Privacy Policy
This Privacy Policy explains what information Trader Blueprint collects, why it collects it, how it is used and protected, and how you can ask for it to be deleted. It describes what the product actually does today.
1. Who we are
Trader Blueprint is a trading journal and analytics service available at https://tradeblueprint.in. It is operated by Akash Dilipbhai Mangukiya, an individual based in Surat, Gujarat, India. Throughout this policy, “we”, “us” and “the service” mean Trader Blueprint as operated by that individual.
For any privacy question, request or complaint, contact tradeblueprintapp@gmail.com. We are the party responsible for deciding how and why your personal data is processed.
2. Scope
This policy covers the public marketing website and the authenticated trading-journal application. Trader Blueprint is a journaling and analytics tool. It is not a broker, an investment adviser, a tax adviser, or a provider of guaranteed trading outcomes, and it does not place, route or execute orders.
3. Information we collect
Account data. When you create an account we collect your email address and the authentication identifiers issued for your sign-in, and you may optionally provide a display name. Supabase Auth handles password authentication for your account; Trader Blueprint cannot read your password.
Journal data you enter. The service stores the information you record about your trading, including trades, executions and fills, portfolios, capital-activity entries, notes, trade reviews, tags, dropdown and setting choices, onboarding choices, and any files or records you import. This content is yours; we hold it so the application can show it back to you and calculate analytics from it.
Optional broker-integration data. If you choose to connect Zerodha Kite, we store the connection configuration you provide and the short-lived or daily access tokens that integration issues, so that a sync you request can run. You are never asked to enter broker secrets into a marketing or onboarding form, and the integration is optional.
Technical and security data. To operate, diagnose and protect the service we process operational records such as request, authentication, error and deployment logs. These can include your IP address, timestamps, the pages or endpoints touched, and diagnostic detail about failures.
Local browser storage. Your theme preference (dark, light or system) is stored in your browser’s local storage and never leaves your device. Your browser also holds the session information Supabase Auth needs to keep you signed in.
We do not knowingly collect special categories of personal data, and we ask that you do not enter such data into free-text notes.
4. How we use information
We use the information above to:
- provide, maintain and secure the service, and authenticate you when you sign in;
- calculate the journal analytics you ask for, such as average price, realised profit and loss, R-multiple, drawdown, and the statistical summaries;
- carry out imports and optional broker integrations that you initiate;
- detect, investigate and prevent abuse, fraud, security incidents and technical faults;
- respond to your support requests and send account and service messages, such as confirmation or security notices;
- keep records and comply with applicable law.
We do not use your data for advertising, behavioural profiling, marketing analytics, or the sale of personal data, because the product does none of those things. If that ever changes, this policy will be updated first and, where the law requires it, we will ask for your consent.
5. Legal grounds and consent
Depending on the activity and on the law that applies to you, we rely on one or more of the following grounds: performance of our agreement with you and steps you request (for example, running the service and a sync you start); your consent (for example, connecting an optional broker integration, or where consent is otherwise required); our legitimate interests in operating, improving and securing the service in a way that is not overridden by your rights; and compliance with legal obligations. No single universal basis applies to everything we do.
6. Service providers and integrations
We rely on a small number of providers to run the service. They process data on our behalf or under their own terms, and we do not imply any partnership or endorsement:
- Supabase — authentication and managed database services that store your account and journal data.
- Render — hosting for the application and its interface.
- Zerodha Kite — only when you connect it; used to fetch the trade and order data you ask to sync.
- Yahoo Finance market-price endpoints — queried for market prices of your open positions; these requests carry the instrument symbol, not your identity.
Each provider processes data under its own terms and privacy practices. We do not expose our database, credentials or infrastructure details, and adding a provider that materially changes how your data is handled would be reflected in an updated version of this policy.
7. Sharing and disclosure
We do not sell your personal data and we do not share it for others’ marketing. We disclose data only: to the service providers listed above, to the extent needed to run the service; to third parties you direct us to, such as a broker integration you enable; where reasonably necessary to comply with law, enforceable legal process, or to protect the rights, safety or property of users, the public or the operator; and, if the service is ever reorganised, transferred or acquired, to a successor operator bound to protect it consistently with this policy. Where practicable we will tell you before your data becomes subject to a materially different privacy policy in that situation.
8. International processing
Our service providers may store and process data on servers located outside India. Where data is transferred across borders, we rely on the providers’ contractual and technical protections and take reasonable steps to ensure the data continues to be protected to a comparable standard.
9. Retention and deletion
We keep your account and journal data for as long as your account is active. A self-service deletion control does not exist yet.
Until it does, you can ask us to delete your account and journal data by emailing tradeblueprintapp@gmail.com from your registered email address. We verify your identity through that address before acting on the request. Once verified, your active account and journal data will normally be deleted within 30 days. After deletion from active systems, residual copies may remain in provider-managed backups until their normal expiry, for no longer than 90 days.
We may retain a limited set of records for longer where this is reasonably required for security, fraud prevention, resolving a dispute, enforcing our terms, or complying with a legal obligation. When we no longer need data for any of these purposes, we delete or anonymise it.
Deleting data that is required to operate your account, such as your email and authentication identifiers, ends your ability to sign in.
10. Security
We use reasonable administrative and technical safeguards appropriate to a service of this size. These include authentication on the application’s routes apart from a small set of health and integration callbacks, a database schema that is not exposed through any public data API, an application database role limited to the minimum privileges it needs, and transport encryption in the browser. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a security incident affecting your personal data, we will act on it and notify you and any regulator where the law requires.
11. Your choices and rights
Subject to the law that applies to you, you may ask to access the personal data we hold about you, correct inaccurate data, delete your account and journal data, withdraw a consent you previously gave (such as a broker connection), or object to or restrict certain processing. You can exercise these rights, or raise a grievance, by contacting tradeblueprintapp@gmail.com. We will respond within the time the applicable law allows. You may also have the right to complain to your local data-protection authority.
12. Children
The service is intended only for people who are at least 18 years old. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
13. Cookies and local storage
The marketing site does not set advertising or tracking cookies and does not run marketing analytics. The application uses your browser’s local storage for your theme preference and uses the storage that Supabase Auth needs to keep your session active. We do not currently use any advertising tracker. Because authentication and session behaviour may evolve, we describe what we use rather than promising there are no cookies at all.
14. Changes and contact
We may update this policy as the product changes. When a change is material we will revise the effective date at the top of this page and, where appropriate, give notice in the application. We will provide notice and request consent where required by applicable law before materially different processing begins.
Trader Blueprint — Akash Dilipbhai MangukiyaSurat, Gujarat, India
tradeblueprintapp@gmail.com
See also our Terms of Service.