leverageclub

Privacy policy

Last updated October 7, 2026

This explains what leverageclub collects about you, why, who sees it and how to get rid of it. We've written it to be read.

Risk disclosure. leverageclub is journaling and analytics software, not financial advice. Trading futures and other leveraged products involves substantial risk of loss and isn't suitable for everyone. Past performance, including anything in your journal or on the leaderboard, doesn't predict future results.

The short version

We collect what's needed to run a trading journal: your account details, the trading data you connect or import, and what you choose to post. We don't sell your data. You can see what's public, change it, and delete your account whenever you want.

What we collect

Account: your name, email address and a password hash, or the identity returned by Google, Apple or X if you sign in with them.

Profile: handle, bio, avatar colour and the visibility choices you make in settings.

Trading data: broker accounts, balances, fills, the trades we match from them, your notes, tags and grades. This comes from the feeds you connect or the files you import.

Community activity: posts, comments, follows and messages you send.

Billing: your plan, subscription status and renewal dates, the billing emails we sent you, and a record that you accepted the renewal terms at checkout. Card details are collected and held by Stripe. We never see or store full card numbers; we show the brand and last four digits that Stripe tells us.

Technical: a session cookie that keeps you signed in, plus basic server logs (IP address, browser, timestamps) used for security and debugging. We don't run advertising trackers.

Usage analytics, and only if you say yes

We'd like to count how the app is used: which pages are opened and which features are used, tied to your account id. We ask first. Until you choose, and if you decline, nothing is collected and the analytics code doesn't even load.

Your choice is saved in your browser and, once you sign in, on your account, so it follows you to other devices. Billing and broker-sync events we record on our servers follow the same choice: if you haven't said yes, they aren't sent.

If your browser sends Global Privacy Control or Do Not Track, we treat that as a no, including when you create your account.

Analytics never includes your trades, P&L, balances, messages, notes, email address or name. Change your mind any time in Settings, under Privacy.

Broker credentials

If you connect a broker, we store the credentials or tokens needed to read your account, encrypted at rest. They're used only to sync your data, and connections are read-only. Disconnecting a feed deletes the stored credentials.

How we use it

To run the product: sync and match fills, compute analytics, show your journal and power the community and leaderboard.

To keep you informed: transactional email such as password resets, and notifications you've switched on in settings.

To protect the service: preventing abuse, fraud and security incidents, and fixing bugs.

To keep the community safe: posts, comments, briefs, profile text, first messages to people who don't follow you, messages that contain links, and images are checked automatically for spam, scams and illegal content before others see them, using [OpenAI's moderation service for text and images, Google Web Risk for links, and Microsoft PhotoDNA for known child-abuse imagery: counsel to confirm the list]. These services don't use the content to train their models [confirm per vendor]. Once a message request is accepted, we don't scan the conversation unless a participant reports it or a message contains a link. Staff read a private conversation only when it's reported to us, for security or to comply with the law, and every such access is logged. Reports, moderation decisions and their audit records are kept for [1 year after resolution]; material we're required to preserve for law enforcement is kept for 1 year from the report.

To bill you: managing subscriptions and invoices through Stripe, and sending billing emails you can't switch off while you have a paid plan: a confirmation when you subscribe, a reminder before a renewal, and a confirmation when you cancel or a plan ends.

What other people can see

Your handle, avatar and anything you post are visible to other members. If your profile is public, so are your bio and the verified stats you've chosen to show. Switching your profile to private hides your profile page. Posts you've already shared stay visible until you delete them.

Your journal, notes, balances and broker connections are private to you unless you explicitly share a trade.

Who we share it with

Only the service providers that run leverageclub, each limited to what they need, and all set up to process data in North America: Railway (hosting, database and file storage, US East), Cloudflare (network protection and the sign-up check), Stripe (payments), Resend (transactional email, US), PostHog (usage analytics, US, only if you said yes), Sentry (error reports, US) and Grafana Labs (service metrics and logs, US), plus the broker platforms you connect (Tradovate, Rithmic) when we sync with them.

Symbol pages can show a chart and quote from TradingView. Nothing from TradingView loads until you press Load chart; after that your browser fetches TradingView's widget directly, and TradingView receives your IP address, the address of the page and the symbol shown. TradingView says its widgets set no cookies and keep IP addresses only briefly, for protection against attacks. Your choice is remembered in this browser. The journal's trade charts are drawn from your own fills and send nothing to TradingView. [Draft, counsel to confirm.]

If you add a TradingView snapshot link to a trade, we show the image TradingView hosts for that link; we don't copy or store it. When you save the link, our server asks TradingView once whether the image exists. Anyone who sees the trade (you, or other members and visitors if you share it) loads the image from TradingView, which then receives their IP address but not the page they're on. Removing the link or the trade removes the image from your shared posts. [Draft, counsel to confirm.]

Error reports and service metrics keep the app working. They identify you by account id only, never by email or name, and have personal details stripped before they're sent.

We may disclose information if the law requires it or to protect people's safety. If the company is ever sold or merged, we'll tell you before your data is transferred and treated under a different policy.

Keeping and deleting data

We keep your data while your account is open. Deleting your account in settings removes your profile, journal, accounts, trades, posts and messages from our systems and cancels any active subscription. Copies in backups age out on our regular backup cycle.

Stripe keeps invoices and payment records for as long as financial regulations require. Server logs are kept for a short period for security.

Your choices and rights

You can edit your profile, switch it to private, turn notifications off, disconnect broker feeds and delete your account from settings. You can ask us for a copy of your data or a correction, and, depending on where you live, object to or restrict certain processing or complain to your data protection authority.

To use any of these, write to [email protected] from the email on your account.

Security

Connections use HTTPS, passwords are hashed, broker credentials are encrypted at rest, and access to production data is restricted. No system is perfectly secure; if there's a breach that affects you, we'll tell you as the law requires.

Children and transfers

leverageclub is for people 18 and over, and we don't knowingly collect data from anyone younger. We store and process data in the United States. If you use leverageclub from elsewhere, your data is transferred there; where required, we rely on recognised safeguards for those transfers.

Changes and contact

If we change this policy in a way that matters, we'll tell you in the app or by email before it applies. Questions: [email protected].