TradeBricks← Back home
Legal

TradeBricks Privacy Policy

Effective June 16, 2026

This policy explains what information TradeBricks collects, how we use and share it, and your privacy rights. The short version: when you connect a broker by direct API key, that key is verified and stored encrypted in a server-side secrets vault (Google Secret Manager), used only by your own live-trading worker, and never shown back to you or kept in your browser; when you connect through an aggregator (SnapTrade) we never receive your raw broker credentials at all; we never see or store your full payment-card details; and we do not sell your personal information.

1. 1. Introduction & Scope

This Privacy Policy explains how TradeBricks (TradeBricks, "TradeBricks," "we," "our," or "us") collects, uses, shares, and protects information when you visit tradebricks.io and use the TradeBricks web application (together, the "Service"). It applies to website visitors and to registered users of both the free tier and the paid "TradeBricks Pro" subscription. In this Policy, "you" and "User" mean the individual using the Service.

This Privacy Policy is incorporated by reference into, and forms part of, our Terms of Use. It should be read together with our Terms of Use, Refund & Chargeback Policy, and Risk Disclosure & Disclaimer. If anything in this Policy conflicts with mandatory law that applies to you, that law controls to the extent of the conflict.

The Service is research and educational software for visually building, backtesting, and (where you choose to enable it) connecting systematic trading strategies. It is not investment, financial, legal, or tax advice, and TradeBricks is not a broker-dealer or registered investment adviser. The Service is intended for users who are at least 18 years old and located in the United States. We provide limited notes below for visitors in the European Economic Area (EEA), the United Kingdom (UK), and certain U.S. states with specific privacy laws.

Effective date: June 16, 2026.

2. 2. Information We Collect

We collect only the information needed to operate the Service. The categories below reflect how the Service actually works.

Account information you provide

When you create an account, we store your email address and, if you sign in with Google, your Google display name. We do not receive or store your Google password. Authentication is handled by Firebase Authentication (Google sign-in or email/password), and Firebase manages the sign-in credentials and tokens on our behalf.

Strategy and content you create or publish

Strategies you build are stored privately under your account and are visible only to you unless you choose to publish them. If you publish a strategy to the TradeBricks Market, the following becomes publicly visible to anyone:

  • The strategy's name, description or thesis, and tags;
  • A public @handle that identifies you as the author. If you have not set a display name, this handle may be derived from your display name or from the portion of your email address before the "@" symbol. We do not publish your full email address;
  • Likes, forks, follower counts, and any comments you post in connection with published content.

Because published content and your handle are world-readable by design, do not include anything you consider private in your handle, strategy descriptions, or comments. You can unpublish or delete published content at any time, though copies or forks others have already made may persist (see Section 9 and our Terms of Use).

Billing and consent metadata via Stripe

If you subscribe to TradeBricks Pro, we receive limited billing metadata from Stripe — such as your subscription plan, status, and billing history. We also store a record of the version of our legal terms you accepted at checkout, together with a timestamp and your browser's user-agent string, to maintain proof of consent. We do not collect or store your full payment-card number, security code (CVV), or bank-account details (see Section 3).

Technical and usage data

Our hosting and infrastructure providers automatically collect limited technical data — such as IP address, device and browser type, timestamps, and pages requested — for security, abuse prevention, and reliability. This data is collected by our infrastructure providers (Google/Firebase), not by separate tracking code embedded in the app.

Communications

If you email us at info@tradebricks.io, we receive the contents of your message and any information you choose to include.

3. 3. Information We Do Not Collect or Store

We minimize how much sensitive information we hold. Some of it — your full payment-card details, and any brokerage link you make through an aggregator such as SnapTrade — never reaches our servers at all. Where we must hold a sensitive credential so the Service can act for you (a direct-broker API key used by your live-trading worker), we store it encrypted in a server-side secrets vault rather than in plaintext or in your browser. This is by design and is one of the core security features of TradeBricks.

