Product: EdgeRecall

Privacy Policy

EdgeRecall is a private trading journal and analytics workspace. This policy explains what data is processed when you use the Service.

Effective date

April 1, 2026

Contact: support@edgerecall.com

This Privacy Policy ("Policy") explains how EdgeRecall ("EdgeRecall", "we", "us", or "our") collects, uses, stores, discloses, and protects personal data when you use our website, web application, trading journal, import tools, analytics, AI-assisted features, file attachments, product telemetry, and related support services (collectively, the "Service").

Please read this Policy carefully. By using the Service, creating an account, uploading or importing trading data, using AI-assisted features, uploading files, or contacting support, you acknowledge that you have read how your personal data is processed in accordance with this Policy.

If you do not agree with this Policy, you must not use the Service.

1. Overview of how we process data

EdgeRecall is a private trading journal and analytics web product for individual users. We process data to let you keep a trading journal, import CSV files, analyze trading results, use AI-assisted features, store attachments, receive support, and help keep the Service secure.

We do not sell your private trading records. We do not make your data public by default. We do not use private user content to train general-purpose AI models.

We aim to collect only the data needed to operate, secure, support, and improve the Service.

2. Who is responsible for data processing

For the purposes of applicable data protection laws, EdgeRecall is the controller of personal data processed in connection with the Service.

The Service is intended for individual users and is not currently offered as a B2B product for organizations. If EdgeRecall is offered to organizations in the future, additional data processing terms may apply.

For privacy and data protection questions, you can contact us at support@edgerecall.com.

3. Who this Policy applies to

This Policy applies to users of the Service, website visitors, people who create an account, upload data, use AI-assisted features, send support requests, or otherwise interact with EdgeRecall.

This Policy does not apply to third-party websites, applications, exchanges, brokers, trading platforms, file export tools, or other services that we do not control. Those third-party services may have their own terms and privacy policies.

4. Data we collect

We may collect and process the following categories of data.

4.1. Account and authentication data

When you create an account or sign in to the Service, we may process:

  • email address;
  • name or display name, if you provide it;
  • authentication data;
  • password hash or data required to sign in through a supported authentication method;
  • session data;
  • account settings;
  • account creation date;
  • account status;
  • technical and security events related to account sign-in and account use.

We do not store your password in plain text.

4.2. Trading data and journal data

When you use the trading journal, manual entry, or import features, we may process:

  • trade records;
  • symbols, instruments, markets, trade sides, prices, quantities, fees, and timestamps;
  • trading session data;
  • tags, notes, comments, mistake categories, playbooks, and review notes;
  • performance metrics, statistics, analytics, charts, and reports;
  • manually entered data;
  • data imported from CSV files;
  • staged import rows before final confirmation;
  • change history or audit trail, if such functionality is used in the Service.

You are responsible for ensuring that the data you enter or import is accurate, lawful, and belongs to you or is otherwise available to you for lawful use.

4.3. CSV files and imported data

If you upload a CSV file, we may process the file itself, its structure, column headers, preview data, selected column mappings, staged rows, import errors, and final records created after import confirmation.

CSV files may contain more information than EdgeRecall requires. Before uploading a file, you should review it and remove unnecessary personal, financial, confidential, or sensitive data if it is not needed for the Service.

CSV compatibility depends on supported columns and file formatting; not all broker or exchange exports are supported.

4.4. Attachments, screenshots, audio, and transcripts

If you upload or create materials in the Service, we may process:

  • screenshots;
  • images;
  • files and attachments;
  • voice notes;
  • audio recordings;
  • transcripts;
  • text notes;
  • materials related to trade reviews or trading behavior.

These data may be used for storage, previews, search, analysis, AI-assisted features, transcription, support, security, and troubleshooting.

Do not upload passwords, API keys, private keys, seed phrases, payment card data, identity documents, or other sensitive information unless it is required to use the Service.

