Privacy Policy
Last updated: July 2026
1. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:
Kennel & Eiser UG (haftungsbeschränkt)
Alexanderstraße 6
66482 Zweibrücken
Germany
Represented by its managing director: Mike Kennel
Email: management@trademate-app.com
Commercial register: Local Court (Amtsgericht) Zweibrücken, HRB 33526
We have not appointed a data protection officer, as the legal requirements for a mandatory appointment (Art. 37 GDPR, Sec. 38 German Federal Data Protection Act) are not met.
2. Overview of processing activities
We process personal data in the following contexts:
- Website (trademate-app.com): provision of the website, server log files, audience measurement (only with your consent), embedded content, contact by email, dispatch of our newsletter (only with your consent).
- TradeMate app: registration and sign-in, profile data, trading-journal data (trades, trading accounts, strategies, notes, photos), optional broker connections, the AI Coach (analysis of aggregated statistics from your own journal by an AI service provider), subscription management.
The app contains no advertising or tracking SDKs. No processing for advertising purposes takes place in the app.
3. Legal bases
We process personal data only where one of the following legal bases applies:
- Art. 6(1)(a) GDPR (consent) — e.g., audience measurement on the website, loading of consent-based third-party content, transmission of broker credentials to service providers.
- Art. 6(1)(b) GDPR (performance of a contract) — provision of app features, account management, synchronization, subscription handling.
- Art. 6(1)(c) GDPR (legal obligation) — e.g., statutory retention obligations under commercial and tax law.
- Art. 6(1)(f) GDPR (legitimate interests) — secure and stable operation of our systems, abuse prevention, server log files.
Where consent is required for storing or accessing information on your device (e.g., cookies, local storage), Sec. 25(1) of the German TDDDG additionally applies; strictly necessary access is based on Sec. 25(2) no. 2 TDDDG.
4. Security measures
In accordance with Art. 32 GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including in particular:
- Encrypted transmission of all data between the app, the website, and our servers (TLS).
- Storage of access tokens exclusively in your device's protected keychain.
- Access restrictions and authorization concepts on our servers.
- Passwords are never stored in plain text.
5. Transfers to third countries
Where we transfer data to countries outside the EU/EEA (in particular the USA), this only occurs:
- to recipients certified under the EU-U.S. Data Privacy Framework (DPF) (European Commission adequacy decision of 10 July 2023, Art. 45 GDPR), and/or
- on the basis of the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary measures, and/or
- on the basis of your explicit consent (Art. 49(1)(a) GDPR).
The specific recipients and safeguards are stated for each processing activity in this policy. In summary, the recipients concerned are:
| Recipient | Processing activity | Safeguard |
|---|---|---|
| GitHub, Inc. (USA), Cloudflare, Inc. (USA) | Hosting and delivery of the website (section 7.1) | DPF, additionally Standard Contractual Clauses |
| Google LLC (USA) | Audience measurement and fonts on the website (sections 7.2, 7.3); possible support access to our backend (section 8.4) | DPF, additionally Standard Contractual Clauses |
| Anthropic — Anthropic Ireland, Limited (Ireland) as our contracting entity, processing on the infrastructure of Anthropic PBC (USA) | AI Coach (section 8.5) | Standard Contractual Clauses (in Anthropic's Data Processing Addendum) |
| HLC Cloud LLC (USA), operator of MetaApi | Optional MetaTrader connection (section 8.6) | UK adequacy decision, additionally Standard Contractual Clauses and your explicit consent |
6. Retention and deletion
We process personal data only for as long as necessary for the respective purposes:
- Account and journal data: until you delete your user account. You can delete your account at any time directly in the app (Settings → Account → Delete Account); this deletes your data stored on our servers.
- Server log files: technical connection and error logs are deleted automatically on a regular basis, at the latest after 30 days.
- Billing-related data: until expiry of statutory retention periods (up to 10 years under German tax and commercial law); such data is restricted for other purposes.
- Backups: database backup copies are created by our database provider in accordance with its standard retention periods and are subsequently overwritten automatically. Until then, deleted data may persist in backup copies.
7. Data processing on the website
Consent to non-essential cookies and to the consent-based services described below is obtained and managed via our cookie banner, provided by Usercentrics A/S (Cookiebot) (Havnegade 39, 1058 Copenhagen, Denmark). A strictly necessary cookie stores your consent choices; you can review or withdraw them at any time via the cookie settings on our website.
7.1 Hosting and content delivery
Our website is hosted by GitHub, Inc. (88 Colin P Kelly Jr St, San Francisco, CA 94107, USA) via GitHub Pages and delivered through the content delivery network of Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).
