Privacy Policy
Last updated: September 30, 2026
This Privacy Policy explains what information Bullia ("Bullia," "we," "us," or "our") collects when you use our trading journal service at bullia.net (the "Service"), how we use it, who we share it with, and the choices you have. By using the Service you agree to this policy.
1. Who we are
Bullia.net is a registered business operating under the laws of the State of Israel. We act as the data controller for the personal information described below. For privacy questions or to exercise your rights under applicable law (including GDPR for EU/EEA residents and CCPA for California residents), contact us at bullia.net@gmail.com.
2. Information we collect
2.1 Account information
- Email address and display name when you register with email and password.
- Profile data from Google (name, email, profile image) when you sign in with Google OAuth.
- A bcrypt hash of your password. We never store, log, or have access to plain-text passwords.
- Email verification timestamps and password change timestamps used to enforce session security (e.g. invalidating sessions after a password reset).
2.2 Broker connection data
- For SnapTrade-supported brokers (e.g. Robinhood, Coinbase): we store the SnapTrade user identifier and brokerage connection ID. SnapTrade itself holds the broker credentials; we never see them.
- For Interactive Brokers (IBKR): we store the IBKR Flex Query token encrypted at rest using AES-256-GCM with an environment-scoped key.
- For CSV imports: we store the parsed trade data, not the original file.
2.3 Trading data
Trade executions, positions, account snapshots, journal entries, strategy / setup definitions, and derived statistics. This is the core product data and is scoped strictly to your account.
2.4 Billing data
We use Cardcom for subscription billing. Your card details are entered and processed on Cardcom's hosted payment page, under their own PCI-DSS security controls — we never see, handle, or store your full card number. To enable recurring monthly charges, Cardcom returns a reusable payment token, which we store encrypted at rest (AES-256-GCM). Alongside it we keep only your card's last four digits and card brand, our own subscription and transaction identifiers, the charged amount and currency, your current tier, and your subscription status — never your full card number or bank details.
2.5 Operational data
- Email delivery metadata via Resend for transactional messages (verification, password reset, welcome).
- Error and performance telemetry via Sentry. Stack traces and request context may be recorded; we redact known sensitive fields (passwords, tokens, API keys).
- Rate-limit counters (Redis) keyed by user ID, IP, or email — used purely to prevent abuse and brute force.
- Standard server logs (request method, path, status, timing). These are retained short-term for debugging.
2.6 Cookies and Local Storage
We use browser-side storage strictly to make the Service work and to remember the interface choices you make yourself — never to track you across other websites. The four groups below are the complete list.
1. Essential authentication and security cookies. Issued by our authentication layer (Auth.js / NextAuth) and required for the Service to function — you cannot sign in or stay signed in without them:
- A session cookie holding your signed session token (JWT), which keeps you logged in and lets us validate your identity on every request.
- A CSRF token cookie that protects form and action submissions against cross-site request forgery.
- A sign-in callback cookie recording where to return you once authentication completes.
- Short-lived OAuth handshake cookies (state, PKCE verifier, and nonce) written only while a Google sign-in is in progress and discarded as soon as it finishes.
These are first-party cookies set on our own domain, marked httpOnly where applicable so page scripts cannot read them, and they expire when your session ends or sooner.
2. Functional preference cookies. First-party cookies that remember a choice you made in the interface. They contain no personal content and are never used for tracking or profiling:
- NEXT_LOCALE — the interface language you selected. Lifetime: up to 1 year.
- active_account — the broker account currently selected in the dashboard filter, so your choice survives page navigation and reloads. Lifetime: up to 30 days.
- dashboard_range, dashboard_from, and dashboard_to — the date range selected on the dashboard. Lifetime: up to 7 days.
3. Local Storage. A small set of interface preferences kept in your browser's Local Storage. This data stays on your device and is not transmitted to our servers:
- Your selected theme (dark or light).
- Which dashboard sections you have collapsed or expanded.
- Where you dragged the Toro chat button on the screen.
- Timing state for the data-enrichment reminder — how many visits have passed since the last prompt, and how long you asked us to wait before showing it again.
- Rendering state for the animated background on our public pages — which version of the background assets your browser already loaded or failed to play, so repeat visits render correctly and instantly.
4. Third-party TradingView widgets. Market-data widgets and price charts inside the logged-in dashboard — on the market data page, the trade detail page, and community pages — are embedded from TradingView and load inside iframes served by TradingView. Within those iframes TradingView may set its own cookies, and it receives standard technical request data — your IP address and browser user-agent — together with the market symbols being displayed. We do not send TradingView your account details, trading history, or any other personal data. TradingView's handling of what it receives is governed by TradingView's own privacy policy.
We do not use cookies, Local Storage, pixels, or any other browser-side mechanism for cross-site tracking, behavioral profiling, third-party advertising, or sale of data to ad networks. There are no advertising or marketing trackers on the Service. The TradingView embeds described above are functional market-data components, not advertising or analytics trackers.