  • Payment-card data. All payments are processed by Stripe through Stripe-hosted checkout and billing pages. TradeBricks never receives or stores your full payment-card number, security code, or bank-account details.
  • Broker and prop-firm credentials (direct API connection). When you connect a prop firm or broker by entering an API key directly (for example, a TopstepX / ProjectX API key), we first verify the key with that provider and then store it encrypted in Google Secret Manager — a server-side secrets vault — so that your always-on live-trading worker can act on it when you are offline. We never display the key back to you, and it is not retained in your browser (only a non-secret marker, such as your username, is kept locally to show the connection as active). Access is restricted by least-privilege service-account permissions. You can delete a stored credential at any time by disconnecting the broker, and all stored credentials are deleted when you delete your account.
  • Funds and raw broker links. TradeBricks does not custody your funds or securities. Where you connect through a third-party account aggregator (for example, SnapTrade), the link to your brokerage is held by that aggregator and TradeBricks never receives your raw broker credentials at all.

Direct-API credentials are stored server-side (encrypted in Secret Manager), so clearing your browser or switching devices does not remove them — disconnect the broker (or delete your account) to remove a stored credential. Credentials you connect through an aggregator like SnapTrade are managed by that aggregator.

4. 4. How We Use Information

We use the information we collect to:

  • Create, operate, and secure your account, and authenticate you;
  • Provide, maintain, and improve the Service, including the strategy builder, backtesting, and Market features;
  • Process subscriptions and billing through Stripe and maintain proof of which legal terms you accepted, including for dispute and chargeback defense;
  • Operate the public Market and social features you choose to use;
  • Communicate with you, including transactional and service messages, account and password-reset emails, and support responses;
  • Detect, prevent, and address security incidents, fraud, and abuse, and enforce our Terms of Use; and
  • Comply with applicable legal obligations.

5. 5. Legal Bases for Processing (EEA/UK Visitors)

If you are in the EEA or the UK, our legal bases for processing your personal data are:

  • Performance of a contract — to provide the Service and process your subscription;
  • Legitimate interests — to secure the Service, prevent fraud and abuse, and improve our product, balanced against your rights;
  • Consent — where required, for any optional analytics or marketing communications; and
  • Compliance with legal obligations — to meet tax, accounting, and other legal requirements.

Users elsewhere, including in the United States, are processed on an equivalent contractual and legitimate-interest footing.

6. 6. Subprocessors & Third-Party Services

We rely on a small number of trusted third-party providers (subprocessors) to operate the Service:

  • Google Firebase — authentication, database, and hosting infrastructure;
  • Stripe — payment processing, provided through the Firebase "Run Payments with Stripe" extension; Stripe collects and stores your payment-card and billing details under its own terms and privacy policy.

If you choose to connect a third-party broker, prop firm, account aggregator (such as SnapTrade), or data provider, your use of and relationship with that third party is governed by that party's own terms and privacy policy, not this Policy. A direct-broker API key you enter is verified and stored encrypted in Google Secret Manager on our infrastructure, as described in Section 3; any credentials you transmit to a third-party broker or aggregator leave TradeBricks' control. We encourage you to review the privacy policies of Google, Stripe, and any provider you connect. We may update our subprocessor list from time to time as our infrastructure evolves.

7. 7. Cookies, Local Storage & Analytics

We use browser storage and a limited set of cookies that are strictly necessary to operate the Service. Specifically:

  • Browser local storage holds your preferences and a non-secret marker that a broker is connected (the API key itself is stored server-side in Secret Manager, not in your browser — see Section 3);
  • Firebase Authentication uses cookies and local storage to keep you signed in; and
  • Our infrastructure providers may set cookies necessary for security and delivery of the Service.

We do not currently use cookies for advertising, and we do not embed third-party advertising or social-media tracking pixels. Analytics is provisioned in our infrastructure but is not actively collecting product-usage analytics at this time. If and when we enable analytics to understand and improve how the Service is used, we will update this Policy and, where required by law (including for visitors in the EEA and UK), obtain your consent before using any non-essential cookies or analytics.

8. 8. How We Share Information

We do not sell your personal information for money. We share information only in the following ways:

  • With subprocessors (Google Firebase and Stripe) to operate, host, secure, and bill for the Service;
  • Publicly, for the content you choose to publish to the Market — your published strategies, public @handle, comments, and social counts (see Section 2);
  • For legal and safety reasons — to comply with applicable law, respond to lawful requests from public authorities, enforce our Terms of Use, or protect the rights, property, or safety of TradeBricks, our users, or others; and
  • In a business transfer — in connection with a merger, acquisition, reorganization, financing, or sale of assets, in which case we will require the recipient to honor this Policy or provide notice as required by law.

