Last updated: September 8, 2026
We collect the minimum information needed to give you a working trading journal:
The trades you import, the journal entries you write, your emotion logs, and your game / Academy scores are stored in Supabase (our cloud database). This data is tied to your account and is not shared with any third party. Row-level security policies at the database layer restrict every read to the authenticated owner — see the Security page for the exact policy shape.
You can export your full trade history at any time from Settings → Data Management → Export Backup or Export CSV.
Payments are processed by Whop. We do not store your credit-card number, billing address, or any payment credentials. Whop handles all payment data under their own privacy policy.
When you connect a brokerage from Settings, that connection is handled by SnapTrade — a licensed third-party aggregator that speaks each broker's API on our behalf. We chose SnapTrade so we never have to see or store your broker login credentials.
trades table under your account, indistinguishable from a trade you typed manually. user_secret per user that lets us call SnapTrade's API for that account — never exposed to your browser, never shared.SnapTrade's own privacy terms cover their handling of your broker session — see snaptrade.com/privacy.
Archive, not deletion. When you click "Clear All Data" from Settings, your account's data (trades, journal entries, emotion logs) is archived rather than immediately dropped. This matches how the app displays the control today ("nothing is ever permanently deleted") and protects you from an accidental one-click wipe. Archived data is retained for 30 days during which you can restore it from support.
Permanent deletion on request. If you want your account and its archived data permanently removed, email support@grabbovoi.com from the address on your account with the subject line Delete my account. We confirm the request, hard-delete every row tied to your user ID from Supabase (trades, journal entries, emotion logs, weekly analyses, user settings, sessions, ticker preferences, game progress, avatar upload, friend links, and the archived backups) within 30 days, and email you a confirmation. Whop billing records are retained separately by Whop for as long as their own retention policy requires.
We use browser storage for authentication, subscription state, and product preferences. The complete list of cookies we set + thelocalStorage categories we use is in Cookies & Local Storage. Highlights:
.grabbovoi.com. Sole purpose is to keep you signed in.localStorage keys prefixed grabbovoi_ holding your theme, watchlists (last 60 days), pre-market checklists (last 60 days), Academy progress (last 90 days), and legacy backup archive. None of this contains your trades, P&L, or balances — those live server-side.We do not use tracking cookies, advertising pixels, or third-party analytics networks that profile you across the web. See below for the two categories of server telemetry we do collect.
We ingest two narrow categories of server-side telemetry, both scoped so they cannot leak the trading data on your account:
/api/perf/vitals). The vitals reporter posts LCP / CLS / INP / TTFB / FCP numbers plus the current pathname (e.g. /dashboard). The ingest endpointstrictly rejects any payload that carries a Supabase user ID, a dollar figure, a P&L number, or a trade field. Data is used only to diagnose performance regressions in the app; retention 30 days; not shared with any third party./api/avatar/discord). When another user has opted into showing a Discord profile photo, our server fetches the image from cdn.discordapp.com on your behalf and re-serves it from our origin, so your browser never contacts Discord. Cached for 24 h at the edge. Only accepts well-formed Discord user IDs + avatar hashes.If you play the trading games, your screen name (which you choose in Settings — it need not be your real name) and game points may appear on the public leaderboard. No email address, trade data, P&L, or Discord username is exposed on the leaderboard.
Data is encrypted in transit (HTTPS) and at rest (Supabase encryption). Row- level security policies ensure you can only access your own data. API keys are stored server-side and never exposed to the browser. Full detail on the Security page.
The Service is not directed at anyone under 18. You must confirm you are 18 or older when you sign up. We do not knowingly collect data from minors — if we learn we've stored data for a minor, we delete it on request from a parent or legal guardian.
We may update this policy. Material changes will be reflected in the "Last updated" date at the top of this page. If you have an account, we will also email you before a material change takes effect.
For privacy-specific requests — data export, correction, deletion, or a question about anything on this page — email support@grabbovoi.com. Community Discord is not the right channel for a privacy request; the email address is, so we have a record.
Grabbovoi — Privacy