Legal
Privacy Policy
Last updated July 11, 2026
1. Scope and Who We Are
This Privacy Policy explains how TheProfitPath ("TheProfitPath," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit our websites, create an account, use our trading journal and analytics platform, or communicate with us (collectively, the "Service"). For purposes of applicable data protection law, TheProfitPath is the controller of the personal information described in this policy unless we state otherwise.
This policy is a notice about our privacy practices, not a request for consent. Where consent is required, we will ask for it separately. If you use the Service on behalf of an organization or share information about another person, you are responsible for having authority to do so.
2. Information You Provide
Depending on how you use the Service, you may provide:
- Account and profile information: name, email address, username, password hash, avatar, biography, public-profile setting, theme and interface preferences, and email-verification status.
- Security and developer information: two-factor authentication settings, recovery-code hashes, active sessions, organization memberships, and API-key names, prefixes, scopes, and usage records. We store API-key hashes rather than the full key after it is issued.
- Trading and journal information: trades, positions, symbols, prices, quantities, profit and loss, account names and balances, strategies, playbooks, backtests, goals, tags, notes, checklists, screenshots, emotions, confidence ratings, mistakes, lessons, reports, and other content you choose to record.
- Integration and import information: CSV files and filenames; Notion workspace details, selected pages, imported text, images, and encrypted connection tokens; and any broker or other connection information you choose to provide. Do not provide credentials unless a feature specifically requests them.
- AI information: AI Tutor prompts, messages, attachments, feedback, selected journal or trade context, conversation history, generated responses, and derived memories, insights, or learning signals.
- Community and collaboration information: profile content, public posts, comments, likes, saves, follows, blocks, stories, story views, shared trades or achievements, direct messages, mentor connections, and content shared with mentors or students.
- Support and feedback information: your name, email, support messages, attachments, the page from which you contacted us, customer-satisfaction responses, bug reports, feature requests, and product-tour activity. Visitors who are not signed in may provide this information through guest support.
- Billing and commercial information: subscription tier, billing status, Stripe customer and subscription identifiers, coupon or referral activity, and transaction-related records. Stripe processes payment-card details; we do not store full card numbers on our servers.
- Notification choices: email and in-app notification preferences, delivery state, and interactions with notifications.
3. Information We Collect Automatically
When you use the Service, we and our service providers may automatically collect technical and activity information such as your IP address, approximate location derived from IP, browser and device type, operating system, requested pages and API routes, referring URL, dates and times, session activity, feature interactions, error records, security events, and rate-limit or abuse signals.
We may combine this information with account information to operate the Service, maintain security, troubleshoot problems, understand feature usage, and improve performance.
4. Information From Other Sources
- Google: If you sign in with Google, we receive information authorized through the Google sign-in flow, such as your Google account identifier, name, email address, and profile image.
- Notion and connected services: At your direction, we receive workspace information and content that you authorize the Service to access or import.
- Other users: We receive information when another user follows, mentions, messages, connects with, reports, or otherwise interacts with you.
- Payment, email, market-data, and infrastructure providers: We may receive transaction status, delivery status, security signals, and operational information needed to provide the Service.
5. Cookies and Local Storage
We use cookies, browser local storage, session storage, and similar technologies. These technologies may store authentication and session tokens, CSRF security values, OAuth state, guest-support identifiers, theme and accent choices, sidebar and dashboard preferences, calendar filters, recent community selections, AI response-mode preferences, and demo or tour state.
- Strictly necessary and security: Used to sign you in, maintain sessions, prevent request forgery, complete OAuth, apply rate limits, and protect the Service.
- Functional: Used to remember appearance, filters, layouts, and other choices you make.
- Measurement: We may record first-party product and support activity to understand reliability and feature use.
We do not currently use third-party advertising cookies or behavioral advertising on the Service. You can clear or block browser storage through your browser, but essential features may stop working.
6. How and Why We Use Information
We use personal information to:
- create and administer accounts, authenticate users, and provide requested features;
- store, organize, analyze, import, synchronize, display, and export trading content;
- provide AI Tutor, vision analysis, reports, coaching, insights, search, and personalization;
- operate community, direct-messaging, mentor, organization, sharing, referral, and support features;
- process subscriptions, coupons, trials, renewals, cancellations, and related communications;
- send service, account, security, support, and opted-in notification emails;
- detect fraud, abuse, prohibited conduct, and security incidents, and enforce our Terms of Service;
- debug, measure, maintain, and improve the Service and develop new features;
- create aggregated or de-identified statistics, evaluations, and learning materials; and
- comply with law, respond to valid legal requests, resolve disputes, and protect rights and safety.
7. Legal Bases for Processing
Where applicable law requires a legal basis, we rely on one or more of the following:
- Contract: Processing necessary to create your account, provide the Service you request, manage subscriptions, and fulfill our Terms.
- Legitimate interests: Securing, maintaining, supporting, measuring, and improving the Service; preventing fraud and abuse; protecting users; and developing useful features, balanced against your rights and expectations.
- Consent: Where we specifically ask for consent, including for certain optional communications or technologies. You may withdraw consent at any time without affecting prior processing.
- Legal obligation: Processing needed for tax, accounting, consumer-protection, sanctions, lawful-request, and other legal requirements.
8. AI, Personalization, and Service Improvement
When you use AI features, we may send your prompt, attached images, relevant conversation history, and selected trading or journal context to an AI service provider, currently including Mistral AI, so the provider can generate a response. The context sent depends on your request and may include information from your account that the feature determines is relevant.
