[ DATA REGISTER ]
PRIVACY POLICY
Controller and scope
Tradesium determines how personal data is processed for the Tradesium website and research workspace and is the data controller for that processing. The operator identity and postal address are published in section 01 of the Terms of Service. This final policy is effective 5 August 2026 and applies to visitors, account holders, purchasers, support correspondents, and people who submit strategy or verification data.
Privacy and data-rights requests may be sent to support@tradesium.dev. Processing subject to Moroccan law is governed by Law No. 09-08 on the protection of individuals with regard to the processing of personal data and overseen by Morocco's Commission Nationale de contrôle de la protection des Données à caractère Personnel ("CNDP").
Data in the system
- Account data: Google/Lovable account identifier, email, display name, avatar, authentication state, plan, role, and verification state.
- Research content: strategy descriptions, structured specifications, requested indicators and rules, generated or uploaded code, repairs, version history, compiler feedback, audit findings, and backtest inputs/results.
- Usage and security data: request status, idempotency keys, credit reservations, rate-limit records, timestamps, provider metadata, model name, request IDs, token counts, latency, error class, browser/device data, and protected or hashed IP data.
- Transaction data: plan, entitlement state, Paddle customer and transaction references, currency, tax, payment status, renewal, cancellation, and refund events. Tradesium does not receive full card details.
- Communications data: sender and recipient addresses, display names, subject, message text, sanitized HTML, selected headers, threading identifiers, attachment metadata, delivery events, suppression status, and support replies. Tradesium does not persist attachment file contents in its own database.
Sources
Data comes from you, your browser, your Google authentication flow, your interactions with the workspace, Paddle purchase events, Supabase/Lovable authentication and database services, model providers, and Resend's sending and inbound-email service. When you request a backtest, data also comes from market-data and simulation services. Compiler reports are user-submitted; Tradesium does not scrape or automate TradingView.
Purposes and legal bases
Depending on where you live, Tradesium processes data because it is necessary to:
- perform the contract by authenticating you and delivering requested features;
- take steps you request before a purchase or generation;
- pursue legitimate interests in preventing abuse, securing accounts, enforcing limits, debugging failures, and maintaining thesis fidelity, provided those interests do not override applicable rights;
- meet tax, accounting, fraud-prevention, sanctions, and legal obligations; or
- act on consent or another express permission where law requires it, including optional communications and the default-off generator-improvement setting.
Tradesium does not use your research content to provide personalized investment advice or determine your eligibility for financial products.
Research-content access and generator improvement
Research Content includes every strategy description, specification, prompt, uploaded source file, generated or repaired code version, compiler report, audit, test, and backtest record stored through an account. Because this content is stored and processed on Tradesium's systems, Tradesium personnel and authorized service providers are technically able to access all of it. The workspace is not a zero-knowledge or end-to-end-encrypted code vault.
Access is limited to authorized purposes such as delivering requested features, maintaining versions, providing support, securing the service, investigating fraud or failures, and performing recorded operator review. Cross-account strategy inspection is restricted to authenticated administrators and the application records each list or source access in a protected audit log.
Future generator-improvement selection is off by default. A missing preference and an objection both prohibit selection. If you expressly enable the control in Settings, an authorized operator may select a stored version for a recorded review. Selection stores a reference and content hash rather than copying raw code into the candidate queue. It does not automatically use the strategy in a generator.
Approval requires a human reviewer other than the selector, a recorded de-identification method and version, and confirmation that the proposed reusable material excludes personal data, identifiable source, and raw strategy code. The approved-asset path accepts a bounded structured schema for generalized tests, failure or repair patterns, or aggregate statistics, rejects unapproved fields and nested free-form objects, and screens text for line breaks and common source-code markers. These safeguards support, but do not replace, the reviewer's required exclusion determination. Approved assets may then be internally reused to improve Tradesium's generators, audits, and repairs. Tradesium does not sell Research Content, make private code public, list it in the Marketplace, give identifiable private code to another customer, or use it to place trades.
Turning the setting off records an objection, prevents new selection, and withdraws pending candidates. It does not remove a genuinely de-identified asset already approved; such an asset may be retained for the useful life of the generator and audit systems, subject to applicable law. The intellectual-property permission is described in the Terms. Where Law No. 09-08 or another applicable law requires consent, a declaration, authorization, or permission for a change of purpose, Tradesium must obtain it before that processing begins. You may also contact support@tradesium.dev.
Model-provider processing
To generate, audit, explain, or repair strategy code, Tradesium sends the normalized strategy specification and the minimum relevant code, findings, or compiler errors to the configured OpenAI or Anthropic commercial API. Provider calls occur server-side; API keys are not sent to the browser.
Tradesium does not log full private strategy descriptions or generated source by default. OpenAI states that API data is not used for model training unless the customer opts in, that standard abuse-monitoring logs may be retained for up to 30 days, and that some API features may retain separate application state. Anthropic states that commercial API inputs and outputs are not used for training by default and are normally deleted within 30 days, subject to its policy and legal exceptions. Actual provider handling depends on the endpoint, account configuration, and current provider terms.
