Privacy Policy
TradeCam · Last updated 11 September 2026
Draft — not yet reviewed by a lawyer. Placeholders in [brackets] must be filled in. This is written to describe what TradeCam actually does today; if the software changes, this must change with it.
The short version
TradeCam is built so that your trading data stays yours. The desktop app runs on your computer and writes to your own Notion and YouTube accounts. We don't have a database of your trades. The one place we hold anything of yours is the web dashboard, which needs a Notion access token to draw your charts — and you can delete that at any time.
1. Who is responsible
[YOUR NAME / COMPANY NAME], [street, postcode, city], Switzerland, is the controller for the personal data described here. Contact: [hello@tradecam.app].
Swiss data protection law (FADP) applies. If you're in the EU/EEA or UK, the GDPR / UK GDPR also applies and you have the rights listed in section 8.
2. The desktop app — what stays on your computer
The app reads your trading platform's log files, takes screenshots of the screens or windows you chose, records the notes you type or dictate, and stores its settings. All of this is on your machine, in folders you can open:
- Screenshots and event data:
~/Desktop/Captures/ - Settings and connection tokens:
~/Library/Application Support/TradeCam/
Voice notes are transcribed on your device using Apple's on-device speech recognition. Audio is not sent to us or to Apple's servers by TradeCam. (Apple's own terms govern their speech framework.)
We don't see any of this. The app doesn't send trade data, screenshots, or notes to our servers.
3. Where the app sends data — to your own accounts
When you connect them, the app writes to services you own:
- Notion — trade pages, screenshots, and notes go into the database you selected in your workspace. Governed by Notion's privacy policy.
- YouTube — session recordings are uploaded to your channel as unlisted videos, with a description built from your trades and notes. Governed by the Google Privacy Policy.
To connect these, the app uses OAuth. Our server exchanges the one-time authorisation code for an access token, then returns the token to your app — it's stored on your computer, not with us. We don't keep a copy.
Google API Services disclosure
TradeCam's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, TradeCam requests the YouTube upload permission only to upload your recordings to your own channel. We don't read your videos, subscriptions, or watch history, and we never use YouTube data for advertising or share it with anyone. You can revoke TradeCam's access at any time at myaccount.google.com/permissions; the app also lets you disconnect, which deletes the stored token from your computer.
4. The web dashboard — what we do hold
The dashboard at [the TradeCam dashboard] renders charts from your Notion trade database and gives you links to embed them in Notion. To do that, we store:
| What | Why | Where | How long |
|---|---|---|---|
| Notion access token | To read the trade database you chose | Cloudflare KV | Until you sign out, or 30 days of inactivity |
| Your workspace name | Shown in the dashboard | Cloudflare KV | Same as the token |
| Which database you chose, and a random widget ID | So widget links work | Cloudflare KV | Until you regenerate or revoke links |
| A cache of your trade rows (time, P&L, instrument, outcome) | So ten widgets on a page don't query Notion ten times | Cloudflare KV and memory | 60 seconds, then discarded |
We don't store your notes, screenshots, or videos on the dashboard. The cache holds only the numeric fields needed to draw charts.
Cookies. One cookie, ts_session, a random ID that identifies your signed-in session. It's HttpOnly and Secure, and contains no personal data. No advertising or analytics cookies.
Widget links are viewable by anyone who has the link. They're long random strings, but not password-protected. Don't post them publicly. Regenerating links in the dashboard revokes the old ones immediately.
5. Purchases and licensing
Payments are handled by Paddle.com Market Ltd, our merchant of record. Paddle collects your name, email, billing country, and payment details; we receive your email and order status but never your card details. See Paddle's privacy policy.
To enforce licences we store your licence key, the email it was issued to, subscription status, and an identifier for each computer it's activated on (a hash, not your hardware serial). This is kept for the life of your subscription and [12] months afterwards for support and fraud prevention.
If you email us for support, we keep the correspondence for as long as needed to help you.
6. What we don't do
- No analytics or tracking in the app or on the dashboard
- No advertising, and no sale or sharing of data for advertising
- No profiling or automated decisions about you
- No access to your trades, screenshots, notes, or videos by us
7. Who processes data on our behalf
| Processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosts the dashboard, licence server, and OAuth exchange; stores dashboard data (KV) | Global edge network; EU/US |
| Paddle.com Market Ltd | Payments, invoicing, tax | UK/EU |
| Notion Labs, Inc. | Your journal (your account, your data) | US |
| Google LLC (YouTube) | Your recordings (your account, your data) | US |
| Apple Inc. | On-device speech recognition | On your device |
Transfers outside Switzerland/EEA rely on the providers' standard contractual clauses or equivalent safeguards.
8. Your rights
You can ask us to access, correct, delete, or export the data we hold about you, or object to or restrict processing. Email [hello@tradecam.app]; we'll respond within 30 days. You can also complain to the Swiss FDPIC or, in the EU, your local supervisory authority.
Doing it yourself:
- Dashboard data: Sign out deletes your session and token. Regenerate links revokes widget links.
- Notion / YouTube access: revoke in those services' settings, or disconnect in the app.
- Everything on your computer: delete the two folders in section 2.
9. Security
Tokens are transmitted only over HTTPS. Dashboard sessions use random IDs in HttpOnly, Secure cookies. Secrets (our Notion and Google client secrets) live only on the server. Widget IDs are 128-bit random. No system is perfectly secure; if we learn of a breach affecting your data we'll tell you without undue delay.
10. Children
TradeCam is for adults. We don't knowingly collect data from anyone under 18.
11. Changes
We'll post updates here and change the date at the top. For material changes we'll email you or notify you in the app.
12. Contact
[YOUR NAME / COMPANY NAME]
[street, postcode, city], Switzerland
[hello@tradecam.app]