TraderControl

Privacy Policy

TraderControl

Operated by JW Apps Ltd

Last updated: 19 May 2026 · Version 4

1. Introduction

JW Apps Ltd (“we”, “our”, or “us”), a company registered in England and Wales, operates the TraderControl mobile application (the “App”). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the App, and what rights you have.

We handle personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (“PECR”).

By using TraderControl you acknowledge that you have read and understood this Privacy Policy. If you do not agree with how we handle your data, please do not use the App.

2. Who We Are

For the purposes of UK data protection law, the data controller is:

3. What Data We Collect

3.1 Data you provide directly within the App

When you use the App you may enter information including:

  • your trading experience level and the focus areas you select;
  • your trading days and session start and end times;
  • trade setup details, such as a name, asset class, and risk parameters;
  • your daily check-in responses and the goals you set;
  • preferences such as currency symbol, time format, and notification settings.

This information is self-reported by you and, as explained in section 5, is stored on your device.

3.2 Data we receive if you sign in with Google

Signing in is optional — the App can be used on the free tier without signing in. If you choose to sign in using your Google account, we receive from Google your name, email address, and the URL of your Google profile photo. We use a Google authentication token solely to verify your identity with our authentication provider (Supabase). We request only the basic “profile” and “email” permissions from Google. Your Google name, email address, and profile photo URL are stored on your device; the profile photo itself is displayed from Google's servers and is not separately stored by us.

3.3 Data collected automatically

When you first open the App, an identifier is generated to distinguish your installation. This identifier does not contain your name or email address, but because it is persistent and linked to your activity we treat it as personal data (a pseudonymous identifier). If you later sign in with Google, this identifier becomes linked to your Google account and can then identify you.

If you give your consent (see section 4), we and our analytics and measurement providers also collect: app usage events; your device type, operating system version, and app version; a device or advertising identifier; your IP address; and crash reports and error logs. Where you do not give consent, these are not collected.

3.4 Data we do not collect

We do not collect:

  • your real name, email address, or profile photo, unless you choose to sign in with Google (section 3.2) or you contact us directly;
  • any financial account information, broker or exchange credentials, or trading profit and loss figures;
  • your payment card details, which are handled entirely by the Google Play Store or Apple App Store;
  • your precise location.

3.5 Focus feature data

The Focus feature provides guided breathwork sessions. We do not collect any health data, biometric data, or recordings from these sessions. If you have consented to analytics, a single event is recorded when you complete or exit a Focus session, indicating the session type (for example, pre-trade or mid-trade) and whether it was completed; this is used only to generate in-app insights and is not shared with our advertising provider. Records of completed Focus sessions are otherwise stored only on your device. The Focus feature is a mindfulness and emotional-regulation tool only and is not medical advice or treatment; please see the Terms of Service for important health information.

4. How We Use Your Data and Our Lawful Basis

We use your data only for the purposes set out below, and we rely on the following lawful bases under the UK GDPR:

Performance of a contract (Article 6(1)(b)) — to provide and operate the App's core features, to create and maintain your account where you sign in, to calculate your process scores, streaks, and statistics, and to manage your subscription through our provider RevenueCat.

Consent (Article 6(1)(a)) — for optional push notifications, and for analytics and advertising/measurement (Mixpanel and the Meta SDK). Before any analytics or measurement data is collected, the App asks for your consent through a consent screen, and these tools are activated only if you agree. You can change your choice at any time in Settings → Support → Analytics & Measurement. Where storing or accessing information on your device is involved, we rely on your consent as required by PECR.

Legitimate interests (Article 6(1)(f)) — to respond to support enquiries you send us, and to protect the security and integrity of the App. Our legitimate interest is operating a secure, functioning App and assisting our users; we have considered your interests and rights and consider this use proportionate. You may object to processing based on legitimate interests (see section 8).

Legal obligation (Article 6(1)(c)) — to keep records, including subscription and transaction records, where the law requires us to do so.

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you. The scores and statistics in the App are tools for your own reflection and have no such effect.

5. Data Storage and Security

Most of your data — including your trade setups, check-in history, goals, preferences, and Focus session records — is stored only locally on your device, using the device's app storage. We do not back this data up to the cloud, and automatic operating-system backup of the App's data is disabled.

Important: because this data is stored only on your device, if you delete the App or lose, reset, or replace your device, the data will be permanently lost and cannot be recovered by us.

