PROOF ← Back to app
Legal Document
Privacy Policy
Last updated: June 24, 2026 Effective: June 24, 2026 Version 1.0
Table of Contents
Section 01

Introduction

Proof ("we," "us," "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes in detail how we collect, use, store, share, and protect your personal data when you access or use the Proof trading discipline platform at useproof.trade and any related services (collectively, the "Service").

We believe privacy is a fundamental right. We built Proof around the principle that your trading data, behavioral patterns, and emotional check-ins are deeply personal — and they belong to you. This policy explains exactly what we do and don't do with your information.

The short version: We collect only what we need to provide the Service. We do not sell your data. We do not use your trade journal entries for advertising. Your data is yours, protected by encryption, and you can request deletion at any time.

By creating an account and using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to our data practices as described herein. If you do not agree with this Privacy Policy, you must not use the Service.

Section 02

Information We Collect

We collect information in the following categories depending on how you interact with the Service:

2.1 Information You Provide Directly

Data TypeWhat We CollectWhy
Account CredentialsEmail address and hashed passwordAuthentication and account access
Trader ProfileName, trader type, daily loss limit, max trades per day, target win ratePersonalize your discipline dashboard
Trade Journal EntriesTrading pair/instrument, direction, result (win/loss/breakeven), P&L, notes, emotions, timestampCore journal functionality
Checklist DataYour configured pre-trade rules and whether each was checked before each tradeDiscipline tracking and scoring
Emotion Check ResponsesSelf-reported emotional state selected from pre-defined optionsBehavioral accountability feature
Payment InformationBilling name, email (for receipts) — card details handled entirely by StripeSubscription processing

2.2 Information Collected Automatically

When you access the Service, we or our service providers may automatically collect limited technical data including:

This technical data is collected in aggregate and is not linked to your personal trade journal entries or emotional data. We use it solely for security monitoring, service performance, and bug resolution.

2.3 Information We Do Not Collect

We want to be explicit about what we do not collect:

Section 03

How We Use Your Information

We use the information we collect strictly for the following purposes:

We will never use your personal trade journal data, emotional check-ins, or discipline records for advertising, profiling, or sale to any third party.

Section 04

Legal Basis for Processing

For users located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws requiring a lawful basis for processing, we process your personal data under the following legal bases:

Section 05

Data Sharing & Disclosure

We do not sell, rent, trade, or otherwise transfer your personal information to third parties for their own commercial purposes. We may share your information only in the following limited circumstances:

Service Providers

We share data with trusted third-party service providers who assist us in operating the Service. These providers are contractually obligated to use your data only for the specific purpose of providing their services to us and are prohibited from using it for any other purpose. Current service providers include Supabase (database/authentication), Stripe (payment processing), and Netlify (hosting).

Legal Requirements

We may disclose your information if required to do so by law, court order, subpoena, or other legal process, or if we believe in good faith that such disclosure is necessary to: (a) comply with applicable law; (b) protect and defend the rights or property of Proof; (c) prevent or investigate possible wrongdoing in connection with the Service; or (d) protect the personal safety of users of the Service or the public.

Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

Section 06

Third-Party Services

The following third-party services are integrated into Proof. Each is subject to its own privacy policy:

Supabase

Supabase provides our database and authentication infrastructure. Your account credentials, trade journal entries, checklist configurations, emotion check data, and profile settings are stored in Supabase's PostgreSQL database with row-level security (RLS) enabled. RLS ensures that database-level access controls prevent any user — including Supabase employees and Proof administrators — from reading your individual journal entries without proper authentication. Learn more at supabase.com/privacy.

Stripe

Stripe processes all subscription payments. When you enter your payment card information, it is transmitted directly to Stripe's servers via their secure SDK and is never transmitted through or stored on Proof's servers. Stripe is PCI DSS Level 1 certified, the highest level of payment security certification. Learn more at stripe.com/privacy.

Netlify

Netlify hosts the Proof web application and executes our serverless backend functions. Netlify processes web traffic and logs for security and performance purposes. Learn more at netlify.com/privacy.

Section 07

Data Storage & Security

We implement robust technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

Encryption

All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Data stored in our database is encrypted at rest. Passwords are hashed using industry-standard algorithms and are never stored in plain text.

Access Controls

Row-level security policies in our database ensure that authenticated users can only access their own data. Administrative access to production systems is strictly limited and audited. Your trade journal entries, emotional check data, and personal checklist configurations are not readable by Proof staff in the normal course of business.

