Privacy Policy
How TradeLabs AI collects, uses and protects your personal data: what we store, how long we keep it, who we share it with and the rights you can use.
Last updated 14 September 2026.
Effective 14 September 2026. This policy applies to tradelabsai.com and every service reached from it.
01Who we are and how to reach us
TradeLabs AI (“TradeLabs”, “we”, “us”) operates tradelabsai.com, an analytics service for traders. For the purposes of the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA, Brazil’s LGPD, Canada’s PIPEDA and the Australian Privacy Act, TradeLabs AI is the controller of the personal data described here. Contact: hello@tradelabsai.com. We answer privacy requests from that address and through the contact page.
02What we collect
| Category | What it includes | Source |
|---|---|---|
| Account | Email address, display name, hashed password (never the password itself), plan, account id, sign-up and last-login times, optional bio and avatar, referral code | You, when you sign up or edit settings |
| Sign-in | If you sign in with Google or an email link, our authentication provider gives us your email, a user id and whether the email is verified | Authentication provider |
| Usage | Pages visited, features used, AI questions you ask and the answers, chart screenshots you upload for analysis, calls you log, paper trades, comments, alert rules | You, while using the service |
| Device and connection | IP address, browser type and version, screen size, coarse location derived from the IP, timestamps of requests | Your browser |
| Payments | Card payments are taken by our payment processor; we receive a customer reference, subscription id, plan and status, never your card number. Crypto payments create an order id, amount and status | Payment processors |
| Alerts | If you connect Telegram: the bot token and chat id you paste into settings. If you enable browser alerts: a permission flag in your browser | You |
| Support | Messages you send through the contact form or by email, questions you type into the help centre ask box, messages in your inbox on the site, and our replies | You |
| Abuse prevention | Hashed IP addresses (including the hashed network address and browser type recorded when an account is created), sign-up attempts, request rates and flags raised by our abuse checks | Generated by us |
We do not ask for, and you should not send us, government identifiers, financial account numbers or any special-category data.
03Why we use it and the legal basis
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Providing the service you signed up for: your account, the chart, the AI assistant, alerts, paper trading | Account, sign-in, usage, alerts | Performance of a contract (Art. 6(1)(b)) |
| Billing and refunds | Account, payments | Contract; legal obligation for tax and accounting records |
| Keeping the service secure and preventing abuse, including rate limits and blocking disposable email domains | Device and connection, abuse prevention, account | Legitimate interests (Art. 6(1)(f)): protecting the service and other users |
| Understanding which pages and features are used | Usage, device (only if you accept analytics cookies) | Consent (Art. 6(1)(a)); withdraw any time from “Cookie settings” in the footer |
| Answering your messages | Support | Legitimate interests; contract where the message concerns your account |
| Complying with law and enforcing our terms | Any of the above, as needed | Legal obligation; legitimate interests |
Outside the EU and UK we rely on the equivalent grounds under local law: for California residents this policy is also our notice at collection. We do not sell personal data and we do not share it for cross-context behavioural advertising. We do not use your data for automated decisions with legal or similarly significant effects; the predictions the service produces are about markets, not about you.
04Who we share it with
We share personal data only with service providers that process it on our behalf, each bound by a contract that limits what they may do with it. They fall into these categories:
- Hosting: running the application and storing its database.
- Authentication: password, Google and email-link sign-in.
- Payments: card and cryptocurrency payments. We never receive your card number.
- Messaging services you connect: delivering alerts you turn on, through your own account with that service.
- Market data: live prices for the charts. No personal data is sent; your browser fetches public price feeds directly.
- AI model providers: answering AI questions and analysing chart screenshots. The question, the chart context and the screenshot are sent; your email is not.
- Translation: showing a page in the language you pick. Only the text shown on the page is sent; your account details (email, password, payments) never are.
- Email delivery: account and support email.
- Review invitations: after a purchase, our review platform is blind copied on your receipt so it can invite you to review us. It receives the email address the receipt went to. Invitations are sent by them, and every invitation carries their own way to stop receiving them. Their script also loads on our pages, so Trustpilot sees your IP address and browser. It sets no cookies.
A current list of these providers is available on request.
We may also disclose data when the law requires it, to protect the rights and safety of users, or to a successor if the service is sold or merged (you would be told first). We do not share data with advertisers.
