Privacy Policy

Last updated: 29 July 2026

The data controller is Pavel Loboda, trading as AURIC. Contact: support@auricjournal.com.

The short version: we store your email and your journal so it can sync between your devices, and nothing more than the Service needs. Auric IQ's analysis runs entirely on your device. We never sell your data, we don't run ads, and payment card details go to Stripe — never to us. You can export everything or ask us to delete it, any time.

1. What we collect

Account data: your email address and a password (stored by our authentication provider as a secure hash — we never see the password itself), plus the display name you choose.

Journal data: what you put into AURIC — trades, prop-firm configurations, notes, debriefs, playbook rules, settings and chart screenshots. This is the product; it exists so it can be shown back to you and synced across your devices.

Billing data: handled by Stripe. We receive your subscription status and plan, never your card number.

Technical data: the minimal operational logs our infrastructure providers keep (such as request logs and IP addresses) to run and secure the Service. We do not use advertising trackers or analytics that follow you across the web.

2. Where your data lives

Your journal is stored in our database and file storage hosted by Supabase, protected by row-level security — a database-enforced rule that only your authenticated account can read or write your rows. A working copy also lives in your own browser's local storage on each device you use, which is what makes AURIC fast and usable offline.

3. On-device analytics

Auric IQ — the statistical engine that analyses your trading — runs entirely in your browser. Your trades are not sent to any analytics service, and no third party receives your journal to "generate insights". The only journal data that leaves your device is the copy synced to your own account's database.

4. Who processes data for us

We use a small number of processors, each only for what the Service requires: Supabase (database, authentication, file storage), Stripe (payments), our hosting provider (serving the website), our email provider (transactional emails such as sign-up confirmations and password resets), Plausible Analytics (privacy-first site analytics — cookieless, no cross-site tracking, no personal profile is built; it counts visits, not people), and Cloudflare Turnstile (bot protection on sign-up and sign-in, so accounts belong to humans). We share only what each needs to perform its role. We do not sell personal data, and we don't share it with advertisers.

4a. International transfers

Supabase and Stripe may process data outside the UK/EEA. Where they do, transfers rely on the safeguards in their data-processing agreements — the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum and the EU–US Data Privacy Framework. Your journal's row-level security applies regardless of region.

4b. Auto-logged trades

If you turn on auto-logging, your closed trades can reach your journal three ways: a read-only bridge script in your trading platform that posts closed trades to your private inbox (the bridge contains no order functions by construction — it can read your history, never trade), a watched statement folder that is read entirely on your device, or a webhook you configure yourself. In every case the data lands only in your own account's rows, under the same row-level security as everything else.

5. How we use your data

To provide and secure the Service, sync your journal, process subscriptions, respond to support requests, and send transactional emails. We'll only send product or marketing email with your consent, and every such email includes an unsubscribe link.

6. Retention and deletion

We keep your data while your account is active. You can export your full journal from Settings at any time. To delete your account and its data, email support@auricjournal.com from your account address — we'll confirm and delete your account data within 30 days, after which it also ages out of routine backups. Data we must keep for legal reasons (such as invoices) is retained as required.

7. Your rights

Depending on where you live (including under UK and EU GDPR), you have rights to access, correct, export, restrict, object to processing of, and delete your personal data, and to complain to your local data-protection authority. Exercise any of these by emailing support@auricjournal.com.

8. Cookies and local storage

AURIC uses only what's essential: an authentication session so you stay signed in, and browser local storage for your journal's device copy and preferences. No advertising cookies, no cross-site tracking.

9. Security

Data is encrypted in transit (TLS), access is scoped by row-level security, and we follow a least-access approach to infrastructure. No system is perfectly secure, but security decisions in AURIC start from "only you can read your journal".

10. Children

The Service is for adults and is not directed at children under 18. We don't knowingly collect data from children.

11. Changes and contact

If we materially change this policy we'll give notice before it takes effect. Questions or requests: support@auricjournal.com.