Privacy Policy
Vaultlog: a manual trade journal for options traders
Last updated: October 7, 2026
Overview
This policy explains what data the Vaultlog app and the Vaultlog web app at app.vaultlog.site ("Vaultlog", "we", "us") collect, how it is used, who processes it for us, and the choices you have. Vaultlog is operated by Gyngergod. Contact: team@vaultlog.site.
Data we collect
Trade and journal data you enter
Vaultlog stores what you enter manually:
- Trades: ticker, trade type, long/short direction, open and close dates, strike, expiration, prices, size, risk amount, and P/L
- Notes, strategy notes, emotion, and risk-taken fields
- Tags, journals (name and starting balance), deposits and withdrawals, goals, and rules
Vaultlog does not connect to brokerages or pull trade data automatically.
CSV imports
- When you import a broker CSV file, the file is read and parsed on your device.
- Only the resulting trades are saved to your account, the same way as manually entered trades.
- Saved CSV column formats stay on your device.
Account data
- Vaultlog requires an account. We collect your email address and a password to create and secure it.
- Passwords are handled by our authentication provider (Supabase Auth) and are stored only in hashed form. We never see your password.
- We also store whether your account has Vaultlog Pro.
- Our authentication provider sends account emails such as sign-up confirmation and password reset.
Purchases
- Vaultlog Pro is a one-time purchase made through the Apple App Store or Google Play. We never receive your payment card or billing details.
- To unlock Pro, the app sends the store's proof of purchase (transaction ID / purchase token) to our server, which checks it with Apple or Google.
- We may keep a record of the purchase so it can't be used to unlock Pro on more than one Vaultlog account. The record holds the store, product, transaction or order ID, purchase date, and whether it was a test purchase.
Data stored only on your device
- A local copy of your data, encrypted with a key kept in your device's secure storage (iOS Keychain / Android Keystore).
- Your App Lock PIN, if you set one, kept in secure storage on your device.
- If you unlock with Face ID, Touch ID, or fingerprint, your device's operating system handles it. We never receive biometric data.
- If the app crashes, a short error report is shown on your device. From version 1.1, a crash report is also sent to our diagnostics provider (see "Service providers" below).
- On the web app, your browser keeps your sign-in session and a few settings (such as your active journal, theme, and saved CSV column formats) in its local storage. The web app does not keep an offline copy of your journal; it loads your data from your account each time.
App usage and diagnostics: see "Service providers" below.
How we use your data
- To provide the app: display your trades, journals, statistics, goals, and calendar
- To sync your data across your devices
- To verify purchases and unlock Vaultlog Pro
- To send account emails (confirmation and password reset)
- To keep the app secure and to find and fix crashes and performance problems
We do not sell or rent your data. We do not share it with third parties except the service providers below, who process it on our behalf. Vaultlog shows no ads, does not use your data for advertising, and does not track you across other companies' apps or websites.
Service providers
- Supabase: hosts our database, account sign-in, and server functions. Your account and trade data are stored here.
- Netlify: hosts this website and the web app. When you visit them, Netlify receives standard web request data such as your IP address and browser type.
- Apple and Google: distribute the app and process purchases under their own privacy policies.
- Expo (650 Industries, Inc.): delivers app updates and provides app analytics and diagnostics for us. Data sent to Expo is tied to a random identifier created when the app is installed. That identifier resets if you reinstall, and it is not linked to your email or Vaultlog account.
- App updates: when the app checks for an update, it sends the random install ID, platform, and app version.
- App launch statistics: each launch sends the random install ID, app version, platform (iOS/Android), and operating-system version.
- Crash and performance diagnostics (applies from version 1.1): device model, OS and version, app version, and approximate country; app startup and screen timings, frame rate, memory, battery and power state, and network type; the number, size, duration, and failures of network requests during startup, and the name of the slowest server contacted; screen names (with sign-in tokens and your own text, such as tag names, removed); and crash reports and error messages with technical stack traces — error text can occasionally include app data that was on screen when the error happened.
Providers may also receive your IP address as part of normal internet traffic when the app or web app talks to them.
Data storage and security
Your account and trade data are stored with Supabase and encrypted in transit and at rest. Database access rules limit each signed-in account to reading and changing only its own data, and account deletion removes all of an account's data in a single step.
Your choices
- Access and export: export your trades at any time from Settings → Data → Export CSV. CSV export is a Pro feature.
- Correct: edit any trade, journal, goal, or rule in the app.
- Delete individual items: delete trades or journals at any time in the app.
- Delete your account: see below.
Delete my account
In the app
- Open Home → Settings (gear icon) → Account → Delete Account. On the web app, Delete Account is at the bottom of Settings.
- Confirm twice.
This immediately and permanently deletes your account and all of its data from our database: journals, trades, tags, goals, rules, deposits and withdrawals, and Pro status. You are then signed out. Copies may remain in our database provider's routine backups for a short time until those backups are overwritten.
By email
If you can't use the app, email team@vaultlog.site from the address on your account with the subject "Account Deletion Request." We will delete your account and data within 30 days.
Deleting your Vaultlog account does not cancel or refund your App Store or Google Play purchase. The purchase stays with your Apple or Google account, and you can restore it on a new Vaultlog account with Restore Purchase. If we hold a purchase record as described above, it is kept after deletion without any link to your account.
Data retention
We keep your account data while your account exists. When you delete your account, your data is deleted as described above. Diagnostic data held by Expo is kept for Expo's retention period and is not linked to your account.
Children's privacy
Vaultlog is not directed at children under 13, and we do not knowingly collect data from children under 13.
Changes to this policy
We may update this policy. Material changes will be reflected in the "Last updated" date above.
Contact
Questions about this policy or your data: team@vaultlog.site