← BACK TO AITRADELY
LEGAL / PRIVACY

Privacy Policy.

How we collect, use, and safeguard your information when you use AiTradely.

LAST UPDATED · AUGUST 24, 2026

AiTradely (“we,” “our,” or “us”) is operated by LaunchMap LLC, a Wyoming limited liability company. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the “Service”).

By using the Service, you agree to the collection and use of information in accordance with this policy.

Summary of the August 2026 update: we added a section on connected brokerage accounts (Section 4), because the Service can now place orders with a broker you connect yourself; a section on product analytics (Section 6) naming PostHog and Google Analytics; a section on cookies (Section 7); and a section on notifications and Live Activities (Section 8). We also corrected the “what we do not collect” list, which was written before broker connections existed.

Summary of the 19 August 2026 update: our Android app now integrates the Facebook SDK, which the iOS app has used since May 2026. Section 5 gains a subsection describing what that SDK collects on Android (the Google Advertising ID and the Google Play install referrer) and how to opt out at the device level. Android has no equivalent of Apple's App Tracking Transparency prompt, so the previous wording in Section 4, which described advertising identifiers as collected only after an ATT consent, no longer described Android accurately and has been corrected.

1. Information We Collect

Information you provide directly:

  • Account information: Email address, display name, and password when you create an account. If you sign in with Google or Apple, we receive the email address and basic profile information those services release to us.
  • Onboarding answers: The markets you follow, your experience level, and similar preferences you select during setup.
  • Trade data: Positions, entry prices, quantities, stop and target levels, and trade notes you log in the portfolio tracker.
  • Trading strategies: The rules, indicators, timeframes, and conditions you define in the Strategy Builder, and the backtests you run against them.
  • AI chat conversations: Messages you send to the AI assistant, and any screenshots or images you upload to it.
  • Watchlist and alert preferences: Assets you follow, price alerts you set, and your notification settings.
  • Payment information: Processed securely by Apple (App Store, on iOS) or Stripe (on the web and Android). We do not store your card number.
  • Telegram connection: Your Telegram chat ID when you connect the Telegram bot for notifications.
  • Support messages: The content of any support request you send us, including attached images. Support conversations are relayed to our operators through Telegram so we can reply to you (see Section 9).
  • Broker connection: If you choose to connect a brokerage account, the authorisation tokens and account details described in Section 4.

Information collected automatically:

  • Usage data: Pages viewed, features used, AI questions asked, session duration, and interaction patterns.
  • Device information: Device type, operating system, app version, and unique device identifiers.
  • Device identifier for abuse prevention: In our mobile apps we read or store a per-device identifier so that our introductory benefits can only be claimed once per device. Those benefits are the introductory subscription price offered to a new account, and any free trial. On iOS this is a randomly generated identifier we store in the device keychain; on Android it is the operating system's per-app device identifier. Neither contains personal information, neither can be used to identify you across other companies' apps, and both persist across reinstalls on the same device. This identifier cannot be turned off, because it is what stops the same device from claiming the same introductory benefit repeatedly under new accounts.
  • Notification tokens: If you enable notifications, the token your device is issued so we can deliver them — Apple Push Notification service on iOS, Firebase Cloud Messaging on Android. It identifies a device, not you, and we use it only to send the alerts you asked for (see Section 8).
  • Approximate location (country only): We derive the two-letter country code of your connection from your IP address at the network edge. We use it solely to comply with regional rules — for example, we do not show CFD broker promotions to visitors in the United States or the European Economic Area. We do not store a location history, and we do not collect precise or GPS location.
  • Analytics data: Product analytics events describing how you use the Service, as described in Section 6.
  • Advertising identifiers: Our mobile apps can collect the advertising identifier your device issues, so that we and our advertising partner Meta Platforms can measure ad effectiveness and attribute app events to advertising campaigns. On iOS this is the Advertising Identifier (IDFA), and it is collected only if you allow tracking at Apple's App Tracking Transparency (ATT) prompt. On Android this is the Google Advertising ID, which the operating system provides unless you delete it in your device settings; Android has no ATT prompt, so this is an opt-out rather than an opt-in. See Section 5 below for details, including how to opt out on each platform.
  • Advertising click identifiers: When you arrive from a paid advertisement, the ad platform appends a click identifier to the link — gclid for Google Ads, fbclid for Meta. We store that identifier, along with any utm_source, utm_medium, utm_campaign, utm_content, and utm_term tags, on your profile so we can attribute your sign-up to the campaign that produced it.
  • IP address and user agent: When you visit our website, your IP address and browser user-agent string are sent server-side to our advertising partner Meta Platforms to support conversion attribution.

Information we do NOT collect:

  • We do not collect your brokerage account password, and we never ask for it. Broker connections use OAuth, so your credentials are entered on your broker's own website and are never visible to us (see Section 4).
  • We do not have the ability to withdraw, transfer, or move funds in or out of any account you connect.
  • We do not access bank accounts, exchange accounts, or any account you have not explicitly connected.
  • We do not collect precise GPS location data.
  • We do not sell your personal information, and we do not share your trade data, strategies, portfolio, or AI conversations with advertisers.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service.
  • Generate AI market analysis contextualised to your selected assets, strategies, and logged positions.
  • Run your saved strategies against live market data and alert you when their conditions are met.
  • Send daily analysis, signal alerts, event reminders, and other notifications via push, Live Activities, and Telegram.
  • Route and place orders you explicitly authorise with a broker you have connected, and keep your portfolio in sync with that broker (see Section 4).
  • Process subscription payments through Apple or Stripe.
  • Analyse usage patterns to improve features and user experience (see Section 6).
  • Measure the effectiveness of our advertising campaigns and attribute conversions to the correct ad source (see Section 5).
  • Determine which regional disclosures and restrictions apply to you.
  • Respond to customer support requests.
  • Prevent fraud and abuse, and enforce our Terms of Service.

3. Third-Party AI Data Processing

AI features in AiTradely are powered by Anthropic, PBC(“Anthropic”), a third-party AI service provider. Before any data is sent to Anthropic, the app requests your explicit consent through an in-app disclosure. No data is transmitted to Anthropic until you accept.

What data is sent to Anthropic:

  • AI chat messages: The text of questions and follow-ups you type in the AI assistant.
  • Market context: Current asset prices, technical indicators (RSI, MACD, support/resistance, etc.), correlations, and recent news headlines for the selected asset.
  • Trade screenshots: Images you upload for AI trade extraction are sent to Anthropic's vision model for analysis.
  • Portfolio context: If you ask the AI about your portfolio, your logged positions and P&L data may be included in the request.
  • Strategy context: If you ask the AI to build, explain, or refine a strategy, the strategy rules and its backtest results may be included.
  • Watchlist context: The assets you follow, so the assistant can answer questions about “my markets” without you naming each one.
  • Order drafts: If you ask the assistant to prepare an order, the instrument, direction, size, and levels of the draft are included so it can fill in the ticket. The assistant prepares tickets; it cannot place them (see Section 4).

How Anthropic handles your data:

  • Anthropic processes your data solely to generate AI responses. Data is not used to train AI models when accessed through their commercial API.
  • Anthropic may retain API inputs for up to 30 days for trust and safety purposes, after which they are deleted.
  • Anthropic's data handling practices provide equal or greater protection of your personal data as described in Anthropic's Privacy Policy and their API Data Usage Policy.

Data we store from AI interactions:

Your AI conversation history is stored on our servers (hosted by Supabase) to maintain chat history and enable features like trade review and performance analysis. You can clear your chat history at any time from within the app.

4. Connected Brokerage Accounts

The Service lets you connect a brokerage account that supports the cTrader platform, so that orders you approve in AiTradely can be sent to your broker. Connecting a broker is entirely optional. If you never connect one, nothing in this section applies to you, and every other feature of the Service continues to work.

How the connection is authorised:

Connections are established through OAuth. You are redirected to your broker's own login page, you authenticate there, and your broker returns an authorisation token to us. We never see, receive, or store your broker username or password. You can revoke the connection at any time, either from within AiTradely or from your broker's account settings.

