Legal
Privacy Policy
Last updated August 13, 2026
1. Scope and Who We Are
This Privacy Policy explains how TheProfitPath ("TheProfitPath," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit our websites, create an account, use our trading journal and analytics platform, or communicate with us (collectively, the "Service"). For purposes of applicable data protection law, TheProfitPath is the controller of the personal information described in this policy unless we state otherwise.
This policy is a notice about our privacy practices, not a request for consent. Where consent is required, we will ask for it separately. If you use the Service on behalf of an organization or share information about another person, you are responsible for having authority to do so.
2. Information You Provide
Depending on how you use the Service, you may provide:
- Account and profile information: name, email address, username, password hash, avatar, biography, public-profile setting, theme and interface preferences, and email-verification status.
- Security and developer information: two-factor authentication settings, recovery-code hashes, active sessions, organization memberships, and API-key names, prefixes, scopes, last-use times, and API request records. We store API-key hashes rather than the full key after it is issued.
- Trading and journal information: trades, positions, symbols, prices, quantities, profit and loss, account names and balances, account cash-flow records, targets, risk rules, prop-firm phases, strategies, playbooks, backtests, goals, tags, notes, checklists, screenshots, emotions, confidence ratings, mistakes, lessons, reports, and other content you choose to record.
- Integration and import information: CSV files and filenames; Notion workspace details, selected pages, imported text, images, and encrypted connection tokens; and any broker or other connection information you choose to provide. Do not provide credentials unless a feature specifically requests them.
- AI information: AI Tutor prompts, messages, attachments, message-level ratings and optional feedback notes, selected journal or trade context, projects and the chats filed in them, chat searches, @ mentions that scope a request, conversation history, generated responses, automatic period reports and their scores, derived memories, insights or learning signals, and AI-turn metadata such as the task and response mode, model, tools used, failures, evidence summary, and latency. For research-backed turns, we may also retain source URLs, hostnames, titles, bounded excerpts, query hashes, publication and retrieval dates, authority indicators, and relevance scores.
- Voice information: when you start a call in live voice mode, audio captured from your device microphone for the duration of that call, the transcript produced from it, the spoken reply generated for you, and your voice settings such as the character and language you select. Your browser asks for microphone permission before any audio is captured, and audio is captured only while a call is active.
- Market Monitor information: the instruments, timeframes, layouts, and other Market Monitor preferences saved to your account, and the market reports generated for the instruments you view.
- Community and collaboration information: profile content, public posts, comments, likes, saves, follows, blocks, stories, story views, shared trades or achievements and the trade fields you choose to reveal, direct messages including images, video, and GIFs you send, mentor connections, and content shared with mentors or students.
- Support and feedback information: your name, email, support messages, attachments, the page from which you contacted us, customer-satisfaction responses, bug reports, feature requests, and product-tour activity. Visitors who are not signed in may provide this information through guest support.
- Billing and commercial information: subscription tier, billing status, Stripe customer and subscription identifiers, coupon or referral activity, and transaction-related records. Stripe processes payment-card details; we do not store full card numbers on our servers.
- Notification choices: email and in-app notification preferences, delivery state, and interactions with notifications.
- Safety, enforcement, and appeal information: reports and safety signals, case summaries, content or activity submitted or preserved as evidence, encrypted evidence copies and excerpts, source and integrity metadata, risk and severity assessments, AI and human decision records, warnings or access restrictions, enforcement history, appeal statements and outcomes, legal holds, administrator notes, and chain-of-custody and audit records.
3. Information We Collect Automatically
When you use the Service, we and our service providers may automatically collect technical and activity information such as your IP address, approximate location derived from IP, browser and device type, operating system, requested pages and API routes, referring URL, dates and times, session activity, feature interactions, error records, security events, and rate-limit or abuse signals.
We may combine this information with account information and User Content to operate the Service, maintain security, troubleshoot problems, understand feature usage, investigate suspected violations, preserve evidence, enforce our Terms, and improve performance. Safety and audit records may include the relevant account or content identifier, actor, action, reason, request or session identifier, IP address, user agent, time, hashes, prior and resulting access state, and related metadata.
Product activity records. While you are signed in, we record a timeline of how your account uses the Service so we can reproduce problems, answer support requests, investigate abuse, and see which features work. These records may include the pages you open, the elements you interact with, which form field you moved through, errors your browser reported, the API routes your actions call, a session identifier, and the time and duration of each event.
These records capture identity, not content. We do not record the values you type into fields, the contents of your clipboard, or the query strings attached to a page — only which field, which element, and which route was involved. Authorized administrators can view this timeline for an account when operating and supporting the Service, and it is not visible to other users. We retain these records for a limited period, currently 90 days, after which they are deleted in the ordinary course. The recording is governed by a platform setting we control and can be switched off for the whole Service; you may also object to this processing as described in the section on your choices and privacy rights below.
