Privacy Policy
Last updated October 4, 2026
Fillbook is a sole proprietorship registered in the State of Arizona.
The English version of this policy controls. Translations are provided for convenience only and have no independent legal effect.
This policy explains what personal information Fillbook collects, how we use and share it, and the choices you have. Please read it together with our Terms of Service.
What changed in this update
We added sections on sharing features and public links (share links, the leaderboard and mentor links), on notifications and near-live refresh, and on behaviour notes; we listed browser push services as a provider; we described how we handle privacy requests and what is kept after you delete your account; we corrected who can see leaderboard entries (other signed-in Core and Elite members, not all signed-in users); and we added a Risk Disclosure page that this policy refers to.
Who we are and how to contact us
Fillbook is a trade journaling and analytics service operated by the sole proprietorship named above. For any question about your data or this policy, or to exercise any of the rights described below, email Developer@fillbookHQ.com.
What we collect
Account info: your email address and sign-in details (a password, or your Google Account details if you sign in with Google), handled by our authentication provider, Supabase, along with the settings and preferences you choose.
Trade and journal data: whatever you enter manually, import from a file, or sync from a connected broker or file source, such as symbols, entry and exit prices, sizes, P&L, fees, timestamps, the trading-account names and rule settings you configure, and any notes, tags, or screenshots you attach. This can be sensitive financial information.
Billing info: if you subscribe to a paid plan, Stripe processes your payment on its own checkout pages. Card details go directly to Stripe and are never stored by Fillbook; we keep only the Stripe customer and subscription identifiers and plan status we need to know which plan you are on.
Broker connection data: if you connect a broker or trading platform, we store the connection details needed to sync your trades, and the trade history we retrieve. Depending on the connection method, connection details can be an API key or access token or, for the Tradovate API-key method, your Tradovate username and password together with the API key details you enter. See "Broker connections and file sync" below.
Usage and device data: when you visit or use Fillbook we record product analytics events in our own database, such as which pages and features are used, together with your account ID if you are signed in. An event can also carry a random visitor ID and session ID generated in your browser, the website you arrived from and any campaign (UTM) tags on the link, the first page you landed on, and the site hostname. These IDs are not derived from your IP address or browser fingerprint. A small set of milestone events (sign-up, finishing onboarding, first logged trade and first paid subscription) is also sent server-side to an internal analytics tool operated by Fillbook, together with any campaign (UTM) tags. These events identify you by a keyed hash (HMAC) of your account ID rather than by your email address, and they contain no email addresses. Fillbook's own team and test accounts are excluded. We also use Vercel Web Analytics for aggregate page-view statistics. Our hosting and infrastructure providers may process technical information such as your IP address and browser type while serving requests and keeping the service secure.
Error reports: when something breaks, error reports are sent to Sentry so we can find and fix bugs. We scrub tokens, passwords, cookies and similar secrets from these reports before they are sent, but a report can still include technical context such as the page or feature involved.
Bot checks: our sign-in, sign-up and password-reset forms use Cloudflare Turnstile to tell people from automated scripts. Your browser contacts Cloudflare when those forms load, and Cloudflare may collect technical signals for that purpose under its own privacy policy.
Notification data: if you turn on push notifications, we store your browser's push subscription (an address and keys issued by your browser's push service) so we can send them to you, along with the notification settings you choose. If you turn on alert, review or behaviour-note emails, we use the email address on your account to send them.
Messages and optional features: anything you send us through the contact form, help chat or feedback prompts, and the information you choose to provide if you use optional features such as the leaderboard (your display name and Edge Score, visible to other signed-in Core and Elite members if you opt in), accountability share links, mentor links, testimonials, Discord recaps, or our newsletter. See "Sharing features and public links" below.
How we use it, and why
We use your information to: provide and operate Fillbook, including your journal, your analytics and our AI features (this is needed to deliver the service you signed up for); process payments and manage your subscription; protect the service, prevent fraud and abuse, and keep it secure; understand how the product is used and improve it; communicate with you about your account, billing, security and support requests and, where you have asked for it, our newsletter; and comply with legal obligations and enforce our Terms. Where the law requires a legal basis (see the EU/UK/EEA section below), these purposes rest on performing our contract with you, our legitimate interests in running and securing the service, your consent where we ask for it, and legal compliance.
While Fillbook is open in a visible tab and you are signed in, the dashboard refreshes about every 30 seconds to show trades that have already reached Fillbook. This uses ordinary requests to our servers under your session and does not collect extra information from you. It reads closed trades only and is not a live view of your broker account.
Optional behaviour notes, if you turn them on (they are off by default), are computed from your own logged trades only, using fixed wording and no AI model, and are sent to you by push notification or email. We keep your settings (such as quiet hours) and a record of the notes we have sent so that limits on how often you are notified can be applied. We use this data only to produce those notes, not for advertising. You can turn them off in Settings at any time.
Signing in with Google
If you sign in with Google, Fillbook receives the email address, name, and profile picture on your Google Account. That information is used only to create your Fillbook account and to identify you when you sign back in.
When you sign in with Google, Fillbook asks for no permissions beyond your basic profile and email address. Signing in does not give Fillbook access to Gmail, Drive, Contacts, Calendar, or any other Google service. (The optional Google Drive file sync described under "Broker connections and file sync" is a separate feature that works differently.)
Your Google account details are stored by our authentication provider, Supabase, in the same way as the rest of your account data described above. They are never sold, and are not shared with anyone other than the service providers listed in this policy.
Fillbook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Fillbook's access to your Google Account at any time at myaccount.google.com/permissions. To have your Fillbook account and its data deleted, see "Your controls" below.
AI features
Fillbook's AI features (such as AI coaching, weekly reviews, trade analysis and chat) use Anthropic's Claude API. Content is sent to Anthropic only when you use an AI feature, or when an AI feature you have access to runs on your behalf. Depending on the feature, this can include a summary of your performance statistics, the details of a trade you ask about, or the messages you type, and it may include notes or tags you have written.
Anthropic acts as our service provider for this purpose, and how it handles data is governed by its own terms and privacy policy, which we encourage you to review. Please do not enter into AI features anything you do not want processed this way. AI output can be inaccurate and is not financial advice; see our Terms of Service.
Fillbook keeps a count of AI requests per day to apply usage limits. AI features are available on certain plans, as shown on the Pricing page.
Connecting an AI assistant (optional, beta)
You can optionally create a personal access token in Settings so that an AI assistant you choose, such as Claude Code, Cursor or claude.ai, can read your Fillbook data through a read-only connection. Nothing is shared this way unless you create a token or approve a connector yourself.
When your assistant uses the token, Fillbook sends it only the trades and rule status of the accounts you selected for that token, as of your last sync. Your trade notes and emotion tags are included only if you ticked that option when creating the token. That data goes to the AI provider you connect, and that provider's own terms and privacy policy apply to it; we do not control how it is handled there.
Fillbook stores only a one-way hash of each token, not the token itself, so it cannot be shown again. We also keep the token's label, selected accounts, creation, last-used and expiry times. A token expires after at most 90 days, and you can revoke it at any time in Settings, after which it stops working. Revoking does not take back data an AI provider has already received.
Fillbook does not see your conversation with the AI assistant. The connection is read-only: it cannot place trades or change anything in Fillbook.
Broker connections and file sync
If you choose to connect a broker or trading platform (currently including Tradovate, NinjaTrader through an add-on, Interactive Brokers, TopstepX and PropReports), we access your trade history on your behalf, on a read-only basis, to import it into your journal. Fillbook does not place trades, modify orders, or move money in your broker account.