What we store:

  • Access and refresh tokens issued by your broker. These are stored as AES-256-GCM ciphertext, never in plain text.
  • The trading account you select — its account identifier, a display label, its currency, and whether it is a live or demo account.
  • Orders you place through the Service — instrument, direction, order type, size, entry, stop loss, take profit, status, and the broker's order and position identifiers.
  • Synced positions — positions and deal history read back from your broker so your Portfolio reflects reality rather than only what you typed in manually.
  • Account state needed to size and validate an order — such as balance, equity, available margin, and the leverage your broker has assigned to the account.

How this data is protected:

Broker tokens grant access to a real-money trading account, so we treat them as the most sensitive data we hold. The tables that store broker connections and broker orders have row-level security enabled with no access policies at all, which means they are unreadable by any browser, app session, or logged-in user. Including you. They are reachable only by our server, and only in order to carry out an action you have requested. Trading tokens are never transmitted to the client.

What we cannot do:

  • We cannot deposit, withdraw, or transfer funds. The broker connection does not grant that permission.
  • We do not place orders on your behalf automatically, on a discretionary basis, or without your explicit confirmation of that specific order.
  • We do not act as your broker, hold your money, or take custody of any asset.

Who sees this data:

Your broker receives the orders you authorise, and its own privacy policy governs what it does with them. We do not share your broker account data, balances, positions, or order history with advertisers, analytics providers, or any other third party. If you disconnect your broker, we delete the stored tokens; order and position records already synced to your Portfolio remain part of your account history until you delete your account.

5. Advertising, Attribution, and Tracking

We run paid advertising campaigns on Facebook and Instagram, which are operated by Meta Platforms, Inc. and its affiliates (collectively, “Meta”), and on Google Search and the Google Display Network, operated by Google LLC (“Google”). To measure how well those campaigns work and to show you ads that are more relevant to your interests, we share a limited set of data with those platforms.

Meta Conversions API (server-side):

When you sign up for an account or complete a purchase on our website, our servers send a conversion event to Meta's Conversions API containing a hashed version of your email address, a hashed version of your user ID, your IP address, and your browser user-agent string. We never send Meta your raw (unhashed) email or name. Meta uses this data solely to attribute the event to a Facebook or Instagram ad you may have clicked, and to improve ad targeting. This processing happens regardless of whether you have installed the Meta Pixel in your browser.

Facebook SDK for iOS (in-app):

Our iOS application integrates the Facebook SDK to support advertising attribution under Apple's SKAdNetwork and Aggregated Event Measurement frameworks. Because Apple requires explicit consent for cross-app tracking, on first launch the app shows you Apple's App Tracking Transparency prompt asking whether you want to allow tracking across other companies' apps and websites.

  • If you tap “Allow Tracking”: the SDK may collect your device Advertising Identifier (IDFA) and send app event data (account creation, subscription purchase) to Meta so your conversion can be attributed to an ad.
  • If you tap “Ask App Not to Track”: no Advertising Identifier is collected, and Meta receives only aggregated, privacy-preserving conversion signals through Apple's SKAdNetwork. We do not attempt to identify you individually.

Facebook SDK for Android (in-app):

Our Android application integrates the same Facebook SDK, so that installs and in-app events can be attributed to the advertisement that produced them. Android has no equivalent of Apple's ATT prompt, so the app does not show you a tracking consent dialog. The SDK reads your Google Advertising ID and sends app event data (app install, app launch, account creation, subscription purchase) to Meta. It also reads the Google Play install referrer, which carries the identifier of the ad you clicked before installing.

You control this at the device level rather than in the app. If you delete your advertising ID in Settings → Google → Ads, Android stops issuing the identifier and the SDK cannot collect it. Opting out of ads personalisation on that same screen also limits how Meta may use what it already received.

Google Ads (conversion measurement):

When you arrive at our website from a Google ad, Google appends a click identifier (a “GCLID”) to the link. We store this identifier with your account so that, if you later sign up or subscribe, we can report that conversion back to Google to measure which ads are effective. We share only the click identifier and the fact that a conversion (sign-up or purchase) occurred ,together with the amount and currency for purchases, never your email, name, trade data, strategies, broker account, watchlist, or AI conversations. Google's handling of this data is governed by Google's Privacy Policy.