We do not use product activity records to build advertising profiles or to sell information about you. Product activity records are not used by themselves to make decisions that produce legal or similarly significant effects. Separate safety systems may use account activity, User Content, security signals, and preserved evidence to recommend or apply Service-access enforcement as described below.
4. Information From Other Sources
- Google: If you sign in with Google, we receive information authorized through the Google sign-in flow, such as your Google account identifier, name, email address, and profile image.
- Notion and connected services: At your direction, we receive workspace information and content that you authorize the Service to access or import.
- Other users: We receive information when another user follows, mentions, messages, connects with, reports, or otherwise interacts with you.
- Payment, email, market-data, and infrastructure providers: We may receive transaction status, delivery status, security signals, and operational information needed to provide the Service.
- Market data and charting providers: We retrieve prices, candles, news, and calendar information from market-data sources to build Market Monitor and its reports. This information is about instruments and markets rather than about you.
5. Cookies and Local Storage
We use cookies, browser local storage, session storage, and similar technologies. These technologies may store authentication and session tokens, CSRF security values, OAuth state, guest-support identifiers, theme and accent choices, sidebar and dashboard preferences, calendar filters, recent community selections, AI response-mode and voice preferences, Market Monitor layout choices, activity-session identifiers, and demo or tour state.
- Strictly necessary and security: Used to sign you in, maintain sessions, prevent request forgery, complete OAuth, apply rate limits, and protect the Service.
- Functional: Used to remember appearance, filters, layouts, and other choices you make.
- Measurement: We may record first-party product and support activity to understand reliability and feature use.
Embedded third-party content. Some pages, including Market Monitor charts, load content directly from a third-party provider inside a frame. That provider receives your request and may set its own cookies or storage under its own privacy policy and outside our control. GIFs offered in the message composer are likewise loaded from their providers' content networks, which receive the request that displays them.
We do not currently use third-party advertising cookies or behavioral advertising on the Service. You can clear or block browser storage through your browser, but essential features may stop working.
6. How and Why We Use Information
We use personal information to:
- create and administer accounts, authenticate users, and provide requested features;
- store, organize, analyze, import, synchronize, display, and export trading content;
- authenticate scoped API requests and provide the journal, collaboration, notification, calendar, news, and eligible Market Monitor resources that you authorize an external application to access;
- provide AI Tutor, live voice conversations, vision analysis, reports, coaching, insights, evidence-assisted web research, search, and personalization, and store bounded source provenance and run metadata for reliability and evaluation;
- provide Market Monitor charts, market data, news, calendars, and generated market reports;
- operate community, direct-messaging, mentor, organization, sharing, referral, and support features;
- process subscriptions, coupons, trials, renewals, cancellations, and related communications;
- send service, account, security, support, and opted-in notification emails;
- detect fraud, abuse, prohibited conduct, and security incidents; create and analyze safety cases; preserve and verify evidence; apply, review, reverse, and audit warnings or access restrictions; and handle appeals under our Terms of Service;
- debug, measure, maintain, and improve the Service and develop new features, including by reviewing product activity records to reproduce a reported problem;
- create aggregated or de-identified statistics, evaluations, and learning materials; and
- comply with law, respond to valid legal requests, resolve disputes, and protect rights and safety.
7. Legal Bases for Processing
Where applicable law requires a legal basis, we rely on one or more of the following:
- Contract: Processing necessary to create your account, provide the Service you request, manage subscriptions, and fulfill our Terms.
- Legitimate interests: Securing, maintaining, supporting, measuring, and improving the Service; preventing fraud and abuse; protecting users; and developing useful features, balanced against your rights and expectations.
- Consent: Where we specifically ask for consent, including for certain optional communications or technologies. You may withdraw consent at any time without affecting prior processing.
- Legal obligation: Processing needed for tax, accounting, consumer-protection, sanctions, lawful-request, and other legal requirements.
8. AI, Personalization, and Service Improvement
When you use AI features, we may send your prompt, attached images, relevant conversation history, and selected trading or journal context to an AI service provider, currently including Mistral AI, so the provider can generate a response. The context sent depends on your request and may include information from your account that the feature determines is relevant. If you scope a request to a project or an @ mention, the content within that scope is what we send as context. Where a request calls for current information, a search query derived from it may be sent to a web-search provider, currently Tavily.