Some U.S. state privacy laws define a "sale" or "sharing" of personal information broadly, including certain disclosures for cross-context behavioral advertising even where no money changes hands. We do not engage in such disclosures today. If we ever do, we will update this Policy and provide the opt-out mechanism described in Section 10.

9. 9. Data Retention

We retain your account data while your account is active and for as long as needed to provide the Service. We retain billing and consent records for as long as required for tax, accounting, audit, and dispute or chargeback-defense purposes. Content you publish to the Market remains public until you unpublish or delete it, or until your account is deleted; however, copies or forks made by other users before deletion may persist beyond your control, as described in our Terms of Use.

After deletion, residual copies of data may remain in routine backups for a limited period before being overwritten. A direct-broker API key you connected is deleted from Secret Manager when you disconnect the broker or delete your account. Credentials managed by an aggregator (such as SnapTrade) are removed through that aggregator.

10. 10. Your Privacy Rights

U.S. state privacy rights (including California)

Depending on your state of residence — for example, under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and under comparable laws in other states — you may have the right to: know and access the personal information we hold about you; correct inaccurate personal information; delete your personal information; obtain a portable copy of it; opt out of any "sale" or "sharing" of personal information and of targeted advertising and certain profiling; and not be discriminated against for exercising your rights.

EEA and UK rights

If you are in the EEA or the UK, you have the rights to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local data-protection or supervisory authority.

How to exercise your rights

You can exercise many privacy choices directly in the Service: edit your profile and display name; delete private strategies; unpublish or delete published strategies and comments; cancel your subscription through the Stripe billing portal; and remove a connected broker credential by disconnecting the broker (which deletes the stored key from Secret Manager). For requests we cannot fulfill in-product, email us at info@tradebricks.io. We will verify your request before acting on it, and we may need to confirm your identity to protect your account.

11. 11. Children's Privacy

The Service is intended only for users who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal information from anyone under 18 (or under 13 within the meaning of the U.S. Children's Online Privacy Protection Act). If you believe a minor has provided us with personal information, contact us at info@tradebricks.io and we will delete it.

12. 12. Data Security & Breach Notification

We use reasonable technical and organizational measures designed to protect your information, including encryption of data in transit, database security rules that limit each account to its own data, Stripe-hosted payment processing so that we never handle full card data, and storage of any direct-broker API keys in Google Secret Manager (encrypted at rest, access restricted to least-privilege service accounts) rather than in plaintext or in your browser.

However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot and do not guarantee absolute security. You are responsible for safeguarding your own device, browser, and account login. In the event of a data breach affecting your personal information, we will notify you and any relevant authority to the extent, and within the timeframes, required by applicable law, and otherwise as we determine appropriate.

This Section describes our security practices and breach posture. It does not limit or expand liability; the allocation of risk and limitation of liability for security incidents, lost or leaked credentials, and data loss are governed by our Terms of Use and Risk Disclosure & Disclaimer.

13. 13. International Data Transfers

TradeBricks operates in the United States, and our infrastructure providers store and process data on servers in the United States. If you access the Service from outside the United States, you understand and consent to your information being transferred to and processed in the United States, which may have data-protection laws different from those in your country.

Where required, transfers of personal data from the EEA or UK rely on appropriate safeguards, such as Standard Contractual Clauses implemented by our subprocessors.

14. 14. Changes to This Policy & Contact

We may update this Privacy Policy from time to time. When we do, we will revise the effective date above and, for material changes, provide reasonable notice — for example, by email or an in-app notice. Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of it. If you do not agree to the changes, you should stop using the Service.

Questions about this Policy, or requests to exercise your privacy rights, may be sent to info@tradebricks.io. The data controller is TradeBricks.

Governing law for this Policy follows our Terms of Use, which default to the laws of the State of Florida, USA; mandatory consumer- and data-protection laws of your home jurisdiction may apply regardless of that choice.