Privacy Policy
Last updated: October 3, 2026
1. Who We Are
This Privacy Policy explains how Tradewink LLC ("Tradewink," "we," "us") collects, uses, and shares personal information when you use the Tradewink website, web dashboard, Discord bots, mobile apps, APIs, and email and webhook alerts (the "Service"). Tradewink LLC is responsible for your personal information. Contact us at support@tradewink.com.
2. Information We Collect
Information you give us: your name, email address, username, and an optional phone number when you create or authenticate an account; your Discord user ID and username if you link Discord; watchlists, alerts, trading preferences, and risk settings; brokerage or exchange API credentials if you connect an account (stored encrypted); messages you send to the in-app assistant, support requests, survey answers, and feedback; strategy publications, public ratings/reviews, report reasons and optional notes, and member block choices; and records of your acceptance of our terms, including the version, the time, and the name you typed as your electronic signature. Information from your connected broker: account balances, buying power, positions, orders, fills, and trade history. Billing information: our payment processor, Stripe, collects your card details; we receive only your plan, subscription status, payment amounts, and similar billing records, never your full card number. Information collected automatically: IP address, browser and device type, pages viewed, links and buttons clicked, referring pages, performance and error diagnostics, and session recordings (see Section 6); and, in our mobile app, push notification tokens and a device public key used to verify trade approvals.
3. How We Use Your Information
We use personal information to: provide and operate the Service; send orders to your broker that you confirm or that your automation settings authorize; generate analysis and answer your questions; process payments and manage subscriptions; send alerts, service notices, and, if you have not opted out, product updates and marketing email; secure the Service and prevent fraud and abuse, including screening submitted research text and reviewing content reports; debug problems and improve the Service; keep records of our agreements with you; and comply with law. We may use trade outcomes, including from your account, in de-identified or aggregated form to evaluate and improve our own strategies and models. We do not give your personal information to AI model providers to train their models.
4. AI Model Providers
To generate analysis and answer questions, we send prompts and context to third-party large language model providers, routed through OpenRouter to model providers such as Google, OpenAI, Anthropic, DeepSeek, and Qwen depending on your plan. If you bring your own key, requests go to the provider you choose under your own agreement with that provider. Most requests contain market data and general context only. When you use the in-app assistant, the context can include your positions, account balances, buying power, profit and loss, recent trades, risk settings, and the messages you write, so the assistant can answer questions about your account. We do not add stored brokerage credentials, passwords, or payment card details to AI prompts. Do not put these details or personal identifiers in chat messages or search queries, because the text you submit may be sent to external providers. Model providers may process this data in the United States or other countries under their own terms.
5. Service Providers We Use
We share personal information with service providers that operate parts of the Service for us, only as needed for that purpose: Clerk (sign-in and account management); Stripe (payments); OpenRouter and the AI model providers described above; brokers, exchanges, and SnapTrade (when you connect an account and send orders); Discord (bot messages); Resend (email delivery); Apple Push Notification service (mobile notifications); Fly.io, Neon, and Cloudflare (hosting, database, and network delivery); Sentry (error tracking); Axiom (application log storage); and PostHog (product analytics and session recording, see Section 6). PostHog receives page views, feature usage, performance and error diagnostics, subscription tier, checkout status, and purchase amount. PostHog does not receive broker credentials, order instructions, positions, portfolio balances, or trade history. Market data vendors (such as Polygon.io, Finnhub, FRED, and SEC EDGAR) receive ticker and data requests. Research search providers, including Tavily and DuckDuckGo, receive search queries; strategy search results may also be processed by AI providers. The iOS app asks for consent before AI chat or online strategy search. Do not include personal identifiers or credentials in a search query.
6. Analytics, Session Recording & Cookies
We use cookies and similar browser storage to keep you signed in, remember your settings, and measure how the Service is used. We use PostHog session recording, which captures how pages are used (for example page content, clicks, scrolling, and mouse movement) so we can find and fix problems. Text you type into form fields is masked, and sensitive areas are excluded, before a recording is sent. We do not use advertising cookies or third-party advertising trackers, and we do not use analytics data to target ads. You can block or delete cookies and browser storage in your browser settings; some features, such as staying signed in, will not work without them.
7. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share personal information only: with the service providers described above; with your broker or exchange, to carry out actions you authorize; if required by law, subpoena, or court order, or to protect the rights, safety, and security of our users, the public, or Tradewink; in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy; and with your consent. When you publish a strategy or submit a public review, its content and display attribution can be seen by other users. Marketplace review responses use a member alias instead of a raw account ID. Content reports and block choices are not public: we keep account identifiers server-side to apply them and allow authorized staff to review report reasons and notes. We do not share personal information with unaffiliated third parties for their own marketing.
8. Data Security
Brokerage API credentials are encrypted at rest with authenticated encryption (Fernet) using keys derived with PBKDF2-HMAC-SHA256 (600,000 iterations) and a per-record salt, are never stored in plaintext, and are decrypted only when needed to talk to your broker. Data is sent over encrypted connections (TLS 1.2 or higher). We use access controls, log sanitization that strips API keys, and security monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not currently hold a SOC 2 or similar third-party certification, and no independent security assessment has been completed as of the date of this Policy.
9. Data Retention
We keep personal information while your account is active and afterwards only as long as reasonably needed to provide the Service, keep an accurate record of the instructions sent to your broker and of your agreements with us, resolve disputes, prevent fraud and abuse, and meet legal, tax, and accounting obligations. When you delete your account, we delete or de-identify your personal information except for records we must or reasonably need to keep for those purposes. Account data cleanup removes your authored marketplace listings and reviews, marketplace subscriptions, your reports, reports/moderation state for deleted content, and member block records involving the verified account identities. Moderation audit events retain a pseudonymous member alias, content ID, action and timestamp, without raw account IDs or report notes; pseudonymous records are not necessarily anonymous. No automatic expiry is currently configured for that audit. An incomplete cleanup is reported for retry or support. Authentication identity removal is a separate step, and signing out alone does not delete an identity. Session recordings and analytics are retained according to our analytics provider's retention settings.
10. Security Incidents
If we learn of a security incident that affects your personal information or brokerage credentials, we will investigate and contain it promptly, notify affected users without unreasonable delay and within the time required by applicable law, rotate any affected encryption keys, advise affected users to revoke and replace their broker API keys, and notify regulators where the law requires.
11. Your Rights & Choices
You can: access and export the personal information we hold about you; correct inaccurate information; delete your account and personal information (subject to Section 9); revoke broker access at any time by removing your keys in the Service and at your broker; and unsubscribe from marketing email using the link in any marketing message (we will still send service and billing notices). To make a request, email support@tradewink.com. We will verify your identity by confirming control of the email address or Discord account on your Tradewink account, and may ask for more information for sensitive requests.
12. California Privacy Rights
If you are a California resident, you have the right to: know what personal information we collect, use, and disclose; delete it; correct it; opt out of its sale or sharing (we do not sell or share personal information); limit the use of sensitive personal information (we use account credentials and similar sensitive information only to provide the Service); and not be discriminated against for exercising these rights. You may use an authorized agent, who must provide proof of authorization. We respond to verified requests within 45 days, as the law requires. Under California Civil Code Section 1798.83, you may also ask whether we disclosed personal information to third parties for their direct marketing; we do not.
13. European & UK Privacy Rights
If you are in the European Economic Area or the United Kingdom, we process personal information to perform our contract with you, for our legitimate interests in operating, securing, and improving the Service, to comply with legal obligations, and, where required, with your consent, which you may withdraw at any time. You have the right to access, correct, erase, restrict, or object to processing of your personal information, to data portability, and to complain to your local data protection authority.
14. International Data Transfers
The Service is operated from the United States, and your information is processed in the United States and in other countries where our service providers operate. Where the law requires, transfers of personal information from the EEA or UK rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses included in our service providers' data processing terms.
15. Children
The Service is only for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us personal information, contact us and we will delete it.
16. Law Enforcement & Legal Process
We disclose personal information to government authorities only in response to valid legal process such as a subpoena, court order, or warrant, or when we believe in good faith that disclosure is needed to prevent imminent harm. Where the law allows, we will make reasonable efforts to notify you before disclosing your information.
17. Changes to This Policy
We may update this Policy. If we make material changes, we will notify you in the Service, by email, or through Discord before they take effect, and update the date below.
18. Contact
Questions or requests about this Policy or your data: Tradewink LLC, support@tradewink.com. By mail: Tradewink LLC, 411 E Huntington Dr, Ste 107 #1334, Arcadia, CA 91006.