Last updated: 21 July 2026
This policy explains what personal data Edgewise collects, why we collect it, and what rights you have over it. We have tried to write it in plain English rather than legalese.
We collect as little as we can: your email address, a securely hashed password (we never see the real one), and the trading records you choose to save. We use them only to run Edgewise for you.
We do not sell your data. We do not advertise. We do not track you across the web. We do not use your trades to train AI models. You can export everything, or delete it all, from inside the app at any time.
[LEGAL ENTITY], of [BUSINESS ADDRESS], United Kingdom, is the “data controller” for the personal data described here. We are registered with the Information Commissioner's Office (registration number [ICO NUMBER]).
For any question about your data, or to exercise any of the rights in section 8, email [SUPPORT EMAIL].
Information you give us:
Information we collect automatically:
We do not use analytics or advertising trackers, and we do not build a profile of you.
| What we use | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Email & password hash | To create your account, sign you in, and let you reset your password | Performance of a contract |
| Your trading records | To store, display and analyse your journal — the core service you asked for | Performance of a contract |
| Payment details (via Stripe) | To take payment for a paid plan and prevent fraud | Performance of a contract; legal obligation |
| Security & technical logs | To keep accounts safe, and to detect and block brute-force and fraud attempts | Legitimate interests (security of the service and of our users) |
| Service emails | To tell you about outages, security matters, renewals, or changes to these policies | Performance of a contract; legitimate interests |
| Transaction records | To meet UK tax and accounting requirements | Legal obligation |
If we ever want to send you marketing emails, we will ask for your consent first, and you will be able to withdraw it at any time.
When you register or reset your password, we check whether that password has appeared in a known public data breach, and refuse it if it has. This protects your account.
We do this using the Have I Been Pwned Pwned Passwords service, and we do it in a way that never reveals your password. Only the first five characters of a one-way hash of it are ever sent; the service returns a list of possible matches, and the comparison happens on our own server. Your password, and the full hash of it, never leave Edgewise.
We do not sell your data or share it for marketing. We share it only with the service providers we need to run Edgewise, and only so far as they need it:
| Provider | What they do | What they see |
|---|---|---|
| Render | Hosts the application and database | Everything stored in Edgewise, as our hosting provider |
| Stripe | Processes payments (once we begin charging) | Your payment details and email — as their own data controller |
| Have I Been Pwned | Checks passwords against known breaches | Five characters of a hash. No password, no email, no identity — see section 4 |
We may also disclose data if the law requires it, or to establish, exercise or defend legal claims. If Edgewise is ever sold or transferred, your data may transfer with it, but your rights under this policy would be preserved.
Our hosting provider operates data centres in several countries, and your data may be processed outside the UK. Where that happens, it is protected by appropriate safeguards recognised under UK data protection law — such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
Your data is held on persistent storage that survives restarts, updates and deployments. As with any online service we cannot entirely rule out loss caused by a technical fault or provider outage, so we recommend exporting your journal from time to time to keep your own copy. See the beta note in our Terms of Service.
Under UK GDPR you have the right to:
Export: download everything — every account and every trade — as CSV or JSON, whenever you like, from the Analytics screen.
Erase: delete your account from within the app, and your journal is erased.
For anything else, email [SUPPORT EMAIL]. We will respond within one month, free of charge.
Edgewise uses one cookie, called tj_session. It keeps you signed in.
It is strictly necessary for the service to work, so it does not require a consent banner under the Privacy and Electronic Communications Regulations. It contains a signed token identifying your session — not your password. It is HttpOnly (scripts cannot read it), SameSite=Lax, and sent only over HTTPS. Logging out clears it.
We use no analytics, advertising or third-party tracking cookies of any kind.
No system is perfectly secure. If a breach ever occurs that puts your rights at risk, we will notify the ICO within 72 hours where required, and we will tell you.
Edgewise is not intended for anyone under 18, and we do not knowingly collect data about children. If you believe a child has given us data, contact us and we will delete it.
If we change this policy in a way that materially affects you, we will email you before it takes effect. The “last updated” date at the top always tells you when it last changed.
If you are unhappy with how we have handled your data, please tell us first at [SUPPORT EMAIL] — we would like the chance to put it right.
You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113.
Edgewise · Terms of Service · Back to Edgewise