This Privacy Policy explains how Dany Liskovich ("note500", "we", "us"), operator of the note500 trade journaling and analytics application (the "Service"), collects and uses your personal data. The data controller is Dany Liskovich. For any privacy question, contact [email protected].
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, display name, hashed password, or Google Sign-In identifier. | You / Google when you sign in. |
| Trade & journal content | Trades, portfolios, entries/exits, tags, psychology notes, day notes, planned risk, and derived statistics. | You (entered or imported). |
| Settings | Theme, AI model preference, auto-review toggle, API keys you generate. | You. |
| Support messages | Name, email, and message content you submit via the support form. | You. |
| Technical / usage data | IP address, browser/device information, and server log timestamps recorded in access and error logs. | Automatically. |
| Payment data | Handled by Stripe when paid plans launch. We do not store full card numbers. | Payment processor. |
We do not sell your personal data, and we do not use your trade content to advertise to you.
Where the GDPR or UK GDPR applies, we process personal data on these bases: contract (to provide the Service you signed up for), legitimate interests (securing and improving the Service), consent (where required, e.g. optional analytics or marketing), and legal obligation. You may withdraw consent at any time.
When you run an AI Trade Review (manually or via auto-review), relevant trade data — such as tickers, entries/exits, tags, and psychology notes — is sent to our AI provider, Anthropic, to generate the review. We send only what is needed for the review. Anthropic processes this data solely to return the review and, under its commercial API terms, does not use inputs or outputs to train its models.
We keep your account and trade data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where we must retain some data to comply with legal obligations or resolve disputes. Backups are purged on a rolling 30-day cycle.
We use reasonable technical and organizational measures to protect your data, including password hashing, access controls, and encryption in transit (HTTPS). No system is perfectly secure; we cannot guarantee absolute security. Keep your password and API keys confidential and revoke API keys you no longer use.
Depending on where you live, you may have the right to access, correct, export (portability), delete, or restrict processing of your personal data, and to object to certain processing. You can export or request deletion of your journal at any time — self-serve export is available in the app, and you can request full deletion via [email protected] or the support page. We will respond within the time required by applicable law. You may also lodge a complaint with your data protection authority.
If you are a resident of California or another US state with a privacy law, you may have rights to know, access, delete, and correct your personal data, and to opt out of "sale" or "sharing." We do not sell or share your personal data as those terms are defined by these laws. To exercise your rights, contact [email protected]. We will not discriminate against you for exercising them.
The Service is not directed to children under 18, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
We and our providers may process data in countries other than yours, including the United States. Where required, we use appropriate safeguards such as Standard Contractual Clauses for such transfers.
We may update this Privacy Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice where appropriate.
Questions or requests about your privacy? Contact [email protected].