Privacy Policy
Version 1.33 · Effective
1. Who is responsible
Nandro IT B.V. (“Nandro IT”, “we”, “us”, “our”) is the controller for the personal data described in this policy — the company that decides why and how your data is processed. Nandro IT B.V. is registered in the Dutch Handelsregister under KvK number 83341439.
Email: support@tradelunatic.com
For our VAT registration details, see our legal notice.
2. What we collect and why
We collect only what running StratVerra requires:
| Data | Where it lives | Purpose | Lawful basis |
|---|---|---|---|
| Email, name, sign-in credentials | Our own identity server (Netherlands) | Your account | Contract |
| Stripe customer reference, subscription status and renewal date | Our platform database | Billing | Contract |
| Strategies you build, and their versions | Our platform database | Running the product | Contract |
| Backtest and live runs, results, fills and logs | Our platform database | Running the product | Contract |
| Conversations with the AI assistant | Our platform database | The assistant feature | Contract |
| A record of AI usage cost | Our platform database | Fair use and abuse prevention | Legitimate interest |
| Broker connection settings — address, port, account number | Our platform database | Live trading | Contract |
| Name, email, category and message you send through the contact form | The mailbox it arrives in — not our database | Answering your enquiry | Legitimate interest, or Contract if it concerns a subscription you hold |
A recording of your visit to this website and the logged-out preview at /try — pointer movement, clicks, scrolling, how the page looked, and, outside our contact form, what you typed — including your prompt, the strategy written for you and your results on /try — plus which pages you viewed and the buttons you pressed |
PostHog, Inc. Not our database. In the app it stops the moment you have an account; on this website it runs on every visit where measurement is allowed, account or no account | Seeing where a page or the guest preview loses people, and what they were doing right before they left, which a count of page views cannot show | Consent in the EEA, UK and Switzerland; legitimate interest elsewhere |
| An advertising click identifier and campaign parameters from the link you arrived on, and — once you have answered — whether you accepted ad measurement | Your browser. The click identifier and campaign parameters also reach our platform database if you start a guest preview or go on to start a trial, and a Google click identifier reaches PostHog with the report described in §4; your consent answer never does — it stays in your browser only | Telling which advertisement led to a preview, a sign-up or a subscription | Consent in the EEA, UK and Switzerland; legitimate interest elsewhere |
| Your email address, hashed (SHA-256) — only if the advertisement that brought you here was Google’s or Reddit’s, and only if you go on to start a trial or a subscription | Sent to that platform. Google’s copy travels through PostHog, which keeps it with the report (see §4); it is never stored in our database | Telling that platform its advertisement led to a sign-up or a subscription | Consent in the EEA, UK and Switzerland; legitimate interest elsewhere |
| The Reddit click identifier from the link you arrived on, and a random identifier for that preview session — only if the advertisement that brought you here was Reddit’s, and only if you start a guest preview. No email address: a guest preview has none | Sent to Reddit. The click identifier is also in our platform database, as described above; the random identifier is the one your guest session already uses there | Telling Reddit its advertisement led to a preview | Consent in the EEA, UK and Switzerland; legitimate interest elsewhere |
| Your answer to “How did you hear about us?”, if you choose to answer it. The question is optional and you can skip it. Picking “Something else” opens a free-text box, so this field holds whatever you type into it — a community name, a person, a website, anything | Our platform database, against your account | Learning which channels bring people here, including ones no advertising click identifier can show | Legitimate interest |
The contact form, and the app’s no-account preview, are both protected by Cloudflare Turnstile, which checks that a submission or a preview session starts from a person rather than a script. To do that it processes your IP address and information about your browser. We use your IP address for that check alone — it is not stored, and it does not appear in the message we read or anywhere in the preview. Cloudflare also carries the contact form’s message itself: the form hands your name, email address, category and message to Cloudflare’s email service, which delivers it to our mailbox.
If you try StratVerra through the guest preview, before you have an account, the browser you are using stores an anonymous identifier so the preview can find its way back to you, and our platform database holds the conversation and the strategy it produces against that identifier — nothing that identifies you personally, because none is collected until you register. That identifier expires 30 days after the preview starts and cannot be renewed, so the preview itself cannot be reopened after that. The conversation and the strategy stay in our database after it expires; if you create an account before then, they move to it and are kept the way the rest of this policy describes, and either way you can ask us to delete them at any time using the contact details in our legal notice. We hold them on the basis of our legitimate interest in letting you evaluate the product before you decide whether to create one.
If you arrived from one of our advertisements, the same anonymous identifier is also where the advertising click identifier and campaign parameters from that link are stored, as the table above describes — not something you supplied, but something the link carried. If you go on to run a backtest, that click identifier is reported to the advertising platform it came from, with no email address attached, because a guest preview has none — see Analytics and ad measurement below. It stays against the preview’s own identifier rather than moving to your account if you create one — but if you create one and the preview is carried into it, deleting that account deletes this too. If you never create an account, we do not state a retention period for it.
3. Three things we do not do
- Card details never reach our systems. Stripe handles payment for us; we store only a customer reference and your subscription status, never your card number.
- We never collect your broker credentials. Authentication to Interactive Brokers — or to MEXEM, LYNX or Easybroker, which reach it the same way — stays with the Trader Workstation or Gateway running on your own machine. We store only the address, port and account number we need to connect to it.
