🎉 Get 30% off your first month — use code WELCOME30 at checkout.

Privacy Policy

Last updated: February 14, 2026

1. Introduction

TradeFlow AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our educational AI data analytics platform.

We are GDPR and KVKK compliant and follow industry best practices for data protection.

2. Information We Collect

2.1 Account Information

When you register, we collect:

  • Email address
  • Full name
  • Encrypted password (bcrypt hashed)
  • Subscription plan type

2.2 Usage Data

We automatically collect:

  • Number of analyses performed
  • Timestamp of platform usage
  • Browser type and version
  • Device information (non-identifying)

2.3 Payment Information

Payment processing is handled by third-party processors (Paddle/Stripe). We do NOT store your credit card details. We only receive:

  • Payment confirmation status
  • Transaction ID (for refund purposes)
  • Subscription status

2.4 Uploaded Chart Data

IMPORTANT: Uploaded charts are processed instantly by our AI and immediately deleted. We do NOT store your research data or chart images permanently.

3. How We Use Your Information

We use collected data to:

  • Provide and improve our AI analytics service
  • Manage your account and subscription
  • Process payments and send receipts
  • Send service updates and important notices
  • Monitor platform usage and prevent abuse
  • Comply with legal obligations

We do NOT use your data for advertising or sell it to third parties.

4. Data Security

We protect your data using:

  • HTTPS/TLS encryption for all data transmission
  • Bcrypt password hashing (passwords never stored in plain text)
  • Secure hosting on Vercel (frontend) and Railway (backend)
  • Database encryption for stored user data
  • Regular security audits and updates
  • Limited employee access to personal data

5. Third-Party Sharing

We share data only with:

5.1 Payment Processors

Paddle/Stripe process payments securely. They have their own privacy policies.

5.2 AI Service Provider

Google Gemini API processes uploaded charts. Charts are sent anonymously(no user identification) and Google does not store them per their API terms.

5.3 Analytics

We may use privacy-friendly analytics (e.g., Plausible) to understand platform usage. No personal data is shared.

5.4 Legal Requirements

We may disclose data if required by law, court order, or to protect our rights.

6. Your Rights (GDPR/KVKK)

You have the right to:

  • Access: Request a copy of your data
  • Correction: Update inaccurate information
  • Deletion: Request account and data deletion
  • Portability: Export your data in machine-readable format
  • Withdraw consent: Opt-out of marketing emails
  • Object: Object to certain data processing activities

To exercise these rights, contact privacy@tradeflowai.cloud

7. Data Retention

We retain data as follows:

  • Account data: Until you request deletion (+ 30 days grace period)
  • Payment records: 7 years (legal requirement for tax purposes)
  • Uploaded charts: Immediately deleted after analysis (NOT stored)
  • Usage logs: 90 days for security monitoring

8. Cookies

We use essential cookies for authentication and session management only. No third-party tracking cookies are used.

9. International Transfers

Data is stored on servers in the EU/US (Railway/Vercel). We ensure GDPR-compliant data transfer mechanisms are in place.

10. Children's Privacy

TradeFlow AI is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted with a new "Last updated" date. Continued use constitutes acceptance.

12. Contact Us

For privacy questions or to exercise your rights:

Email: privacy@tradeflowai.cloud

Website: tradeflowai.cloud