Privacy Policy

WillTrade is a read-only trade analytics platform. Your trade records, exchange API credentials, and computed analytics remain under your control. WillTrade does not collect behavioral telemetry, sell your data, or share it with advertising or analytics third parties.

Data We Process

WillTrade processes the following categories of data to provide the service: your account information (email address, display name), workspace and membership records, exchange API keys and secrets you choose to store, trade history fetched from connected sources or uploaded via CSV, and the analytics computed from that history (P&L, volume, win rate, and breakdowns). Your locale preference is stored as a cookie and, when you are signed in, in your account preferences.

API Credentials & Key Handling

Exchange API keys and secrets are encrypted at rest using AES-256-GCM encryption. Credentials are stored server-side only and are never transmitted to the browser or included in client bundles. We strongly recommend using read-only API keys scoped to trade-history access. You can review, rotate, or revoke stored credentials at any time from your source settings.

Read-Only Access

WillTrade is strictly read-only. It reads trade history to compute analytics and never executes orders, places trades, withdraws, or moves your assets. Connecting a source never grants WillTrade the ability to act on your exchange account beyond reading data.

Security Posture

All traffic is served over HTTPS. Authentication relies on a single httpOnly session cookie. Credentials are encrypted with AES-256-GCM and API access is rate-limited to protect against abuse. No client-side tracking scripts, advertising pixels, or third-party analytics are included on authenticated or public pages.

Data Retention & Deletion

Your trade data, computed analytics, and stored credentials are retained for as long as your workspace is active. You can delete individual sources to remove their credentials and fetched trades, or delete your workspace to remove its associated data. Deleting your account removes your personal information and workspace membership.

Data Export

You can export the trade records that you imported or synced at any time. Because WillTrade stores the history it reads, you always retain a copy of the data used to compute your analytics.

Cookies & Locale

WillTrade uses a single session cookie for authentication and a locale cookie (willtrade:locale) to remember your language preference. No tracking cookies, analytics scripts, or advertising pixels are included. Your language preference is also synced to your account when you are signed in.

Integrations

When you connect an exchange account, you authorize WillTrade to read trade history through that provider's API using the credentials you provide. WillTrade interacts with connected providers only to fetch trade data on demand. Each provider is a separate third party with its own terms; your relationship with your exchange remains independent of WillTrade.

Your Choices

You can add or remove sources, rotate or revoke API keys, switch between English and Spanish at any time, and export or delete your data. These controls are available in your dashboard settings.