When you visit the website, these providers necessarily process, in particular: IP address, date and time of access, page accessed, referrer URL, browser type and version, operating system.
- Purposes: delivery of the website, stability, security (including DDoS mitigation).
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and efficient provision of the website.
- Third-country transfer: GitHub and Cloudflare are certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses apply in addition.
- Retention: log data is deleted by the providers in accordance with their policies; we do not store website log files ourselves.
7.2 Google Analytics 4
Only with your consent (via our consent banner) do we use Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, USA).
Google Analytics uses cookies or comparable technologies and processes, among other things: truncated IP address (GA4 does not log or store IP addresses; they are used solely for coarse geolocation and then discarded), device and browser information, approximate location, pages visited, interactions, session duration, and a pseudonymous user ID.
- Purposes: audience measurement, statistical analysis of website usage, improvement of our services.
- Legal basis: your consent, Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via the cookie settings on our website.
- Third-country transfer: transfers to Google LLC in the USA cannot be excluded. Google LLC is certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses apply in addition.
- Retention: the retention period for event-level data is set to 2 months and for user-level data to 14 months.
- Processing agreement: we have concluded a data processing agreement with Google (Art. 28 GDPR).
Further information: https://policies.google.com/privacy
7.3 Google Fonts
Fonts from the Google Fonts service (Google Ireland Limited) are currently loaded from Google servers on our website. Loading only occurs after you have consented via our consent banner. When loading, your IP address is transmitted to Google servers.
- Legal basis: Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG (consent, revocable at any time).
- Third-country transfer: see section 7.2.
7.4 Contact by email
If you contact us by email (e.g., management@trademate-app.com), we process your email address and the content of your message to handle your request.
- Legal basis: Art. 6(1)(b) GDPR (pre-contractual or contractual communication) or Art. 6(1)(f) GDPR (responding to other inquiries).
- Retention: deletion once your request has been fully handled, unless retention obligations apply.
7.5 Newsletter
If you subscribe to our newsletter, we use your email address to send you information and updates about TradeMate. Subscription uses a double opt-in procedure: after entering your address you receive a confirmation email, and you are added to the distribution list only once you confirm.
- Legal basis: your consent, Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future; every newsletter contains an unsubscribe link, and unsubscribing is sufficient to withdraw.
- Retention: your email address is stored for as long as you remain subscribed and is deleted once you unsubscribe.
8. Data processing in the TradeMate app
8.1 Registration and sign-in
A user account is required to use the app with synchronization. For authentication we use Firebase Authentication, a service of Google Ireland Limited (partly processed by Google LLC, USA — DPF-certified).
We process: email address, password (stored by Firebase in hashed form only), authentication tokens, time of registration/sign-in.
Alternatively, you can sign in with:
- Sign in with Apple (Apple Distribution International Ltd., Ireland / Apple Inc., USA): Apple provides us with your name and email address (optionally an anonymized relay address).
- Google Sign-In (Google Ireland Limited): Google provides us with your name, email address, and, where applicable, your profile picture.
Use of third-party sign-in is voluntary; the processing carried out by Apple or Google under their own responsibility is governed by their privacy policies.
- Legal basis: Art. 6(1)(b) GDPR (provision of the user account).
8.2 Profile data (voluntary)
You may voluntarily add further details to your profile: display name, profile photo, date of birth, gender, trading experience level, trading goals, strategies, confluences, emotion factors, and app preferences. These details are used exclusively to personalize your trading journal and the in-app analytics.
- Legal basis: Art. 6(1)(b) GDPR. All details are optional and can be changed or removed in the app at any time.
8.3 Trading-journal data
The core of the app is your trading journal. We process the data you enter or import: trades (symbol, direction, volume, prices, profit/loss, timestamps), trading accounts, trading rules, strategies, notes, emotional self-assessments, and photos/screenshots you attach to trades.
This data is stored locally on your device and — if you are signed in with a user account — synchronized with our servers (including trade photos and your profile photo) so that you can access your journal across devices (iPhone, iPad, Mac).
- Legal basis: Art. 6(1)(b) GDPR (core functionality of the app).
- Note: your journal data is not analyzed for advertising purposes and is not sold to third parties.
8.4 Server infrastructure (backend)
Our own backend infrastructure — application server and database — runs on Google Cloud (Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland):
- Application server (API): the application logic runs on Google Cloud Run in the europe-west1 region (Belgium).
