Privacy Policy
1.Who we are
Marginalia is the trading-journal service operated at marginalia.trade ("Marginalia", "we", "us"). For the purposes of the EU General Data Protection Regulation (GDPR), Marginalia is the data controller for the personal data described in this policy. We operate from Ireland.
Privacy questions and requests: support@marginalia.trade.
2.What we collect — and what we don't
Account data. Your email address and a securely hashed password (we never store or see the password itself), managed through our authentication provider. Optionally, a display name and avatar you set yourself, and your two-factor authentication preference.
Content you create. Your journal is your data: trades, pre/post-market notes and written plans, backtest sessions, strategies and entry models, and any chart screenshots you upload. We store this solely so the service can show it back to you.
Subscription data. Whether you're on the Free or Pro plan, your subscription status and renewal date, a Stripe customer reference, and any access code you've redeemed.
Technical data. Standard, short-lived server and function logs (such as timestamps and error diagnostics) used to keep the service running and secure.
What we do not collect:
- No payment card data. Card numbers, expiry dates, and billing details go directly to Stripe and never touch our servers. We only receive a customer reference and subscription status.
- No advertising or cross-site trackers, no marketing pixels, no fingerprinting, and no behavioural advertising profiles.
- No sale of personal data — to anyone, ever.
3.How we use your data
- To provide the service: authenticate you, store and display your journal, sync across devices, and enforce plan limits.
- To process subscriptions: start, renew, and cancel Pro billing through Stripe.
- To send essential, transactional email only — signup confirmation, password reset, email change, security notifications, and two-factor codes. We do not send marketing email.
- To keep the service secure and diagnose faults.
Legal bases (GDPR): performance of our contract with you (Art. 6(1)(b)) for the service and billing; our legitimate interest (Art. 6(1)(f)) in security and fault diagnosis; and your consent where you opt in to optional features such as email two-factor authentication.
4.Who can see your vault
Your vault is private by default. Every table in our database is protected by row-level security rules, so your data is only ever returned to your own authenticated session — other users cannot query it.
Our team does not browse or read user vaults. Limited administrative access to the underlying database exists, as it does for any hosted service, and is used only where strictly necessary: to resolve a support issue at your request, to investigate abuse or a security incident, or to comply with a legal obligation. We never access your content for any commercial purpose.
Sharing is entirely in your hands. If you create a share link (view-only or view-plus-notes, for your whole vault or a scoped part of it), anyone holding that link can see exactly what the link covers — so treat share links like the content itself. You can revoke any link at any time from inside the app, which cuts off access immediately.
5.Our processors (who handles data on our behalf)
We deliberately keep the list short. These providers process data strictly to run Marginalia, under their own GDPR-compliant data processing terms:
| Provider | Role | What they handle |
|---|---|---|
| Supabase | Database, authentication & file storage | Hosts our database and auth system in the EU (Ireland, eu-west-1) — your account data, journal content, and uploaded screenshots live there, protected by row-level security. |
| Stripe | Payment processing | Handles all payment and card data as a PCI-DSS Level 1 certified processor. Marginalia never receives your card details — only your subscription status and a customer reference. |
| Netlify | Web hosting & CDN | Serves the application files and keeps standard, short-lived access logs (such as IP addresses) needed to operate and secure the site. |
| Resend | Transactional email | Delivers the essential account emails listed above (confirmations, resets, security notices, 2FA codes) from noreply@marginalia.trade. |
Where a provider processes data outside the EEA (for example, some Stripe or Netlify infrastructure), transfers are covered by recognised safeguards such as the EU Standard Contractual Clauses.
6.Cookies & local storage
We use no advertising or analytics cookies. The browser storage we do use is strictly necessary or functional:
- Authentication session — keeps you signed in (Supabase auth token).
- Preferences — your theme and display-performance choice.
- Trusted device — if you enable email 2FA, a local flag remembers this device for 30 days so you aren't asked for a code on every sign-in.
Because none of this is used for tracking or advertising, no cookie consent banner is required — there is simply nothing to consent to.
7.Retention & deletion
We keep your data for as long as your account exists, because the service is the data — your journal has no value to you if we delete it early. If you want your account and all of its content permanently deleted, email support@marginalia.trade from your account address and we will erase your account data without undue delay, except for the minimal records we are legally required to keep (for example, invoicing records held by Stripe for tax law).
8.Your rights (GDPR)
You have the right to access the personal data we hold about you, to rectify it, to erase it, to restrict or object to processing, and to data portability. To exercise any of these, email support@marginalia.trade. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Irish Data Protection Commission (dataprotection.ie), though you may complain to the authority in your own EU member state.
9.Security
- All traffic is encrypted in transit (TLS/HTTPS).
- Passwords are hashed — never stored or visible in plain text.
- Row-level security is enforced at the database layer, not just in the app.
- Optional email two-factor authentication with 30-day device trust.
- Subscription state is written only by verified Stripe webhooks — it cannot be forged from a browser.
No online service can promise absolute security, but if we ever become aware of a personal-data breach that risks your rights, we will notify the Data Protection Commission and affected users as the GDPR requires.
10.Children
Marginalia is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
11.Changes to this policy
If we make material changes, we will update the date at the top of this page and, for significant changes, notify you by email or in the app before they take effect.