Privacy Policy

What ChristTrade collects, why, where it goes, and what you can do about it. Written to be read, not to be skipped.

Effective Date: August 1, 2026

First published: December 29, 2024

The short version

ChristTrade is charting, backtesting and journaling software. We are not a broker, not a financial advisor, and not an investment firm. We do not execute trades, hold funds, or give financial advice. See the Terms of Service for the full picture.

1. Who we are


ChristTrade is run by one person. For the purposes of the GDPR, the data controller is:

Carl Sterner, trading as ChristTrade

Sole trader (enskild firma) registered in Sweden

help@christtrade.com

ChristTrade is run by one person out of a home office, so the registered address and organisation number aren't published here. If you need them — including to make a complaint to a supervisory authority — email and ask, and you'll get them.

This policy covers christtrade.com and its subdomains (app, docs, status). By using the site you agree to it. If you don't, please stop using the site — and if you have an account, email us and we'll delete it.

2. What we collect


If you don't have an account

Your settings, chart preferences and journal entries are written to your own browser (LocalStorage and IndexedDB) and stay there. We don't receive them. Our servers still see the ordinary technical information any web server sees — described below under "Technical data".

Account data

  • Email and display name. Required — it's how you log in and how we reach you about your account.
  • Password. Stored only as a salted hash. We cannot read it, and nobody here can tell you what it is.
  • Profile picture, if you upload one.
  • Email verification and password-reset tokens, which expire.

If you sign in with Discord

Signing in with Discord is optional. If you use it, Discord sends us your user ID, username, avatar and the email address on your Discord account.

The sign-in also requests the guilds scope, which means Discord shows us the list of servers you're in. We use it for exactly one thing: checking whether you're in the ChristTrade server, so we can show community features. We do not store the list, and we're not interested in the rest of it. You can revoke this access at any time in Discord's settings under Authorized Apps.

Content you create

Journal entries, notes, screenshots and images you attach, backtest results, custom strategies and indicators you write, chart layouts, and your settings. If you're signed in, this is synced to our storage so you can reach it from another device. Journal entries can contain whatever you type into them — please don't put anything in there you'd be upset to lose or to have someone read. See §5.

Technical data

  • Session records: when you log in we store a session with your IP address and browser user-agent. This is what keeps you logged in and lets us spot someone else using your account.
  • Request logs: Cloudflare, our host, logs requests (IP address, timestamp, path, response code) for security, abuse prevention and debugging.
  • Approximate location: Cloudflare tells us the country and rough region an IP resolves to. We use it for things like timezone defaults. It is not GPS and it is not stored as a profile of you.
  • Rate-limit counters, keyed to an identifier, to stop abuse.
  • Backtesting time: while you have a backtesting session open, your browser pings us every 20 seconds so we can count how long you actually spent working. We store a running total per session and the time of the most recent ping. We don't keep a history of when you were online, and we don't record what you did. The ping stops when you switch tabs or go a minute without touching anything — that's the whole point of it, and it's why we can't just measure the clock instead.

Payment data (Pro subscribers)

Payments are handled by Creem, who act as the merchant of record. Your card number never reaches our servers and we never see it. What we store is a subscription record: a Creem customer and subscription ID, which product you're on, whether it's active, and when the current period ends. Creem separately holds your billing details under their own privacy policy.

Things we deliberately don't collect

No advertising identifiers. No third-party analytics or product-analytics SDKs. No session recording or heatmaps. No behavioural profiling. No cross-site tracking pixels. No brokerage credentials, no bank details, no national ID numbers.

3. Why we use it, and our legal basis


Under the GDPR every use of your data needs a lawful basis. Ours:

What we doLegal basis
Run your account, log you in, sync your content across devicesPerformance of a contract (Art. 6(1)(b))
Take payment, manage your Pro subscription, handle refundsPerformance of a contract (Art. 6(1)(b))
Send account email — verification, password reset, service noticesPerformance of a contract (Art. 6(1)(b))
Keep the service secure, prevent abuse, debug failures, keep aggregate counts of how many people use a featureLegitimate interests (Art. 6(1)(f)) — running a service that works and isn't abused
Keep accounting records for the subscriptionLegal obligation (Art. 6(1)(c)) — Swedish Bokföringslagen
Anything optional we might add later (e.g. a newsletter)Consent (Art. 6(1)(a)) — asked for separately, withdrawable anytime

We do not use your content to train machine-learning models, and we do not make automated decisions that produce legal effects for you.

4. Cookies and local storage


We use two kinds of browser storage, and neither is for tracking:

  • Strictly necessary cookies: the session cookie that keeps you logged in, and CSRF tokens. Without these, logging in doesn't work. These are exempt from consent requirements because they're essential to a service you asked for.
  • Local storage (LocalStorage / IndexedDB): your chart settings, layouts, cached market data and — for logged-out users — your journal. This lives on your device, and for logged-out users it isn't transmitted anywhere.

There are no advertising cookies, no analytics cookies and no third-party tracking cookies on this site. That's why you're not seeing a cookie banner — there's nothing to consent to. You can clear everything at any time via your browser settings, though doing so will log you out and wipe local journal data that hasn't been synced.

5. Security, and what our encryption actually means


What we do:

  • All traffic is served over HTTPS/TLS.
  • Passwords are stored as salted hashes, never in plaintext.
  • Your synced content is compressed and encrypted in your browser before it's uploaded, and stored encrypted at rest in Cloudflare R2.
  • Access to the production systems is limited to the one person who runs ChristTrade.

Being precise about "encrypted", because the word gets abused

Your content is encrypted, but the encryption keys are derived and held by ChristTrade, not by you. This is not end-to-end encryption and it is not zero-knowledge.

In practice that means: it protects your data in transit and adds a layer of protection at rest, but we are technically able to decrypt your content. We don't read it as a matter of routine, we don't mine it, we don't sell it, and we don't hand it to anyone unless we're legally required to. But we could, and we'd rather you knew that than assumed otherwise and were wrong.

If we ever ship true end-to-end encryption, where the key is derived from something only you know, this section will say so explicitly and in plain terms. Until it says that, assume it isn't the case.

No online service can promise perfect security, and anyone who does is lying. If we ever discover a breach affecting your personal data, we'll notify the Swedish supervisory authority (IMY) within 72 hours where required, and tell you directly if it's likely to be a high risk to you.

6. Who else touches your data


We do not sell personal data, and we never will. We don't share it for advertising or for anyone else's marketing. It goes to a short list of service providers who process it on our instructions, under contract, only to make the product work:

Cloudflare, Inc.

Hosting, Workers, D1 database, R2 object storage, CDN and DDoS protection. Effectively everything the site runs on.

Data: All account data, all content you upload, request logs, IP addresses

Location: USA / global edge network · their privacy policy

Creem

Payment processing and subscription management for Pro. Creem is the merchant of record — they take the payment and handle tax.

Data: Email address, billing country, subscription status. Card details go to Creem directly and never touch our servers.

Location: EU / USA · their privacy policy

Resend

Sending transactional email — verification links, password resets, account notices. No marketing email.

Data: Email address, message contents

Location: USA · their privacy policy

Discord, Inc.

Optional "Sign in with Discord". Only applies if you choose it.

Data: Discord user ID, username, avatar, the email on your Discord account, and your server list (see §2)

Location: USA · their privacy policy

Beyond that, we may disclose data if we're legally required to (a valid court order or law-enforcement request), or if it's genuinely necessary to protect the rights or safety of users. If ChristTrade were ever sold or transferred, your data would move with it and you'd be told in advance.

The charting library used on the site is self-hosted — using our charts does not send your data to a third-party chart provider. If you paste an external link (e.g. a TradingView chart) into a journal entry, opening that link is governed by that site's own policies, not ours.

7. International transfers


Some of the providers above are based in, or operate infrastructure in, the United States, so your data may be processed outside the EU/EEA. Where that happens we rely on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework where the provider is certified, as applicable. You can ask us for details of the safeguards in place for any specific provider.

8. How long we keep things


  • Account and synced content: for as long as your account exists. Delete your account and it's removed, along with backups, within 30 days.
  • Session records: until the session expires or you log out.
  • Server and security logs: a rolling window, typically no more than 30 days.
  • Payment and accounting records: kept for seven years after the end of the financial year, because Swedish accounting law (Bokföringslagen 7 kap. 2 §) requires it. This is the one category we can't delete on request — but it's invoice-level data, not your journals or strategies.
  • Backtesting time totals: for as long as your account exists, and deleted with it. They're totals, not a timeline — there's no per-day or per-hour record of you to hand over or to lose.
  • Local browser data: stays on your device until you clear it. We can't delete it for you.

9. Your rights


Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you
  • Rectification — have inaccurate data corrected
  • Erasure — have your account and data deleted
  • Portability — receive your data in a structured, machine-readable format
  • Restriction — limit how we process your data
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where we relied on consent, without affecting what came before

Email help@christtrade.com and we'll handle it within 30 days. It's free — we won't charge you for asking, and we won't make it difficult.

Account deletion is currently handled by email rather than a button in the app. That's a gap we intend to close; until then, one email does it.

If you think we've mishandled your data, you can complain to the Swedish Authority for Privacy Protection — Integritetsskyddsmyndigheten (IMY), imy@imy.se — or to the supervisory authority in your own EU/EEA country. We'd appreciate the chance to fix it first, but it's your call.

10. Children


ChristTrade is not intended for children under 18, and Pro subscriptions require you to be 18 or older. We don't knowingly collect data from children under 13. If you believe a child has given us personal data, email us and we'll delete it.

11. Changes to this policy


We'll post updates here and move the "Effective Date" at the top. If a change materially affects your rights or how we use your data, we'll email registered users before it takes effect rather than quietly editing the page.

12. Contact


Privacy questions, data requests, or anything in this document that reads like nonsense — email help@christtrade.com. A real person reads it.