- We do not build a profile of you, and we do not run retargeting. We measure which of our own
ads bring people here, for measurement and optimisation, and nothing else — no cross-site
profile, no retargeting audience, no uploaded customer list, no data broker, no sale of your data
in any sense. To be plain about the one thing that might look like an exception: we do record how
this website is used, and how the logged-out preview at
/tryis used, visit by visit, as described below. That recording is not used to advertise to you. If you accepted measurement and then create an account, it is linked to that account in PostHog, so that we can see what led you to sign up — see Linking your visits to your account. In the app it stops the moment you have an account; on this website it does not — every page here is recorded on every visit where measurement is allowed, whether or not you have an account. That recording stays on this site and in the preview, and never follows you into the signed-in app. That is what we do with it. Where that measurement is reported to Google or Reddit, each receives it as its own, independent controller — not as a processor following our instructions — so what happens to it after that is governed by that company’s own privacy policy, not by a promise we can make on its behalf. See Analytics and ad measurement below for exactly what is sent, and to whom.
Beyond that: signing in sets strictly necessary session cookies, and the spam check on our contact form may store a short-lived token on your device while it runs. Neither is analytics and neither needs your consent — they keep the site and the form working. Analytics and ad measurement below covers everything else this site stores.
4. Analytics and ad measurement
Three things measure how this website is used. None of them has any access to your StratVerra account, your strategies or your trading.
Cloudflare Web Analytics counts page views for every visitor. It is cookieless: it stores nothing on your device, sets no identifier, and does not follow you to other websites. Because it cannot identify you and stores nothing on your device, it runs without asking, on the basis of our legitimate interest in knowing which pages are read.
PostHog is the only measurement tool we put on the page ourselves — Cloudflare’s beacon above is added by Cloudflare at its own edge — and it does two jobs.
One practical note before those two, because it is visible to anyone who looks at their own
network traffic: what your browser sends goes to k.tradelunatic.com, a name of ours, rather
than to a posthog.com address. That is PostHog’s own managed reverse proxy — their servers,
our name in front of them — and we use it so that the measuring is not blocked by browser
extensions that match on the vendor’s name. It changes the address, not who receives the data or
where it is processed: PostHog is still the recipient, still as our processor, still on their EU
infrastructure, exactly as set out below and in §7.
It counts page views, and additionally tells us which pages a visit moved between — so we can see where people lose interest and fix that page. It also records when you press one of the buttons that opens the app, and which of them it was: the same offer appears in the header, in the hero, beside the price and at the foot of several pages, and without this we cannot tell which of them people actually use. What is recorded there is the position of the button on the page, nothing about you.
It also records your visit so that we can watch it back: where you moved the pointer, what you clicked, how far down each page you scrolled, and a reconstruction of the page as it looked to you. We use that to find the places where a page confuses people — a button nobody finds, an explanation everybody scrolls past — which a count of page views cannot show us.
It runs on this website, and on the app’s logged-out preview at app.tradelunatic.com/try, where
anyone can try StratVerra before creating an account. There it does not record every click; it
records one named event instead: that a guest session started, which is the moment you send the
preview your first message. If you then create an account from the preview, PostHog is told that the
guest who used it is that account — see
Linking your visits to your account. A beat later the
preview’s identifier is dropped from your browser. Until 23 September 2026 the preview also
recorded that it opened, each message you sent, that your backtest started and how it finished,
that you reached the screen asking you to create an account and why, that you began doing so, and
whether you claimed the account.
Session recording on both surfaces is largely unmasked, and you should know exactly what that
means. A session recorder can be set to replace everything you type with blank shapes before it
leaves your browser, and the one this site used before PostHog worked that way. PostHog here does
the opposite by default: what you type is recorded as typed, with one exception — our contact
form, whose name, email address and message are masked inside your browser before anything is
sent, so PostHog never receives them. Nothing else is masked. That means PostHog does record what you type into the strategy box on our
AI options backtesting page, and on /try it records your prompt, the
strategy an agent wrote for you, and your results. That is a deliberate choice, not an oversight: a
masked recording of /try would show that someone stopped, not what they had asked for when they
did, and the second half is the entire reason we record it. None of that is a name or an email
address, but a recording carrying what you typed is still personal data about you under the GDPR
whether or not your name is attached to it, and this policy would be misleading if it implied
otherwise.
In the app, recording stops the moment you have an account. The recording described above runs only on the part of the app that serves a visitor with no token. Once you are signed in, nothing of your screen is recorded: not your positions, not your results, not what you type.
The signed-in app does count what you do, though, and that is new. It sends us a short list of named actions — that you started a backtest and how it finished, that you saved a strategy, that you began a live session. It is not a recording and it carries nothing you wrote. It works differently from everything else in this section, including how we ask, so it has its own part below: see Measurement inside the app.
On this website, it does not. Every page here is recorded on every visit where measurement is allowed, whether or not you have an account and whether or not you are signed in somewhere else — so if you are a subscriber reading our blog, that visit is recorded like any other. Having an account protects the app, not this site. If you would rather not be recorded here either, the Measurement link in the footer of every page on this site reopens the choice, and refusing stops the recording.
We never send PostHog your name or your email address. Once you have a StratVerra account, we do send it one identifier of that account, and we tell it which of the visits it measured here were yours: Linking your visits to your account below describes when that happens and when it does not.
PostHog needs to tell one browser apart from another, and — because that identifier is stored on
.tradelunatic.com rather than kept to this site alone — the same one follows you from here to
/try, which is how a visit and a later guest backtest are read as one journey instead of two
strangers. That cookie is described in the table below. PostHog processes what it collects as our
processor, on our instructions, on infrastructure PostHog hosts in the EU. This is not strictly
necessary, so in the EEA, the UK and Switzerland none of that happens until you accept.