Campaign tags:

We also record standard campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) and Meta's fbclid click identifier when they are present in the link you arrived from. These are stored on your profile and used only to understand which channel produced a sign-up. They are not shared with anyone other than the advertising platform that issued them.

What the ad platforms receive from us:

  • Event name (e.g., “CompleteRegistration,” “Subscribe,” “Purchase”)
  • Event timestamp
  • Hashed email address (SHA-256, Meta only)
  • Hashed internal user ID (SHA-256, Meta only)
  • The click identifier that brought you to us (GCLID or fbclid)
  • Purchase amount and currency (for purchase events only)
  • IP address and user-agent string (Meta, website events only)
  • Advertising Identifier / IDFA (iOS app events, only if you grant ATT consent)
  • Google Advertising ID (Android app events, unless you delete it in your device settings)
  • Google Play install referrer, including the ad click identifier (Android installs)

What the ad platforms do NOT receive:

  • Your raw email address or name
  • Your trade data, portfolio positions, or P&L figures
  • Your trading strategies or backtest results
  • Your connected broker, broker account details, or order history
  • Your AI chat conversation content
  • Your watchlist contents
  • Any financial account credentials

Your choices:

  • iOS app tracking: You can revoke ATT consent at any time in Settings → Privacy & Security → Tracking → AiTradely.
  • Android advertising ID: You can delete your advertising ID, or opt out of ads personalisation, in Settings → Google → Ads.
  • Web advertising (Meta): You can opt out of personalised advertising from Meta at facebook.com/settings?tab=ads.
  • Web advertising (Google): You can manage or opt out of personalised Google advertising at adssettings.google.com.
  • Browser-level opt-out: Enable “Do Not Track” in your browser, or use tools like Apple's Intelligent Tracking Prevention.
  • Opting out of advertising attribution does not stop you from using AiTradely, all core features remain available.

Meta's own handling of the data it receives from us is governed by Meta's Privacy Policy.

6. Product Analytics

To understand which features people actually use and where the Service is confusing or broken, we record product analytics events using two providers:

PostHog:

We use PostHog, Inc. for product analytics, on their US-hosted cloud. When you are signed in, we associate events with your internal user ID and your email address, so that we can investigate a support issue for a specific account and understand how individual accounts progress through onboarding and subscription. We also attach your device type and operating system.

We record named events only — such as opening the calendar, asking the AI a question, saving a strategy, or viewing the pricing page. PostHog's “autocapture” is deliberately disabled, so we do not record every click. We do not use session replay, so we do not record your screen, your keystrokes, or the contents of what you type. Analytics events never include your AI conversation content, your broker credentials, or your broker account balances.

Google Analytics:

Our website loads Google Analytics 4 to measure traffic, referral sources, and page performance. Google Analytics sets its own cookies and receives your IP address, the pages you view, and general device and browser information. Its use of that data is governed by Google's Privacy Policy. You can prevent Google Analytics from collecting your data entirely by installing Google's opt-out browser add-on.

7. Cookies and Similar Technologies

We and our providers use cookies, browser local storage, and similar technologies. The categories in use are:

  • Strictly necessary: Authentication and session cookies set by our sign-in provider (Supabase), and local storage holding your language and last-viewed tab. These keep you signed in and the app usable. They are always active and cannot be switched off, because the Service does not function without them.
  • Analytics: Cookies and local storage set by PostHog and Google Analytics, as described in Section 6.
  • Advertising: Cookies set by Meta and Google in connection with the advertising described in Section 5.

If you are in the European Economic Area or the United Kingdom, analytics and advertising cookies are not set until you agree to them. We ask when you first visit, and you can change your answer at any time from Your Privacy Choices. Refusing is as easy as agreeing, and refusing does not restrict any feature of the Service.

Outside those regions, analytics and advertising cookies are set by default. You can still opt out at any time from Your Privacy Choices, or by blocking cookies in your browser. Blocking strictly necessary cookies will prevent you from signing in.

