This describes what GoJournalBro stores, who else sees it, and how to get it back or get rid of it.
What we store
- Your account: name, email address, and a hash of your password. We never store the password itself.
- Your book: the fills you import and everything derived from them — trades, fees, accounts, tags, notes, session plans, rules, saved views and dashboard layout.
- Your conversations: questions you ask the assistant, its answers, and any image you paste into it.
- Billing state: your plan, your Stripe customer and subscription identifiers, and how many assistant messages you have used this month. No card details.
We use one analytics tool to see how the app is used. It records the pages you open, what you click, and session recordings of your screen while you use the app, so what is on screen at the time is part of it. Its servers are in the United States. That tool is never used for advertising. Some of its cookies are for that purpose; the rest are your session and your display preferences.
Three other cookies come from the tools listed below. The support chat sets one so a conversation survives a page reload, and it is set whether or not you are signed in — the chat is on our public pages too. Affiliate tracking sets one only if you arrived through somebody’s referral link, and it records which link, nothing else. Neither of those is used for advertising.
The third one is. If you arrived from a Reddit advert, we keep the identifier Reddit put on that link so we can tell Reddit the advert worked. It records which advert brought you and nothing else, and it is set only if you arrived from one.
Who else sees it
Only these, and each only for the feature it provides:
- Anthropic — when you use the AI assistant. This is the significant one: answering a question about your book means sending your question, the trade rows needed to answer it, and any screenshot you attach. If you would rather no third party saw your trades, do not use the assistant; every other feature works without it.
- Stripe — your name, email and payment details when you upgrade. Card details are entered on Stripe’s own hosted page and never touch our servers.
- Resend — your email address, to send verification and password-reset mail.
- Databento — market data provider. Receives instrument symbols and date ranges only. Price bars are shared across all users, so nothing about you is sent.
- ProjectX (TopstepX) — market data provider, used for recent sessions where it can answer faster than Databento. Receives instrument symbols and date ranges only, exactly as above. It is not told which account or which trade prompted a request, and no order is ever placed: the integration is read-only.
- An analytics provider — in the United States. Receives how you use the app: which pages you open, what you click, and session recordings, which show whatever the page was showing you.
- Featurebase — the feedback board and the support chat. Receives your name, email address and which plan you are on, so you do not have to make a second account to vote on a feature or ask a question, and so we know who we are replying to. Anything you write in a feature request, a comment or a chat message is stored by them. A feature request is public to other traders by design; a chat message is not.
- Rewardful — affiliate tracking. If you arrived through somebody’s referral link, a cookie records which one, and Rewardful is told when you subscribe so that person gets paid. It receives nothing about your trading, and if you did not arrive through a referral link it receives nothing at all.
- Reddit — advertising measurement, so we know which adverts are worth paying for. It is told which pages you open and which of six things you did: opened the demo, looked at pricing, created an account, started a checkout, subscribed. On a subscription it is also told the amount. It is never told anything about your trading — not a trade, not a figure, not an account name — and it never receives session recordings. To match you to an advert it is sent your email address, your account identifier and your IP address as one-way hashes rather than as themselves, along with your browser’s user-agent string and the identifier Reddit’s own script sets. Blocking that script in your browser stops the page-by-page half of this; creating an account, starting a checkout and subscribing are reported by our server, so those three are sent either way.
We do not sell your data or use it to train models. We do use it for advertising measurement, and only in the one way described above: Reddit is told which of those steps you reached, so that an advert can be judged. No other tool here is used for advertising, and nothing about your book is.
Where it lives
In a PostgreSQL database on a server we control, not a shared platform database. Your rows carry your account’s identifier and every query is filtered by it.
How long we keep it
Until you delete it. Deleting your account removes everything listed above immediately and permanently — accounts, fills, trades, notes, plans, rules, conversations and attachments — and it cannot be undone. Backups are retained for a short period for disaster recovery and are then overwritten. Billing records are kept where tax law requires.
Two things do not go when your account does, because they do not live here. Analytics events and session recordings sit with the provider named above and expire on its retention schedule instead. And anything you posted on the feedback board stays on the board: a feature request other traders have voted on and replied to is a shared thread rather than a row of yours, and removing it would delete their votes and comments too. Ask us and we will detach your name from it or take it down; support chat messages we will delete on request.
Your rights
You can export your data at any time from Settings, in CSV. You can delete your account at any time from Settings. You can correct anything from within the app. If you are in the UK or EU you also have the rights the GDPR gives you, including to object and to complain to your supervisory authority.
Security
Traffic is encrypted in transit. Passwords are hashed. The database is not reachable from the internet. Access to production is limited to the operator. No system is perfectly secure, and we will tell you promptly if we learn of a breach affecting your data.
Contact
Questions about any of this, or a request under the rights above: privacy@gojournalbro.com.