Privacy Policy

Last updated: September 2026

FuturesLog ("FuturesLog," "we," "us," or "our") is a trading journal application operated as a sole trader based in the Netherlands. This Privacy Policy explains what personal data we collect when you use futureslog.com (the "Service"), why we collect it, and what rights you have over it. We've tried to write this in plain language rather than dense legal text — if anything is unclear, please reach out.

1. Who we are

FuturesLog is operated by an individual sole trader established in the Netherlands. For the purposes of the EU General Data Protection Regulation (GDPR), we are the "data controller" of the personal data described below.

Contact for privacy questions or data requests: privacy@futureslog.com.

2. What data we collect

We collect only what's needed to run the Service:

We do not run advertising, we do not use analytics or tracking cookies, and we do not sell your data to anyone.

3. Why we process your data (legal basis)

Under GDPR, we rely on the following legal bases:

4. Who processes your data

We use a small number of trusted third-party processors to run FuturesLog. We do not sell or rent your data to anyone, and we don't share it with data brokers or advertisers.

Each of these providers has its own privacy policy and acts as a data processor on our behalf, bound by data processing agreements (DPAs) for the personal data they handle for us.

5. How long we keep your data

We keep your account, trading, and journal data for as long as your account is active. If you delete your account, we permanently delete your personal data, trading data, and uploaded screenshots within 30 days, except where we're legally required to retain billing/tax records for longer (typically up to 7 years under Dutch accounting law).

6. Your rights under GDPR

If you're in the EU/EEA (or anywhere, really), you have the right to:

To exercise any of these rights, email privacy@futureslog.com. You can also export or delete most of your trading data directly from your account settings. We'll respond to verified requests within 30 days.

7. California residents (CCPA)

If you're a California resident, you have the right to:

To make a CCPA request, email privacy@futureslog.com with "CCPA Request" in the subject line.

8. Cookies

We use only essential session cookies — small files needed to keep you signed in and your session secure. We do not use advertising cookies, tracking cookies, or third-party analytics cookies. Because these cookies are strictly necessary for the Service to function, we don't show a cookie consent banner, as none is required under EU ePrivacy rules for essential-only cookies.

9. International data transfers

Where our processors (Supabase, Stripe, Vercel) transfer data outside the EU/EEA, they do so under appropriate safeguards such as the EU Standard Contractual Clauses (SCCs). Where possible, we configure our infrastructure (e.g. Supabase's EU region) to keep your data within the EU/EEA.

10. Security

We rely on industry-standard security practices provided by Supabase, Stripe, and Vercel, including encryption in transit (HTTPS/TLS) and access controls on our database and storage buckets. No system is 100% secure, but we take reasonable steps to protect your data.

11. Children's privacy

FuturesLog is not directed at children, and we don't knowingly collect data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we'll delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or via an in-app notice. Continued use of the Service after changes take effect means you accept the updated policy.

13. Contact us

Questions, requests, or concerns about this Privacy Policy or your data? Email us at privacy@futureslog.com. For formal Data Processing Agreement (DPA) requests, please include your business details and intended use case.