If you refuse, we still count your visit — but anonymously. PostHog then runs in a cookieless mode: it cannot record your visit, because the part of it that makes recordings is never started at all, and the only thing it leaves on your device is a note that you refused, so that we do not start measuring you again by mistake. What it still sends is which page you are on, how quickly it loaded, when you leave it, and which links and buttons you press, with no identifier of yours attached. PostHog works out a temporary one of its own, on its own servers, from your IP address, your browser’s details and the site you are on, combined with a secret that changes every day and is then deleted — so it cannot recognise you tomorrow, and it cannot follow you to another website. We never receive your location from these visits: your IP address is discarded before the step that would work it out. Your IP address does reach PostHog to make the count possible, as it reaches any company whose code a page loads. We run this on the basis of our legitimate interest in knowing which of our pages are read, which is the same basis as the Cloudflare count described at the top of this section, and for the same reason: it cannot single you out over time.
If you simply leave the banner alone, none of that happens either. Until you answer it — one way or the other — PostHog is not loaded at all on this website. Nothing is sent, nothing is stored, and no request is made to PostHog from your browser. Only your own choice starts any of it.
Ad measurement records which advertisement brought you here, and — if you go on to start a
guest preview, start a trial, or take out a paid subscription — reports that back to the
advertising platform whose click you arrived on, so it and we can measure and optimise our own
advertising. That is the only purpose: we do not enable
that platform’s targeting or retargeting features, and we do not upload a list of our customers to
it. No advertising company’s code does either part: when you arrive on a link carrying an
advertising click identifier, the site itself — not a script loaded from Google or Reddit — reads
it and stores it in your browser, in the tl_attr cookie described below. No measurement code
on this site is fetched from a third party any more. Google Analytics’ and Microsoft Clarity’s
tags were the last two that were, and both are gone; PostHog is code we bundle ourselves and serve
from our own domain, not a script fetched from PostHog’s servers. The one remaining third-party
script on the page is Cloudflare’s cookieless beacon, which Cloudflare adds at its own edge and
which stores nothing. PostHog is still a third-party recipient of what it records. It neither
reads nor writes tl_attr, but it does carry one of the reports described below — Google’s — as
explained under “How a report reaches Google”.
If you start a guest preview — the moment you send it your first message — before you have an account, we send the advertising platform your click identifier came from — and only that platform — a much smaller report: that a preview started, with no value attached, because a preview is not a sale. What identifies you in that report is the same random identifier your guest session already uses in our database, described above — never your email address, because a guest preview has none. However long the preview runs, only one such report is ever sent for it. Until 23 September 2026 this report was sent when a guest preview ran its first backtest, rather than when it started.
If you go on to start a trial, or a trial you started becomes a paid subscription, we send the advertising platform your click identifier came from — and only that platform — a report of that one event: whether it was a trial starting or a subscription starting, and, for a subscription, its value. In practice that is one platform, because Google and Reddit each add only their own identifier to a link; a link carrying both identifiers would be reported to both, and there is no link of ours that does. Each report states a currency only for a subscription, beside its value. Each of these reports also includes a SHA-256 hash of your email address, so the platform can match the event to the advertisement that led to it, and Reddit’s also includes an internal account identifier. Google uses the hash to find the Google account that clicked the advertisement when the click identifier alone does not, for example when you clicked on your phone and signed up on your computer. A hash is not your email address, but it is still personal data, derived from it, and this is a disclosure of it to that platform like any other. We never send your email address itself, and never anything beyond what is listed here. Until 23 September 2026 Google’s report carried no hash. Beyond the guest-preview report described above, nothing else is sent for a visit that never becomes a trial or a subscription, and nothing is ever sent to a platform whose click you did not arrive on.
How a report reaches Google. Our server does not send Google its report directly. It hands the report to PostHog, as our processor, and PostHog’s connection to our Google Ads account uploads it to Google. So PostHog receives Google’s report too: the Google click identifier, which of the three events it was, when it happened, a reference number that lets Google recognise a repeat of the same report, for a trial or a subscription the hash of your email address described above, and, for a subscription, its value and currency. PostHog passes the hash on as it is; it never receives your email address itself. For a trial or a subscription PostHog files it under your account’s id, the one described in Measurement inside the app; for a guest preview, under a random id used for nothing else. Reddit’s report does not pass through PostHog: our server sends it to Reddit itself. Until 23 September 2026 Google’s report went from our server into a spreadsheet that Google Ads collected once a day.
Google and Reddit each receive their report as their own, independent controller: they decide for themselves what they do with it, under their own privacy policies, not under instructions from us. We do not control, and this policy does not promise, what either of them does with a report once it reaches them — only what we send and why, as described above.
Separately from all of that, the app asks — once, when you start your trial — “How did you hear about us?”, with a list of channels and a free-text box behind “Something else”. Answering is optional and skipping it changes nothing. It is not part of the measurement described above and nothing about it is ever sent to Google, to Reddit, or to anyone else: it is stored with your account and read only by us, because the touch that actually brought you here often leaves no click identifier at all. Because the box is free text, what it holds is whatever you typed into it, so please do not put anything in it you would not want us to have. It is deleted with your account like everything else, and you can ask us to remove the answer on its own at any time.
Visitors from the EEA, the UK or Switzerland are asked first, with a banner giving Accept and Reject equal weight. Because PostHog stores a cookie on any visit at all, that banner appears on every visit from those regions, not only on visits arriving from an advertisement. One answer covers both of the things above that need one — PostHog and ad measurement: accept and they run, refuse and neither does, in the form described above. Refuse, or simply leave the banner alone, and nothing is recorded — no session recording, and no advertising click identifier. Refusing leaves the anonymous, cookieless count described above running, and a note of your refusal on your device so that we honour it; leaving the banner alone leaves nothing at all, because PostHog is not loaded until you answer. The Cloudflare count described at the top of this section is not affected either way, because it stores nothing and identifies nobody.
