Skip to content

    Privacy Policy

    Last updated: March 1, 2026

    1. Information We Collect

    We collect information you provide directly: name, email address, phone number, and trading data you choose to log. We also collect usage data such as page views and feature usage to improve the Service.

    2. How We Use Your Information

    • To provide and maintain the Service
    • To generate your trading analytics and reports
    • To send notifications you have opted into (Telegram, email)
    • To process payments and manage subscriptions
    • To improve the Service based on usage patterns

    3. Data Security

    Your data is encrypted in transit and at rest. Broker API tokens are stored securely and are only ever sent back to the broker that issued them — never to anyone else. We use row-level security to ensure users can only access their own data.

    4. Data Sharing

    We never sell or rent your personal data or trading data, and we do not share it with advertisers or data brokers. We do rely on a small number of service providers to run specific features, and each receives only the data that feature needs:

    • AI providers (Groq, OpenAI, or Google Gemini, depending on which is configured) — power the AI features: trade coach, trade insights, auto-tagging, auto-journal, pattern detection, alert suggestions, and the morning briefing. The trade fields, journal text, notes, and tags relevant to a request are sent as the prompt for that request. Most of these run only when you ask for them; Auto-Journal runs automatically when you close a trade unless you disable it in the Agent Control Center. You can also supply your own AI provider and API key, or remove the key entirely, in Settings → Integrations.
    • Supabase — our database, authentication, and file storage.
    • Razorpay — payment processing, used only when you buy or renew a paid plan. Card details go to Razorpay and are never stored by us.
    • Your broker (currently Dhan) — only if you choose to connect one. Requests are made with your own broker credentials to fetch your orders, positions, and prices.
    • Telegram — only if you enable Telegram notifications. The alerts and reports you configure are delivered through Telegram's API to the chat you nominate.
    • Google Drive — only if you enable Drive backup. Your exported data is written to your own Drive account.

    Your trading journal is private by default. Public trader profiles are off unless you switch one on in Settings — once enabled, the statistics on that page are visible to anyone with the link and can be indexed by search engines until you switch it off again.

    We may also disclose data where we are required to by law, or by SEBI or another regulator.

    5. Broker Integration

    When you connect a broker we store your API credentials securely to sync metadata and orders. You can disconnect at any time, which removes stored credentials.

    6. Cookies

    We use essential cookies for authentication and session management. No third-party tracking cookies are used.

    7. Data Retention & Storage

    Your data is retained as long as your account is active. If you ask us to delete your account, we permanently remove your personal data and trading records within 30 days of verifying the request — see section 8 for how to make one. Your data is stored securely in our database hosted by Supabase in the appropriate regional data centers in compliance with data sovereignty laws.

    8. Your Rights (GDPR/CCPA/DPDP)

    Depending on where you live, you have the right to access, export, correct, or delete your data. Here is exactly how each works today:

    • Access & export: download your full trade history and journal from Settings → Data at any time.
    • Correction: edit or delete any individual trade, study, journal entry, or alert directly in the app.
    • Deleting your trading data: Settings → Data → Danger Zone → "Clear all data" permanently erases every trade, study, journal entry, and alert on your account. It does not remove the account itself, your profile, subscription, broker connections, or notification settings.
    • Deleting your account: there is no self-service button for full account deletion yet. Email support@mrchartist.com from your registered address and we will erase the account and everything attached to it within 30 days.

    To exercise any other right under GDPR, CCPA, or India's DPDP Act, write to support@mrchartist.com.

    9. Contact

    For privacy-related questions, contact us at support@mrchartist.com.

    10. Regulatory & Grievance Redressal

    TradeBook is operated by INVESTOLOGY, the trade name of Rohit Singh (@MrChartist), a SEBI Registered Research Analyst — INH000015297. Perpetual registration granted March 2024. You can verify this registration on sebi.gov.in.

    Registered address: Mira Road East, Thane, Maharashtra — 401107, India.

    Grievance officer: Neelima Pillai — investologypartners@gmail.com. Write to us there with any complaint about how your data is handled. If it is not resolved to your satisfaction, you may escalate it on SEBI SCORES.

    Registration granted by SEBI and certification from NISM in no way guarantee the performance of the intermediary or provide any assurance of returns to investors. TradeBook is a trade journaling and analytics tool — it does not provide buy/sell recommendations, tips, or assured returns.