Privacy Policy
Last updated: July 5, 2026
1. Introduction
My Prop Journal ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our trading journal platform and related services.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address, name, and password. You may optionally provide additional profile information.
2.2 Trading Data
We collect and store the trading information you input, including:
- Trade logs and transaction details
- Account balances and positions
- Performance metrics and analytics
- Trading plans, strategies, and playbooks
- Chart images and annotations
- Trade writeups and notes
2.3 AI Feature Usage Data
When you use our AI-powered features (AI Coach, AI writing tools), we process:
- Your prompts and queries to AI systems
- AI-generated responses and suggestions
- Context from your trading journal used for AI features
- Usage patterns to improve AI performance and accuracy
Important: Your trading data used with AI features is processed securely and is not used to train public AI models or shared with other users. We use third-party AI providers (such as OpenAI) who process this data according to their enterprise terms, which prohibit training on customer data.
2.4 API and MCP Usage Data
If you generate an API key or connect a third-party AI assistant through our MCP (Model Context Protocol) server (such as Claude Desktop or Claude.ai), we process:
- Metadata about API and MCP requests (timestamps, endpoints accessed, and last-used information) for security, billing, and abuse monitoring
- The journal data returned in response to authenticated API or MCP requests, which is transmitted to the client or AI assistant you have authorized
Important: When you connect a third-party AI assistant via MCP, your journal data is sent to that third party's own systems so it can respond to your requests. That provider (for example, Anthropic, if you connect Claude) processes your data under its own privacy policy and terms, which we do not control. We recommend reviewing the privacy practices of any AI assistant or application before connecting it to your account.
2.5 Technical Information
We automatically collect:
- IP address and device information
- Browser type and version
- Usage statistics and feature interactions
- Error logs and performance data
3. How We Use Your Information
We use your information to:
- Provide and maintain our services
- Process your transactions and manage subscriptions
- Generate analytics and insights from your trading data
- Power AI features including the AI Coach and writing tools
- Send important account and service updates
- Improve our platform and develop new features
- Detect and prevent fraud and security threats
- Comply with legal obligations
4. Data Storage and Security
Your data is stored securely using industry-standard encryption:
- Data encrypted in transit (TLS/SSL)
- Data encrypted at rest in secure databases
- Regular security audits and monitoring
- Access controls and authentication requirements
We use Supabase for data storage, which provides enterprise-grade security and compliance with SOC 2 Type II standards.
5. AI Data Processing
5.1 Third-Party AI Providers
Our AI features use third-party services (including OpenAI) to process your data and generate insights. These providers:
- Process data under strict enterprise agreements
- Do not train their models on your data
- Do not retain your data beyond the processing period
- Maintain their own security and privacy standards
5.2 AI Data Retention
AI interactions (prompts and responses) are stored in your account for feature functionality (e.g., conversation history). You can delete AI conversation history at any time from your settings.
6. API Keys and Third-Party AI Integrations (MCP)
6.1 How API and MCP Access Works
Our public API and MCP server let you, or an AI assistant you authorize, access your own journal data programmatically using a personal API key. Requests are authenticated on every call, and data returned is strictly scoped to your account — no user can access another user's data through the API or MCP server.
6.2 Connecting Third-Party AI Assistants
When you connect a third-party AI assistant (such as Claude Desktop or Claude.ai) to your account via MCP, you are directing us to share your journal data with that provider so it can carry out your requests. This is different from our use of AI providers like OpenAI for in-app features, because:
- You choose which AI assistant or application to connect
- That provider processes your data under its own privacy policy and terms, not ours
- We do not control how that provider retains, uses, or secures your data once it has been transmitted in response to an authorized request
You can review or revoke API keys, and disconnect any authorized AI assistant, at any time from Settings → API Keys. Revoking a key immediately stops all further data access through that key.
6.3 Security
API keys are securely hashed and never stored in plaintext. All API and MCP traffic is encrypted in transit. We retain logs of API and MCP request metadata (not full response payloads) for security monitoring and to help you audit key usage.
7. Data Sharing and Disclosure
We do not sell your personal information. We may share data:
- With your consent: When you explicitly choose to share (e.g., share links for trades or reports)
- With service providers: Payment processors, hosting providers, AI providers, and analytics services
- With AI assistants you authorize: When you connect a third-party AI assistant or application via our API or MCP server, as described in Section 6
- For legal reasons: To comply with legal obligations, enforce our terms, or protect rights and safety
- Business transfers: In connection with a merger, acquisition, or asset sale
8. Your Rights and Choices
You have the right to:
- Access and download your data
- Correct inaccurate information
- Delete your account and data
- Opt out of marketing communications
- Restrict certain data processing
- Data portability (export your data)
To exercise these rights, contact us at support@mypropjournal.com.
9. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- Your personal data and trading data are permanently deleted within 30 days
- Some data may be retained for legal or accounting purposes
- Aggregated, anonymized data may be retained for analytics
10. Cookies and Tracking
We use cookies and similar technologies for:
- Authentication and security
- Preferences and settings
- Analytics and performance monitoring
You can control cookies through your browser settings. Disabling cookies may limit functionality.
11. Children's Privacy
Our services are not intended for users under 18. We do not knowingly collect data from children. If we learn we have collected data from a child, we will delete it promptly.
12. International Data Transfers
Your data may be processed in the United States or other countries where our service providers operate. We ensure appropriate safeguards are in place for international transfers.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or a prominent notice on our platform. Continued use after changes constitutes acceptance.
14. Contact Us
For privacy questions or concerns, contact us:
- Email: support@mypropjournal.com
- Website: mypropjournal.com/support