This policy explains how DT Journal (also presented as DT Terminal, “DT Journal,” “we,” “us,” or “our”) handles personal data across our websites, web app, desktop app, APIs, community, broker-sync features, affiliate program, and DT Scholarships (the “Service”). DT Journal is responsible for the processing described here unless a third party tells you it acts separately under its own policy.
1) Information we collect
Account and contact data: email address, user ID, profile name, handle, avatar, country, timezone, preferences, age or eligibility confirmations, and authentication-provider identifiers. Password authentication is handled by our authentication provider; we do not display your password to our staff.
Trading and journal data: accounts, trades, orders, balances, journals, reflections, strategies, rules, analyses, chart annotations, backtests, forward tests, performance calculations, attachments, and the context you provide to Edge.
Broker-sync data: broker or exchange name, account identifiers, server details, connection status, synchronization logs, and imported trading history. For supported crypto exchanges, API credentials are encrypted server-side and retained until you disconnect or delete the account. For MetaTrader sync, your investor password is sent to MetaApi, which operates the connection; DT Journal does not persist that password in its own database.
AI inputs and outputs: prompts, screenshots, files, relevant journal or trade context, generated responses, and safety or quality metadata when you request an AI feature.
Community content: posts, comments, reactions, follows, messages, reports, shared trades or analyses, and the visibility choices attached to them. Content you mark public can be viewed by people outside your account.
Commercial and program data: plan, billing status, transaction and invoice identifiers, affiliate application and attribution data, payout-onboarding status, scholarship applications, eligibility snapshots, testimonials, and donation records. We do not receive full payment-card or payout-bank credentials.
Technical and security data: IP address, device and browser information, app version, timestamps, request and audit logs, crash details, abuse signals, and approximate location inferred from network data.
Optional analytics and referral data: feature usage, page paths, session identifiers, masked replay, campaign parameters, and affiliate referral codes only after you allow the relevant optional category. Affiliate link attribution lasts up to 60 days.
2) How and why we use data
Provide, secure, personalize, synchronize, and support the Service, perform purchases, and deliver features you request.
Import broker history, maintain connection health, and show whether records were synced or verified.
Process AI requests and return generated results using the context required for the feature you selected.
Operate community, affiliate, and scholarship programs; prevent fraud, enforce rules, attribute valid referrals, and process approved payouts or sponsorships.
Send essential account, security, billing, and service communications. We send marketing only where you separately opted in, and you can withdraw that choice at any time.
Measure and improve the Service using optional analytics, and diagnose crashes and security incidents using necessary, minimized logs.
Meet legal, accounting, tax, dispute-resolution, and regulatory obligations.
Depending on the law that applies, we rely on performing our contract with you, your consent, compliance with legal obligations, and legitimate interests such as security, fraud prevention, support, and improving a service you use. Where consent is the basis, you may withdraw it prospectively.
3) Who receives data
We do not sell personal data. We disclose only what is reasonably needed to:
Infrastructure and operations: Supabase for database, storage, and authentication; Vercel for hosting and, with consent, web analytics; Resend for email delivery; Sentry for error monitoring and, with consent, performance and masked replay; and PostHog for consented product analytics.
Requested integrations: Anthropic to process AI requests; MetaApi to operate MetaTrader connections; Stripe to process subscriptions, donations, affiliate onboarding, and payouts; and Google or Apple when you choose their sign-in service.
Connected AI assistants: when you connect an AI through DT Terminal Connect, data covered by the permissions you tick on the consent screen is sent to that application and to the AI provider operating it, and is handled under their terms and their privacy policy, not ours. These applications are registered by third parties and are not verified by us, so check the address shown on the consent screen before approving one. A connection starts read-only; if you tick a write permission, the assistant can also create, change, and delete records in your account, and those changes are treated as yours. A connection can only ever reach your own profile, journal, backtests, and connected-account records; it cannot reach community content or chat messages, so no other member's writing is disclosed through it. You can review and disconnect any connection at any time in Settings, Connected AI, which stops all further access immediately but cannot recall what was already sent.
Other users and the public: profile or community content according to the visibility controls you choose. A frozen copy of content you deliberately share can remain attached to the post until that post is removed.
Legal and safety recipients: courts, regulators, law enforcement, advisers, or affected parties where required or reasonably necessary to protect rights, safety, and the Service.
Business transfers: a buyer, successor, or restructuring participant, subject to appropriate confidentiality and notice where required.
These providers may process data under their own terms when acting independently. Links to third-party brokers, prop firms, and other sites are governed by those parties’ privacy practices.
4) Cookies, local storage, and privacy choices
Essential: authentication, security, theme, app settings, offline data, explicit invite or manually entered referral state, and your privacy-choice record. These are used to provide the Service or remember a choice you made.
Product analytics: optional PostHog and Vercel analytics, first-party analytics events, campaign parameters, and Sentry performance or masked replay.
Referral attribution: an optional affiliate cookie and local-storage record retained for up to 60 days.
Optional storage stays off until you choose, and you are asked once: one choice covers both DT Terminal sites, thedtterminal.com and dtterminal.app, in that browser.
Rejecting optional storage does not block the Service. Withdrawing consent stops new optional collection and clears optional referral and campaign records on that device. Provider-side records already collected are retained under the schedule below.
5) Retention and account deletion
Account, journal, trade, community, and program data is generally kept while your account or relevant content remains active.
Encrypted exchange credentials are retained until the connection is disconnected or the account is deleted. MetaApi retains connection credentials under its service until the MetaApi account is removed.
Failed MetaTrader credential fingerprints exist in memory for the current page session only and are not written to durable browser storage.
Security, billing, payout, tax, fraud, and dispute records may be kept for the period required by law or reasonably needed to establish or defend claims.
Optional referral records on your device expire after 60 days. Analytics and service-provider logs follow configured provider retention periods and are deleted or aggregated when no longer needed.
Account deletion first attempts to revoke or destroy broker access, remove stored files, delete user-owned database records, and then delete the authentication account. If a required step fails, we keep the account so the deletion can be retried rather than falsely reporting completion. We retain a limited deletion audit containing internal and payment-provider identifiers, timestamps, step status, and deletion counts where needed for compliance, fraud prevention, billing disputes, and proof of completion. It does not retain your journals, trades, reflections, passwords, or broker secrets.
6) Your rights and controls
Subject to local law, you may request access, correction, export, deletion, restriction, objection, portability, or withdrawal of consent. You may also:
change profile, visibility, notification, and privacy settings;
disconnect broker integrations and revoke credentials at the provider;
unsubscribe from marketing using the email link or account settings without stopping essential messages;
export available trade data and delete your account from Settings; and
complain to your local data-protection authority.
We may verify your identity before fulfilling a request and may decline or limit a request where law permits. Authorized agents should contact us and provide proof of authority.
7) Security and credential handling
We use access controls, row-level database policies, encrypted transport, server-side authenticated encryption for supported stored broker API secrets, secret-column restrictions, audit logging, and service-provider controls. Use read-only broker or exchange credentials with trading and withdrawal permissions disabled, use a unique DT Journal password, and disconnect access you no longer need. No security measure can guarantee absolute protection.
8) International processing
DT Journal and its providers operate across countries, so data may be processed outside your location. Where required, we use contractual or other recognized safeguards and assess provider protections. Local law and government-access rules can differ from those in your country.
9) Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children under 18. Contact us if you believe a child has provided data.
10) Policy changes
We may update this policy as the Service or law changes. We will post the revised date and provide prominent notice of material changes. Where law requires fresh consent, we will ask before applying the change to consent-based processing.
11) Contact and privacy requests
Contact the DT Journal privacy contact at hi@dtjournal.app. Include “Privacy Request” in the subject. Formal notices and requests for the operator’s registered identity or service address may be sent to the same address.
Your privacy choices
Essential storage keeps DT Terminal working. Optional: product analytics and 60-day referral attribution. Change it any time in our Privacy Policy.