Privacy Policy
Last updated: July 26, 2026
Your privacy comes first. This policy explains what data Trader Leap collects, how we use it, and your rights as a data subject.
Who processes your data
Trader Leap is operated by the company below, which acts as the controller of your personal data under Brazil's data protection law (LGPD, Law 13.709/2018):
Fta Software Ltda · CNPJ 45.813.274/0001-38
Rua José Licínio Lopes, 1241, Centro, Florianópolis/SC, CEP 88.070-780
Data we collect
During pre-registration we collect your email and password (stored as a secure hash by our authentication provider, never in plain text) and a record of your consent to this Policy and the Terms, with its date and version. If you sign in with Google, we receive your email and profile name. Once you use the product, we also process the trading data you record or import.
How we use it and our legal basis
We process your data to run the service: create and authenticate your account, send transactional emails (confirmation, sign-in, and password recovery), and, inside the product, compute and show your metrics. The legal basis is the performance of preliminary procedures and of the contract at your request (art. 7 V and X of the LGPD). Access-release notices, such as the email that opens the product for you, rely on the consent you give when signing up (art. 7 I) and can be withdrawn at any time. Access logs and platform protection measures rest on our legitimate interest in keeping the service secure (art. 7 IX).
Who we share it with
We do not sell your data. We share only what is needed with processors that support the service: Supabase (authentication and database), Resend (email delivery), Vercel (hosting and aggregate audience metrics), and PostHog (usage analytics and error monitoring). Once plan billing is active, Stripe will process payments and receive only the data needed for that. Each one processes the data solely to provide these services on our behalf, and you can ask us for the list of who your data was shared with.
Usage analytics and error monitoring
Inside the app we use PostHog, hosted in the European Union, for two things: counting a handful of product events (account created, trade logged, import finished, review closed, checkout started) and receiving the errors that break a screen or a request. Each event is tied to your account id and nothing else: we do not send your email, your name, a symbol, an amount, a note, or an account name, and page addresses travel without their query string, which is where your journal's filters live. There is no session recording and no automatic click capture. PostHog sets its own cookie in your browser to keep that id across pages. On this site and in the app we also use Vercel Web Analytics, which counts visits in aggregate, without cookies and without identifying you.
International transfer
Your account data lives in Supabase, in a region in Brazil (São Paulo). Other processors handle data outside Brazil: PostHog in the European Union, and Resend, Vercel and — once billing is active — Stripe in the United States. Where an international transfer occurs, it is carried out with the safeguards required by the LGPD (art. 33).
How long we keep it
We keep your data while your account exists. You can delete your account and its data directly in the app, at any time. The usage events and error records described above follow the same rule: deleting your account also asks PostHog to erase your profile and every event tied to it. Inactive pre-signups are removed after 24 months. Consent records and backup copies may be kept for an additional period to meet legal obligations.
Your rights
You can confirm processing; access your data; correct incomplete or outdated data; request anonymization, blocking, or deletion; request portability; learn who we shared your data with; withdraw consent; and object to processing, within the limits of art. 18 of the LGPD. Trader Leap is run from Brazil, so the LGPD is the law that governs it, and its protections mirror what the GDPR grants: access, correction, deletion, portability, and the right to withdraw consent. Wherever you live, you exercise them through the contacts at the end of this page. Some rights have legal conditions, and we will tell you the consequences of any refusal. You may also file a complaint with the Brazilian data protection authority, the ANPD (gov.br/anpd). Consumer-protection law where you live may grant you further rights, and nothing in this Policy limits them.
Security and cookies
We apply technical and organizational measures to protect your data, such as encryption in transit and per-user access control. The cookies we use are there to make the product work: in the app, the session cookies that keep you signed in, your language, theme, and time-zone preferences, and a couple of interface details (whether the sidebar is collapsed, which release notes you have already seen); on this site, at most the language preference. To those add the PostHog cookie described above, which holds only your account id. We do not use advertising cookies and we do not hand data to ad networks.
Minors
Trader Leap is intended for people aged 18 or over. We do not knowingly collect data from minors; if we identify an account created by a minor, we will remove it.
Changes to this policy
We may update this Policy. When a change is significant, we will note it on this page, revise the update date, and, where the law requires, ask for new consent.
Get in touch
For questions about this Policy or to exercise your rights, email contact@traderleap.com.
Our data protection officer (encarregado) can be reached at contact@traderleap.com.