Privacy Policy
Last updated: August 2026
1. Controller
Aftercharts LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States. Email: hello@aftercharts.com.
This policy covers the Aftercharts website and, depending on the features you use, the Aftercharts app.
2. Data categories
- Account and profile: email address, authentication data, display name, settings and account identifiers.
- Trades and journal: imported or entered transactions, positions, notes, tags, strategies, screenshots and analytics. These may reveal financial circumstances or personal assessments.
- Payments: order, product, price, tax, payment-status and refund data; complete payment details may be processed directly by Whop and may not be fully available to us.
- Support: messages, contact details and attachments you choose to provide.
- Broker imports: where this feature is available and you enable it, the selected connection, access tokens/API credentials and imported trading data. We use such credentials only for the connection you request; limit permissions to what is necessary.
- Technical and security: IP address, timestamps, route, user agent, error, authentication, security and audit logs.
3. Purposes and legal bases
- Contracting, account operation, app features, imports, support and transactional emails: GDPR Art. 6(1)(b).
- Payment, tax and bookkeeping duties: Art. 6(1)(c).
- Security, reliable operation, abuse prevention, debugging and legal claims: Art. 6(1)(f).
- Optional communications or non-essential processing: Art. 6(1)(a), where consent is requested.
4. Recipients and processors
- Supabase, where used, for authentication, database and file storage.
- Vercel, where the relevant service is deployed there, for hosting, delivery and technical logs.
- Whop, when you use the offered checkout, for checkout and payment handling; Whop's own terms and privacy roles may also apply.
- Resend, where used, for necessary transactional emails.
- Brokers/exchanges only when you initiate a connection, and advisers or authorities where legally required.
5. Optional website analytics with self-hosted Rybbit
We self-host Rybbit at analytics.aftercharts.com. The analytics script is loaded only after your explicit consent. If you decline, Rybbit does not measure your visit. We store your choice in Local Storage under aftercharts-analytics-consent so that it can be respected.
After consent, data may include pages visited, time, referrer, language, device and browser information, approximate region, events, outbound-link destinations and a visitor identifier. Before rendering, all other query parameters are stripped except the expressly allowlisted campaign parameters utm_source, utm_medium, utm_campaign, utm_content and utm_term; after consent, Rybbit may process those retained campaign parameters. The deployed version may store an identifier such as rybbit-visitor-id in Local Storage. The server technically receives the IP address; whether and how truncated or hashed identifiers are derived depends on the Rybbit configuration. Rybbit is not an advertising network and the instance is operated by us. Our website code does not call Rybbit user-identification or session-recording functions. If we expand the analytics scope in the future, we will provide prior notice and request any required new consent.
The legal basis for loading the script, accessing Local Storage and subsequent analytics is your consent under GDPR Art. 6(1)(a) and, where applicable, section 25(1) TDDDG. You can withdraw consent at any time using “Analytics settings” in the footer, with effect for the future. This removes known Rybbit identifiers from Local Storage and reloads the page so the script is not loaded again. Withdrawal does not automatically erase data already collected on the server; you may send a deletion request to the contact address. The consent choice remains until you change it or clear browser storage. Our operational retention target for Rybbit event data is no more than 90 days; production retention settings must be kept aligned with and periodically verified against that target. Data reaching the configured limit is deleted or aggregated so that it is no longer linked to a visitor identifier. Fonts are not loaded from Google or another external font service.
6. International transfers
The controller and service providers may process data in the United States or other countries outside the EEA. Where the GDPR applies, transfers rely on an adequacy decision, appropriate safeguards such as EU Standard Contractual Clauses, or a statutory derogation. You may request information about applicable safeguards.
7. Retention
We keep account data for the account and contract lifecycle. Following a valid account-closure or deletion request, we generally remove account, trade, journal and file data from active systems within 30 days unless a legal duty or preservation of specific legal claims requires otherwise. Backups are overwritten in the regular cycle within no more than 90 days. We generally keep support records for up to 24 months after resolution. Technical security and audit logs are usually kept for 30 to 90 days; extracts relating to a security incident may be retained until the incident is resolved and for applicable limitation periods. Payment, tax and bookkeeping records are subject to statutory periods that are typically 6 to 10 years, depending on the record and applicable law.
8. Rights and requests
You may request access, correction, deletion, restriction and portability, and object to processing based on legitimate interests. You may withdraw consent at any time for the future. Send deletion or export requests to hello@aftercharts.com; we may request proportionate identity verification. You may lodge a complaint with a competent data protection authority.
9. Automated decision-making, trading and minors
We do not make solely automated decisions producing legal or similarly significant effects. Analytics are journaling aids, not investment advice or trading recommendations. The service is not intentionally directed to children. Where applicable law does not allow a minor to consent or contract independently, consent from a parent or guardian is required. If we learn that a minor's data was processed unlawfully, we will assess and delete or restrict it as required by applicable law.
10. Security and changes
Safeguards depend on the service and may include access restrictions, encryption in transit, logging and backups, but no system is absolutely secure. Never grant broker trading or withdrawal permissions where read-only access is sufficient. We will update this policy when services or legal requirements change.