3. How we use your information
- To provide, operate, and maintain the Service.
- To authenticate you, secure your account, and recover access (e.g. password reset, email verification).
- To sync, parse, and analyze your broker-imported trading data so that the journal, analytics, and statistics can function.
- To process subscription billing through Cardcom and to send transactional emails about your account or subscription.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
We do not sell your personal information. We do not use your trading data to train third-party AI models. We do not share your data with advertisers.
4. Service providers we share data with
- SnapTrade — broker OAuth and execution data sync.
- Interactive Brokers — only when you actively use your own Flex Query token; data flows from IBKR to us, not the other way.
- Yahoo Finance — historical price candles for the chart on a trade's page. Our server requests the instrument symbol, the candle interval, the session type, and calendar-aligned start/end bounds of a data block. Your account details, trade prices and stored entry/exit timestamps are not transmitted as fields.
- European Central Bank — the source of the euro foreign exchange reference rates we use for currency prices and conversions. A rate between two non-euro currencies is our own calculation from them, not an ECB figure. We send no account or trade details to obtain them.
- Cardcom — payment processing and recurring subscription charges (card details are entered on Cardcom's hosted page).
- Resend — outbound transactional email delivery.
- WhatsApp (Meta) — optional contact channel. A "chat on WhatsApp" button on our public pages opens a conversation with our business number. The button is a plain link: it loads no third-party script, and nothing is sent to Meta when the page loads. Clicking it, however, takes you to WhatsApp — a Meta service — so from that point Meta's own privacy policy governs, including anything Meta observes about your visit before you send a message. If you do message us, the conversation and the phone number you write from are processed by WhatsApp under that policy, and are visible to us in our WhatsApp Business account. Please do not send passwords, card details, or broker credentials over WhatsApp.
- Anthropic (Claude) — powers our optional AI features: the AI Coach and Toro, the in-app AI assistant that answers questions about your own trading. Both are available only to paying subscribers, are disabled by default, and send data to Anthropic only when you actively use them. When you do, we transmit only the slices needed to answer you — aggregated performance statistics, short summaries of recent trades, and brief excerpts of your own journal entries, trade notes, and tags — never your full history in bulk, and never another user's data. We access Anthropic exclusively through their Commercial API, which operates under a strict zero-data-retention policy for model training: requests and responses are not stored beyond what is required to serve the response, and they are not used to train, fine-tune, or improve Anthropic's public or shared models. Your private trading data and strategies are NEVER used to train public AI models.
- Sentry — error monitoring (with PII redaction).
- TradingView — embedded market-data widgets and price charts shown inside the dashboard. When you open those pages, TradingView receives your IP address, browser user-agent, and the market symbols displayed; it never receives your account details or trading history.
- Hosting and database providers (e.g. Vercel, managed Postgres) for the underlying infrastructure.
5. Data retention
We keep your account data for as long as your account exists. When you delete your account, we delete your trading data, journal entries, connected broker links, and authentication records within 30 days, except where we are required to retain records for legal, tax, or fraud-prevention purposes (e.g. Cardcom tax-invoice records).
Verification and password-reset tokens are short-lived (minutes to hours) and are deleted immediately on use or expiry.
6. Security
- HTTPS in transit; managed Postgres encryption at rest.
- Passwords stored as bcrypt hashes (cost factor 12).
- IBKR Flex tokens encrypted with AES-256-GCM before being written to the database.
- Sensitive verification tokens (password reset, email verification) stored as SHA-256 hashes — the raw token is only sent to your email.
- Per-IP and per-email rate limiting on authentication, password reset, and verification flows to mitigate brute force and abuse.
- Session invalidation on password change so a compromised session cannot survive a reset.
No method of electronic storage is 100% secure. If we become aware of a breach affecting your data, we will notify you and the appropriate regulators as required by law.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, port, restrict, or delete your personal information, and to object to certain processing. To exercise any of these rights, email bullia.net@gmail.com. We will respond within the timeframe required by applicable law (typically 30 days under GDPR).
EU/EEA residents have the right to lodge a complaint with their local data protection authority. California residents have the rights described in the CCPA, including the right not to be discriminated against for exercising them.
8. International data transfers
Our infrastructure providers may process data in the United States, the European Union, and other regions. Where data is transferred out of the EU/EEA, we rely on Standard Contractual Clauses or equivalent safeguards offered by those providers.
9. Children
The Service is not directed to anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18. This strict minimum age is required because the Service handles financial trading data and integrates with regulated broker APIs (including SnapTrade and Interactive Brokers), whose own terms and underlying brokerages restrict account ownership to legal adults. If you believe someone under 18 has provided us with personal information, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent substantive revision. For material changes, we will notify registered users by email or through an in-product notice.
11. Contact
For privacy questions, requests, or complaints, email us at bullia.net@gmail.com.