We previously used Yandex.Metrika for site analytics. It was removed on 15 August 2026 and is no longer loaded on any page.

8. Notifications and Live Activities

If you enable notifications, we store the push token your device issues so we can deliver alerts. On iOS this includes Live Activity tokens, which allow us to display a live position or event card on your Lock Screen and Dynamic Island and update it as prices move. These tokens identify a device or a running activity, not you personally, and they expire on their own. We use them only to deliver the alerts you asked for.

You can turn notifications off at any time in your device settings or in the app's notification preferences, and you can disconnect Telegram from within the app.

9. Data Sharing and Disclosure

We do not sell your personal information. We share data only in the following circumstances:

  • Service providers: We use third-party services to operate the platform, including Anthropic (AI analysis — see Section 3), Supabase (database and authentication), Vercel (web hosting), Stripe (payment processing), Apple (App Store payments and push delivery), Resend (transactional email), Telegram (notifications and support relay), PostHog and Google (analytics. See Section 6), and Meta Platforms and Google (advertising attribution. See Section 5). Market data is retrieved from providers including CoinGecko, TwelveData, and Yahoo Finance; these requests are made by our servers and do not identify you. These providers access only the data necessary to perform their functions and are contractually required to protect your data with safeguards equal to or greater than those described in this policy.
  • Your connected broker: If you connect a brokerage account, the orders and instructions you authorise are transmitted to that broker (see Section 4).
  • Support handling: Support conversations, including any images you attach, are relayed to our operators through Telegram so we can read and answer them. Do not include passwords or card numbers in a support message.
  • Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

10. Data Retention

We retain your account data, trade history, and strategies for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention, or records of completed transactions we are required to keep).

Broker authorisation tokens are deleted when you disconnect the broker or delete your account, whichever happens first. AI conversation history is retained for the duration of your subscription. Anonymised and aggregated data may be retained indefinitely for analytics purposes.

11. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS/SSL), encryption at rest, row-level security on our database, and secure authentication. Brokerage authorisation tokens receive an additional layer of application-level AES-256-GCM encryption and are restricted to server-side access only. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

12. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your personal data.
  • Data portability: Request your data in a machine-readable format.
  • Objection and restriction: Object to, or ask us to restrict, processing carried out on the basis of our legitimate interests — including analytics and advertising attribution.
  • Withdraw consent: Where processing relies on your consent (AI processing, App Tracking Transparency, notifications, broker connection), you may withdraw it at any time without affecting the lawfulness of processing already carried out.
  • Opt-out: Disable notifications, disconnect Telegram, disconnect your broker, revoke App Tracking Transparency consent, or adjust privacy settings within the app.
  • Non-discrimination: We will not deny you service, charge you a different price, or give you a lower quality of service for exercising any of these rights.

If you are in the European Economic Area or the United Kingdom, our legal bases for processing are: performance of a contract (operating your account, running your strategies, routing orders you authorise), consent (AI processing, advertising identifiers, notifications), legitimate interests (product analytics, security, fraud and abuse prevention), and legal obligation where applicable. You also have the right to lodge a complaint with your local supervisory authority.

To exercise any of these rights, contact us at support@aitradely.com. See also our Privacy Choices page.

13. Children's Privacy

The Service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will delete it promptly.

14. International Data Transfers

Your data may be processed and stored in the United States and other countries where our service providers operate. By using the Service, you consent to the transfer of your data to these jurisdictions, which may have different data protection laws than your country of residence. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses for transfers out of the European Economic Area and the United Kingdom.

15. Third-Party Links

The Service contains links to third-party websites and services, including news sources referenced in AI analysis, and the brokers we introduce. Some of these links are commercial: we may be compensated when you open an account with a broker we link to, as disclosed in our Terms of Service. We are not responsible for the privacy practices of these third parties, and once you follow such a link, the data you provide is governed by their policy rather than ours. We encourage you to review it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy in the app and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

17. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

LaunchMap LLC
30 N Gould St, Ste R
Sheridan, WY 82801, United States
Email: support@aitradely.com