Privacy Policy

Last updated: July 28, 2026 · Effective: July 28, 2026

Contents

  1. Who we are
  2. Data we collect
  3. How we use data
  4. Legal bases (GDPR)
  5. Who we share with
  6. AI processing
  7. Cookies & storage
  8. Data retention
  9. Security
  10. Your rights
  11. US state rights
  12. Children
  13. International transfers
  14. Changes
  15. Contact

1.Who we are

This Privacy Policy explains how Dany Liskovich ("note500", "we", "us"), operator of the note500 trade journaling and analytics application (the "Service"), collects and uses your personal data. The data controller is Dany Liskovich. For any privacy question, contact [email protected].

2.Data we collect

CategoryExamplesSource
Account data Email address, display name, hashed password, or Google Sign-In identifier. You / Google when you sign in.
Trade & journal content Trades, portfolios, entries/exits, tags, psychology notes, day notes, planned risk, and derived statistics. You (entered or imported).
Settings Theme, AI model preference, auto-review toggle, API keys you generate. You.
Support messages Name, email, and message content you submit via the support form. You.
Technical / usage data IP address, browser/device information, and server log timestamps recorded in access and error logs. Automatically.
Payment data Handled by Stripe when paid plans launch. We do not store full card numbers. Payment processor.

3.How we use data

  • To create and operate your account and provide the Service.
  • To store and display your trades, notes, and analytics.
  • To generate AI trade reviews when you request them or enable auto-review.
  • To respond to support requests.
  • To secure the Service, prevent abuse, and enforce our Terms.
  • To comply with legal obligations.
  • To send you service-related emails (email verification, password resets, and billing receipts).

We do not sell your personal data, and we do not use your trade content to advertise to you.

5.Who we share data with

We share personal data only with service providers ("processors") that help us run the Service, under contracts that require them to protect it:

  • Hosting / database — Oracle Cloud Infrastructure (server hosting) and MongoDB Atlas (database).
  • Authentication — Google (for Google Sign-In).
  • AI provider — Anthropic, to generate trade reviews (see Section 6).
  • Payments — Stripe.
  • Email — Resend (transactional email delivery).

We may also disclose data if required by law, to protect our rights, or in connection with a merger or acquisition (with notice where required).

6.AI processing

When you run an AI Trade Review (manually or via auto-review), relevant trade data — such as tickers, entries/exits, tags, and psychology notes — is sent to our AI provider, Anthropic, to generate the review. We send only what is needed for the review. Anthropic processes this data solely to return the review and, under its commercial API terms, does not use inputs or outputs to train its models.

7.Cookies & local storage

We use a session cookie (or equivalent) to keep you logged in, and browser local storage for small preferences such as your last tab and selected date ranges. We use a single essential authentication cookie to keep you signed in; we do not use analytics or third-party tracking cookies.

8.Data retention

We keep your account and trade data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where we must retain some data to comply with legal obligations or resolve disputes. Backups are purged on a rolling 30-day cycle.

9.Security

We use reasonable technical and organizational measures to protect your data, including password hashing, access controls, and encryption in transit (HTTPS). No system is perfectly secure; we cannot guarantee absolute security. Keep your password and API keys confidential and revoke API keys you no longer use.

10.Your rights

Depending on where you live, you may have the right to access, correct, export (portability), delete, or restrict processing of your personal data, and to object to certain processing. You can export or request deletion of your journal at any time — self-serve export is available in the app, and you can request full deletion via [email protected] or the support page. We will respond within the time required by applicable law. You may also lodge a complaint with your data protection authority.

11.US state privacy rights

If you are a resident of California or another US state with a privacy law, you may have rights to know, access, delete, and correct your personal data, and to opt out of "sale" or "sharing." We do not sell or share your personal data as those terms are defined by these laws. To exercise your rights, contact [email protected]. We will not discriminate against you for exercising them.

12.Children

The Service is not directed to children under 18, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

13.International transfers

We and our providers may process data in countries other than yours, including the United States. Where required, we use appropriate safeguards such as Standard Contractual Clauses for such transfers.

14.Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice where appropriate.

15.Contact

Questions or requests about your privacy? Contact [email protected].