4.5. AI data

When you use AI-assisted features, we may process:

  • prompts;
  • AI chat messages;
  • AI responses;
  • journal entries and trade narratives;
  • selected context needed to generate a response;
  • imported rows or trade records passed to an AI-assisted feature;
  • screenshots, attachments, audio, or transcripts if used in an AI-assisted feature;
  • AI request metadata;
  • feedback on AI responses;
  • embeddings or other technical representations of data, if used for search, journal memory, or relevant context.

AI-assisted features may be processed using third-party AI providers and infrastructure providers. We do not use private user content to train general-purpose AI models. Any optional use of private user content for additional model training or similar purposes would require a clear opt-in or another valid legal basis where permitted by applicable law.

AI outputs may be inaccurate or incomplete. They are not investment, financial, tax, legal, or professional advice.

4.6. Product telemetry, technical data, and logs

We may collect data about how the Service is used, including:

  • feature usage events;
  • import events;
  • diagnostic events;
  • error logs;
  • crash reports;
  • performance metrics;
  • IP address;
  • browser and device type;
  • operating system;
  • approximate location based on IP, if applicable;
  • date and time of actions;
  • referral source;
  • session identifiers;
  • authentication events;
  • security events.

These data help us operate the Service, detect errors, improve reliability, protect accounts, prevent abuse, and understand which features need improvement.

4.7. Cookies and similar technologies

We may use cookies, local storage, session storage, and similar technologies to:

  • sign you in and maintain your session;
  • support security;
  • remember settings;
  • operate core Service functionality;
  • perform product analytics;
  • diagnose issues and improve user experience.

Some cookies and similar technologies are necessary for the Service to work. For analytics cookies or other non-strictly necessary technologies, we will request consent or provide choices where required by applicable law.

Details may be described in a separate Cookie Policy.

4.8. Support and communication data

If you contact us, send a bug report, provide feedback, or submit a support request, we may process:

  • your email;
  • name or display name;
  • message content;
  • attachments you send;
  • technical information needed to resolve the issue;
  • support history;
  • request status and outcome.

4.9. Payment data, if paid features are introduced

The Service may currently be offered for free, in beta, or under limited access. If we introduce paid features, subscriptions, or purchases in the future, we may process data needed for payment, invoicing, taxes, payment confirmation, support, and payment error prevention.

Payments may be processed by third-party payment providers. We do not intend to store full payment card details on our own servers unless expressly stated in a separate policy or notice.

5. Data we do not require

EdgeRecall does not currently require or store user-created exchange or broker API keys.

EdgeRecall does not execute trades, custody assets, receive funds, withdraw funds, or act as a broker, exchange, custodian, financial adviser, or investment adviser.

You should not upload data that is not needed for the product, including passwords, private keys, seed phrases, payment cards, identity documents, or sensitive data belonging to third parties.

6. Sources of data

We receive data from the following sources:

  • directly from you when you create an account, enter data, upload files, or contact support;
  • from CSV files and other materials you upload;
  • from your actions in the Service;
  • from technical systems that operate, secure, and diagnose the Service;
  • from our service providers when they help us provide the Service;
  • from payment providers if paid features are introduced in the future.

7. How we use data

We use personal data for the following purposes.

7.1. Providing the Service

We process data to create and maintain your account, save trade records, perform CSV imports, display analytics, store attachments, create reviews, provide AI-assisted features, and operate core product functionality.

7.2. AI-assisted features and automated help

We process data to provide AI summaries, AI chat, journaling prompts, explanations, transcription, tagging suggestions, behavior analysis, and other AI-assisted features.

We may limit AI requests if they seek investment recommendations, violate applicable rules, or create unsafe use risks.

7.3. User support

We use data to answer questions, fix bugs, investigate issues, restore account access, and improve support quality.

7.4. Security and reliability

We use data to protect accounts, detect errors, investigate suspicious activity, prevent abuse, maintain Service availability, and protect system integrity.

7.5. Product analytics and Service improvement

We use telemetry, diagnostic events, error logs, and aggregated or de-identified data to understand how the product works, which features are used, where errors occur, and what should be improved.