We store AI conversations, feedback, generated content, and derived learning records to preserve conversation history, personalize later responses, evaluate quality and safety, troubleshoot, and improve the Service. We may create training or evaluation examples from selected interactions after applying measures designed to remove or generalize identifiers, financial amounts, dates, account IDs, image links, and similar details. Approved de-identified examples may be used to improve or fine-tune our AI systems through an AI provider.
De-identification reduces privacy risk but may not eliminate every risk in free-form text. Do not include information about yourself or others that is unnecessary for your request. Information that has been irreversibly anonymized so it can no longer reasonably identify a person is not treated as personal information under this policy.
AI features generate guidance and content but do not make decisions that produce legal or similarly significant effects about you. AI output may be inaccurate and should be independently reviewed, especially before any trading or financial decision.
9. How We Disclose Information
We may disclose personal information to:
- Vendors and processors: Providers that support hosting, databases, content delivery, file storage (such as Cloudinary), AI processing (such as Mistral AI), payments (Stripe), email delivery (Resend), web search or market information, security, and support. They may process information only to perform services for us or as otherwise permitted by their terms and applicable law.
- Integrations you choose: Services such as Google and Notion when you connect an account, authorize access, or request an import.
- Other users and the public: Information you place in a public profile, post, comment, story, shared AI thread, shared trade, achievement, or other public area. Direct messages are visible to their participants and are not public, but they are not end-to-end encrypted and may be accessed when reasonably necessary for support, safety, security, or legal compliance.
- Mentors, students, and organizations: Information made available through a mentor connection or shared workspace. Review your connections and sharing choices before posting sensitive journal information.
- Professional advisers: Lawyers, accountants, auditors, insurers, and similar advisers subject to confidentiality duties.
- Authorities and affected parties: When we reasonably believe disclosure is required by law or necessary to protect the Service, users, our rights, or the rights and safety of others.
- Transaction participants: Parties involved in a financing, reorganization, merger, acquisition, sale, insolvency, or similar business transaction, subject to appropriate confidentiality protections.
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising or use it to serve targeted ads.
10. Public Content and Sharing
Public profiles and content can be viewed, copied, indexed, reshared, or captured by others. Deleting content from the Service may not remove copies already shared by other users, stored in browser or search caches, or retained where legally permitted.
Mentor mode and shared AI links can reveal journal, analytics, or conversation information to the people who receive access. Only connect with people you trust, check whether a profile or item is public, and remove sensitive details before sharing.
11. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this policy. Retention depends on the type of information, whether your account is active, the sensitivity of the information, operational and security needs, applicable limitation periods, and legal, tax, accounting, or dispute-resolution requirements.
- Account, journal, community, mentor, and AI content is generally retained while your account or the relevant feature remains active, unless you delete it or request deletion.
- Subscription, transaction, audit, fraud-prevention, security, and support records may be retained after account closure when needed for legal compliance, legitimate business records, dispute resolution, or protection of the Service.
- Expired stories and deleted content may remain for a limited period in backups, logs, or abuse-prevention records before being overwritten in the ordinary course.
- De-identified or aggregated information that no longer reasonably identifies you may be retained for analytics, safety, research, and Service improvement.
12. Security
We use technical and organizational safeguards designed to protect personal information, including transport encryption, password hashing, access controls, session controls, rate limiting, and encryption for selected secrets such as two-factor and Notion connection secrets. Access is limited according to operational need.
No system is completely secure. You are responsible for protecting your password, recovery codes, API keys, connected-service credentials, and devices; enabling two-factor authentication where available; and notifying us promptly if you suspect unauthorized access.
13. International Data Transfers
We and our providers may process information in countries other than the one where you live, including the United States and countries in the European Economic Area. Those countries may have different data protection laws. Where required, we use a recognized transfer mechanism or safeguard, such as an adequacy decision or approved contractual protections. You may contact us for more information about applicable safeguards.
14. Your Choices and Privacy Rights
You can manage certain information directly by:
- editing your profile and public-profile setting;
- deleting individual trades, posts, comments, stories, AI threads, and other supported content;
- disconnecting Notion, mentors, students, or other integrations;
- revoking API keys and active sessions;
- changing notification preferences or using an email unsubscribe link where available; and
- clearing cookies or local storage through your browser.
Depending on where you live, you may have rights to request access to personal information, correction, deletion, restriction, portability, or information about processing; to object to certain processing; to withdraw consent; and to appeal a refusal of a request. You may also have the right to complain to your local data protection or privacy authority.
To exercise a right, request an account-level data export, or request account deletion, contact us as described below. We may need to verify your identity and may retain information where an exception under applicable law applies. We will respond within the period required by applicable law.
15. Children
The Service is intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided personal information, contact us so we can investigate and take appropriate action.
16. Third-Party Services
Third-party websites, integrations, market-data sources, payment services, and linked content operate under their own terms and privacy policies. This policy does not govern their independent processing. Review their policies before connecting an account, following a link, or providing information.
17. Do Not Track and Global Privacy Control
Because there is no uniform standard for browser Do Not Track signals, the Service does not currently respond to them. We do not sell personal information or use it for cross-context behavioral advertising, so a Global Privacy Control signal does not change those practices. If our practices change, we will update this policy and honor legally required signals.
18. Changes to This Policy
We may update this Privacy Policy to reflect changes to the Service, our practices, or legal requirements. We will post the revised policy and update the date above. If a change materially affects your rights or how we use personal information, we will provide additional notice when required, such as through the Service or by email.
We will request consent for a new use when applicable law requires consent; continued use alone will not be treated as consent where an affirmative choice is required.
19. Contact Us
For privacy questions or requests, use the support chat available on the Service or submit a request through our contact support page. Please write "Privacy Request" in the subject or first line and identify the account email involved.
TheProfitPath
Privacy requests: Support chat or contact support page
This Privacy Policy should be read together with our Terms of Service.