Depending on the connection method, we store an API key, access token or other connection details so that syncing can continue. If you connect Tradovate through OAuth (Fillbook's standard Tradovate connection), that access token and refresh token are encrypted at rest with authenticated encryption. For every other connection method currently offered -- including the separate Tradovate API-key method, which stores your Tradovate username and password -- connection details are protected by access controls and row-level security in our database, but are not yet encrypted at the application level. Where your broker lets you, use API keys or tokens with the narrowest permissions available.
You can disconnect a broker at any time from within Fillbook, after which we stop syncing it and delete the connection details we hold for it. You can also revoke access from your broker's own settings. Disconnecting does not by itself delete trades that were already imported; see "Your controls" below. Deleting your Fillbook account does not revoke Fillbook's access at your broker, so also remove Fillbook's access in your broker's own settings.
If you turn on Google Drive file sync, Fillbook reads only files you have explicitly shared with its service account, using read-only access; we do not store a Google credential for you. If you turn on Discord recaps, we send the recap to the Discord webhook URL you provide.
Sharing features and public links
Accountability share link. If you turn this on in Settings, Fillbook creates a link that shows a weekly summary of your results (profit and loss, win rate, number of trades, and best and worst day, without account sizes or firm names) to anyone who has the link, without signing in. The link is a long random token and is not password protected, and we ask search engines not to index it. You can turn it off, or regenerate it so the old address stops working, in Settings. Where supported, Fillbook stores only a one-way hash of the token for new links; links created earlier may be stored in readable form until you regenerate or re-enable them.
Leaderboard. If you opt in (it is off by default), your display name and Edge Score are shown to other signed-in Core and Elite members. Scores are self-reported from your own data and are not audited. You can opt out in Settings, which removes you from the board.
Mentor links. Where this feature is available, you can create a link that lets a person you choose view your trades and statistics, and your notes and screenshots only if you tick that option. Fillbook stores only a one-way hash of each link's token; a link has an expiry and can be revoked at any time. A mentor can leave comments, which we store with your account. Anyone who has the link, not only the intended person, can use it until it expires or you revoke it.
Images and links you post. Share cards and screenshots you create are yours to post. Once you post an image or send a link, we cannot control or recall copies, so please think before sharing financial information.
Service providers and who we share it with
We use the following service providers to run Fillbook. They process personal information only to provide their service to us, and each is subject to its own terms and privacy policy.
- Supabase: hosts our database, file storage and sign-in, and stores your account, trades, journal and settings.
- Vercel: hosts the website and our server functions, and provides aggregate web analytics.
- Stripe: processes payments and subscriptions.
- Cloudflare (Turnstile): bot checks on sign-in, sign-up and password-reset forms.
- Sentry: receives error reports so we can find and fix bugs.
- Anthropic: processes the content of AI feature requests, as described above.
- Resend: sends transactional emails such as sign-in, billing and support messages. Messages you send to our addresses are received through our email provider.
- Beehiiv: manages our newsletter, only if you subscribe.
- Brokers and trading platforms you connect (see above): only if you connect them.
- Google Drive and Discord: only if you turn on file sync or Discord recaps.
- TradingView: Trade Replay's chart for futures trades is drawn with their open-source charting library, bundled directly into Fillbook's own code -- no data is sent to TradingView for those, and the underlying market data comes from a public Yahoo Finance endpoint our server queries with only a symbol and time range, never your account or trade data. For other markets (stocks, options, forex, crypto), Trade Replay uses TradingView's own embedded chart widget instead, since their restriction on futures data for third-party embeds doesn't apply there -- opening one loads a frame directly from TradingView's servers, which then sees the symbol you're viewing along with the same connection details (your IP address, browser) any embedded website content would see.
- Browser push services (such as those operated by Google, Apple and Mozilla): only if you turn on push notifications; they process the delivery address for your browser and the notification so it can reach your device.
We may also disclose information if we believe in good faith that it is required by law, legal process or a government request; to protect the rights, property or safety of Fillbook, our users or others, including to enforce our Terms and to prevent fraud or abuse; at your direction or with your consent (for example through a share link you create); or in connection with a merger, acquisition, financing or sale of all or part of our business, in which case we would notify you if the policy that applies to your information materially changes.
We do not sell your information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use advertising networks or data brokers, and we do not use advertising or cross-site tracking cookies or pixels.
Cookies, local storage and similar technologies
Fillbook uses only what it needs to work: browser storage (local storage, session storage and, for offline support, IndexedDB and a service worker cache) and, where applicable, small cookies. These keep you signed in through Supabase Auth, remember your language, theme and other preferences and dismissed tips, hold the random visitor and session IDs used for our product analytics, and keep temporary copies or queued writes so the app keeps working on a poor connection. We may set a cookie or storage flag on our own devices to exclude internal traffic from analytics. Vercel Web Analytics measures aggregate page views. We don't use advertising or cross-site tracking cookies, and we don't respond differently to browser "Do Not Track" signals because we don't engage in the kind of cross-site tracking those signals are meant to limit. You can clear or block browser storage in your browser settings, but parts of Fillbook, such as staying signed in, may then stop working.
Your controls
From within Fillbook you can export your trades as a CSV file from the Trades page; clear all trades on the active trading account from Settings; delete a trading account (subject to the conditions shown in the app); disconnect a broker or other connection; and turn optional sharing features, such as the leaderboard, off. Clearing trades or deleting a trading account in the app removes that data from your Fillbook account and cannot be undone. You can delete your entire Fillbook account yourself from Settings (Privacy section). This permanently removes your login and the data tied to it; it requires a recent sign-in, and if you have a subscription it must have fully ended first. You can also email Developer@fillbookHQ.com to have your account, or any other personal information, deleted. Some records (like billing history) may be retained as required for tax/accounting purposes, fraud prevention, or to comply with a legal obligation, even after deletion, and copies in our backups may persist for a limited period before they are overwritten.
When you delete your account, we also try to remove your email address from our newsletter provider, Beehiiv, automatically. If that fails, or you were subscribed under a different address, email Developer@fillbookHQ.com. Deleting your account does not automatically remove you from Resend (email logs) or Sentry (error reports); to have your information removed from them, email Developer@fillbookHQ.com and we do it by hand.
Onboarding tips and weekly reviews include an unsubscribe link, and you can manage notification and email preferences in Settings. We will still send essential messages about your account, billing, security and legal notices. Newsletter emails come from Beehiiv and include their own unsubscribe link.
Data retention
We keep your account data until you delete your account (Settings > Privacy > Delete account). After that it is removed from the Fillbook app database. Some things are kept separately: billing and payment records stay with Stripe for tax and accounting purposes; server logs are kept for a limited period, about 30 days; and database backups that we make ourselves are kept for up to about 90 days, so deleted data can remain in a backup until we delete it. Some records needed to prevent fraud or abuse, or to resolve disputes, may also be kept for a limited period. Error reports are kept only as long as reasonably needed to fix bugs. These periods describe our current practice and may change.
After you delete your account: your trades, journal, settings, connections and share links are removed from the app database and any share link stops working; product analytics events may be kept without any link to your account; billing records stay with Stripe; email logs at Resend and error reports at Sentry are removed by hand on request (see "Your controls"); and backups roll off as described above.
Security
We use industry-standard safeguards such as encrypted connections (HTTPS) in transit, access-controlled service keys, and row-level security in our database so that each account can read only its own rows. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please choose a strong, unique password, keep your devices secure, and tell us right away at Developer@fillbookHQ.com if you think your account has been compromised.
Other safeguards include a bot check (Cloudflare Turnstile) on sign-in and sign-up forms, storing only a one-way hash of AI-assistant and mentor-link tokens, and scrubbing secrets from error reports. Fillbook is a small operation and has not been independently audited or certified (for example SOC 2 or ISO 27001).
