Start free — 14 days of Pro includedNo card needed; until you subscribe, Trader's AI budget and charts for NQ, ES, GC and their micros. Afterwards you keep a free plan with one synced account.Start free →

Privacy Policy

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:
Core Structure Trading - Thomas Seifert
Silberweidenweg 10
10365 Berlin
Germany
Email: privacy@tradelyst.ai

Due to company size we are not required to appoint a data protection officer. Please direct any privacy-related enquiries to the address above.

2. Overview of processing

The following overview summarises the categories of data we process and why:

  • Server and application logs (technical data; IP addresses truncated in access logs, Section 3)
  • Inventory data (email address, optional name, language, timezone, time and version of the accepted terms, redeemed invite code and referral code where applicable, Section 5)
  • Authentication data (password hash; encrypted session token in a cookie)
  • Usage data (trade records, setups, rules and rule breaches, notes, mood/energy, screenshots, settings)
  • Broker data if you connect a Tradovate account (Section 7a)
  • Billing data (via Stripe; we hold the customer ID, subscription status and your consent to early performance)
  • AI processing data (details of individual trades and aggregated statistics, Section 7)
  • Communication data (contact form, termination declarations, transactional emails)
  • Error reports (Sentry, Section 12)

3. Server and application logs

When you access our website or the application, our web server (nginx) records in its access logs: the truncated IP address (for IPv4 the last octet is removed, for IPv6 only the first 48 bits are kept), date and time of the request, requested URL and host name, HTTP status code, transferred byte count, referrer URL and user-agent string. Web-server error logs may contain the full IP address for failed requests.

The application writes technical event logs (e.g. errors, synchronisations, background jobs), usually with your internal user ID. For security events such as blocked login attempts they also contain the email address and IP address used.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security, error analysis and abuse prevention).
Retention: at most 30 days, then automatic deletion.
Recipients: hosting provider (see Section 12).

4. Cookies and storage on your device

We store information on your device only where this is strictly necessary to provide functions you have expressly requested (§ 25(2)(2) TDDDG). No consent is required for this. The subsequent processing is based on Art. 6(1)(b) GDPR (login and functions you set up) or Art. 6(1)(f) GDPR (security).

Cookies (application only, app.tradelyst.ai):

Browser storage (application only):

The marketing website (https://tradelyst.ai) sets no cookies and stores no data on your device. The only exception: if loading part of a page fails after a software update, the browser keeps the entry tradelyst:chunk-error-reload (sessionStorage) for the life of the tab so the page reloads automatically only once. This entry can also be created in the application. Language selection (de/en) is carried in the URL prefix (e.g. /de/pricing), not in a cookie. Referral links work without cookies (Section 5a).

We use no tracking or advertising cookies, no advertising networks, and no social-media plugins.

4a. Reach measurement (Umami, cookieless)

On the marketing website we operate a self-hosted instance of the open-source software Umami (umami.tradelyst.ai) for statistical reach measurement. Umami operates cookielessly and writes no data to your device — no cookies, no localStorage, no sessionStorage, no IndexedDB. The script only checks whether you have set an opt-out entry in your browser yourself (localStorage key umami.disabled) so that your objection is respected. As a result, no consent under § 25(1) TDDDG is required.

We collect only aggregated data: page visited, referrer, coarse country/region (derived from IP, not stored), browser class, screen-size bracket, timestamp. To distinguish returning visitors within a single day, Umami computes a server-side hash of IP address, user-agent, and a daily-rotating secret salt; that hash is deleted after 24 hours and cannot be reversed. There is no cross-day recognition.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in statistical reach measurement to improve the service).
Retention: aggregated statistics indefinitely. The daily-rotating hash id is deleted after 24 hours.
Recipients: none. Umami runs on our own server in Germany (hosting see Section 12); no data is transmitted to third parties or abroad.
Objection: you can object to reach measurement at any time by email to privacy@tradelyst.ai, or by blocking the domain umami.tradelyst.ai in your browser or via an extension such as uBlock Origin. The application (the authenticated area, app.tradelyst.ai) is not instrumented for reach measurement.

