Privacy Policy

Last updated: August 29, 2026

This policy explains what information STRATLOG collects, why, and how it's handled. STRATLOG is operated by an individual sole trader based in Sweden.

In short: if you use STRATLOG without creating an account, your data never leaves your browser. If you create an account, we collect your email, an optional username, and the backtest data you enter, so we can run your account and sync your worksheets across devices. We don't sell your data. Payment card details never touch our servers — Stripe handles that directly.

1. What we collect

Using STRATLOG without an account

You can use STRATLOG's core backtesting features without creating an account. In that case, your worksheets, logged conditions, and saved patterns are stored only in your own browser's local storage. That data is never transmitted to or stored on our servers, and we have no way to see or access it. It also means we can't back it up or recover it for you — if you clear your browser's data or switch devices, it's gone, which is why we recommend creating a free account if you want your data preserved.

Account information

Content you create

Payment information

If you subscribe to STRATLOG Pro, your payment is processed entirely by Stripe. We never receive or store your card number, expiry date, or CVC — Stripe handles that directly, and we only receive confirmation that a payment succeeded, along with your email so we can identify your account.

Automatically collected information

Our infrastructure providers (see Section 3) may log basic technical data such as IP address and browser type for security and abuse-prevention purposes. We don't use this for tracking or advertising.

2. How we use your information

We do not use your data for advertising, and we do not sell or rent your personal information to third parties.

3. Third-party services we use

STRATLOG is built on a small number of infrastructure providers, each of which processes a limited slice of your data solely to provide their specific function:

ProviderPurposeWhat they handle
SupabaseAuthentication & databaseYour account, password (hashed), and backtest data
StripePayment processingPayment details, billing history
ResendTransactional emailYour email address, to deliver account emails
NetlifyWebsite hostingStandard web server logs

Each of these providers has its own privacy policy governing how they handle data on our behalf. If you use our anonymous, no-account backtesting features, none of these providers receive your worksheet data, since it never leaves your browser.

4. Data storage & security

Your account data is stored in a Supabase-managed database with row-level security, meaning your data is only accessible to your own authenticated account — not to other users. Passwords are hashed, never stored in plain text. While we take reasonable steps to protect your information, no method of transmission or storage is 100% secure, and we can't guarantee absolute security.

5. If a data breach happens

If we become aware of a security incident that compromises your personal data, we'll investigate promptly and take reasonable steps to contain it. Where required by law — including under the GDPR if you're in the European Economic Area — we'll notify the relevant data protection authority within the required timeframe, and notify affected users without undue delay where the breach poses a meaningful risk to you. Any such notice will explain what happened, what data was involved, and what steps we're taking in response.

6. Your rights

Depending on your location, you may have rights including the ability to:

If you're located in the European Economic Area, these rights are provided under the General Data Protection Regulation (GDPR). To exercise any of these rights, contact us at the email below.

7. Data retention

We retain your account data for as long as your account is active. If you delete your account, we delete your associated backtest data within a reasonable period, except where we're required to retain certain records (such as billing history) for legal or accounting purposes.

8. Local storage

STRATLOG uses your browser's local storage to keep you signed in and remember your app preferences and, for anonymous use, your actual backtest data. We don't set tracking or advertising cookies.

9. Children's privacy

STRATLOG is not directed at, and not intended for use by, anyone under the age of 18.

10. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above.

11. Contact

Questions about this policy or your data? Reach out to privacy@stratlog.net.

This policy is provided for transparency and does not constitute legal advice. It has not been reviewed by a lawyer.