Privacy policy
Last updated 1 September 2026
Alpha Ledger holds something sensitive: a complete record of how you trade. This page says exactly what we store, why we store it, and how to take it back.
1. What we collect
Only what the product needs:
- Account details — your email, name if you give one, timezone and language
- Trading data — trades, accounts, plans, notes, tags, setups, screenshots and challenges
- Broker credentials — encrypted at rest, read-only, used solely to fetch your trades
- Usage data — pages visited and features used, only if you accept analytics cookies
- Technical data — IP address and browser, kept briefly in server logs for security and rate limiting
2. What we do not collect
We do not collect payment card details — Stripe handles payments and we store only a customer reference.
We do not buy data about you from third parties, and we do not build a profile of you from anything outside Alpha Ledger.
We do not sell, rent or share your trading data with anyone.
3. Why we process it
To provide the service you signed up for — that is the contractual basis for your trading data and account details.
To keep the service secure and prevent abuse — our legitimate interest, covering logs and rate limiting.
To send you product and marketing email — with your consent, withdrawable in one click.
To meet legal obligations, such as keeping billing records.
4. Cookies
Essential cookies keep you logged in and remember your theme. They cannot be turned off without breaking the service.
Analytics cookies are off until you accept them. The banner offers "Essential only" as prominently as "Accept all", and declining costs you nothing.
5. Who we share it with
Only the processors that run the service, each bound by a data processing agreement:
- Supabase — database, authentication and file storage
- Vercel — application hosting
- Stripe — payments
- Resend — transactional and report email
- Anthropic — AI coach requests, when you use it
- Market-data and broker-connectivity providers, where you have connected an account
6. Where it is stored
Data is stored in the region of your Supabase project. Some processors operate in other countries, and transfers are covered by standard contractual clauses or an equivalent mechanism.
7. How long we keep it
Your data is kept for as long as your account exists. When you delete your account it is removed permanently — there is no soft-delete and no recovery window.
Billing records are retained for as long as tax law requires.
8. Your rights
You can export everything at any time from Settings → Data & privacy, as CSV or JSON. You can delete everything from the same page, in one click plus a typed confirmation.
Under the GDPR and the Australian Privacy Act you also have rights to access, correct, restrict and object to processing, and to complain to a supervisory authority. Email us and we will action any request within 30 days.
9. Security
Row-level security on every table, so a query cannot return another user’s rows. Broker credentials encrypted with AES-256-GCM. Two-factor authentication available on every account. All traffic over TLS. An audit log of sensitive actions.
If a breach affects your data we will tell you and the relevant authority within 72 hours.
10. Children
Alpha Ledger is not for anyone under 18 and we do not knowingly collect their data.
11. Contact
Email privacy@the-alpha-ledger.com for anything on this page, including a data request.