Data breach notification
If we become aware of a security breach that compromises your personal information in a way that requires notice under applicable law, we'll notify affected users and any required regulator within the timeframe the law requires, using the email address on your account.
Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent you have given. You can do many of these yourself in Fillbook (for example, export your trades and clear or edit your data). You can delete your account yourself in Settings. For anything else, or to request deletion by email, write to Developer@fillbookHQ.com from the address on your account. We may need to verify your identity, and we will respond within a reasonable time and within any period applicable law requires. We won't discriminate against you for exercising your rights.
How we handle requests: email Developer@fillbookHQ.com from the address on your account and say what you would like us to do. We will confirm we received it, may ask you to verify your identity, and aim to respond within 30 days (some laws allow or require a different period, and we may extend where the law permits). An authorized agent may make a request for you with your written permission. If we decline a request you can reply to ask us to reconsider, and you can also contact your state attorney general or local data protection authority. We do not charge for reasonable requests.
California residents (CCPA/CPRA)
Fillbook does not sell or share personal information (as those terms are used in California law), and has not done so in the past 12 months. In the past 12 months we have collected the categories of personal information described in "What we collect", for the purposes described in "How we use it, and why", and have disclosed them only to the service providers listed above for business purposes. California residents have the right to know what personal information we hold, request its deletion, correct inaccuracies, and not be discriminated against for exercising these rights. Submit a request to Developer@fillbookHQ.com; we may need to verify your identity (typically by confirming account access) before acting on it.
We do not use or disclose sensitive personal information, such as financial information in your trade data, for purposes other than providing the Service you asked for. We do not knowingly sell or share the personal information of anyone under 18. California residents may also ask which categories of personal information we disclosed to third parties for their direct marketing; we make no such disclosures.
EU/UK/EEA users (GDPR)
If you're located in the EU, UK, or EEA, we are the controller of the personal information described in this policy, and we process it on the following legal bases: performance of a contract (running the Service you signed up for), legitimate interests (security, fraud prevention, product analytics and improvement), legal obligation, and consent (where we ask for it, e.g. optional marketing, which you can withdraw at any time). You have the rights described above, plus the right to lodge a complaint with your local data protection authority.
We do not make decisions about you with legal or similarly significant effects based solely on automated processing; AI output in Fillbook is informational. Where we rely on consent, you can withdraw it at any time without affecting processing that took place before.
International data transfers
Your Fillbook account data is stored in the United States: our Supabase database is hosted in the West US (N. California) region. Fillbook and its service providers may process and store information in the United States and in other countries where those providers operate, which may have different data protection laws than your country. Where required, we rely on the safeguards our providers make available for those transfers, such as contractual clauses. By using Fillbook you understand that your information may be processed in these locations.
Children's privacy
Fillbook is intended for adults and is not directed to anyone under 18; our Terms require users to be at least 18. We don't knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact Developer@fillbookHQ.com and we'll delete it.
Changes
We may update this policy from time to time. When we do, we will change the "last updated" date at the top of this page, summarize what changed, and, if the changes are material, provide additional notice where required by law (for example by email or in the app). To the extent permitted by law, continuing to use Fillbook after an update means you accept the updated policy.
Not financial advice
Fillbook is a journaling and analytics tool. What it shows you, including analysis of your own data, is not investment, financial, tax or legal advice. See our Terms of Service for the full disclaimers and our Risk Disclosure page for the trading risk disclosure.
Governing law and language
This policy, and Fillbook's operation generally, is governed by the laws of the State of Arizona, without regard to its conflict of law provisions.
This policy is written and published in English. Any translated version is provided for convenience only and has no independent legal effect. In the event of any conflict, discrepancy, or difference of interpretation between the English version and a translated version, the English version governs and prevails.
Contact
Questions about your data or this policy, or to make a privacy request: Developer@fillbookHQ.com