We do not use private user content to train general-purpose AI models.

7.6. Communications

We may use your email to send service messages, security notifications, changes to terms or policies, support responses, and important product notices.

If we send marketing messages in the future, we will do so in accordance with applicable law and provide an unsubscribe option where required by law.

7.7. Legal and administrative purposes

We may use data to comply with applicable legal obligations, handle claims, protect rights, resolve disputes, keep internal records, and enforce our Terms of Use.

8. Legal bases for processing

If GDPR, UK GDPR, or similar data protection laws apply, we process personal data on the following legal bases:

  • performance of a contract - where processing is necessary to provide the Service, account, imports, analytics, AI-assisted features, data storage, or support;
  • legitimate interests - where processing is necessary for security, abuse prevention, diagnostics, product improvement, request handling, rights protection, or internal analytics, provided those interests are not overridden by your rights and freedoms;
  • consent - where consent is required by law, such as for certain cookies, analytics technologies, marketing messages, or optional features;
  • legal obligations - where processing is necessary to comply with law, respond to mandatory requests, or meet other legal requirements.

You may withdraw consent at any time where processing is based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

9. How we disclose data

We do not sell your private trading records.

We may disclose data to the following categories of recipients.

9.1. Infrastructure and service providers

We use Railway as a hosting and infrastructure provider for the Service.

We may also use a limited number of other service providers where necessary to operate specific Service features, such as authentication, file storage, AI-assisted features, transcription, email notifications, monitoring, analytics, support, or payments if paid features are introduced in the future.

These providers process data on our behalf and should use data only to provide the relevant services to us, unless otherwise permitted by applicable law, their terms, and this Policy.

If the list of key providers materially changes, we will update this Policy or provide an additional notice where required by applicable law.

9.2. Services you choose to use independently

If you visit a third-party website, use a third-party export tool, obtain a CSV file from a broker or exchange, or otherwise interact with a third-party service independently, that service processes your data under its own rules. We do not control those services.

9.3. Legal requirements and protection of rights

We may disclose data if we believe it is necessary to comply with applicable law, a court order, a mandatory request, protect our rights, protect user safety, investigate violations, or prevent harm.

9.4. Business transfers

If EdgeRecall is involved in a merger, acquisition, reorganization, sale of assets, financing, project transfer, or similar corporate transaction, data may be transferred as part of that transaction, subject to reasonable safeguards and applicable notices.

9.5. With your consent or at your direction

We may disclose data with your consent or at your direction, for example if you choose to use an export, sharing, or integration feature in the future.

10. AI providers and model training

Some AI-assisted features may be performed using third-party AI providers. In those cases, data needed for the request may be shared with the relevant provider for processing and response generation.

We aim to share only the context needed for the specific AI-assisted feature.

We do not use private user content to train general-purpose AI models. If an optional feature involving the use of private user content for additional model training or similar purposes is introduced in the future, that feature will require a clear opt-in or another valid legal basis where permitted by applicable law.

11. How long we keep data

We keep personal data no longer than necessary for the purposes described in this Policy, including providing the Service, maintaining your account, security, troubleshooting, complying with legal requirements, resolving disputes, and legitimate business needs.

As a general rule, the following retention periods apply unless a longer period is required by law, security needs, rights protection, dispute resolution, or abuse prevention:

  • account data is kept while your account is active. After account deletion, we delete or de-identify it from active systems within a reasonable period, usually within 30 days;
  • trade records, journal data, notes, reviews, tags, and analytics are kept while your account is active or until you delete the relevant data, if such functionality is available. After account deletion, they are usually deleted or de-identified from active systems within 30 days;
  • CSV files, staged import rows, and import errors are kept as long as needed to perform the import, verify results, provide support, and troubleshoot issues. If such data is not needed to preserve final journal records, we aim to delete or de-identify it within 30 days after import completion or account deletion;
  • attachments, screenshots, audio, and transcripts are kept while they are linked to your account or relevant journal entry. After account deletion, they are usually deleted from active systems within 30 days;
  • AI chats, prompts, AI responses, embeddings, and related AI data are kept as long as needed to provide AI-assisted features, history, search, security, support, and product reliability. After account deletion, they are usually deleted or de-identified from active systems within 30 days;
  • product telemetry, diagnostic data, and ordinary technical logs are usually kept for up to 12 months;
  • security logs and authentication events may be kept for up to 24 months where needed for security, incident investigation, and Service protection;
  • support messages are usually kept for up to 24 months after the request is closed, unless a longer period is needed for dispute resolution, security, or legal requirements;
  • backups may be kept for up to 90 days and deleted through normal backup cycles.

When data is no longer needed, we delete, de-identify, or anonymize it in accordance with our retention practices and applicable law.

12. Account deletion and data export

You may request account deletion or data export by emailing support@edgerecall.com. In the current version, account deletion and data export are handled through support.

After a deletion request, we will delete or de-identify personal data associated with your account, except for data we need to keep for legal requirements, security, abuse prevention, dispute resolution, backup retention, or other legitimate purposes.

Some data may remain in backups and logs for a limited period before deletion through normal backup cycles.

If you request data export, we will provide it in a reasonable format where technically feasible and required by applicable law.

13. Your rights

Depending on your jurisdiction, you may have the following rights regarding personal data:

  • the right to know what data we process and why;
  • the right to access personal data;
  • the right to correct inaccurate or incomplete data;
  • the right to delete data;
  • the right to restrict processing;
  • the right to object to processing;
  • the right to data portability;
  • the right to withdraw consent where processing is based on consent;
  • the right not to be subject to a decision based solely on automated processing if that decision has legal or similarly significant effects;
  • the right to lodge a complaint with a competent data protection authority.

To exercise your rights, contact us at support@edgerecall.com.

We may ask you to verify your identity before fulfilling a request. We will respond within the time required by applicable law. In some cases, we may deny a request or fulfill it only partially where permitted by law, such as due to legal obligations, security, protection of other people's rights, or technical limitations.

14. Automated processing and AI

EdgeRecall may use automated processing and AI-assisted features to create summaries, prompts, reviews, tags, transcripts, analytics, and other supporting outputs.

These features are intended to support journaling, analysis, and educational understanding of your own trading activity. They are not intended to make decisions for you and are not investment, financial, tax, legal, or professional advice.

We do not use AI-assisted features to make decisions that have legal or similarly significant effects on you without human involvement, unless expressly disclosed and permitted by applicable law.

15. Security

We use reasonable technical and organizational measures to protect personal data, including measures designed to protect accounts, systems, data, files, and communications.

However, no method of internet transmission or electronic storage is completely secure. We therefore cannot guarantee absolute security.

You are also responsible for securing your account, email, device, password, and any files you upload to the Service. Do not upload passwords, API keys, private keys, seed phrases, or other sensitive information unless it is required to use the Service.

If you believe your account or data has been compromised, contact us at support@edgerecall.com.

16. Privacy by default and future sharing

The Service is private by default. We do not publish your trade records, attachments, notes, AI chats, or analytics publicly without your action or permission.

If we add sharing features, public profiles, community features, or trade publication features in the future, we will provide additional settings, notices, or terms where needed. You should carefully review what data you choose to publish or share with others.

17. Children

The Service is not intended for people under 18. We do not knowingly collect personal data from children.

If you believe a child has provided us with personal data, contact us at support@edgerecall.com, and we will take reasonable steps to delete such data where required by applicable law.

18. Changes to this Policy

We may update this Policy from time to time. If changes are material, we will take reasonable steps to notify you, such as by email, in-app notice, or posting an updated version on the website.

The updated Policy becomes effective on the date stated in the updated version. Continuing to use the Service after the updated Policy becomes effective means you have reviewed the updated Policy.

19. Contact

If you have questions about this Policy, data processing, your rights, or security, contact us: