Proof ("we," "us," "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes in detail how we collect, use, store, share, and protect your personal data when you access or use the Proof trading discipline platform at useproof.trade and any related services (collectively, the "Service").
We believe privacy is a fundamental right. We built Proof around the principle that your trading data, behavioral patterns, and emotional check-ins are deeply personal — and they belong to you. This policy explains exactly what we do and don't do with your information.
The short version: We collect only what we need to provide the Service. We do not sell your data. We do not use your trade journal entries for advertising. Your data is yours, protected by encryption, and you can request deletion at any time.
By creating an account and using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to our data practices as described herein. If you do not agree with this Privacy Policy, you must not use the Service.
We collect information in the following categories depending on how you interact with the Service:
| Data Type | What We Collect | Why |
|---|---|---|
| Account Credentials | Email address and hashed password | Authentication and account access |
| Trader Profile | Name, trader type, daily loss limit, max trades per day, target win rate | Personalize your discipline dashboard |
| Trade Journal Entries | Trading pair/instrument, direction, result (win/loss/breakeven), P&L, notes, emotions, timestamp | Core journal functionality |
| Checklist Data | Your configured pre-trade rules and whether each was checked before each trade | Discipline tracking and scoring |
| Emotion Check Responses | Self-reported emotional state selected from pre-defined options | Behavioral accountability feature |
| Payment Information | Billing name, email (for receipts) — card details handled entirely by Stripe | Subscription processing |
When you access the Service, we or our service providers may automatically collect limited technical data including:
This technical data is collected in aggregate and is not linked to your personal trade journal entries or emotional data. We use it solely for security monitoring, service performance, and bug resolution.
We want to be explicit about what we do not collect:
We use the information we collect strictly for the following purposes:
We will never use your personal trade journal data, emotional check-ins, or discipline records for advertising, profiling, or sale to any third party.
For users located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws requiring a lawful basis for processing, we process your personal data under the following legal bases:
We do not sell, rent, trade, or otherwise transfer your personal information to third parties for their own commercial purposes. We may share your information only in the following limited circumstances:
We share data with trusted third-party service providers who assist us in operating the Service. These providers are contractually obligated to use your data only for the specific purpose of providing their services to us and are prohibited from using it for any other purpose. Current service providers include Supabase (database/authentication), Stripe (payment processing), and Netlify (hosting).
We may disclose your information if required to do so by law, court order, subpoena, or other legal process, or if we believe in good faith that such disclosure is necessary to: (a) comply with applicable law; (b) protect and defend the rights or property of Proof; (c) prevent or investigate possible wrongdoing in connection with the Service; or (d) protect the personal safety of users of the Service or the public.
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
We may share your information with third parties when you have given us explicit consent to do so.
The following third-party services are integrated into Proof. Each is subject to its own privacy policy:
Supabase provides our database and authentication infrastructure. Your account credentials, trade journal entries, checklist configurations, emotion check data, and profile settings are stored in Supabase's PostgreSQL database with row-level security (RLS) enabled. RLS ensures that database-level access controls prevent any user — including Supabase employees and Proof administrators — from reading your individual journal entries without proper authentication. Learn more at supabase.com/privacy.
Stripe processes all subscription payments. When you enter your payment card information, it is transmitted directly to Stripe's servers via their secure SDK and is never transmitted through or stored on Proof's servers. Stripe is PCI DSS Level 1 certified, the highest level of payment security certification. Learn more at stripe.com/privacy.
Netlify hosts the Proof web application and executes our serverless backend functions. Netlify processes web traffic and logs for security and performance purposes. Learn more at netlify.com/privacy.
We implement robust technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Data stored in our database is encrypted at rest. Passwords are hashed using industry-standard algorithms and are never stored in plain text.
Row-level security policies in our database ensure that authenticated users can only access their own data. Administrative access to production systems is strictly limited and audited. Your trade journal entries, emotional check data, and personal checklist configurations are not readable by Proof staff in the normal course of business.
Payment card data is handled entirely by Stripe and never touches our servers. We receive only a tokenized reference and subscription status confirmation from Stripe.
In the event of a data breach that affects your personal information, we will notify you as required by applicable law, typically within 72 hours of becoming aware of the breach, where feasible. Notification will be sent to the email address associated with your account.
While we implement industry-standard security measures, no system is completely secure. You are responsible for maintaining the security of your account credentials and for any activity that occurs under your account.
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
You may request deletion of your account and personal data at any time by contacting support@useproof.trade.
Proof uses a minimal set of cookies and local storage strictly necessary to operate the Service. We do not use advertising cookies, behavioral tracking cookies, or third-party marketing pixels.
We use session cookies and local storage tokens issued by Supabase's authentication system to keep you logged in during and between sessions. These are strictly necessary for the Service to function and cannot be disabled without breaking your account access.
We use browser local storage to store your access status and certain app preferences locally on your device, reducing the need for repeated server requests.
We do not use: Google Analytics, Facebook Pixel, advertising retargeting tags, heat-mapping tools that capture keystrokes or personal data, or any third-party behavioral tracking technology.
You may configure your browser to block or delete cookies and local storage, but doing so may impair your ability to use the Service.
Depending on your location, you may have the following rights with respect to your personal data. We honor these rights for all users, regardless of jurisdiction:
To exercise any of these rights, email us at support@useproof.trade with the subject line "Privacy Rights Request." We will respond within 30 days. We may need to verify your identity before processing certain requests.
The Proof Service is intended exclusively for adults aged 18 and older. We do not knowingly collect, use, or disclose personal information from anyone under the age of 18. The Service is not directed at, marketed to, or designed for use by minors.
If you are a parent or guardian and believe that your minor child has provided us with personal information or created an account without your consent, please contact us immediately at support@useproof.trade. We will promptly delete any such information and close the account upon verification.
If we discover that we have inadvertently collected personal information from a person under 18, we will take immediate steps to delete that information from our servers.
Proof is operated from and our primary data infrastructure is located in the United States. If you access the Service from outside the United States — including from the European Economic Area, United Kingdom, or any other jurisdiction — your personal data may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
These countries may have data protection laws that differ from those of your home country. By using the Service, you acknowledge and consent to this transfer. We take appropriate steps to ensure that international data transfers are conducted in compliance with applicable data protection laws, including relying on standard contractual clauses where required.
For users in the EEA or UK, we rely on adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms recognized under applicable law when transferring your personal data internationally.
Proof does not sell, rent, or trade your personal information to any third party for monetary or other valuable consideration. This includes your email address, trading journal entries, emotional check-in data, discipline scores, and any other personal data you provide to us.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). Because we do not sell personal information, there is no opt-out mechanism required. However, California residents may submit a request for details about any personal data we have collected, shared, or disclosed in the past 12 months by contacting support@useproof.trade.
We do not engage in profiling, targeted advertising, or cross-context behavioral advertising using your personal data.
We reserve the right to update or modify this Privacy Policy at any time. When we make material changes, we will:
Material changes will take effect no less than 14 days after notice is provided, giving you time to review the changes before they apply to you. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
We encourage you to review this Privacy Policy periodically. The most current version is always available at useproof.trade/privacy.html.
If any change significantly reduces your privacy protections, we will seek your consent where required by applicable law.
If you have questions, concerns, complaints, or requests related to this Privacy Policy or our data practices, please contact us:
Proof Privacy Team
Email: support@useproof.trade
Subject line: "Privacy Request" or "Privacy Concern"
Website: useproof.trade
We aim to acknowledge all privacy-related inquiries within 48 hours and to provide a substantive response within 30 days. If you are not satisfied with our response, you have the right to escalate your complaint to the appropriate data protection supervisory authority in your jurisdiction.