Visitors from elsewhere — including the United States, where our advertising is aimed — are not
shown that banner, and both run by default for them. Wherever you are, the Measurement
link in the footer of every page on this website opens the same choice at any time, and your
answer there covers the preview at app.tradelunatic.com/try as well, because both read the same
tl-consent cookie. The preview itself carries the banner but no footer link of its own, so
changing your mind while you are on it means coming back to this site to do it — we would rather
say so than leave you looking. Your answer takes effect immediately: from that moment nothing
further is stored, and no further recording is made — including of the page you are on, which
stops where you refused rather than running on to the end of the page. What continues on this
website is the anonymous count described above, and a note that you refused; on the preview at
app.tradelunatic.com/try, refusing stops everything. The site works identically either way.
Session recording was added to this site after the banner first appeared, and an answer you had already given was kept rather than asked for again. The banner has always said that we measure how this site is used, and that is what session recording is — so the question you answered is the question we are still asking, and we did not treat the addition as a new one. If you would rather revisit it now that you know what the measuring involves, the Measurement link in the footer reopens the choice, and refusing stops the recording and everything stored with it.
The following may be stored on your device:
| Name | Set by | What it does | Kept for |
|---|---|---|---|
tl-consent |
Us | Remembers your answer once you have given one, so we do not ask again. Set on .tradelunatic.com so the same answer covers this site and the guest preview at app.tradelunatic.com/try |
365 days |
ph_<project token>_posthog |
PostHog | Tells one visitor’s browser apart from another — PostHog calls this your distinct_id — so that a visit here and a later guest backtest at app.tradelunatic.com/try can be read as one journey rather than as two strangers. Set on .tradelunatic.com for that reason. It holds a randomly generated id and nothing else: no name and no email address. If you create an account, PostHog is told that this id belongs to it — see Linking your visits to your account |
365 days |
ph_<project token>_window_id |
PostHog | Tells one of your open browser tabs apart from another during the same visit, so activity in different tabs is not blended into one recording | Until you close the tab |
ph_<project token>_primary_window_exists |
PostHog | Marks which of your open tabs is the one PostHog is actively recording from, so having this site open in two tabs at once does not record the visit twice | Until you close the tab |
ph_replay_pending_buffer_["<project token>","<project token>"] |
PostHog | Holds a short buffer of page content already recorded but not yet sent — for example while this tab is in the background — so nothing already captured is lost before it can be sent. Unlike the others in this table, this one can hold actual recorded page content, not just an identifier | Until you close the tab, or sooner once it is sent |
__ph_opt_in_out_<project token> |
PostHog | PostHog’s own record of whether it may capture, separate from tl-consent above. It is written only once PostHog has actually run: set to “may” each time measurement starts with your permission, and to “may not” when you withdraw permission part-way through a visit here, or when you claim an account from the preview at app.tradelunatic.com/try and measurement stops there. Refusing the banner writes it too, including the first time: recording your refusal is what stops PostHog measuring you fully, and it is the only thing PostHog leaves on your device when you refuse. Leaving the banner alone writes nothing, because PostHog is not loaded until you answer. tl-consent stays the answer that decides; this only stops PostHog resuming on its own before that answer is read again |
Until you clear your browser storage |
tl_attr |
Us | Set when you arrive from one of our advertisements, and stores the advertising click identifier and campaign parameters from that link. First party: it is set by this site alone. If you start a guest preview, or go on to start a trial or a subscription, the identifier is read from this cookie and stored in our platform database. From there it reaches the advertising platform it came from only once there is something to report: a backtest you ran as a guest, or a trial or subscription starting, as described above | 90 days |
tl-consent is stored whichever way you answer, including when you refuse — it is what stops us
asking again. It is a cookie, not browser storage, because the same answer has to be readable from
app.tradelunatic.com too, for the guest preview described above — being a cookie means it travels
with every request to our servers the way any cookie does, even though nothing there reads it; it
is set and read entirely by the code running in your browser. It records nothing but the word
“granted” or “denied”, and a cookie that only records a consent decision needs no consent of its
own to be set. If we ever want to do something the banner’s sentence does not already describe, we will
change that sentence before doing it, and say here, with the date, whether answers given before the
change still count. That has happened once: linking your visits to your account, described in
Linking your visits to your account, where they did.
PostHog keeps a record of its own, separately from tl-consent: the
__ph_opt_in_out_<project token> key above. It is not a temporary safety net and it is not only a
record of refusal. It is PostHog’s own copy of whether it may capture, and it is written whenever
PostHog actually runs — set to “may” each time measurement starts with your permission, and to
“may not” the moment you withdraw permission part-way through a visit here, or when you claim an
account from the preview at app.tradelunatic.com/try, which is where measurement ends. Refusing
the banner writes it as well, including the first time you refuse: it is how the refusal is
honoured, and it is the only thing PostHog leaves on your device in that case. Leaving the banner
alone writes nothing at all, because PostHog is not loaded until you answer it. tl-consent remains the answer that decides: whenever measurement starts we
set this key from that answer rather than the other way round, so an old refusal recorded here can
never quietly outlive the answer you have since given. It is the one exception to “nothing further
is stored” after withdrawing part-way through a visit — a record that you withdrew is, itself,
still stored, for the same reason tl-consent is.
The legal basis for PostHog and ad measurement alike is your consent (Art. 6(1)(a) GDPR) if
you are in the EEA, the UK or Switzerland — the region asked via the banner above. For PostHog that
consent covers storing the identifier cookie and the other PostHog keys listed above, the recording
of your visit — and, on /try, of your guest session — the counting of the pages you view and the
buttons you press, and PostHog’s processing of all of it on our instructions, so that we can see
which pages are read and where a visit or a guest preview loses people.
The anonymous count is the exception, and it rests on a different basis. If you refuse in one of those regions, the cookieless count described above continues on our legitimate interest (Art. 6(1)(f) GDPR) in knowing which of our pages are read — the same basis the Cloudflare count at the top of that section has always had. It applies only to a visitor who has actually refused: if you have not answered the banner, nothing is loaded and there is nothing to have a basis for. We have weighed that against your interests on the footing that it stores nothing on your device, produces no identifier that survives the day, cannot follow you to another website, and is never linked to you or to any account; what it produces is a count of readers per page. You can object to it at any time under §9, and refusing the banner already stops everything else. For ad measurement it covers sharing that data with Google and/or Reddit for measurement and optimisation of our advertising, which is the only purpose it is used for — not for targeting or retargeting, which we do not enable. Outside those regions we rely instead on our legitimate interest (Art. 6(1)(f) GDPR) in understanding how our own site is used and which of our ads work: Nandro IT B.V. is established in the EU, so the GDPR reaches this processing wherever you are, and outside those regions we are not asking for consent, so it needs a different basis. For ad measurement that single basis covers both capturing the identifier when you arrive and, later, reporting a guest preview, a trial or a subscription back to Google or Reddit as described above — it is one activity with two steps, not two separate ones.
The transfer of that report to Reddit specifically also has an international-transfer basis under GDPR Chapter V, separate from the consent basis above: Reddit, Inc.’s own EU-US Data Privacy Framework and UK Extension certifications, which its advertising terms rely on for this transfer. See §7 below.
Measurement inside the app
Everything above is about this website and the logged-out preview. The app you sign in to — both
the desktop application and app.tradelunatic.com — measures how it is used as well, and it does
so on different terms. This part describes those.
What is sent. A short, named list of things you did, and nothing else:
- that you started a backtest, what type of strategy it ran, and whether that strategy was written by you or by an agent;
- that a backtest finished, with its outcome and how long it took;
- that you saved a new strategy, and which of the three ways you made it;
- that you sent a message to the assistant, and how many you had already sent in that conversation;
- that you started or stopped a live session, which broker it used, and whether it was a paper or a real-money account;
- that you began subscribing or started a trial;
- that you finished or dismissed the get-started checklist.
Each of these also says which screen it happened on, by its place in the app rather than its
address — runs/:id, never which run. Until 23 September 2026 the app also sent one of its own each
time you opened a screen.
What is never sent. Your screen is not recorded, at all. Nothing you type is sent: not a prompt, not a strategy, not a strategy’s name or description, not a support message. No figures: no position, no profit or loss, no balance, no amount of money. No identifier of any run, strategy, conversation or broker account. And nothing that names you: not your name, not your email address. The one identifier that is sent is described next.
How you are counted. Each event carries one identifier: your account’s id. It is an opaque value our sign-in service gives your account — not your name, not your email address — and it is the same one our server already attaches to its crash reports, described in §12. Because it belongs to your account, what the app sends is measurement of you, not of an anonymous installation: using StratVerra on two computers counts as one person, and what you did in the app can be read together with how you found us, as described in Linking your visits to your account. Until 23 September 2026 the app used a random identifier belonging to the installation instead, and none of this was connected to your account.
We do not ask first, and there is no setting to turn it off. Unlike the website, the app shows no banner and carries no measurement switch. This is the same footing as crash reporting, described in §12, and we would rather state it plainly here than let you go looking for a control that does not exist.
It runs on our legitimate interest (Art. 6(1)(f) GDPR) in knowing which parts of our own product are used and which are not. We have weighed that against your interests on the footing that it records no screen, carries nothing you type and no figures of yours, identifies your account only by an opaque id and never by your name or email address, and is limited to the named list above. You should weigh the other side of that for yourself: it is on for everyone who signs in, everywhere, and switching it off is not something the product lets you do.
What you can still do, and what we cannot. You have the right to object under Art. 21 GDPR, and §9 says how to reach us. We would rather be straight about what that means in practice than imply more than is true.
There is no setting that stops this measurement. Because it is tied to your account’s id, though, we can find what it has already sent: if you object, or ask us to erase it, we will have PostHog delete everything it holds under your account — the app’s measurement and any visits linked to it as described in Linking your visits to your account. Deleting your account in the app does not do this on its own; see Deleting your account. Stopping the measurement of one account from then on is not something the product can do today. If you object, write to us — we will answer you individually and tell you what we are actually able to do, rather than point you at a control that does not exist.
Your answer to the banner on this website does not carry into the app either. That banner asks for your consent to the measuring and recording we do here. The app is a different thing on a different basis, so refusing here does not switch it off there.
What it stores on your device. Two entries, kept by PostHog in the app’s own storage, separate from anything set by this website:
| Name | What it does | Kept for |
|---|---|---|
ph_tl_app |
Your account’s id described above, and PostHog’s working state for it. Signing out or deleting your account replaces the id with a random one, so the next person to sign in on the same device does not start as you | Until you clear the app’s storage |
__ph_opt_in_out_tl_app |
PostHog’s own record that it may measure. The app writes it on every start, so that a leftover entry from an older version cannot silently stop the measuring described here | Until you clear the app’s storage |
Neither is shared with this website. The browser version of the app does read this website’s identifier — it never writes to it — to link your visits here to your account, as described in Linking your visits to your account. The desktop application cannot read it at all.