- Database: your account, profile, and journal data is stored in a managed PostgreSQL database (Google Cloud SQL) in the europe-west1 region (Belgium).
Google processes the data as a processor (Art. 28 GDPR) under the Google Cloud Data Processing Terms.
When the app accesses our servers, connection data is necessarily generated (IP address, timestamp, endpoint accessed) and processed briefly in log files for operational security (Art. 6(1)(f) GDPR).
- Third-country transfer: storage and processing take place within the EU (Belgium). Access by Google LLC (USA) in the context of support and operations cannot be fully excluded; Google is certified under the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses apply in addition (Art. 46(2)(c) GDPR).
Your journal data is stored exclusively on this infrastructure. The only feature for which data is passed on to a further provider is the AI Coach described in the next section.
8.5 AI Coach ("M8")
The app contains an AI-based coach (displayed as "M8") that generates written recommendations about your own trading behaviour. For this purpose, our backend transmits a compact statistical summary of your trading journal to Anthropic, which operates the language model that produces the text.
Recipient: Anthropic. Under Anthropic's Commercial Terms of Service, the contracting entity for customers in the EEA is Anthropic Ireland, Limited (Ireland); the service is provided on the infrastructure of the parent company Anthropic PBC, San Francisco, USA.
What is transmitted. Your trades are aggregated on our servers before transmission. Anthropic does not receive your individual trades. Transmitted is a summary of the last 90 days, containing:
- aggregate performance figures: number of trades, wins and losses, win rate, average win/loss, expectancy, profit factor, net profit/loss (in your account currency), longest losing streak, average holding periods;
- behavioural aggregates: results broken down by entry hour, weekday, asset class and direction (long/short); number of trading days; results on days with more than five trades; results on trades placed after a loss on the same day; results on trades with above-average position size;
- the up to eight instruments (symbols) with the largest effect on your result;
- your confluences and your trading rules as free text — see the note below;
- coverage figures for your journal: the percentage of trades for which you have added notes, screenshots or an emotional self-assessment;
- your time zone and the analysis period, so that hours and weekdays match what is displayed in the app.
What is not transmitted: your name, your email address, your user ID or any other direct identifier; your trades in raw form; the content of your notes; your screenshots; your emotional self-assessments; your broker credentials.
Please note: confluences and trading rules are free-text fields that you fill in yourself. Whatever you enter there is transmitted to Anthropic verbatim (up to 20 rules). Please do not enter names, contact details or other personal information in these fields that you do not wish to have transmitted.
Even though no direct identifier is transmitted, this data remains personal data: it comes from your account, it is requested specifically for you, and the result is stored against your user account with us.
- Purpose: generating the analysis and the adoptable rules displayed to you in the app.
- Legal basis: Art. 6(1)(b) GDPR — the AI Coach is part of the premium features you have booked.
- Third-country transfer: processing takes place on Anthropic's infrastructure in the USA. We base this transfer on the Standard Contractual Clauses of the European Commission (Art. 46(2)(c) GDPR), which form part of Anthropic's Data Processing Addendum and which we accepted together with Anthropic's Commercial Terms of Service.
- Processing agreement: Anthropic processes this data as a processor (Art. 28 GDPR) on the basis of its Data Processing Addendum, which is incorporated into Anthropic's Commercial Terms of Service.
- No training of AI models: under Anthropic's Commercial Terms of Service, Anthropic may not use the transmitted content to train its models.
- Retention: the generated analysis is stored on our servers until you delete your account (section 6). Anthropic stores the transmitted content in accordance with its own terms for the purpose of providing the service and for abuse prevention.
- Frequency: an analysis is regenerated only after a fixed interval and is additionally subject to a monthly cap. Data is therefore not transmitted every time you use the app.
Anthropic's privacy policy: https://www.anthropic.com/legal/privacy
8.6 Broker connections (optional)
You can optionally have your trading journal populated automatically by connecting a broker account. A connection is only established at your active request.
a) cTrader
The connection is established via OAuth through the cTrader Open API (Spotware Systems Ltd., Cyprus — EU). We receive an access token and your trading data (account number, positions, orders, trade history). Your cTrader password is never disclosed to us. You can revoke the connection at any time in the app or in your cTrader account.
b) MetaTrader 4 / MetaTrader 5
The connection is established via the technical service provider MetaApi, operated by HLC Cloud LLC, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, USA (metaapi.cloud). For this purpose, the trading-account credentials you enter — account number, broker server, and password — are transmitted to MetaApi in encrypted form so that MetaApi can connect to your broker and retrieve your trade history. For this we use exclusively MetaApi's server infrastructure in the United Kingdom (London).
We strongly recommend using the investor password (read-only access) for this purpose, not the master password.
- Legal basis: Art. 6(1)(b) GDPR (feature requested by you); for the transmission of your credentials to MetaApi, additionally your explicit consent, Art. 6(1)(a) GDPR, which you give when setting up the connection and can withdraw at any time by disconnecting.
- Third-country transfer: storage takes place in the United Kingdom, for which the European Commission adopted an adequacy decision on 28 June 2021 (Art. 45 GDPR); a transfer there is therefore treated, for data protection purposes, like a transfer within the EU. The operator of MetaApi is nonetheless HLC Cloud LLC, based in the USA, so access from the USA in the course of operations and support cannot be entirely excluded. For that case, we additionally base the transfer on the Standard Contractual Clauses agreed with MetaApi (Art. 46(2)(c) GDPR) and on your explicit consent (Art. 49(1)(a) GDPR).
- Retention: access tokens and connection data are deleted when the connection is removed or the account is deleted.
8.7 Subscriptions and payments
Premium features are offered as in-app subscriptions via the Apple App Store (Apple Distribution International Ltd., Ireland). Payment data (e.g., credit card details) is processed exclusively by Apple; we have no access to it.
For subscription validation we use StoreKit (Apple): we receive signed transaction information (product ID, purchase/expiry timestamps, original transaction ID) and validate it on our servers to unlock premium features. This data is not shared with any further service provider for subscription management.
- Legal basis: Art. 6(1)(b) GDPR (subscription handling); retention of billing-related data under Art. 6(1)(c) GDPR.
8.8 App permissions
The app requests system permissions only when needed:
- Photos: only when you add a photo to a trade or as a profile picture. Access is provided through the system picker; the app only receives the images you select.
- Camera: only when you take a photo directly from within the app.
- Notifications: the app uses local notifications (e.g., reminders, sync notices). No data is transmitted to our servers or third parties for this purpose.
You can revoke any permission at any time in your device's system settings.
8.9 Account deletion
You can delete your user account at any time in the app (Settings → Account → Delete Account). Upon deletion, your account, profile, and journal data stored on our servers, including photos, are deleted; you can remove local data by deleting the app. Statutory retention obligations (section 6) remain unaffected.
9. Automated analysis; no automated decisions in individual cases
The statistics and evaluations displayed in the app are computed for you alone, from your own data, on your device or on our servers.
Going beyond this, the AI Coach (section 8.5) has aggregated statistics of your trading behaviour analysed by a language model operated by Anthropic, which generates written recommendations and proposed rules from them. This is an automated analysis of personal aspects — in particular of behavioural patterns such as results by time of day, position size, or conduct after losses. We want to be transparent about this rather than describe it merely as a "statistic".
The result is a non-binding recommendation. It is displayed to you, you decide for yourself whether to adopt a proposed rule, and you can choose not to use the feature. The recommendations are not investment advice and contain no recommendation to buy or sell financial instruments; they relate solely to your own past trading behaviour.
An automated decision in individual cases, including profiling, within the meaning of Art. 22(1) GDPR — that is, a decision which produces legal effects concerning you or similarly significantly affects you — does not take place. In particular, we do not use this analysis to decide on your contract, your access to the app, your terms, or any assessment of your creditworthiness.
10. Minors
Our services are directed at persons who are at least 18 years of age. They are not directed at children. We do not knowingly collect data from persons under 16; if we become aware of such data, we delete it without undue delay.
11. Your rights as a data subject
Under the GDPR, you have the following rights:
- Access (Art. 15 GDPR) to the data we process about you;
- Rectification (Art. 16 GDPR) of inaccurate or incomplete data;
- Erasure (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR);
- Withdrawal of consent (Art. 7(3) GDPR) at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.
Right to object (Art. 21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR.
To exercise your rights, an informal message is sufficient: management@trademate-app.com
Right to lodge a complaint: You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. The authority competent for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (State Commissioner for Data Protection and Freedom of Information, Rhineland-Palatinate)
Hintere Bleiche 34, 55116 Mainz, Germany
https://www.datenschutz.rlp.de
12. Obligation to provide data
You are under no statutory or contractual obligation to provide your data. However, without the data required for a given feature (e.g., an email address for a user account), that feature cannot be provided.
13. Changes to this privacy policy
We will update this privacy policy whenever changes to our data processing or the legal situation so require. The current version is available at https://trademate-app.com/privacy and in the app. We will inform you in the app of any material changes.