← Back to front page

Privacy Policy

1. Who we are

NeoTLog ("we", "us") is operated by NeoTradeLog AB (org. nr 559596-8115, VAT nr SE559596811501), Hörnbovägen 5B, 756 55 Uppsala, Sweden. For any privacy question or request, contact support@neotlog.com. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller of the personal data described below.

2. What this policy covers

This explains what personal data NeoTLog collects, why, how we store and protect it, who we share it with, and the rights you have. It applies to the NeoTLog web application.

3. Data we collect

Account data. When you create an account we collect your email address and a password. Your password is never stored in plain text — it is stored hashed by our authentication provider (see Section 5). If you choose Continue with Google instead, Google confirms your identity and shares your name, email address and profile picture with us; no password is created, and we never receive your Google password or access to your Google account beyond that basic profile.

Trading data you create or import. The trades you import or enter (such as symbols, quantities, prices, profit/loss, dates and times), plus anything you add: notes, tags, strategies, account labels, journal entries, fee settings and display settings (currency, time format and time zone; the time zone starts as your device's own and can be changed in Settings). You provide this data; we store it so the app can display and analyze it for you. Trading data may constitute personal data when it can be linked to your NeoTLog account or otherwise identify you. We use this information only to provide the journal and analytics features you request.

Local data on your device. The app keeps a copy of your data in your browser's local storage so it loads quickly and works offline. This stays on your device and is cleared if you clear your browser data.

AI report data (Pro). If you generate an AI performance report, the app sends summary statistics only for the period you selected — totals such as win rate, profit factor, expectancy, maximum drawdown and streaks, P&L per hour/day/session/strategy, per-symbol P&L totals for your five most-traded symbols, the P&L sequence of your last 10 trades, and — where you have recorded the relevant data — aggregate risk statistics (R-multiples such as average and median R and win/loss R), aggregate excursion statistics (MAE/MFE and exit-efficiency averages), and aggregate economic-news-day statistics (performance on high-impact release days versus quiet days). All of these are aggregates for the period. Your full trade records, individual prices, order details, notes, account names, and email are never included, and no screenshot is ever sent with a report — the separate screenshot SL/TP reader is described below. The generated report is stored with your account data so you can re-read it.

Billing data. If you subscribe to a paid plan, your purchase is handled by Stripe and Link (see Section 5). We receive and store your subscription status (plan, billing cycle, renewal date) so the app can unlock your tier. Your card number never reaches our servers — it is entered on and processed by Stripe.

Usage analytics. To understand which features are used and where people get stuck, we collect pseudonymous usage events (for example "opened the reports tab", "imported a file from Tradovate", "a file could not be imported", "started checkout"). We store them ourselves, in our own analytics database hosted by Cloudflare in the EU; while we move over to it, the same events are also sent to PostHog, hosted in the EU. This is cookieless: no analytics identifier is stored on your device. With each event we record the page, your plan and the app theme you use, the website that referred you, your approximate country (worked out from your IP address — the address itself is not stored), and your type of device and browser. To count visitors without placing anything on your device, a visitor code is calculated from your IP address and browser together with a secret value that changes every day and is then deleted, so visits cannot be linked from one day to the next. For signed-in users, events are linked to a random account identifier (never your name or email) so we can see feature usage across visits. That identifier is why we call these events pseudonymous rather than anonymous: they carry nothing that names you, but we can tell that the same account did two things. Each time you open the app, and again when your journal changes, we also record a few counts about your journal, so we can see what kinds of traders use NeoTLog: how many trades it holds of each type of instrument (futures, stocks, options, forex, CFDs, crypto), how many trading accounts you have, and which markets you ticked in your profile. These are counts only, and they are stored only in our own analytics database, never sent to PostHog. Your trades themselves, symbols, prices, P&L values, notes, journal entries, screenshots, and the contents or names of files you import are never sent to analytics. On our public pages (not inside the app) we also record which links and buttons are clicked. When something breaks in the app or on the website, an error report (the technical error message and where in the code it happened) is sent the same way so we can fix it; sign-in links, codes and email addresses are removed before it is stored. You can turn analytics and error reports off at any time in Settings → Account → Privacy.

Screenshots. Images you attach to trades are stored with your account, so they are there on every device you sign in on. They are held in private per-account storage at Supabase, in the EU (Ireland) — the same processor that holds the rest of your journal — and can only be retrieved by your own signed-in account; there is no public or shareable link to them. A copy is also kept in your browser so they load instantly and still open when you are offline. Screenshots are never included in your AI reports, and are not used for any purpose other than showing them back to you. As with everything else you store with us, our staff can reach them in the course of running and supporting the Service, but we do not look at them unless you ask us to while helping with a problem. Deleting a screenshot deletes the stored copy; deleting your account deletes all of them. The one automated exception is the screenshot reader described next, which only ever runs when you press its button.

Until 20 September 2026 screenshots were kept only in the browser they were added in. If you attached images before that date, they are moved into your account automatically the next time you sign in on that same browser. Images added in a browser you no longer use, or that has since been cleared, cannot be recovered — there was never a second copy.

Screenshot SL/TP reader (Pro). If you use the screenshot reader on a trade, the app sends a downscaled copy of that one image — together with an enlarged crop of its price axis — to our server, which passes it straight on to Anthropic's Claude to read the stop-loss and take-profit levels printed on it. Only the prices it read come back to you, as a suggestion you confirm or discard. The image is not stored: our server holds it only for the moment it takes to handle the request and keeps no copy, nothing is written to your account, and under Anthropic's commercial API terms it is not used to train their models. The reader is limited to 200 reads per calendar month.

Broker auto-sync (optional, Pro). If you switch on Broker auto-sync under Settings → Early access and connect a trading account, you authorise us to read that account's completed trades on your behalf. Depending on the broker or exchange, you do that either by creating a read-only API key and giving it to us, or by signing in at the provider and granting us read access there. We only ever ask for permission to read: where a provider lets us check what a credential can do, we check it before accepting and refuse anything that can place orders, withdraw or transfer funds. What you give us is stored encrypted, with the encryption key held only by our server, so our database never holds it in readable form. It is used for nothing but pulling your own completed trades while your plan is active — plus, if you connect without naming the instruments yourself, a single read of what your account currently holds, so we can work out which instruments to sync. It is never shown back to you or to anyone else, and is deleted — together with the raw fills we pulled — when you disconnect the account or delete your NeoTLog account. Trades already imported into your journal stay there, exactly as they would after a file import, and you can delete them yourself. You can also revoke our access at the provider at any time, which stops the sync immediately. The feature is off unless you turn it on, and the app shows which brokers and exchanges are currently supported (at present, Binance).

Suggestion board. If you post a suggestion, the text you write and a masked form of your name (for example "is***") are shown publicly to other NeoTLog users once the suggestion is approved. How you vote is not shown to anyone — only the total. Your suggestions and votes are removed if you delete your account.

What we do not collect. We do not see or store your card details. We do not sell your data, and we do not use it for advertising. NeoTLog does not sell personal information and does not share personal information for cross-context behavioral advertising. NeoTLog never receives your broker or exchange login credentials — your username, password or two-factor codes — and never places orders, executes trades, or acts on your behalf with any broker or trading platform. The optional Broker auto-sync feature described above works only with a read-only API key that you create and can revoke, which can read your completed trades and nothing more. You remain solely responsible for your brokerage accounts and trading activity.

