Privacy Policy
This policy explains what information STRATLOG collects, why, and how it's handled. STRATLOG is operated by an individual sole trader based in Sweden.
1. What we collect
Account information
- Email address (required, to create and secure your account)
- Username (chosen by you at signup)
- Password — stored as a secure hash, never in plain text; we cannot see your actual password
Content you create
- Backtest sheets, logged conditions, saved patterns, and any other data you enter into the app
Payment information
If you subscribe to STRATLOG Pro, your payment is processed entirely by Stripe. We never receive or store your card number, expiry date, or CVC — Stripe handles that directly, and we only receive confirmation that a payment succeeded, along with your email so we can identify your account.
Automatically collected information
Our infrastructure providers (see Section 3) may log basic technical data such as IP address and browser type for security and abuse-prevention purposes. We don't use this for tracking or advertising.
2. How we use your information
- To create and maintain your account
- To sync your backtest data across the devices you sign in on
- To send account-related emails — confirming your email address, and (if you subscribe) payment-related notices
- To provide customer support if you contact us
- To detect and prevent fraud or abuse of the service
We do not use your data for advertising, and we do not sell or rent your personal information to third parties.
3. Third-party services we use
STRATLOG is built on a small number of infrastructure providers, each of which processes a limited slice of your data solely to provide their specific function:
| Provider | Purpose | What they handle |
|---|---|---|
| Supabase | Authentication & database | Your account, password (hashed), and backtest data |
| Stripe | Payment processing | Payment details, billing history |
| Resend | Transactional email | Your email address, to deliver account emails |
| Netlify | Website hosting | Standard web server logs |
Each of these providers has its own privacy policy governing how they handle data on our behalf.
4. Data storage & security
Your account data is stored in a Supabase-managed database with row-level security, meaning your data is only accessible to your own authenticated account — not to other users. Passwords are hashed, never stored in plain text. While we take reasonable steps to protect your information, no method of transmission or storage is 100% secure, and we can't guarantee absolute security.
5. Your rights
Depending on your location, you may have rights including the ability to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your account and associated data
- Export your data
If you're located in the European Economic Area, these rights are provided under the General Data Protection Regulation (GDPR). To exercise any of these rights, contact us at the email below.
6. Data retention
We retain your account data for as long as your account is active. If you delete your account, we delete your associated backtest data within a reasonable period, except where we're required to retain certain records (such as billing history) for legal or accounting purposes.
7. Cookies & local storage
STRATLOG uses browser local storage and essential cookies to keep you signed in and to remember your app preferences. We don't use tracking or advertising cookies.
8. Children's privacy
STRATLOG is not directed at, and not intended for use by, anyone under the age of 18.
9. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above.
10. Contact
Questions about this policy or your data? Reach out to privacy@stratlog.net.