Live voice mode. While a voice call is active, audio from your microphone is streamed through our real-time voice gateway to a speech provider, currently Mistral AI, which converts it to text; the reply is then converted back to speech and played to you. Audio is processed to produce that transcript and reply and is not retained by us as a recording. The transcript, the reply, and any memories derived from them are stored with your other AI conversations and are used the same way, so a voice call and a typed chat share the same history and context. Your browser controls microphone permission, and no audio is captured outside an active call.
We store AI conversations, feedback, generated content, and derived learning records to preserve conversation history, personalize later responses, evaluate quality and safety, troubleshoot, and improve the Service. We may create training or evaluation examples from selected interactions after applying measures designed to remove or generalize identifiers, financial amounts, dates, account IDs, image links, and similar details. Approved de-identified examples may be used to improve or fine-tune our AI systems through an AI provider.
De-identification reduces privacy risk but may not eliminate every risk in free-form text. Do not include information about yourself or others that is unnecessary for your request. Information that has been irreversibly anonymized so it can no longer reasonably identify a person is not treated as personal information under this policy.
Safety review and access enforcement. Separate from AI Tutor guidance, our safety systems may send case summaries and relevant evidence to AI providers, currently including Mistral AI, for classification and independent adjudication. The systems may assess category, severity, confidence, evidence sufficiency, proposed action, affected scopes, duration, and rationale. When enabled and the configured evidence and confidence requirements are met, a warning, throttling, feature restriction, suspension, or permanent ban may be applied automatically. We also retain decision hashes and related records so the process can be audited.
AI Tutor guidance does not itself make legal or similarly significant decisions about you. Safety enforcement affects access to the Service and may be automated, but an available appeal is reviewed by an authorized person using the original case and preserved evidence. Automated systems may be wrong; you may challenge an enforcement through the appeal route presented by the Service or contact us using the details below. AI-generated trading or financial content may be inaccurate and should be independently reviewed.
9. How We Disclose Information
We may disclose personal information to:
- Vendors and processors: Providers that support hosting, databases, content delivery, image and video storage and playback (such as Cloudinary), AI processing including generation, speech recognition, speech synthesis, and safety classification or adjudication (such as Mistral AI), payments (Stripe), email delivery (Resend), web search (such as Tavily), market data, charting, news sources, security, and support. They may process information only to perform services for us or as otherwise permitted by their terms and applicable law.
- Embedded and media providers: Charting embeds and GIF providers (such as Tenor and Giphy) receive the requests your browser makes to display their content, under their own privacy policies. We do not send them your journal, trade, or conversation information.
- Integrations you choose: Services such as Google and Notion when you connect an account, authorize access, or request an import. An external application to which you give an API key can receive or change the resources permitted by that key until you revoke it; that application's independent handling of exported data is governed by its own terms and privacy practices.
- Other users and the public: Information you place in a public profile, post, comment, story, shared AI thread, shared trade, achievement, or other public area. Direct messages are visible to their participants and are not public, but they are not end-to-end encrypted and may be accessed when reasonably necessary for support, safety, security, enforcing our Terms, or legal compliance.
- Authorized administrators: Personnel with an operational need may access account, profile, journal, trade, AI, community, support, safety, enforcement, and related records to operate and support the Service, investigate abuse or security incidents, review evidence and appeals, enforce our Terms, and comply with law. Administrative access is subject to role controls and may be recorded in tamper-evident audit logs.
- Mentors, students, and organizations: Information made available through a mentor connection or shared workspace. Review your connections and sharing choices before posting sensitive journal information.
- Someone who referred you: If you joined through another user's referral link, that user can see that you signed up and whether the referral qualified, and can export a list of the people they referred that includes username, email address, and those dates. We require them to use it only for the referral program and in line with applicable privacy law. If you would rather this not apply to you, do not sign up through a referral link.
- Professional advisers: Lawyers, accountants, auditors, insurers, and similar advisers subject to confidentiality duties.
- Authorities and affected parties: When we reasonably believe disclosure is required by law or necessary to protect the Service, users, our rights, or the rights and safety of others.
- Transaction participants: Parties involved in a financing, reorganization, merger, acquisition, sale, insolvency, or similar business transaction, subject to appropriate confidentiality protections.
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising or use it to serve targeted ads.
10. Public Content and Sharing
Public profiles and content can be viewed, copied, indexed, reshared, or captured by others. Deleting content from the Service may not remove copies already shared by other users, stored in browser or search caches, or retained where legally permitted.
Mentor mode and shared AI links can reveal journal, analytics, or conversation information to the people who receive access. Only connect with people you trust, check whether a profile or item is public, and remove sensitive details before sharing.
11. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this policy. Retention depends on the type of information, whether your account is active, the sensitivity of the information, operational and security needs, applicable limitation periods, and legal, tax, accounting, or dispute-resolution requirements.