One thing our server sends, rather than your app. The first time you use your account, our own server tells PostHog that a registration happened. That message carries your account’s id described above and nothing else about you — not your name, not your email address. What it carries besides is the moment it happened and which sign-in service issued your login. It lands on the same account as the app’s own measurement, which is what lets us see whether the people who sign up go on to use the product, and PostHog is instructed not to build or change a profile from it.
Until 20 September 2026 the same event was an email to our own support address, and that email did name you — your address, your username and a link to your account. We replaced it with this event, and we describe it here so that this section is a complete account of what PostHog hears about the app.
Linking your visits to your account
This is the one place where the measuring on this website and the measuring inside the app meet, and it happens only if you accepted measurement here — or live outside the regions where we ask.
When you have an account, we tell PostHog that the random id in your ph_<project token>_posthog
cookie and your account are the same person. From then on, what PostHog holds about your visits to
this website and to the guest preview — the pages, the buttons you pressed, the preview’s events
and the recordings — sits with your account’s measurement described above, under your account’s
id. We do this to see the whole path: which pages and which preview sessions lead people to sign
up, and whether the people who sign up go on to use the product. It happens at one of two moments:
- when you claim an account from the guest preview at
app.tradelunatic.com/try; or - when you sign in to
app.tradelunatic.comin a browser that still holds that cookie. Because it can happen at any sign-in, visits you make to this website after you have signed up are linked too, the next time you sign in in the same browser.
What it does not do: it does not send PostHog your name or your email address — the account id is the same opaque one described above. The desktop application cannot read this website’s cookie, so signing in there links nothing. And if you refused measurement, or never answered the banner, there is nothing to link: refusing deletes the cookie, and leaving the banner alone never creates it.
This was added on 23 September 2026, and answers given before then still count. The banner’s
sentence has said since then that your visits are linked to your account if you sign up; before
then it did not, and we did not ask again. If you accepted before that date and would rather your
visits were not linked, use the Measurement link in the footer and refuse before you create an
account, or before you next sign in to app.tradelunatic.com in this browser: refusing deletes the
identifier, so there is nothing left to link. Visits that are already linked stay linked; ask us
(§9) and we will have PostHog delete them together with the rest of your account’s
measurement.
5. Where live trading runs
When you run a strategy live, it executes on your own machine, and the orders it places go directly from you to your broker — never through our servers.
What does reach our servers is the record of that activity: the fills, results and logs from your live runs are synced to and stored in our platform database, so you can review your history and so we can support you if something goes wrong.
6. Publishing a run
StratVerra lets you publish one finished backtest or live run as a public page. Nothing you run is ever published unless you ask for it: you pick the run, you write the title, and you choose whether the page shows amounts or percentages. The product works exactly the same if you never publish anything.
Who receives it. A published run is served to anyone with the link. That recipient is the public, not a processor acting for us, and it is the one place where data you gave us leaves our control — at your instruction and for as long as you leave the link live. The page asks search engines not to index it, so we do not advertise it anywhere, but that is a request search engines are free to ignore and it does nothing to stop a reader passing the link on, saving the page, or reposting a screenshot of it. Cloudflare delivers the page and holds a copy of it at its edge for up to five minutes.
What the page contains. A copy of that one run’s results, frozen at the moment you publish and never updated afterwards: the title you wrote, whether it was a backtest or a live run, the underlying it traded, the dates it covers, its equity curve, its result figures — maximum drawdown, Sharpe, win rate, profit factor, number of trades, total return and, where it applies, CAGR — and the date you published it. Unless you choose percentages, the figures also include the run’s starting capital, closing equity and net profit or loss.
What it does not contain. Your name, your email address, your account, your broker and your broker account number appear nowhere on it, and neither do the individual trades, the fills, the run log, nor anything at all about the strategy — its name, its type, its parameters and its source code are all withheld. The page carries no identifier that points back to you — other than anything you choose to write in the title yourself.
Revoking it. You can revoke a published link at any time from the app, and we may revoke one ourselves in the circumstances set out in our terms. Either way the page stops resolving within about five minutes and we stop serving it. What we keep afterwards is described under How long we keep it below.
7. Who else receives data
We use a small number of other organisations to run StratVerra. Each receives only what it needs to do its job, and most of them process it on our instructions, as our processor. Ad measurement is the exception: the report described in Analytics and ad measurement reaches Reddit — and, separately, Google — as that company’s own, independent controller, not as a processor following our instructions, meaning it decides for itself what it does with what it receives, under its own privacy policy rather than ours. Google appears in the table for ad measurement alone. It was also our processor for Google Analytics until September 2026 — a different arrangement over a different set of data — and that arrangement has ended: we no longer use Google Analytics, or Microsoft Clarity, on this site.
