Draft — needs legal review. Trading, AI, broker data and subscriptions require counsel sign-off (AFM / GDPR / consumer law). Placeholders remain where noted.

Privacy Policy

Effective date: 30 April 2026 (confirm at launch)

This Privacy Policy explains how Trading OS, trading as AXE Companion and/or Trading OS, processes personal data when you use our websites, apps, dashboards, AI features, account tools, journal features and connected services.

1. Controller

Controller: Trading OS
KvK: 74239422
VAT: NL002314900B21
Address: [BUSINESS ADDRESS]
Privacy contact: support@tradingosapp.com

2. Personal data we process

We may process:

Account and identity data

  • email address
  • user ID
  • login/session data
  • profile name
  • account settings
  • onboarding answers

Subscription and payment data

  • subscription plan
  • billing status
  • Stripe/customer identifiers
  • invoices/payment status
  • VAT/country information where needed

We do not store full card details ourselves.

Trading account metadata

  • connected account label
  • provider
  • masked login
  • server/broker name
  • connection method
  • provider status
  • sync timestamps
  • account snapshots where available

Trade and journal data

  • symbols
  • side/direction
  • size/volume
  • open/close time
  • open/close price
  • P&L
  • fees/commission/swap
  • trade tags/labels
  • journal notes
  • screenshots/attachments if supported
  • strategy tags and review ratings

Chat and AI data

  • chat messages
  • prompts
  • AI responses
  • AXE memory
  • user rules
  • knowledge preferences
  • active symbol/account context used for responses

Notes and watchlist data

  • notes
  • tags
  • watchlists
  • symbols
  • alerts
  • preferences

Technical and usage data

  • IP address
  • device/browser data
  • app logs
  • error logs
  • feature usage
  • usage counters
  • cookies/session identifiers
  • security logs

Market/context data

Where relevant, we may store or cache market context, news context, macro context or analysis snapshots linked to your workspace.

3. How we collect data

  • directly from you;
  • through your use of the app;
  • from connected accounts or integrations you authorise;
  • from payment providers;
  • from authentication and hosting infrastructure;
  • from support communication.

4. Purposes and legal bases

Provide the service — Legal basis: contract. Account access, app functionality, journal, chat, connected accounts, analytics, alerts, account sync.

Improve and secure the service — Legal basis: legitimate interests. Debugging, abuse prevention, security logging, performance improvements, service reliability.

Personalise AXE output — Legal basis: contract and/or legitimate interests. Using journal, memory, trades and preferences to provide relevant responses.

Billing and subscription management — Legal basis: contract and legal obligations. Payment status, invoices, tax records, subscription access.

Legal compliance — Legal basis: legal obligation. Accounting, tax obligations, lawful requests, compliance records.

Marketing communication — Legal basis: consent or legitimate interests where allowed. Product updates, waitlist communication, launch news, marketing emails where permitted.

5. AI processing

AXE may use your chat messages, journal entries, trade history, notes, memory, active account, watchlist and market context to produce responses.

AI outputs may be generated through third-party AI providers such as OpenAI or similar providers. We aim to send only the data needed to provide the requested AI feature.

Do not enter highly sensitive personal information into the chat unless necessary.

6. Broker and MT5 data

If you connect a broker or MT5 account, we process the data needed for analytics, journal, account insights and AXE context.

Where possible, use read-only/investor access. We do not store raw passwords in normal frontend storage. Server-side providers or secure functions may process credentials for connection setup where required.

7. Sharing with processors and subprocessors

We may use subprocessors such as:

  • Supabase — database, auth, storage, backend
  • OpenAI or AI provider — AI responses
  • Stripe — billing and payments
  • Vercel or hosting provider — hosting/deployment
  • Cloudflare — security, CDN, workers, realtime infrastructure
  • MetaApi or MT5 connector provider — account connection/sync
  • market-data providers — market/news/macro data
  • analytics/error tools — diagnostics and product improvement

A more detailed list is available on the Subprocessors page.

8. International transfers

Some providers may process data outside the European Economic Area. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions or other lawful transfer mechanisms.

9. Retention

We keep data only as long as needed for the purposes described above.

Typical retention: account data while your account exists; billing records as required by tax/accounting law; journal/trade data until deleted by you or account deletion, unless retention is legally required; logs for a limited period unless needed for security/legal purposes; AI memory until deleted/reset by you where supported.

Exact retention may depend on product settings and legal obligations.

10. Your rights

Depending on your location and applicable law, you may have rights to:

  • access your personal data
  • correct data
  • delete data
  • restrict processing
  • object to processing
  • data portability
  • withdraw consent
  • lodge a complaint with a supervisory authority

For GDPR requests, contact: support@tradingosapp.com

11. Security

We use reasonable technical and organisational measures to protect personal data, including authentication, RLS/access controls, server-side secrets, encryption in transit, role-based access and logging where appropriate.

No system is 100% secure.

12. Cookies and tracking

We use necessary cookies/session storage for authentication and app functionality. Analytics or marketing cookies are described in our Cookie Policy.

13. Children

The services are not intended for children. Users must be old enough to enter into a binding agreement and use trading-related tools lawfully in their jurisdiction.

14. Changes

We may update this Privacy Policy. If changes are material, we will take reasonable steps to notify you.

15. Contact

Privacy questions: support@tradingosapp.com