Legal
Privacy Policy
Last updated October 11, 2026
1. Scope#
This Privacy Policy explains how the operator of daqverse (“daqverse,” “we,” “us”) collects, uses, stores, shares and protects personal information when you use the daqverse trading journal and workspace, including the web application, its installable (home-screen) version, the public website, and the account, notification and storage services that run them (together, the “Service”).
daqverse is a journal and daily workspace for traders: you record your own trades, prop-firm accounts, plans, journal entries, habits and study notes, and the Service organises and calculates on what you enter. Most of what we hold is information you choose to put into it.
We act as the controller of the personal information described here. If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, this policy also sets out our legal bases and your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR and the Swiss Federal Act on Data Protection (“FADP”). If you live in a U.S. state with a consumer privacy law, Section 12 explains how the rights under that law apply.
This policy does not cover websites or services run by others that the Service links to or lets you open — for example your broker, your prop firm, TradingView, YouTube or Forex Factory. Their own privacy policies apply.
2. Information We Collect#
- Account and identity data — your email address, a user ID, the time you signed up and last signed in, and your email-confirmation status. If you sign up with a password, it is stored by our authentication provider only as a salted hash; we never see or store it in readable form. If you choose “Continue with Google,” we receive the identifiers Google shares for sign-in (your email address and account identifier, and where provided your name and profile picture).
- Trading records you enter or import — trades and their details (instrument, direction, prices, size, times, fees, profit and loss, exits, grades, tags, setup, notes and screenshots), trading accounts and prop-firm accounts (firm, account size, phase, balances, limits you configure, payouts, withdrawals and certificates), and the statistics the Service calculates from them.
- Planning, journal and personal-development content — daily and weekly plans, checklists, key price levels, journal entries (including reflections, gratitude, goals, mood and energy ratings, and body check-ins such as sleep or exercise if you choose to record them), habits and their completions, focus-timer sessions, achievements, playbook models, and Flowstate notes, concepts, collections and any library you import.
- Files you upload — chart screenshots, certificate images and other images you attach, and files you import (such as a Tradovate or MT5/Myfxbook statement export, or a library file). Images are kept in private storage tied to your account.
- Settings and preferences — your display timezone, layout choices, notification settings, calendar filters, custom kill zones and similar preferences.
- Notification data — if you turn on push notifications, the push subscription your browser creates (an endpoint address and encryption keys) and the alerts you asked for.
- Technical, usage and security data — IP address, browser and device type, operating system, pages requested, timestamps, error details and security logs that our hosting and database providers record when you use the Service, and the session cookies that keep you signed in.
- Public-page analytics — on the public pages only (the home page, sign-in pages, these Terms and this policy), aggregate, cookieless page-view statistics (see Section 8).
- Early-access requests — if you request early access on the home page (open to Gmail addresses for now): your email address, what you trade (futures, forex and CFD, or both) and whether you trade a prop-firm account, if you answer, and the time of the request.
- Communications — messages you send us, and records of the service emails we send you (such as an invitation, sign-up confirmation and password reset).
- Payment and subscription data — when paid plans are offered, your plan, status and renewal dates, and the limited transaction details our payment processor returns to us. Card numbers are entered with and held by the payment processor, never by us.
What we do not collect. We do not ask for, receive or store your broker or prop-firm login credentials: trades come in only through what you type and statement files you export yourself. We do not collect government identity documents, and we do not ask for information about racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data, or sexual orientation. Some journal fields invite personal reflection (for example mood, energy or sleep); fill them in only if you want to, and please do not enter sensitive information about yourself or others that you do not want stored.
3. How We Collect Information#
Directly from you, when you create an account, sign in, enter or edit anything in the Service, upload or import a file, change a setting, turn on notifications, or contact us.
Automatically, from your browser and device when you use the Service: session cookies, request and security logs kept by our hosting and database providers, and cookieless page-view counts on the public pages.
From third parties you choose to use: Google, if you sign in with Google; your browser’s push service, which confirms a push subscription; and our payment processor, once paid plans are offered. Files you export from your broker, from Myfxbook or from another platform reach us only because you upload them.
We also fetch public market information — such as the economic calendar published by Forex Factory — from the server. No personal information about you is sent in those requests.
