Privacy Policy

Last updated: August 6, 2026

Your privacy comes first. This policy explains what data Trader Leap collects, how we use it, and your rights as a data subject.

Who processes your data

Trader Leap is operated by the company below, which acts as the controller of your personal data under Brazil's data protection law (LGPD, Law 13.709/2018):

Fta Software Ltda · CNPJ 45.813.274/0001-38
Rua José Licínio Lopes, 1241, Centro, Florianópolis/SC, CEP 88.070-780

Data we collect

During pre-registration we collect your email and password (stored as a secure hash by our authentication provider, never in plain text) and a record of your consent to this Policy and the Terms, with its date and version. If you sign in with Google, we receive your email and profile name. Once you use the product, we also process the trading data you record or import.

How we use it and our legal basis

We process your data to run the service: create and authenticate your account, send transactional emails (confirmation, sign-in, and password recovery), and, inside the product, compute and show your metrics. The legal basis is the performance of preliminary procedures and of the contract at your request (art. 7 V and X of the LGPD). Access-release notices, such as the email that opens the product for you, rely on the consent you give when signing up (art. 7 I) and can be withdrawn at any time. Access logs and platform protection measures rest on our legitimate interest in keeping the service secure (art. 7 IX). Analytics on this site work differently: nothing is loaded or stored until you agree, so the basis for that is your consent (art. 7 I), which you can withdraw at any time.

Who we share it with

We do not sell your data. We share only what is needed with processors that support the service: Supabase (authentication and database), Resend (email delivery), Vercel (hosting and aggregate audience metrics), and PostHog (usage analytics and error monitoring). Once plan billing is active, Stripe will process payments and receive only the data needed for that. Each one processes the data solely to provide these services on our behalf, and you can ask us for the list of who your data was shared with.

Usage analytics and error monitoring

Inside the app we use PostHog, hosted in the European Union, for two things: counting a handful of product events (account created, trade logged, import finished, review closed, checkout started) and receiving the errors that break a screen or a request. Each event is tied to your account id and nothing else: we do not send your email, your name, a symbol, an amount, a note, or an account name, and page addresses travel without their query string, which is where your journal's filters live. There is no session recording and no automatic click capture. Importing a file is the one place we record text from the file itself: its column names, never its rows, so we can tell which broker formats we read badly. Those names usually come from your broker; if you renamed a column, your name for it travels with them. PostHog can work out an approximate location from an IP address, and we tell it not to, on this site and in the app: no country, no city, no postal code, no coordinates. In the app and on this site we also record how long each page stayed open, and only here how quickly the pages loaded; both measure the page, not you. PostHog sets its own cookie in your browser to keep that id across pages. On this site PostHog only runs if you agree to it: it stores nothing and sends nothing until you answer, and no event carries a name, an email, or anything else that says who you are. Of the query string, only campaign parameters (utm_*) travel with the address: they are what shows which ad or link brought you here. You can change that answer at any time from the Cookies control in the footer. On this site and in the app we also use Vercel Web Analytics, which counts visits in aggregate, without cookies and without identifying you.

International transfer

Your account data lives in Supabase, in a region in Brazil (São Paulo). Other processors handle data outside Brazil: PostHog in the European Union, and Resend, Vercel and, once billing is active, Stripe in the United States. Where an international transfer occurs, it is carried out with the safeguards required by the LGPD (art. 33).

How long we keep it

We keep your data while your account exists. You can delete your account and its data directly in the app, at any time. The usage events and error records described above follow the same rule: deleting your account also asks PostHog to erase your profile and every event tied to it. Inactive pre-signups are removed after 24 months. Analytics on this site sit outside that rule, because those events belong to no account: they carry a random id kept in your browser and nothing else about you. We keep those events in PostHog for 7 years. Withdrawing your consent deletes that id and stops the collection; what was already recorded stays in the totals until those 7 years are up, with nothing tying those numbers to you. Consent records and backup copies may be kept for an additional period to meet legal obligations.

Your rights

You can confirm processing; access your data; correct incomplete or outdated data; request anonymization, blocking, or deletion; request portability; learn who we shared your data with; withdraw consent; and object to processing, within the limits of art. 18 of the LGPD. Trader Leap is run from Brazil, so the LGPD is the law that governs it, and its protections mirror what the GDPR grants: access, correction, deletion, portability, and the right to withdraw consent. Wherever you live, you exercise them through the contacts at the end of this page. Some rights have legal conditions, and we will tell you the consequences of any refusal. You may also file a complaint with the Brazilian data protection authority, the ANPD (gov.br/anpd). Consumer-protection law where you live may grant you further rights, and nothing in this Policy limits them.

Security and cookies

We apply technical and organizational measures to protect your data, such as encryption in transit and per-user access control. The cookies we use are there to make the product work: in the app, the session cookies that keep you signed in, your language, theme, and time-zone preferences, and a couple of interface details (whether the sidebar is collapsed, which release notes you have already seen); on this site, at most the language preference. To those add the PostHog cookie described above, which holds only your account id. On this site PostHog sets no cookie at all: its id lives in your browser's local storage, and only once you have agreed to analytics. Nobody signs in here, so that id belongs to no account. If you refuse, nothing is stored; if you agree and change your mind later, the collection stops and the id is deleted. Your answer is kept in local storage too, so it is never sent to our server. We do not use advertising cookies and we do not hand data to ad networks.

Minors

Trader Leap is intended for people aged 18 or over. We do not knowingly collect data from minors; if we identify an account created by a minor, we will remove it.

Changes to this policy

We may update this Policy. When a change is significant, we will note it on this page, revise the update date, and, where the law requires, ask for new consent.

Get in touch

For questions about this Policy or to exercise your rights, email contact@traderleap.com.

Our data protection officer (encarregado) can be reached at contact@traderleap.com.