| Recipient | What they receive | Where |
|---|---|---|
| Stripe | Payment and subscription data | Ireland / United States |
| OpenRouter — only if you use the AI assistant | Your messages, the strategy code involved, and backtest results | United States (OpenRouter), then Google, which runs the model. We pin every request to that one endpoint and require it to keep nothing, so the model is not run anywhere else. Google runs it on its global infrastructure rather than in the EU |
| An AI assistant you connect yourself (ChatGPT, Claude, VS Code, or similar) — only if you connect one to our API through its MCP integration | Whatever that assistant requests during the session — typically your strategy source code and backtest results | Wherever that assistant’s own vendor operates |
PostHog, Inc. — product analytics and session replay, on every visit to this website and to the logged-out preview at /try, and product analytics without any recording in the signed-in app (see Measurement inside the app, which describes exactly what that sends and under which identifier; everything else in this row is about the website and /try). If you are in a region we ask and have refused, PostHog receives only an anonymous, cookieless count of the pages you view and the buttons you press on this website — never a recording, never an identifier of yours, and nothing at all from /try. If you have not answered the banner, PostHog receives nothing whatsoever, because it is not loaded; see §4. Everything else in this row describes a visit where measurement was accepted |
A recording of your visit: pointer movement, clicks, scrolling, and a reconstruction of the pages as they looked to you, with everything you typed included except our contact form, whose name, email address and message are masked inside your browser before anything is sent — and, on /try, your prompt, the strategy written for you and your results. Also which pages you viewed, the buttons you pressed, the random id in the ph_<project token>_posthog cookie above, your approximate location worked out from your IP address, and your browser and device type. We never send PostHog your name or your email address; the one thing derived from it that PostHog receives is the hash on Google’s report of a trial or a subscription, described in §4. If you create an account, PostHog is also told your account’s id and that the random id above belongs to it — see Linking your visits to your account. PostHog also carries our ad measurement reports to Google, whatever you answered on this site’s banner about PostHog’s own measuring, because it is how the Google row below is delivered: the Google click identifier, the hash of your email address for a trial or a subscription, and the rest of the report described in §4, filed under your account’s id, or a random one for a guest preview. Because the recording is unmasked everywhere except our contact form, anything you type into a prompt box — the strategy box on our AI options backtesting page, or the one on /try — is recorded as you typed it, so what reaches PostHog there is whatever you chose to put in it. PostHog receives this as our processor, on our instructions |
United States, hosted on PostHog’s EU infrastructure (Frankfurt, Germany) |
| Google Ireland Limited — ad measurement, only if the advertisement that brought you here was Google’s, and you start a guest preview, go on to start a trial, or take out a subscription | The advertising click identifier from that link, whether it was a preview, a trial or a subscription starting, and a reference number for the report. A subscription report also carries its value and currency; a preview or a trial report carries neither. A trial or a subscription report also carries a SHA-256 hash of your email address; a preview report does not, because a preview has no email address. Delivered to Google by PostHog, as described in §4. Google receives it as its own, independent controller | Ireland / United States |
| Reddit, Inc. — only if the advertisement that brought you here was Reddit’s, and you start a guest preview, go on to start a trial, or take out a subscription | The advertising click identifier from that link, and whether it was a preview, a trial or a subscription starting. A trial or a subscription report also carries a SHA-256 hash of your email address and an internal account identifier, and a subscription report carries its value and currency; a preview report carries neither hash nor value — only a random identifier for that preview session, which names nobody | United States |
| Cloudflare | Website delivery, API traffic and installer downloads. Also our outgoing email: the address you sign up with, and the account-verification and password-reset messages we send to it. And anything you send us through the contact form — both the anti-bot check and the relay that delivers your message to our mailbox | United States, with European edge locations |
| TransIP | Hosting for our servers and databases | Netherlands |
| Sentry (Functional Software, Inc.) | Crash and error reports — see Crash and error reporting below | European Union (Germany) |
Where a recipient is outside the European Economic Area, the transfer relies on the European Commission’s adequacy decisions, on standard contractual clauses, or — for Google, for PostHog and for Reddit — on that company’s own EU-US Data Privacy Framework certification. For ad measurement we contract with Google Ireland Limited, inside the EEA; where it passes data on to Google LLC in the United States, Google’s data processing terms rely on that Framework certification, with standard contractual clauses behind it. For PostHog there is no EU-established company to contract with instead — PostHog, Inc. is the counterparty either way — but the account uses PostHog’s EU hosting, an independent instance in Frankfurt, Germany, which PostHog states carries no transfer of EU data to the US at all; for anything that does cross regardless, such as support access to the account, PostHog, Inc. separately complies with the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework, and PostHog’s own data processing agreement additionally makes standard contractual clauses available. Reddit, Inc. holds an active certification under that Framework, with its UK Extension, and its advertising terms rely on it as the basis for this transfer; Reddit’s terms also carry Standard Contractual Clauses and a UK Addendum as a documented fallback for if the Framework ever stops covering the transfer.
Everyone else in this table receives data because running StratVerra requires it. The two ad measurement rows are the exception: for those, Google and Reddit receive nothing about a visit unless you start a guest preview, start a trial, or take out a subscription; even then, each receives only the report described in Analytics and ad measurement above, and only the platform whose advertisement actually brought you here receives anything at all. The PostHog row is not subject to that limit and does not work that way — it covers ordinary visits, which is why it is listed separately and why, in the regions we ask, it happens only if you accept. There is one further recipient that isn’t in this table at all: the public, when you publish a run — see Publishing a run above.
8. How long we keep it
- Account data: for as long as you have an account.
- Invoices: 7 years, because Dutch tax law requires it (Art. 52 AWR). Our invoices are held by Stripe and carry the name and billing address you gave at checkout. This is the one thing that survives deleting your account — it outlasts the rest on purpose, because we are not allowed to destroy it.
- Strategies, runs, run logs, assistant conversations and AI usage costs: deleted together with your account.
- Run logs: capped automatically even while your account is open — on a long run we keep the beginning and the end of the log and discard the middle.
- Published runs: for as long as the link is live, and then indefinitely in our database. Revoking a link stops the page being served, but it does not delete our record of the share — we keep it, including the frozen copy of the results, so that a revoked link can never be reissued to a different run and so that a revocation leaves a trace of what was published and when. That record is deleted together with your account, like everything else in this list.