4. How We Use Information#
- To provide the Service: create and run your account, store and display your records, calculate statistics, estimates and analytics (for example P&L, R-multiples, drawdown headroom, consistency and payout-day progress), tag trades with kill zones and macro windows, and show your plans, journal, habits and study notes back to you.
- To authenticate you and keep accounts separate: sign you in, keep you signed in, confirm your identity again before sensitive actions such as deleting your account, and make sure every user can reach only their own data.
- To answer early-access requests: read your request, reply to it, and email you an invitation to create your account when your spot opens.
- To send what you asked for: service emails (invitation, confirmation, password reset, security notices) and, if you turned them on, push notifications about the releases and reminders you chose.
- To keep the Service secure and working: detect and prevent abuse, fraud, unauthorised access and misuse; investigate errors; maintain backups; and plan capacity.
- To understand how the public pages are used, through aggregate, cookieless page-view counts.
- To handle payments, once paid plans are offered: manage subscriptions, renewals, cancellations, invoices and refunds.
- To communicate with you: answer your messages and tell you about material changes to the Service, these policies or your account.
- To meet legal obligations and to establish, exercise or defend legal claims and enforce our Terms.
We do not sell your personal information, we do not use it for advertising, and we do not build advertising profiles. We do not use your trades, journal or notes to train artificial-intelligence models. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects; the calculations the Service shows are for your own information.
5. Legal Basis for Processing (EEA, UK, Switzerland)#
If you are in the EEA, the UK or Switzerland, we process personal data only where Article 6(1) GDPR (and the equivalent UK GDPR and FADP provisions) gives us a lawful basis. For the purposes in Section 4 we rely on:
- Performance of a contract (Article 6(1)(b)) — to take the steps you ask for before an account exists (answering your early-access request and inviting you), to create and operate your account, store and process the records you enter, provide the features you use, send service emails and notifications you requested, and, once paid plans exist, process your subscription.
- Legitimate interests (Article 6(1)(f)) — to secure the Service, prevent abuse and fraud, keep security logs and backups, understand aggregate use of the public pages, improve reliability, and defend legal claims. We weigh these interests against your rights and freedoms, and you can object at any time (Section 12).
- Consent (Article 6(1)(a)) — for push notifications (your browser asks you first), for any optional personal information you choose to record in journal fields such as mood, energy or sleep, and for anything else we ask you to opt into. You can withdraw consent at any time — by turning notifications off, deleting the entry, or contacting us — without affecting processing that took place before.
- Legal obligation (Article 6(1)(c)) — to keep tax, accounting and billing records once paid plans exist, and to respond to lawful requests from public authorities.
Where you choose to record information that could reveal health data (for example sleep or exercise in a body check-in), we process it only because you explicitly chose to enter it for your own journal (Article 9(2)(a) GDPR). It is never used for any other purpose, and you can delete it at any time.
6. Trading Data, Calculations and Market Information#
Your records stay yours. Trading records, prop-firm figures, journal entries and notes are used to run your own journal. They are not shared with brokers, prop firms, other users or anyone else, except the service providers in Section 7 that store and process them on our behalf.
Figures are estimates from your data. Balances, profit and loss, drawdown headroom, daily-loss allowance, consistency, payout-day counts and similar numbers are calculated from what you entered or imported. They are not live broker equity and not your prop firm’s official numbers. Keeping your records accurate also keeps these calculations accurate.
Imports. When you import a statement file, the Service reads it to create the trades you confirm, checks for duplicates, and keeps the resulting records. We do not connect to your broker account and never hold broker credentials.
Market information. Kill zones and macro windows are fixed time windows built into the Service. Economic-calendar events come from a third-party public source and are shown as published; they may be delayed, changed or incomplete.
Links, images and videos from others. If you add a link to an external image (for example a TradingView chart) or open a lecture or thumbnail hosted on YouTube, your browser loads it directly from that site, which will receive your IP address and browser information under its own policy. We do not control those sites.
9. Retention#
We keep your personal information for as long as your account exists, because the purpose of a journal is to keep your history. You can delete individual records whenever you like.
When you delete your account in Settings, we delete your images and files from storage first, then your account and the records linked to it. Copies may remain in our providers’ routine, encrypted backups for a limited period until those backups are overwritten; they are not used for anything else in the meantime.