05Cookies and consent
We set two essential cookies: poly_session, which keeps you signed in, and tl_dev, a random identifier that limits abuse of the free plan; they need no consent because the service cannot work without them. With each sign-in we also keep the browser and device type your browser reports and when that sign-in was last used, never your IP address or location, so you can see your sign-ins in Settings and end any of them. Those details last only as long as the sign-in: they are deleted when you sign out, when you end the sign-in in Settings, or soon after it expires (at most 90 days). If you turn on 2-step login, we keep the key your authenticator app uses, encrypted, and your backup codes only as one-way hashes; both are deleted when you turn 2-step login off, when we turn it off at your request or when you delete your account, and a set-up you start but do not finish is deleted after a day. For each browser you let skip the code, we keep a one-way hash of its cookie, the browser type it reports and when that ends (30 days); those are deleted soon after they end, or when you choose Forget them, sign out everywhere else, use Change password in Settings, change your sign-in email, or turn 2-step login off. If you change your sign-in email in Settings, our authentication provider emails a confirmation link to the new address and, once the change is made, a notice with a link to undo it to the old address; your account switches to the new address when it is confirmed, and your other sign-ins end. If you pay through Stripe and the billing email there was your old sign-in address, it changes to the new one too. We set tl_consent to remember your cookie choice. Analytics events (which page was opened, which feature was clicked, screen size) are sent to our own server only after you choose “Accept analytics” in the banner shown on your first visit. They are stored with a daily-rotating hash of your IP address, never with your name or email, and are kept for 90 days. Choosing “Essential only” under Preferences sends nothing. You can change your choice at any time from cookie preferences. Your browser’s local storage holds preferences such as theme and chart layout; nothing in it is sent to us.
06How long we keep it
- Account data: while your account exists, then deleted within 30 days of deletion, except records we must keep for tax and accounting (payment records, up to 7 years) and abuse records needed to keep a blocked actor blocked (hashed, up to 2 years).
- Sessions: until you sign out, they expire, or you change your password or sign-in email.
- AI questions, screenshots and answers: screenshots are processed in memory and not stored; questions and answers stay in this browser, kept for next time unless you turn off Save chat under the chat box, and in our request logs for up to 30 days.
- Request logs (IP address, the page opened, the site that linked to it, the browser type your browser reports, and the time): 30 days. After that the rows are deleted and only counts remain, with no address in them.
- Account creation record (hashed network address and browser type at sign-up): while the account exists.
- Sign-up attempt records (hashed network address): 400 days.
- Analytics events: 90 days.
- Support messages: 2 years, so we can follow up.
- Backups: kept for a limited period and then overwritten. Data you delete disappears from backups within that period.
07Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you, and receive it in a portable machine-readable form (use Download my data in Settings, which returns JSON).
- Correct anything inaccurate (most fields can be edited in Settings).
- Delete your account and data (use Delete my account in Settings, or email us).
- Restrict or object to processing based on legitimate interests, including abuse prevention, where your situation justifies it.
- Withdraw consent for analytics at any time, without affecting the service.
- Not be discriminated against for exercising these rights (CCPA), and to opt out of sale or sharing, which we do not do in any case.
We respond within one month (45 days for CCPA requests) and may ask you to confirm you control the account. If you are unhappy with our response you can complain to a supervisory authority: in the EU, the data protection authority of your country; in the UK, the Information Commissioner’s Office; in Brazil, the ANPD; in Canada, the Office of the Privacy Commissioner; in Australia, the OAIC; in California, the California Privacy Protection Agency.
08Where your data is processed
Your data is stored in the European Union. Some of the providers above operate in the United States. Where data leaves the EU, UK or another jurisdiction with transfer rules, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum), the EU-US Data Privacy Framework where the processor is certified, and the processor’s own data-processing terms. You can ask us for a copy of the relevant safeguards.
09Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, hashed passwords, encrypted storage of sensitive credentials, access controls and regular backups. No system is perfectly secure: if we learn of a breach that affects you we will tell you and, where required, the relevant authority, without undue delay.
10Children
TradeLabs AI is for adults. You must be at least 18 years old (or the age of majority where you live, if higher) to create an account. We do not knowingly collect data from anyone younger; if you believe we have, email us and we will delete it.
11Deleting your account and exporting your data
In Settings, Download my data returns everything we hold about you as a JSON file: your profile, settings, alert rules, paper trades, calls, comments and payment references. Delete my account asks you to confirm, then removes your profile, sessions, API keys, paper trades, alerts, comments, calls and referral records, deletes your sign-in identity at our authentication provider, cancels any active subscription and signs you out. We keep only a one-way hash of your account id with the time of deletion, so we can show the deletion happened, plus the payment records the law requires. Deletion is immediate and cannot be undone.
12Changes to this policy
When we change this policy we update the date at the top and, for material changes, tell signed-in users on their next visit. The current version is always at tradelabsai.com/privacy.