Your data is yours. Always.

TradeInsights is designed for post-trade analytics. It does not expose an order-entry, transfer, or withdrawal workflow. Connection capabilities still depend on the provider, so use read-only permissions whenever they are available.

Exactly what we can — and cannot — do

What TradeInsights CAN do

  • Import eligible trade and account-history fields
  • Display analytics for the records that arrived
  • Generate evidence-linked findings from eligible trades
  • Refresh supported connections on their available schedule
  • Show available balance or position fields when a provider returns them

What TradeInsights CANNOT do

  • Provide a TradeInsights control for placing, modifying, or cancelling orders
  • Provide a TradeInsights control for withdrawing or transferring funds
  • Change broker account settings through the TradeInsights interface
  • Guarantee that a provider token is read-only if you grant it broader permissions
  • Sell personal information as a data-broker product
Your part matters: Grant only the history or read scopes documented in the connection guide. Never enable trading, transfer, or withdrawal permissions for a TradeInsights API key. Revoke a key at the provider if its permissions are uncertain.

Read-only broker access

TradeInsights asks for the minimum permissions needed to retrieve eligible history. The product does not need trading, transfer, or withdrawal permissions.

Use an MT4/MT5 investor password and read-only crypto keys. OAuth and personal-token scope behavior is controlled by the provider; review the provider's authorization screen before approving it.

Encrypted credential storage

Direct-connection secrets are protected with authenticated application-layer encryption before storage and are not returned to the browser after submission. Provider-managed OAuth tokens remain subject to the provider integration's storage design.

The server reveals a stored direct credential only when it needs to validate or refresh that connection. Connection responses expose status and safe account labels, not API keys, API secrets, or passphrases.

Encryption in transit

The production site and supported external API connections use HTTPS. Do not submit credentials if your browser reports a certificate or connection warning.

TradeInsights stores account passwords as salted one-way hashes and supports legacy password hashes during sign-in migration; it does not need the original password to authenticate you.

Trusted infrastructure

TradeInsights runs its application on Railway and stores application data in Postgres. Access to production services is controlled through deployment credentials and environment configuration.

Retention and deletion depend on the data type, legal obligations, and active provider records. See the Privacy Policy for the current customer-facing terms rather than relying on a fixed backup-retention promise.

Privacy-first AI processing

SageAI requests can include the question you submit and selected trading context needed to generate a response. Avoid placing credentials, account numbers, or other unnecessary personal data in a prompt.

External AI processing is governed by the applicable provider terms and the TradeInsights Privacy Policy. An AI response is analytical assistance, not individualized financial advice.

Security reporting

TradeInsights will assess suspected incidents and provide notices when required by applicable law and the facts of the incident.

We do not have a public bug bounty programme. Send responsible disclosures to [email protected] and avoid accessing or retaining other users' data.

Compliance

GDPR (EU/EEA/UK)

  • • Right of access and portability
  • • Right to deletion ("right to be forgotten")
  • • Data minimisation and purpose limitation
  • • Requests handled subject to identity and legal checks

CCPA (California)

  • • We do not sell personal information
  • • Right to know what data is collected
  • • Right to delete personal data
  • • No discrimination for exercising rights

Data controls

  • • Use available export controls or contact support
  • • Request account deletion, subject to required retention
  • • Disconnect TradeInsights and revoke access at the provider
  • • Choose whether to submit a request to SageAI
  • • Review current controls in Settings and the Privacy Policy

Security questions or concerns?

We take security seriously. If you have a question, a responsible disclosure, or you just want to understand how something works, reach out.

Contact security team
Ask me anything

AI Assistant

Hi! How can I help you today?
Powered by AssistLayer