Last updated: September 2026
Privacy Policy
Data We Collect
We collect only the data necessary to provide and secure TradeBo:
- Account information: your email address, name, country, and a hashed password (or your Google account identifier if you sign in with Google).
- Broker account data: positions, balances and order history from your connected broker account, sent by the Broker Agent. Your broker password is not part of this data; it stays on your computer.
- Strategy and trading activity: the strategies you set up, the decisions the engine made, and the orders it asked the Broker Agent to place.
- Billing information: your credit balance, purchases, receipts and tax country. Card details are collected by Stripe, not by TradeBo.
- API and automation: if you create API keys or authorize OAuth clients (for example to connect an AI assistant over MCP), we store what is needed to authenticate and revoke access (hashed secrets, labels, timestamps).
How We Use Your Data
Your data is used only to:
- Work out the buy and sell orders for the strategies you assign.
- Show your portfolio and strategy results in the app.
- Bill for the credits you use and send receipts.
- Send the account and notification emails you ask for.
- Keep your account and the service secure and working.
Data Storage & Security
- Passwords: TradeBo passwords are stored hashed; we never store them in plain text.
- Broker login: your broker password is kept by the Broker Agent in your computer's keychain and is never sent to TradeBo.
- Connections: data between your browser, the Broker Agent and TradeBo travels over encrypted (HTTPS) connections.
- No funds: TradeBo never holds your money or assets; they stay at your broker.
Service Providers
We use the following companies to run TradeBo. Each one receives only the data it needs for its job.
- Northflank: Hosting for the TradeBo servers and databases.
- Cloudflare: Delivery of the TradeBo web app to your browser.
- Stripe: Card payments. Your card details go directly to Stripe and never touch TradeBo.
- Postmark: Sending account and notification emails.
- Sentry: Error monitoring, so we can find and fix crashes.
- Axiom: Application logs used to run and secure the service.
- Google: Sign-in with Google, if you choose it, and reCAPTCHA spam protection on guest backtests.
Third-Party Disclosure
We do not sell, trade, or rent your personal information. Apart from the service providers listed above, orders are shared only with your own broker, through the Broker Agent on your computer.
If you connect an AI assistant via MCP, tool responses may be sent to that assistant's provider. TradeBo does not control how those providers retain or process content. Use only clients you trust.
OAuth, API Keys & MCP
You may create API keys or complete an OAuth 2.0 authorization flow to allow third-party clients to call TradeBo tool APIs on your behalf. Secrets are stored hashed; full API key values are shown only once at creation. You can revoke keys or tokens from your account at any time.
Security Logs
We record security-relevant events for tool and API access (for example which tool was invoked, success or failure, and a hash of arguments). We do not store full portfolio payloads in these logs unless required for a specific investigation.
Retention & Deletion
We keep your data while your account is open. You can delete your account at any time from Account › Profile › Delete account.
When you delete your account:
- Your positions, orders, runs, strategies, sessions and API keys are deleted.
- Your name, email address, password and Google sign-in link are removed from your account record.
- A one-way, keyed fingerprint of your email address is kept to prevent abuse of the free sign-up credits. You can sign up again with the same address and use TradeBo normally, but the sign-up credits are not granted a second time. The fingerprint cannot be turned back into your email address and is not linked to any account.
- Payment records and receipts are kept in de-identified form, because tax and accounting rules require us to keep them.
- The identifier of the broker account you connected is kept to prevent abuse. That broker account cannot then be connected to a new TradeBo account without contacting support.
Application logs and error reports are kept only as long as needed to run and secure the service.
User Control
You have the right to:
- Stop the Broker Agent or remove your broker account from it at any time; the web app does not connect to your broker directly, only the Broker Agent does.
- Delete your TradeBo account as described above.
- Ask us what data we hold about you by writing to the address below.
Contact
Contact: [email protected]