- Account, journal, community, mentor, and AI content is generally retained while your account or the relevant feature remains active, unless you delete it or request deletion.
- Subscription, transaction, audit, fraud-prevention, security, safety-case, decision, enforcement, appeal, custody, and support records may be retained after account closure when needed for legal compliance, legitimate business records, dispute resolution, or protection of the Service.
- Preserved safety evidence is assigned a retention period of approximately seven years by default. Evidence and linked records may be retained longer under a legal hold, to establish, exercise, or defend legal claims, to comply with law, or where deletion would undermine the integrity of a tamper-evident audit or chain-of-custody record.
- Product activity records are retained for a limited period, currently 90 days, and are then pruned automatically.
- Voice audio is not retained as a recording; the transcript and any derived memories follow the retention that applies to your AI conversations.
- Expired stories and deleted content may remain for a limited period in backups, logs, or abuse-prevention records before being overwritten in the ordinary course.
- De-identified or aggregated information that no longer reasonably identifies you may be retained for analytics, safety, research, and Service improvement.
12. Security
We use technical and organizational safeguards designed to protect personal information, including transport encryption, password hashing, role-based access controls, session controls, rate limiting, encryption for selected secrets such as two-factor and Notion connection secrets, encryption of safety evidence and appeal statements, integrity hashes, append-only custody records, and tamper-evident audit chaining. Access is limited according to operational need, and access to evidence contents and legal-hold controls may require elevated authorization and two-factor authentication. Live voice mode runs through a dedicated real-time gateway we operate separately from the main application; audio reaches it over an encrypted connection and is held only for as long as the call needs it.
No system is completely secure. You are responsible for protecting your password, recovery codes, API keys, connected-service credentials, and devices; enabling two-factor authentication where available; and notifying us promptly if you suspect unauthorized access.
13. International Data Transfers
We and our providers may process information in countries other than the one where you live, including the United States and countries in the European Economic Area. Those countries may have different data protection laws. Where required, we use a recognized transfer mechanism or safeguard, such as an adequacy decision or approved contractual protections. You may contact us for more information about applicable safeguards.
14. Your Choices and Privacy Rights
You can manage certain information directly by:
- editing your profile and public-profile setting;
- deleting individual trades, posts, comments, stories, AI threads, projects, and other supported content;
- ending a voice call, muting the microphone, or withdrawing microphone permission in your browser;
- choosing which trade fields a shared post reveals before you publish it;
- disconnecting Notion, mentors, students, or other integrations;
- revoking API keys and active sessions;
- using a read-only key where possible and reviewing its resource scopes and last-use time before leaving an integration connected;
- changing notification preferences or using an email unsubscribe link where available; and
- clearing cookies or local storage through your browser.
Depending on where you live, you may have rights to request access to personal information, correction, deletion, restriction, portability, or information about processing; to object to certain processing; to withdraw consent; and to appeal a refusal of a request. You may also have the right to complain to your local data protection or privacy authority.
If access is restricted or suspended and the Service presents an appeal route, you may submit an appeal statement for review by an authorized person. You may also contact us to request information about the enforcement, challenge incorrect facts, or ask for human review where applicable law provides that right.
To exercise a privacy right, request an account-level data export, or request account deletion, contact us as described below. We may need to verify your identity. Deletion and objection rights are not absolute: we may retain safety evidence, legal-hold material, and audit, custody, decision, enforcement, appeal, security, transaction, or dispute records where applicable law permits or requires it. We will respond within the period required by applicable law.
15. Children
The Service is intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided personal information, contact us so we can investigate and take appropriate action.
16. Third-Party Services
Third-party websites, integrations, market-data sources, payment services, and linked content operate under their own terms and privacy policies. This policy does not govern their independent processing. Review their policies before connecting an account, following a link, or providing information.
17. Do Not Track and Global Privacy Control
Because there is no uniform standard for browser Do Not Track signals, the Service does not currently respond to them. We do not sell personal information or use it for cross-context behavioral advertising, so a Global Privacy Control signal does not change those practices. If our practices change, we will update this policy and honor legally required signals.
18. Changes to This Policy
We may update this Privacy Policy to reflect changes to the Service, our practices, or legal requirements. We will post the revised policy and update the date above. If a change materially affects your rights or how we use personal information, we will provide additional notice when required, such as through the Service or by email.
We will request consent for a new use when applicable law requires consent; continued use alone will not be treated as consent where an affirmative choice is required.
19. Contact Us
For privacy questions or requests, use the support chat available on the Service or submit a request through our contact support page. Please write "Privacy Request" in the subject or first line and identify the account email involved.
TheProfitPath
Privacy requests: Support chat or contact support page
This Privacy Policy should be read together with our Terms of Service.
