Skip to main content

Privacy policy

Last updated 1 September 2026

Alpha Ledger holds something sensitive: a complete record of how you trade. This page says exactly what we store, why we store it, and how to take it back.

1. What we collect

Only what the product needs:

  • Account details — your email, name if you give one, timezone and language
  • Trading data — trades, accounts, plans, notes, tags, setups, screenshots and challenges
  • Broker credentials — encrypted at rest, read-only, used solely to fetch your trades
  • Usage data — pages visited and features used, only if you accept analytics cookies
  • Technical data — IP address and browser, kept briefly in server logs for security and rate limiting

2. What we do not collect

We do not collect payment card details — Stripe handles payments and we store only a customer reference.

We do not buy data about you from third parties, and we do not build a profile of you from anything outside Alpha Ledger.

We do not sell, rent or share your trading data with anyone.

3. Why we process it

To provide the service you signed up for — that is the contractual basis for your trading data and account details.

To keep the service secure and prevent abuse — our legitimate interest, covering logs and rate limiting.

To send you product and marketing email — with your consent, withdrawable in one click.

To meet legal obligations, such as keeping billing records.

4. Cookies

Essential cookies keep you logged in and remember your theme. They cannot be turned off without breaking the service.

Analytics cookies are off until you accept them. The banner offers "Essential only" as prominently as "Accept all", and declining costs you nothing.

5. Who we share it with

Only the processors that run the service, each bound by a data processing agreement:

  • Supabase — database, authentication and file storage
  • Vercel — application hosting
  • Stripe — payments
  • Resend — transactional and report email
  • Anthropic — AI coach requests, when you use it
  • Market-data and broker-connectivity providers, where you have connected an account

6. Where it is stored

Data is stored in the region of your Supabase project. Some processors operate in other countries, and transfers are covered by standard contractual clauses or an equivalent mechanism.

7. How long we keep it

Your data is kept for as long as your account exists. When you delete your account it is removed permanently — there is no soft-delete and no recovery window.

Billing records are retained for as long as tax law requires.

8. Your rights

You can export everything at any time from Settings → Data & privacy, as CSV or JSON. You can delete everything from the same page, in one click plus a typed confirmation.

Under the GDPR and the Australian Privacy Act you also have rights to access, correct, restrict and object to processing, and to complain to a supervisory authority. Email us and we will action any request within 30 days.

9. Security

Row-level security on every table, so a query cannot return another user’s rows. Broker credentials encrypted with AES-256-GCM. Two-factor authentication available on every account. All traffic over TLS. An audit log of sensitive actions.

If a breach affects your data we will tell you and the relevant authority within 72 hours.

10. Children

Alpha Ledger is not for anyone under 18 and we do not knowingly collect their data.

11. Contact

Email privacy@the-alpha-ledger.com for anything on this page, including a data request.