Edgewise
← Back to Edgewise

Privacy Policy

Last updated: 21 July 2026

This policy explains what personal data Edgewise collects, why we collect it, and what rights you have over it. We have tried to write it in plain English rather than legalese.

The short version

We collect as little as we can: your email address, a securely hashed password (we never see the real one), and the trading records you choose to save. We use them only to run Edgewise for you.

We do not sell your data. We do not advertise. We do not track you across the web. We do not use your trades to train AI models. You can export everything, or delete it all, from inside the app at any time.

1. Who is responsible for your data

[LEGAL ENTITY], of [BUSINESS ADDRESS], United Kingdom, is the “data controller” for the personal data described here. We are registered with the Information Commissioner's Office (registration number [ICO NUMBER]).

For any question about your data, or to exercise any of the rights in section 8, email [SUPPORT EMAIL].

2. What we collect

Information you give us:

Information we collect automatically:

We do not use analytics or advertising trackers, and we do not build a profile of you.

3. Why we use it, and our lawful basis

What we useWhyLawful basis (UK GDPR)
Email & password hashTo create your account, sign you in, and let you reset your passwordPerformance of a contract
Your trading recordsTo store, display and analyse your journal — the core service you asked forPerformance of a contract
Payment details (via Stripe)To take payment for a paid plan and prevent fraudPerformance of a contract; legal obligation
Security & technical logsTo keep accounts safe, and to detect and block brute-force and fraud attemptsLegitimate interests (security of the service and of our users)
Service emailsTo tell you about outages, security matters, renewals, or changes to these policiesPerformance of a contract; legitimate interests
Transaction recordsTo meet UK tax and accounting requirementsLegal obligation

If we ever want to send you marketing emails, we will ask for your consent first, and you will be able to withdraw it at any time.

4. The password breach check

When you register or reset your password, we check whether that password has appeared in a known public data breach, and refuse it if it has. This protects your account.

We do this using the Have I Been Pwned Pwned Passwords service, and we do it in a way that never reveals your password. Only the first five characters of a one-way hash of it are ever sent; the service returns a list of possible matches, and the comparison happens on our own server. Your password, and the full hash of it, never leave Edgewise.

5. Who we share it with

We do not sell your data or share it for marketing. We share it only with the service providers we need to run Edgewise, and only so far as they need it:

ProviderWhat they doWhat they see
RenderHosts the application and databaseEverything stored in Edgewise, as our hosting provider
StripeProcesses payments (once we begin charging)Your payment details and email — as their own data controller
Have I Been PwnedChecks passwords against known breachesFive characters of a hash. No password, no email, no identity — see section 4

We may also disclose data if the law requires it, or to establish, exercise or defend legal claims. If Edgewise is ever sold or transferred, your data may transfer with it, but your rights under this policy would be preserved.

6. Where your data is stored

Our hosting provider operates data centres in several countries, and your data may be processed outside the UK. Where that happens, it is protected by appropriate safeguards recognised under UK data protection law — such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

7. How long we keep it

Your data is held on persistent storage that survives restarts, updates and deployments. As with any online service we cannot entirely rule out loss caused by a technical fault or provider outage, so we recommend exporting your journal from time to time to keep your own copy. See the beta note in our Terms of Service.

8. Your rights

Under UK GDPR you have the right to:

Two of these are built into the app

Export: download everything — every account and every trade — as CSV or JSON, whenever you like, from the Analytics screen.

Erase: delete your account from within the app, and your journal is erased.

For anything else, email [SUPPORT EMAIL]. We will respond within one month, free of charge.

9. Cookies

Edgewise uses one cookie, called tj_session. It keeps you signed in.

It is strictly necessary for the service to work, so it does not require a consent banner under the Privacy and Electronic Communications Regulations. It contains a signed token identifying your session — not your password. It is HttpOnly (scripts cannot read it), SameSite=Lax, and sent only over HTTPS. Logging out clears it.

We use no analytics, advertising or third-party tracking cookies of any kind.

10. How we protect your data

No system is perfectly secure. If a breach ever occurs that puts your rights at risk, we will notify the ICO within 72 hours where required, and we will tell you.

11. Children

Edgewise is not intended for anyone under 18, and we do not knowingly collect data about children. If you believe a child has given us data, contact us and we will delete it.

12. Changes to this policy

If we change this policy in a way that materially affects you, we will email you before it takes effect. The “last updated” date at the top always tells you when it last changed.

13. Complaints

If you are unhappy with how we have handled your data, please tell us first at [SUPPORT EMAIL] — we would like the chance to put it right.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113.


Edgewise · Terms of Service · Back to Edgewise