Authentication
Google authentication is provided through Lovable Cloud and Supabase. Authentication tokens and essential session state are used to keep you signed in and to derive the account server-side. Do not share your session or permit another person to use your account.
Billing and Paddle
Paddle processes checkout as the authorized reseller and Merchant of Record. Paddle collects payment-method, billing, tax, fraud, and transaction data under its own privacy notice and shares with Tradesium the records needed to grant entitlements, reconcile purchases, respond to billing events, and prevent fraud. Do not send payment-card data through a Tradesium text field.
Processors and recipients
Data may be disclosed only as needed to:
- Supabase and Lovable for authentication, database, server, and hosting functions;
- Google for OAuth authentication;
- OpenAI and Anthropic for configured generation and review operations;
- Paddle for checkout, tax, subscription, billing, and refunds;
- Resend for transactional email, delivery-status processing, inbound support mail, replies, and attachment handling;
- market-data and backtesting infrastructure when you request eligible simulations;
- professional advisers, authorities, or counterparties where law or a transaction requires it.
Tradesium does not sell personal data and does not intentionally configure advertising trackers in the current application. Providers may process data as processors or, for some functions, as independent controllers under their own notices.
Cookies and local storage
Tradesium uses essential browser storage, cookies, or equivalent technologies for authentication, security, theme preference, and application state. Google, Lovable, Supabase, Paddle, or other embedded provider flows may set their own essential storage. A consent mechanism must be added before any non-essential analytics or advertising technology is introduced where consent is required.
International transfers and CNDP formalities
Providers and infrastructure may process data outside Morocco or your country. Transfers governed by Moroccan law must satisfy Articles 43 and 44 of Law No. 09-08, including a sufficient level of protection or another permitted basis, and any required CNDP transfer request or authorization. Provider contracts do not replace those formalities. Provider locations and transfer terms can change; their current notices control their independent processing.
Tradesium must submit the declarations, authorization requests, purpose changes, and foreign-transfer filings required by the CNDP before carrying out processing for which those formalities are mandatory. Any CNDP receipt or authorization reference applicable to this service will be added to this policy once issued; no reference number is fabricated.
Retention
Tradesium keeps account, strategy, version, audit, compile-feedback, backtest, credit, and transaction records while needed to provide the workspace and maintain its evidence trail. Security and rate-limit records are kept only for their operational window where possible; some implemented short-window limiter records expire after roughly two days.
Limited transaction, dispute, fraud, and security records may be retained after account closure where required or reasonably necessary. Support correspondence and email-delivery records are retained while needed to answer the request, maintain the support and legal evidence trail, enforce suppression lists, resolve disputes, and meet legal obligations. Raw Research Content is retained while needed for the account, version history, support, security, legal obligations, and any expressly permitted pending improvement review. Genuinely de-identified, human-approved improvement artifacts may be retained for the useful life of the generator and audit systems. Resend and model providers apply their own retention rules under their current terms.
Security
Tradesium uses server-derived identity, row-level access controls, server-only provider and service credentials, request validation, size limits, idempotency, persistent rate and concurrency controls, credit reservations, restricted usage telemetry, and protected IP identifiers where implemented. Generated strategy source is not executed by the web generation worker.
No system is completely secure. You are responsible for securing your Google account and for keeping secrets, brokerage credentials, and sensitive personal data out of strategy prompts and source files.
Your privacy rights
Under Morocco's Law No. 09-08, eligible people have rights including information, access, rectification, and objection on legitimate grounds. Depending on your location, you may also have rights to delete or restrict processing, receive portable data, withdraw consent, and complain to the CNDP or another competent data-protection authority. Withdrawing consent does not invalidate earlier lawful processing.
Identity must be verified before fulfilling a request. Tradesium may retain the minimum data necessary for legal claims, security, fraud prevention, or other lawful exceptions and will explain an applicable limitation. Submit a request to support@tradesium.dev from the account email where possible and describe the right you want to exercise. Do not include passwords, API keys, brokerage credentials, or complete payment-card information. Moroccan data-protection complaints may also be directed to the CNDP.
Automated checks
Tradesium uses deterministic and model-assisted checks to normalize specifications, detect ambiguity, audit code, protect strategy thesis fidelity, enforce abuse controls, and decide whether a generation can proceed. These checks affect use of the software and credits; they do not make financial, employment, lending, insurance, or other similarly significant decisions about you.
Children and changes
Tradesium is not directed to children and should not be used by anyone unable to enter a binding agreement under applicable law. If Tradesium learns that prohibited child data was collected, it will take appropriate deletion or restriction steps.
Material policy changes will carry a new revision date and, where required, notice or consent. Continued use after an effective change is subject to applicable law and the updated record.
Privacy contact and final status
Contact support@tradesium.dev for privacy questions, data-rights requests, objections to future code-improvement processing, or security concerns involving personal data. Authenticated users can also record the future-improvement preference in Settings. This is the final published Privacy Policy effective 5 August 2026. Mandatory rights and CNDP requirements remain controlling regardless of any provision in this policy.