- PostHog — this covers the page counting, the session recording and the app measurement
described in §4, which are one tool
here: the
ph_<project token>_posthogcookie in your own browser expires after 365 days, and clearing your browser storage removes it sooner. The other PostHog keys in the table above go when you close the tab, except its own record of a refusal, which stays until you clear your browser storage. If you refused, the record of that refusal is the only one of these keys that exists — the cookieless count described in §4 writes nothing else to your device. If you never answered the banner, none of them exists, because PostHog is not loaded until you do. How long PostHog holds the events and the recordings themselves is a retention period configured on our PostHog project: we keep them only for as long as they can still answer the question they were collected for — where a page, the guest preview or the app loses people — and PostHog deletes them when that period expires. The two entries the app stores on your own device are listed in §4 and stay until you clear the app’s storage. There is no setting that stops anything further being written, which is part of why that section says what it does about objecting. We have not stated the exact period here yet, because the setting on that project has not been confirmed; we will state it here once it is, and until then the criteria above are what governs it. Two honest limitations. First, unlike the rest of this list, none of it is deleted by deleting your account in the app. What the app sent, and any visits linked to your account as described in Linking your visits to your account, are held under your account’s id, so we can find them — and so are Google’s reports about your trial or subscription, with the hash they carry: ask us and we will have PostHog delete them. Second, visits that were never linked to an account carry only a random id, and we hold nothing that maps it to a person — so although PostHog can delete a person’s data on request, we could not find which of those recordings were yours in order to ask. If you would rather not be recorded at all, refuse measurement in the banner or through the Measurement link in the footer, and nothing is recorded in the first place. - Ad measurement: the advertising click identifier and campaign parameters recorded when your
trial starts, together with your “How did you hear about us?” answer if you gave one and the
record of each conversion reported to Google or Reddit, are kept for as long as you have an
account and are deleted with it. A guest preview’s click identifier and campaign parameters are
recorded the same way, against that preview’s own anonymous identifier rather than an account —
see What we collect and why. They keep that identifier rather than
moving onto an account, but they are still yours: if you create an account and the preview is
carried into it, deleting the account deletes them along with everything else it holds. If you
never create one, the account-based retention above has nothing to attach to, and we do not state
a retention period for them here. The
tl_attrcookie in your own browser expires after 90 days regardless (see Analytics and ad measurement), and what Google or Reddit keeps on their side is governed by their own retention policies, not ours. - Contact form messages: kept only in the mailbox they arrive in, for as long as we need them to deal with what you asked. The form writes nothing to our database, so erasing one is a question about that mailbox rather than about your account.
9. Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we process it;
- receive your data in a portable format; and
- withdraw, at any time, any consent you have given — for example, for ad measurement.
One of these you can exercise yourself, immediately, without asking: Settings → Your account in the app deletes your account. For everything else — including asking for a copy of your data — contact us using the details in our legal notice. We respond within one month.
Deleting your account
Delete your account yourself, from Settings → Your account in the app, or ask us and we will do it. Either way it takes effect immediately and cannot be undone: we cancel your subscription, erase everything we hold about you — your login record, strategies, runs, run logs, published runs, broker connections, assistant conversations, AI usage costs, notification settings and your ad-measurement record (including any “How did you hear about us?” answer) — and destroy your login identity, so the address and password you signed in with are gone too. Any run you had published stops resolving at the same moment. It does not reach the measurement PostHog holds under your account’s id, described in Measurement inside the app: ask us and we will have PostHog delete that as well.
The one exception is the invoices described above. Dutch law requires us to keep them for seven years and they carry the name and billing address you gave at checkout, so we cannot delete them and neither can you. We tell you so again at the moment you ask, rather than leaving you to find it here.
10. Complaints
If you are unhappy with how we handle your personal data, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the data protection authority in your own EU country.
11. No automated decision-making
We do not make automated decisions about you that have legal or similarly significant effects, and we do not profile you. Every strategy StratVerra runs is one you built and chose to run — the product does not decide anything on your behalf.
12. Crash and error reporting
When the API, a backtest or live run, or the desktop app hits an unexpected error, a report is sent to our crash-reporting provider so we can find and fix it. What the report contains depends on where the error happened:
| Where | What’s included |
|---|---|
| Desktop app (the Rust process and the app’s browser view) | The error and its stack trace, your operating system, and the app version, together with a randomly generated identifier stored on your machine — not your account, and not your name or email address |
| Our API | The error and its stack trace, together with the signed-in account’s Keycloak subject id — a pseudonymous identifier, never your name or email address |
| A backtest or live run | The error and its stack trace, tagged with the run id and the strategy type |
It never includes your trading data, the source code of a strategy, your broker credentials, or your account balances.
We rely on this to find and fix defects, which is a legitimate interest in the security and correct functioning of the service (GDPR Art. 6(1)(f)).
Who processes it: Sentry — operated by Functional Software, Inc. — acting as our processor under a data-processing agreement. Reports are stored in the European Union (Germany).
How long we keep it: [PLACEHOLDER — RETENTION PERIOD NOT YET SET. The Sentry projects that will hold this data had not been created as of the effective date above, so no retention period has been configured yet. This bracketed text must be replaced with the actual retention period configured on those projects before this policy — and the feature it describes — ship.]
Not user-configurable: Crash reporting has no setting. It is on in the desktop app, in every live run the desktop app starts on your machine, in the API and in every backtest on our servers, and it cannot be switched off from within the product. That is why it is limited to what is listed above — the error itself, the environment it happened in, and a pseudonymous identifier — and never your name, email, or trading data. Your right to object under GDPR Art. 21 is unaffected; see your rights.
13. Changes
When we update this policy, we publish the new version here with a new version number and effective date. If a change is material, we will tell you before it takes effect.