytics)
- Stripe (payment processing)
- Anthropic and other AI providers (to power the AI Coach feature)
- Resend (transactional emails)
- Legal compliance: We may disclose information if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred as part of the transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
6. Data Retention and Deletion
We retain your data for as long as your account is active. If you delete your account, we permanently delete all Your Data (including trade data, notes, screenshots, strategies, and AI chat history) within 30 days. Exchange API keys are deleted immediately upon account deletion.
You may export your data at any time from your Account settings. You may also delete individual exchange connections, trade records, or content without deleting your entire account.
We may retain certain information after account deletion where required by law (such as transaction records for tax purposes), for fraud prevention, or to resolve disputes. Any retained data is stored in accordance with this policy and only for as long as necessary.
7. Cookies and Analytics
We use only essential cookies necessary for the operation of the Service — such as session cookies for authentication and preference cookies for theme settings. We do not use advertising cookies, tracking cookies for behavioral advertising, or third-party marketing cookies.
We use PostHog (hosted in the EU cloud region) for product analytics to understand how users interact with the Service and where we can improve. PostHog is configured to:
- Not collect personally identifiable information in analytics events beyond a randomly generated user ID.
- Not track users across different websites or services.
- Honor “Do Not Track” browser settings where applicable.
8. AI Features
The Service includes AI-powered features, including the AI Coach, trade insights, and other generative AI capabilities. When you use these features:
- Your trading data, journal entries, and conversation context are sent to our AI service providers (currently Anthropic) for processing.
- Data sent to AI providers is processed in real time and is not used by those providers to train their models.
- AI-generated responses are not financial advice and should not be treated as such.
9. Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal data:
GDPR (EU/EEA and UK)
If you are located in the European Union, European Economic Area, or the United Kingdom, you have the right to:
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erasure(“right to be forgotten”) — delete your data.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — limit how we process your data.
- Objection — object to certain types of processing.
Our legal basis for processing is the performance of our contract with you (providing the Service), your consent (where explicitly given), and our legitimate interests in improving the Service and preventing fraud.
CCPA (California)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion of your personal information; and to opt out of the sale of personal information (note: we do not sell personal information). We do not discriminate against users who exercise these rights.
To exercise any of these rights, email us at privacy@thejournal.app. We will respond within 30 days (or within the timeframe required by applicable law). We may ask you to verify your identity before fulfilling your request.
10. International Data Transfers
Your data is stored and processed in the United States. When we transfer personal data from the EU/EEA, UK, or other jurisdictions with data transfer restrictions, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, or adequacy decisions where applicable. Our service providers are contractually bound to equivalent data protection standards.
11. Children’s Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will delete it promptly. If you believe a child has provided us with personal information, please contact us.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email and/or through the Service at least 14 days before the changes take effect. The date at the top of this policy indicates when it was last revised. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or would like to exercise your data rights, contact us at:
Email: privacy@thejournal.app
Mail: The Journal Inc., [Insert Registered Address], United States
For GDPR-specific inquiries, you may also contact our EU Representative at eu-representative@thejournal.app.