A pseudonymous identifier, and — if you sign in with Google — your account identity, are stored with our authentication provider Supabase, on infrastructure hosted in Ireland (the eu-west-1 region) within the European Economic Area. The authentication token used to keep you signed in is held in your device's secure, operating-system-protected storage (the Keychain on iOS, the Keystore on Android).

All data transmitted between the App and our service providers is encrypted in transit using HTTPS/TLS. The local App database on your device is stored within the App's sandboxed storage, which is protected by your device's operating-system security, but is not separately encrypted by the App; you should keep your device itself secured with a passcode or biometric lock.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office, and you where required, in accordance with our legal obligations.

Retention periods

  • Data stored locally on your device: Retained on your device until you delete it within the App or delete the App.
  • Pseudonymous / account identifier (Supabase): Deleted 12 months after your last use of the App, or sooner if you request account deletion.
  • Analytics data (Mixpanel): Retained for 12 months, then deleted or aggregated.
  • Subscription / transaction records (RevenueCat): Retained for 6 years after the end of the relevant tax year, to meet accounting and tax record-keeping obligations.
  • Support correspondence: Retained for up to 24 months after your enquiry is resolved.

You can request earlier deletion at any time — see section 8.

6. Third-Party Service Providers

We use the following third-party services. Each acts as our processor or, where indicated, as a separate controller, and each has its own privacy policy governing its handling of data. We are not responsible for the content of third-party privacy policies, and we encourage you to read them.

  • Supabase — authentication and storage of the pseudonymous/account identifier; hosted in Ireland (EEA). Privacy policy: supabase.com/privacy.
  • RevenueCat — management of subscriptions and transaction records. Privacy policy: revenuecat.com/privacy.
  • Mixpanel — product analytics, used only with your consent. Privacy policy: mixpanel.com/legal/privacy-policy.
  • Meta Platforms (the Meta SDK) — advertising attribution and conversion measurement (for example, app installs, registrations, trial starts, and subscriptions), used only with your consent. The Meta SDK may collect a device or advertising identifier and your IP address. Privacy policy: facebook.com/privacy/policy.
  • Google Play Store / Apple App Store — app distribution and payment processing. We never receive your payment card details.
  • Expo / EAS — the platform used to build and distribute the App. This is part of our development and release process and does not receive your personal data in normal use of the App.

We do not sell your personal data, and we do not share it with third parties except as described in this Privacy Policy.

7. International Data Transfers

Supabase hosts the data described above in Ireland, within the European Economic Area, so that data is not transferred outside the UK or EEA.

Mixpanel and Meta Platforms are headquartered in the United States, and Expo/EAS is US-based. Where personal data is transferred to the United States or another country outside the UK, we rely on a transfer mechanism recognised under UK GDPR — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified — together with any additional safeguards required. Because Mixpanel and the Meta SDK operate only with your consent, no such transfer occurs unless you have consented to those tools.

8. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

  • the right to be informed about how we use your data (which this Policy provides);
  • the right of access to the personal data we hold about you;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure of your data;
  • the right to restrict processing in certain circumstances;
  • the right to data portability;
  • the right to object to processing based on our legitimate interests; and
  • the right to withdraw consent at any time, where we rely on consent (for example, for analytics, measurement, or notifications), which you can do in Settings → Support → Analytics & Measurement, or in your device settings for notifications.

How to exercise your rights. Most of your data is stored only on your own device. You can rectify or erase that data directly within the App, and erase all of it by deleting the App. For data held by us or our providers, you can use the “Delete Account & Data” option in the App's Account settings, or contact us at support@tradercontrol.app. We do not currently offer an in-app data export feature; if you wish to exercise your right of access or portability for data held by us, please contact us and we will assist you.

We will respond to a rights request within one month. We may extend this by up to a further two months for complex or numerous requests, and will tell you if we need to do so. We may need to verify your identity before acting on a request. Exercising these rights is normally free of charge.

If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113, and you may also seek a remedy through the courts. ICO Registration Number: ZC104090.

9. Children's Privacy

TraderControl is intended solely for adults aged 18 or over. The App is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe that a person under 18 has provided us with personal data, please contact us at support@tradercontrol.app and we will take steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated Policy within the App and update the “Last updated” date. Where a change is significant, we will take reasonable steps to bring it to your attention.

11. Contact Us

If you have any questions about this Privacy Policy or your personal data, please contact us: