Privacy Policy

Last updated: 3 October 2026.

Ghanshyam Tech Trading Journal is a small, honest product. This page explains — in plain language — what we collect, what we use it for, and how you can delete it. It covers both the website and the Android app.

What we collect

  • Your account email and password. The password is stored as a bcrypt hash — we never store or see your plaintext password.
  • The trading-journal entries you type: trades, legs, notes and discipline scores.
  • Trade screenshots you optionally attach to a trade.
  • Your theme and language preferences.
  • On the website, a problem report you choose to send through Report an issue: your message, the page address you were on, your browser's name and version, your screen size, and any screenshots you add to it. A report sent while signed in is linked to your account. A report sent without an account carries an email address only if you choose to leave one.
  • On the website only: usage measurements and error reports, detailed under Analytics & error reporting. Neither carries your name, your email or your account identifier.

What we use it for

Running your journal and its analytics — win rate, expectancy, R-multiples, drawdown and the rest. A problem report is used to find and fix the problem you describe, and to answer you. On the website we also measure which pages are used and record technical errors, both described under Analytics & error reporting below. We never sell your data, never hand it to anyone to use for their own purposes, and never use it for advertising.

What we don't do

  • No tracking or analytics SDKs in the Android app at all.
  • No advertising trackers, and no cross-site profiling, anywhere.
  • No ads.
  • No data brokers.

Where it lives

Your data lives on our own server and in private object storage. Screenshots are never publicly accessible — the app server checks who you are on every single request before returning one. That holds for a screenshot on a problem report too: only you and the site's administrator can open it.

Third-party embeds

Course videos are embedded from YouTube in privacy-enhanced (youtube-nocookie) mode, which limits the cookies YouTube can set until you press play; YouTube's own privacy policy applies when you play one. News articles may link out to their original source — visiting that link is subject to that site's own policy.

Analytics & error reporting on the website

The website uses two third-party services. Neither is used in the Android app.

  • Google Analytics 4 — measures which pages and calculators are used, so we know what to improve. It runs only when you are signed out. The moment you sign in it is not loaded at all, so no page of your journal is ever seen by it. While signed out it sets cookies, and receives the page address, a randomly generated visitor identifier, and coarse device and location data. IP addresses are anonymised. We never send it your email, your account identifier, or anything you type into the journal or a calculator.
  • Sentry — records technical details when something breaks on the server, so we can fix it. It receives the error, the URL and a stack trace. Cookies, authentication headers, request bodies and any email-like field are stripped before the report is sent; a technical header such as the browser version is kept so the error can be diagnosed.

Both are processors: they handle this data on our behalf and under their own privacy policies. Your journal contents — trades, notes and screenshots — are never sent to either of them.

Cookies & tokens

On the web, a session cookie keeps you signed in — that's its only purpose. While you are signed out, Google Analytics additionally sets its own cookies, as described above; they are used to count visits and sessions, not for advertising. The Android app doesn't use cookies at all; it uses a revocable access token instead.

Data deletion

You can delete your account any time, and it takes effect immediately and permanently:

Your trades, screenshots, problem reports and sign-in tokens are removed outright. Audit-log rows that reference your account are anonymized rather than deleted outright (kept only for security / abuse investigation) — your email and every other identifying detail are stripped from them, so no personal data is retained.

A problem report sent without an account is removed with your account only if it carries your account's email address. Any other is not tied to anyone we can identify: to have one deleted, email us its number (it is shown when the report is sent) and we will remove it.

Contact

Questions about this policy or your data? Email ghanshyamtech@hotmail.com.