How TraderBalance handles your data

Draft, not a legally reviewed notice. This page is a product/engineering draft of what a privacy notice should cover. Health data is UK special-category personal data (spec section 10.1) — the lawful basis, Article 9 condition, DPIA and final wording must be confirmed by qualified legal/privacy counsel before this feature launches to real users. Do not treat this page as compliant as written.

General account data

TraderBalance stores the account, prop-firm, payout, expense and goal data you enter directly, tied to your account and protected by row-level access control — no other user can read it. This data is used solely to run the dashboard you see; it is not sold or shared with third parties.

Health data (Readiness feature)

If you connect a wearable health provider, TraderBalance imports the specific metric categories shown on the consent screen at the time you connect (for example: sleep duration, heart rate variability, resting heart rate, and a recovery score where the provider offers one). This data is used only to:

  • Calculate your daily Readiness score and its component breakdown.
  • Show your own trends over time.
  • Compare your own health patterns against your own trading records, once enough paired history exists.

Readiness and any correlation output are performance information, not medical or financial advice (see spec section 8). Provider access/refresh tokens are stored encrypted and separately from your profile data, never in plain text, logs, or analytics.

Your controls

From Settings → Health & Privacy you can disconnect your provider at any time, delete your imported health data (samples, daily summaries, readiness results, AI briefs and the trading data correlations are computed from), switch providers, and export a copy of your own health data as a downloadable file. Disconnecting stops new syncing immediately; it does not by itself delete data already imported — use the separate delete control for that.

Retention

TraderBalance does not currently enforce an automatic retention period on health data — it is kept until you delete it or your account is closed. Spec section 10.5 requires a configurable, approved retention duration before production launch; that duration has not yet been set (seesrc/lib/health/retention.tsfor the mechanism this will use once approved).

Questions

This is a development build. Production contact details for data-protection queries will be added once this feature is legally reviewed for launch.