Service: Trading Journl
Operator: awaik
Version and effective date: 2026-07-15-v2
Contact: yong@awaik.io
Trading Journl is a web service for recording and reviewing trades. This policy describes information actually processed by the web service.
1. Information we process
Account and authentication information: Firebase UID, email address, and Google profile information made available to us.
Service data: trade records, positions, balances, journals, journal images, import files and batches, preferences, locale, and time zone.
Exchange connections: exchange API keys and secrets entered by you. They are encrypted before server-side storage and used only for connection verification and synchronization.
Contact and waitlist submissions: name, email address, message or survey response, and opt-in record.
Technical, security, and behavior information: limited diagnostic information, security events, error and performance information, Turnstile verification results, Analytics usage information, and clicks, scrolling, navigation, and session behavior on masked screens.
We do not collect dates of birth, guardian information, resident registration numbers, or location information. Firebase Authentication handles passwords; Trading Journl does not store them in its server or database.
2. Purposes
We process information to authenticate and secure accounts, provide trade-recording, journal, image, import, preference, and exchange synchronization features, prevent abuse, improve reliability, and process contact or waitlist requests.
We do not currently operate advertising-message delivery through email, SMS, KakaoTalk, or app push notifications.
3. Retention and deletion
Account and user-owned service data are deleted when an account is withdrawn. The withdrawal workflow deletes connections, balances, trades, positions, rounds, leverage records, journals, images, import data, quiz history, same-email waitlist data, and the Firebase account. After completion, we retain only a deletion receipt ID, processing timestamp, and a dedicated HMAC-pseudonymized value used solely to prevent the same email from rejoining for 30 days. We do not retain the original email for this purpose, and MongoDB TTL automatically purges the record after that period. We do not offer payment or e-commerce functions. If those are introduced, retention requirements will be reviewed and disclosed before launch.
4. Processors and international transfers
The following processors may handle information for the stated purposes: Google Firebase (authentication), MongoDB (service database), Vercel (web hosting and execution), Sentry (sanitized error and performance monitoring), Microsoft Clarity (masked session replays, heatmaps, and usage-flow analytics), Google Analytics (usage analytics), Cloudflare Turnstile (bot prevention), and Slack (contact and waitlist operating alerts).
Clarity receives masked interaction and navigation behavior and a Firebase UID that its SDK hashes before transmission. It is enabled only for authenticated users who have accepted the current policy; analytics storage is then granted while ad storage remains denied. Authenticated app and dashboard surfaces are fully masked so trade and journal contents are not included in recordings.
Their actual production regions and retention settings are not inferred. A release that makes this policy public is not approved until Vercel, MongoDB Atlas, Sentry, and Microsoft Clarity settings are verified and the transfer table is completed with each recipient, country/region, transfer method and timing, data categories, and retention period. The live release blocker is recorded in apps/web/docs/privacy-policy-release-blocker.md.
5. Your rights and contact
You may request access, correction, deletion, restriction, or withdrawal of consent. Use the account-management screen to request deletion or contact yong@awaik.io.
6. Children
The service is for people aged 14 or older. At sign-up or first use, users separately self-confirm that they are at least 14 and agree to the Terms and this Privacy Policy. We do not collect date-of-birth or guardian information.
7. Security and updates
We use encrypted transport, access controls, encrypted exchange credentials, token revocation checks, input and request limits, and sensitive-data filtering in logs and error monitoring. We will announce material changes with the effective date. Contact: yong@awaik.io.