5. Registration and account

Using the SaaS application requires an account. You register directly with your email address and a password; in special cases (such as partner or community campaigns) you create the account with an invite code. On registration we collect:

  • Email address (required, used as login; we send a confirmation link)
  • Password (stored as a bcrypt hash, cost factor 12)
  • Optional display name
  • Language preference, timezone
  • The time and version of the terms you accept with the checkbox at registration (including your confirmation that you are of legal age)
  • When registering with an invite code: the redeemed code and the redemption timestamp
  • If you arrived via a referral link: the referral code (Section 5a)
  • Once your free trial starts: a normalised form of your email address (without a "+tag" and, for Gmail, without dots), so that it is granted only once per mailbox (Terms § 4(3))

Against automated registrations the form contains a field that is invisible to people. To limit registrations per IP address we use your IP address briefly in memory; it is not stored for this.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for recording the acceptance of the terms and for preventing abuse Art. 6(1)(f) GDPR (legitimate interest in proving the conclusion of the contract and in preventing automated registrations).
Retention: for the duration of the contractual relationship. After account deletion all personal data is irrevocably erased once the 30-day waiting period has passed (see Section 13).

5a. Referral links (affiliate programme)

If you reach us through a referral link (tradelyst.ai/r/<code>), we only count the visit: we store the referral code and the time — no IP address, no user agent, no referrer and no cookie. The code is passed on in the address to the registration page (/signup?ref=<code>). If you register there (or with an invite code, to which the link carries it on), we store the code with your account so the referral can be credited to the partner.

The partner only ever sees aggregated numbers (clicks, sign-ups, number of paying accounts), never your name or email address.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in attributing referrals in the affiliate programme).
Retention: on your account until account deletion; the click counters contain no personal data about visitors.

6. Authentication and session management

After login we store the session as an encrypted JSON Web Token in an HTTP-only, Secure, SameSite-Lax cookie (Section 4). The token contains your user ID, your email address, your display name if set, and the issue and expiry times; it is encrypted with a key only we hold. If you suspect a session is compromised you can use "Sign out everywhere" to invalidate every existing session server-side.

Brute-force protection: after repeated failed logins, further attempts are blocked for 15 minutes (5 attempts per email address, 25 per IP address). The counters are kept only in the server's memory. Legal basis: Art. 6(1)(b) and (f) GDPR.

7. Trading data and AI processing

Within the application we process the trade records you enter or import, setups, rules and rule breaches, notes (e.g. thesis and reflection), mood and energy ratings, uploaded screenshots, and statistics derived from them. This data is visible only to you and is processed solely to provide the service. Screenshots are served from random, unguessable addresses; anyone who knows such an address can view the image without logging in — so do not share screenshot links.

AI Coach. The AI features are enabled by default. For three features we send data to OpenAI to generate text:

  • Post-trade review (for closed trades that our local analysis cannot cover on its own): symbol, direction, number of contracts, R-multiple, holding time, setup name, tags, the texts you wrote as "thesis" and "reflection", your mood and energy rating, detected behavioural patterns (e.g. revenge trade), statistics for the same setup (count, win rate, average R), R-multiples of your last five trades in the same market, a situation summary (trading session, time of day and weekday in your timezone, result of the three preceding trades, number of trades that day), and the names and descriptions of your active setups and the account currency.
  • Morning brief (daily): aggregated statistics for the last 7 and 30 days (including win rate, R distribution, results by time of day, weekday, setup and market, adherence to your rules with the rule names, streaks, drawdown, projections, the exit times of trades in the equity curve and the number of trades per day), the previous day's trades (symbol, direction, setup, R-multiple, holding time, tags), the names and descriptions of your active setups, your timezone and the account currency.
  • Daily review (after the trading session closes): aggregated figures for the trading day (number of trades, win rate, markets traded, distribution by hour, best and worst trade with symbol and R-multiple, number of detected behavioural patterns) and the account currency.

Privacy mode is on by default for every account. Before transmission it replaces every computed money amount (e.g. profit and loss per trade and in total, the day's result, average win, drawdown, projections) with its sign; R-multiples, percentages and counts are still transmitted. With privacy mode switched off, these amounts are sent too. Text you write yourself (thesis, reflection, setup descriptions, tags) is transmitted as written — privacy mode cannot detect amounts inside it. Your name, email address, user ID, account names, exact entry and exit prices and screenshots are not sent to OpenAI.

OpenAI contractually commits not to use API inputs for training its own models (see OpenAI API Data Usage Policies). Requests are retained by OpenAI, including on servers in the US, for up to 30 days for abuse monitoring. We store the generated text with your trade or as a morning brief or daily review in your account.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
International transfer: EU Standard Contractual Clauses (SCCs) + EU–US Data Privacy Framework. OpenAI Ireland Ltd. is the primary contracting entity.
Switching off: under Settings → AI Coach (/settings/coach) you can switch off the AI features as a whole ("LLM features"), switch off the morning brief and the post-trade review individually, and switch privacy mode on or off. With the AI features switched off as a whole, no data is sent to OpenAI; the text is then produced by a deterministic, purely local analysis on our server. The daily review has no switch of its own and follows the main switch.

7a. Tradovate connection

Under "Connections" (/connections) you can connect an account at the broker Tradovate, LLC (USA) so that your trades are imported automatically. You start the connection yourself, and it uses the OAuth procedure: you log in directly at Tradovate and grant access there; we never learn your Tradovate password. Tradovate is an independent controller for its own processing and not our processor; Tradovate's privacy policy applies to it.

From Tradovate we receive:

  • access and refresh tokens with their expiry times, your Tradovate user ID and your Tradovate login name — stored encrypted with AES-256-GCM; the numeric Tradovate user ID additionally unencrypted so the connection can be matched;
  • the list of your Tradovate accounts (ID, name, account type) — we store only the mapping to your Tradelyst trading accounts, or the name you choose for a newly created account;
  • orders, executions (fills) and performance reports — from these we create closed trades (symbol, direction, quantity, entry and exit time and price, computed result), which are stored in your journal like manually entered trades;
  • open positions, account balances, the cash history (including deposits and withdrawals) and risk and auto-liquidation settings — we fetch these only for display (e.g. on the account pages and in the drawdown card) and do not store them.

While the connection exists we synchronise every 5 minutes and renew the tokens every 15 minutes. In doing so we send Tradovate the access token and, for report requests, the name of the Tradovate account concerned and the date range. Tradelyst does not place orders. If the connection fails, we notify you by email (can be switched off under Settings → Notifications).

Legal basis: Art. 6(1)(b) GDPR (a function you requested).
Transfer to the US: takes place at your request and is necessary for the connection you asked for (Art. 49(1)(b) GDPR).
Disconnecting: on the connection's detail page you can disconnect — the tokens are deleted immediately — or "forget" the connection, which deletes the connection record entirely. Trades already imported stay in your journal until you delete them (individually, in bulk, or together with the trading account).

8. Payment processing (Stripe)

Paid subscriptions are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. You are redirected to Stripe for payment (Stripe Checkout); you manage your payment method and invoices in the Stripe customer portal. Payment, card and bank data is handled exclusively by Stripe — we receive only status information (Stripe customer ID, subscription ID, subscription status, period end, failed payments) via webhook. The free trial at registration collects no payment method; if you take out a subscription during it, Stripe collects the payment method then and charges it only from the end of the trial — or, if you take it out in the trial's last 48 hours, from the day you take it out (Terms § 4(3)). Stripe is an independent controller for certain processing (e.g. fraud prevention, statutory payment obligations).

Before checkout you confirm in a checkbox that we should begin performance before the withdrawal period ends (see Terms § 8). We store this consent with its time and text version on your account and pass the same details to Stripe as metadata (checkout session and subscription).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the record of your consent Art. 6(1)(c) GDPR.
International transfer: Stripe processes some data in the US; Stripe Payments Europe Ltd. (Ireland) is the contracting entity; EU SCCs + DPF.
Retention with us: while your account exists. Stripe applies its own retention periods to satisfy financial-services obligations.

9. Market data (Databento)

Historical market data (e.g. NQ, ES, MNQ, MES, GC, MGC) is pulled from Databento, Inc. No personal data is transmitted to Databento; requests are made from our server using an API key.