Early-access requests are kept until we invite you and your account is created, or until you ask us to remove your request, and no longer than twelve months after you sent it. To have a request removed sooner, write to us by email at contact@daqverse.com.
Security and request logs are kept by our hosting and database providers for the limited periods set by those providers. Billing records, once paid plans exist, are kept for as long as tax and accounting law requires. Information we need to establish, exercise or defend legal claims may be kept until that need ends.
10. Security#
We use administrative, technical and organisational measures designed to protect your information, including:
- row-level security in the database, so every query can reach only the signed-in user’s own rows, with ownership also checked in the application;
- encryption in transit (TLS) for every connection, and encryption at rest by our database and storage providers;
- private file storage, with images served only to their owner;
- passwords stored only as salted hashes by the authentication provider, and a fresh identity check before an account can be deleted;
- server-only handling of administrative credentials, least-privilege database permissions, and size and type limits on uploads.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. Please use a strong, unique password and keep your devices secure. If a personal-data breach is likely to put your rights and freedoms at risk, we will notify you and the relevant authorities as the law requires.
11. International Transfers#
Our service providers may store and process information in the United States, in the European Union and in other countries where they or their sub-processors operate. These countries may have data-protection laws different from those where you live.
When personal data from the EEA, the UK or Switzerland is transferred to a country that has not been recognised as providing an adequate level of protection, we rely on appropriate safeguards under Article 46 GDPR — typically the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss amendments where they apply — or, where a provider is certified, on the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. You may ask us for a copy of the safeguards for a given transfer (Section 15).
12. Your Rights and Choices#
In the app, at any time, you can view, correct and delete your records; change or turn off notifications; download a backup of your core records from Settings; and delete your account and its data in Settings.
If you are in the EEA, the UK or Switzerland, you also have these rights, subject to the conditions in the GDPR, UK GDPR and FADP:
- Access (Article 15) — to confirm whether we process your personal data and to receive a copy of it.
- Rectification (Article 16) — to have inaccurate or incomplete data corrected.
- Erasure (Article 17) — to have your personal data deleted.
- Restriction (Article 18) — to have processing limited in certain circumstances.
- Portability (Article 20) — to receive the data you provided in a structured, commonly used, machine-readable format and to have it sent to another controller. The in-app backup covers your core records; for a fuller copy, ask us.
- Objection (Article 21) — to object to processing based on legitimate interests.
- Withdrawal of consent (Article 7(3)) — at any time, without affecting earlier processing.
- Automated decisions (Article 22) — we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
If you live in a U.S. state with a consumer privacy law (such as California, Colorado, Connecticut, Virginia or Utah), you may have the right to know what personal information we hold and how we use it, to access it, to correct it, to delete it, to receive a portable copy, and to opt out of sale, sharing for targeted advertising and profiling. We do not sell or share personal information and do not profile you in ways that produce legal or similarly significant effects. We will not discriminate against you for exercising any of these rights. You may use an authorised agent, and you may appeal a decision we make about your request by replying to it.
To exercise a right, contact us by email at contact@daqverse.com. We may need to verify that the request comes from the account holder before acting on it. We answer within one month; where requests are complex or numerous we may extend that by up to two further months, and we will tell you why (Article 12(3) GDPR). U.S. state requests are answered within the period that law sets.
You also have the right to lodge a complaint with a supervisory authority — in particular in the EEA country or UK where you live, work or where you believe the infringement happened. The European Data Protection Board lists the EU authorities at edpb.europa.eu; in the UK the authority is the Information Commissioner’s Office (ico.org.uk); in Switzerland it is the Federal Data Protection and Information Commissioner (edoeb.admin.ch). We would appreciate the chance to address your concern first.
13. Children#
The Service is a tool for trading and prop-firm accounts and is intended only for adults aged 18 or older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
14. Changes to This Policy#
We may update this Privacy Policy as the Service or the law changes. We will change the “Last updated” date at the top and, for material changes, give you notice in the app or by email before the change takes effect. Where the law requires your consent to a change, we will ask for it.
15. Contact#
daqverse is operated by the operator of daqverse, which is the controller responsible for your personal information.
Questions about this policy, your data or your rights can be sent by email at contact@daqverse.com.
See also the Terms of Service.