4. Why we use your data, and our legal basis

PurposeGDPR legal basis
Create and operate your account; provide the journal featuresPerformance of a contract
Authenticate you and keep your account secureContract / legitimate interests
Maintain, debug, and protect the service from abuseLegitimate interests
Understand feature usage and improve the product (pseudonymous, cookieless analytics with an opt-out)Legitimate interests
Read stop-loss and take-profit levels from a screenshot you submit, and sync trades from an exchange you connect (both optional, both started by you)Performance of a contract
Comply with legal obligationsLegal obligation

5. Where your data is stored and who processes it

We use the third-party services below, and they fall into two groups. Supabase, Cloudflare, Anthropic, Resend and PostHog act as our processors: they handle personal data on our behalf, only on our instructions, under a data processing agreement. Stripe and Link, Google, and the brokers, exchanges and market-data providers are independent of us — Link sells the subscription to you in its own name, and each of the others decides for itself how it handles what it receives, under its own terms and privacy policy.

6. International transfers

Your account and trading data are stored within the European Union (Ireland) and are not transferred outside the European Economic Area for storage. However, some service providers used to operate and protect the Service (for example, payment, email, network protection, and the AI features) may process limited technical or account information outside the European Economic Area. Where required under GDPR, appropriate safeguards such as the European Commission's Standard Contractual Clauses are used to protect that data.

7. How long we keep your data

We keep your account and trading data for as long as your account is active. If you delete your account, or ask us to delete your data, we remove it from our live systems within 30 days, except where we must retain certain records to comply with the law. In particular, invoices and payment records are kept for as long as Swedish accounting law requires (currently seven years) even after your account is deleted.

Usage events and error reports in our own analytics database are deleted automatically after about 13 months, and deleting your account deletes the usage events linked to it straight away. The daily visitor code described in Section 3 cannot be recalculated once its day has passed, because the secret value it depends on is deleted.

8. Your rights

Under GDPR you have the right to access, correct, delete, restrict, or object to the processing of your data, to receive it in a portable format, and to withdraw consent where processing is based on consent.

You also have the right to complain to your supervisory authority. In Sweden this is the Integritetsskyddsmyndigheten (IMY), imy.se.

9. How we protect your data

Data is transmitted over encrypted connections (HTTPS). Access is restricted at the database level so you can only access your own records (row-level security), and passwords are stored hashed. No system is perfectly secure, but we take reasonable measures to protect your information.

If you discover a security vulnerability, or suspect your account has been accessed without your permission, please report it to security@neotlog.com so we can respond quickly.

10. Cookies and local storage

NeoTLog uses essential browser storage and login session mechanisms to keep you signed in, maintain security, cache your data for performance, and provide core application functionality. We do not use advertising cookies or third-party tracking cookies. Our usage analytics (Section 3) is deliberately cookieless: it stores no cookie and no identifier of any kind on your device, which is why no cookie consent banner is shown. The only analytics-related value ever written to your browser is your own opt-out preference if you turn analytics off. If you subscribe, Stripe's hosted checkout and billing pages set their own cookies for payment security and fraud prevention — these are governed by Stripe's cookie policy.

11. Children

NeoTLog is not intended for anyone under 18, and trading-related tools are not appropriate for minors. We do not knowingly collect data from children. If we become aware that we have collected such data, we will take reasonable steps to delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the new version here and update the "Last updated" date.

13. Contact

NeoTradeLog AB (org. nr 559596-8115, VAT nr SE559596811501), Hörnbovägen 5B, 756 55 Uppsala, Sweden

General enquiries: info@neotlog.com
Support & privacy requests: support@neotlog.com
Security & data protection: security@neotlog.com

Risk disclosure. Trading futures, forex, stocks, options and cryptocurrencies involves substantial risk and is not for every investor. An investor could potentially lose all or more than the initial investment. Risk capital is money that can be lost without jeopardizing one's financial security or lifestyle. Only risk capital should be used for trading, and only those with sufficient risk capital should consider trading. Past performance is not necessarily indicative of future results. NeoTLog is a trade-tracking and analytics tool, not a broker or adviser, and does not provide financial, investment or trading advice. The CFTC's customer advisories explain more about the risks of trading virtual currencies.

Last updated: 1 October 2026