Payment Security

Payment card data is handled entirely by Stripe and never touches our servers. We receive only a tokenized reference and subscription status confirmation from Stripe.

Incident Response

In the event of a data breach that affects your personal information, we will notify you as required by applicable law, typically within 72 hours of becoming aware of the breach, where feasible. Notification will be sent to the email address associated with your account.

While we implement industry-standard security measures, no system is completely secure. You are responsible for maintaining the security of your account credentials and for any activity that occurs under your account.

Section 08

Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:

You may request deletion of your account and personal data at any time by contacting support@useproof.trade.

Section 09

Cookies & Tracking Technologies

Proof uses a minimal set of cookies and local storage strictly necessary to operate the Service. We do not use advertising cookies, behavioral tracking cookies, or third-party marketing pixels.

Session Cookies

We use session cookies and local storage tokens issued by Supabase's authentication system to keep you logged in during and between sessions. These are strictly necessary for the Service to function and cannot be disabled without breaking your account access.

Local Storage

We use browser local storage to store your access status and certain app preferences locally on your device, reducing the need for repeated server requests.

What We Don't Use

We do not use: Google Analytics, Facebook Pixel, advertising retargeting tags, heat-mapping tools that capture keystrokes or personal data, or any third-party behavioral tracking technology.

You may configure your browser to block or delete cookies and local storage, but doing so may impair your ability to use the Service.

Section 10

Your Privacy Rights

Depending on your location, you may have the following rights with respect to your personal data. We honor these rights for all users, regardless of jurisdiction:

Right of Access
Request a copy of the personal data we hold about you and how it is being processed.
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
Right to Portability
Request a copy of your trade journal and account data in a structured, machine-readable format.
Right to Restriction
Request that we restrict processing of your personal data in certain circumstances.
Right to Object
Object to our processing of your personal data based on legitimate interests.
Right to Withdraw Consent
Withdraw consent for any processing based on consent at any time, without affecting prior lawful processing.
Right to Complain
Lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.

To exercise any of these rights, email us at support@useproof.trade with the subject line "Privacy Rights Request." We will respond within 30 days. We may need to verify your identity before processing certain requests.

Section 11

Children's Privacy

The Proof Service is intended exclusively for adults aged 18 and older. We do not knowingly collect, use, or disclose personal information from anyone under the age of 18. The Service is not directed at, marketed to, or designed for use by minors.

If you are a parent or guardian and believe that your minor child has provided us with personal information or created an account without your consent, please contact us immediately at support@useproof.trade. We will promptly delete any such information and close the account upon verification.

If we discover that we have inadvertently collected personal information from a person under 18, we will take immediate steps to delete that information from our servers.

Section 12

International Data Transfers

Proof is operated from and our primary data infrastructure is located in the United States. If you access the Service from outside the United States — including from the European Economic Area, United Kingdom, or any other jurisdiction — your personal data may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

These countries may have data protection laws that differ from those of your home country. By using the Service, you acknowledge and consent to this transfer. We take appropriate steps to ensure that international data transfers are conducted in compliance with applicable data protection laws, including relying on standard contractual clauses where required.

For users in the EEA or UK, we rely on adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms recognized under applicable law when transferring your personal data internationally.

Section 13

Do Not Sell My Personal Information

Proof does not sell, rent, or trade your personal information to any third party for monetary or other valuable consideration. This includes your email address, trading journal entries, emotional check-in data, discipline scores, and any other personal data you provide to us.

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). Because we do not sell personal information, there is no opt-out mechanism required. However, California residents may submit a request for details about any personal data we have collected, shared, or disclosed in the past 12 months by contacting support@useproof.trade.

We do not engage in profiling, targeted advertising, or cross-context behavioral advertising using your personal data.

Section 14

Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time. When we make material changes, we will:

Material changes will take effect no less than 14 days after notice is provided, giving you time to review the changes before they apply to you. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically. The most current version is always available at useproof.trade/privacy.html.

If any change significantly reduces your privacy protections, we will seek your consent where required by applicable law.

Section 15

Contact Us

If you have questions, concerns, complaints, or requests related to this Privacy Policy or our data practices, please contact us:

Proof Privacy Team
Email: support@useproof.trade
Subject line: "Privacy Request" or "Privacy Concern"
Website: useproof.trade

We aim to acknowledge all privacy-related inquiries within 48 hours and to provide a substantive response within 30 days. If you are not satisfied with our response, you have the right to escalate your complaint to the appropriate data protection supervisory authority in your jurisdiction.