10. Email (Resend)

We send email via Resend, Inc., USA. Transmitted: the recipient address, the subject and the body of the respective email. We send:

  • the link to confirm your email address after registration (it starts the free trial) and, when registering with an invite code, also a welcome email,
  • a password-reset link (when you request one),
  • a confirmation link to the new address when you change your email address,
  • the morning brief with AI- or locally generated text about your trading (on by default, can be switched off under Settings → AI Coach),
  • notices about broker-connection errors (on by default, can be switched off under Settings → Notifications),
  • a reminder three days before the free trial ends, with the plan that fits your accounts (not sent if you have already taken out a subscription), and when it ends a notice which of your synced accounts keep syncing on the free plan and which pause,
  • notices about failed payments and the confirmation that your subscription has ended,
  • after you take out a subscription, the contract confirmation (plan, price, term, cancellation, your consent to performance starting early) with the Terms and the cancellation policy attached; we store when it was sent and which version of the Terms and of the consent it carried, until your account is deleted,
  • the confirmation that your account has been deleted,
  • the confirmation of receipt of a termination declaration and, where applicable, a notice to the account holder (Section 11a).

Notifications about new contact enquiries and termination declarations to our own mailboxes are also sent via Resend.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the contract confirmation additionally Art. 6(1)(c) GDPR in conjunction with § 312f BGB; for the termination confirmation additionally Art. 6(1)(c) GDPR in conjunction with § 312k BGB.
International transfer: EU SCCs + EU–US Data Privacy Framework.

11. Contact form

When you use the contact form we store name, email address, subject and message, plus IP address, user agent, language and time of submission. We also receive a notification with these details (including the IP address) by email. Spam protection uses a hidden form field, a plausibility timing check and a limit on requests per IP address; we use no external services such as reCAPTCHA.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (answering your enquiry, abuse prevention).
Retention: 12 months from receipt; after that, enquiries are deleted automatically by a daily clean-up job.

11a. Termination declarations ("Cancel contracts here")

On the Cancel contracts here page you can terminate a subscription without logging in. We store the type of termination, the reason where given, your name, the email address for the confirmation, optionally your account's email address, the plan and a customer or invoice number, the requested end date, the language and the time of receipt. Your IP address is used only briefly in memory to limit requests and is not stored. You immediately receive a confirmation of receipt by email; we receive a notification. To apply the termination we match the declaration to your account by email address. If the confirmation address given differs from the account's email address, we also notify the account holder when we apply it.

Legal basis: Art. 6(1)(c) GDPR in conjunction with § 312k BGB, and Art. 6(1)(b) GDPR.
Retention: 3 years from receipt (regular limitation period, proof of the termination), also beyond an account deletion; then automatic deletion.

12. Hosting, error monitoring, processors and recipients

Hosting: we run the website, the application, the database, uploaded screenshots and the Umami instance on servers of IP-Projects GmbH & Co. KG, Am Vogelherd 14, 97295 Waldbrunn, Germany, in data centres in Frankfurt am Main (Germany). A data processing agreement is in place with IP-Projects.

Backups: we back up the database and uploaded screenshots daily. Backups are kept on the server and additionally on hardware owned by the operator; they are encrypted before they leave the server. Each backup is deleted after 30 days (Section 13). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing data loss) and Art. 32 GDPR.

Error monitoring (Sentry): when a technical error occurs in the application, we send an error report to Sentry, a service of Functional Software, Inc., USA. The report contains the error message and stack trace, the requested address or route, the time, technical information about browser, device and runtime and, for logged-in users, the internal user ID — but not name or email address. Transmission of IP addresses and cookies is disabled in our configuration. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable, error-free operation). Retention: Sentry deletes error reports when the contractual retention period ends, at the latest after 90 days.

We engage the following carefully selected processors within the meaning of Art. 28 GDPR:

  • IP-Projects GmbH & Co. KG, Waldbrunn, Germany — hosting (servers in Frankfurt am Main). DPA in place.
  • Stripe Payments Europe Ltd., Ireland — payments (partly an independent controller). SCCs + DPF.
  • OpenAI Ireland Ltd., Ireland — AI models (Section 7). SCCs + DPF.
  • Resend, Inc., USA — email delivery. SCCs + DPF.
  • Functional Software, Inc. (Sentry), USA — error monitoring. EU Standard Contractual Clauses or EU–US Data Privacy Framework.
  • Databento, Inc., USA — market data (no personal data).

Tradovate, LLC (USA) receives or transmits data only if you set up a connection, and acts as an independent controller when doing so (Section 7a). We operate the Umami reach measurement ourselves; it has no recipients.

Beyond this, we do not share your data with third parties — except where legally required (e.g. tax authorities, law enforcement). We never sell or share personal data for advertising or marketing purposes.

13. Retention and erasure

We retain personal data only as long as necessary for the stated purpose or as required by statute.

  • Account data and trade history: for the duration of the contractual relationship. Cancelling a subscription does not end the account: it continues on the free tier with all your data.
  • Account deletion: when you trigger deletion, the account enters a 30-day pre-delete state (you can reverse it at any point in that window). After expiry we first cancel every running Stripe subscription; only once that has succeeded are your account and all its content — trades, setups, rules, notes, uploaded screenshots, AI reviews, morning briefs, daily reviews, trading accounts and broker connections including tokens — irrevocably deleted, as are unredeemed invite codes bound to your email address; of the invite code you redeemed only the code remains, without the email address and notes. You then receive a confirmation by email. This data remains in backups for up to 30 days, until the respective backup is deleted.
  • Invoicing and tax data: 10 years per § 147 AO, §§ 238, 257 HGB. This data is held by Stripe.
  • Server and application logs: at most 30 days.
  • Backups: 30 days per backup (automatic deletion).
  • Contact-form enquiries: 12 months (automatic deletion).
  • Termination declarations: 3 years (automatic deletion).
  • Error reports at Sentry: at most 90 days.
  • Requests to OpenAI: at OpenAI, at most 30 days.

14. Your rights

Subject to the statutory conditions, you have the following rights:

  • Access to your data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Portability (Art. 20 GDPR) — under Settings → Account & data export you can download at any time a ZIP archive with your profile, trading accounts, trades, setups, rules, morning briefs, your AI usage log and your imports; we provide further data (e.g. screenshots, daily reviews, broker connections) on request
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of given consents, effective going forward
  • Complaint to a supervisory authority (Art. 77 GDPR)

To exercise these rights, email privacy@tradelyst.ai.

The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit). You may also contact the supervisory authority where you live; a list is available at bfdi.bund.de.

15. Security of processing

We apply technical and organisational measures within the meaning of Art. 32 GDPR, including: HTTPS (TLS) encryption for website and application, bcrypt password hashing, AES-256-GCM encryption of broker-connection tokens and other secrets, encrypted session tokens, request limits on authentication and other selected endpoints, and servers with restricted access in Germany. Please note the remark on screenshot addresses in Section 7.

16. Automated decision-making

No automated decision-making within the meaning of Art. 22 GDPR takes place. AI-generated text (morning brief, post-trade review, daily review) as well as automatically detected behavioural patterns and suggestions (e.g. for setup, tags or rule breaches) are purely informational and have no legal effect.

17. Changes to this Privacy Policy

We adapt this Privacy Policy when legal or operational circumstances change. The current version is always available at https://tradelyst.ai/en/legal/privacy. We notify registered users by email of material changes.

Last updated: 2026-09-13 (notice when the trial ends; before that 2026-09-12: contract confirmation by email after taking out a subscription; direct registration without an invite code: the stored acceptance of the terms, protection against automated registrations, the normalised email address for the once-only trial, referral links lead to the registration page; requesting invite codes by email is discontinued; free trial without a payment method, and the billing start for a subscription taken out in its last 48 hours; invite codes on account deletion; the email about the end of the trial; before that 2026-09-11: added hosting at IP-Projects, backups, error monitoring with Sentry, the Tradovate connection, the exact scope of AI processing and privacy mode, the full list of cookies and browser storage, cookieless referral links, termination declarations, the emails we send and retention periods; TTDSG replaced by TDDDG)