Privacy Policy
Last Updated: September 23, 2026
Journalit is designed with privacy as a core principle. Your journal files live in your Obsidian vault, and features that send or store data on Journalit servers are optional and described below.
Overview
This Privacy Policy covers both the Journalit website (journalit.co) and the Journalit Obsidian plugin. We are committed to protecting your privacy and being transparent about what data we collect.
What We Collect
Website (journalit.co)
When you use our website:
- Account Information - Email address and name from your OAuth provider (Google, GitHub, Discord)
- Session Data - Authentication tokens stored in secure cookies
- Payment Information - Processed by Stripe (we never see your full card details)
- Operational Telemetry - Service-health metrics and essential error traces used to keep the web app reliable. This does not include your trading journal content.
- Referral Attribution Data - If you allow the optional referral cookie, we record the partner and link, landing path, consent version and time, and a random-token hash needed to attribute a later subscription. We do not store IP or User-Agent hashes in the affiliate click record.
For a detailed breakdown, see Data, privacy and offline.
Obsidian Plugin
The plugin operates locally by default. No data is transmitted unless you enable sync features:
- Local Data - Manual trades, notes, attachments, and journal files stay in your Obsidian vault
- Prop Challenges - Challenge phases, rules, payouts, and personal firm profiles stay in your vault and plugin settings
- Plugin Settings - Most settings are stored locally in your vault's plugin folder. Network-backed features transmit only the settings and identifiers described below.
- Cache Data - Query results and indexes for performance, never transmitted
Optional Sync Features
When you enable backend integration:
- Email Address - For authentication via verification code
- MetaTrader Trades - Synced trade data (symbol, times, prices, P&L)
- Vault Identifier - Random opaque identifier for sync and projection coordination. It does not contain your vault path or name.
- MT Account Info - Account IDs and display names
Optional Tradovate Sync
Tradovate Sync is an optional Pro feature. Authorization and connection management take place on Journalit.co. You may authorize multiple independent Tradovate identities. OAuth credentials, raw numeric provider identifiers, and provider tokens are encrypted and stored by the Journalit backend. They are never returned to the website UI or plugin. The Tradovate username for a connection may be shown only to its authenticated Journalit owner to distinguish their connections.
When you configure or run Tradovate Sync, the plugin sends:
- Selected backend account records and history boundaries
- Random vault, client-installation, and operation identifiers used to coordinate synchronization and projection
- The plugin version
- Privacy-safe synchronization event codes, timestamps, and aggregate counts
- Projection acknowledgements containing canonical trade IDs, versions, local paths for written notes, and success or failure codes
The anonymous client-installation identifier is stored in Obsidian's device-local storage rather than the vault settings file. Client diagnostics do not include note contents, frontmatter, account names, symbols, prices, quantities, P&L, raw exception messages, stack traces, response bodies, or Tradovate credentials and tokens.
The backend stores connection-scoped account configuration, normalized provider source data, canonical synchronized trades, durable sync jobs, reconciliation state, projection state, and restricted diagnostics required to operate and support the feature. Disconnecting one connection preserves cloud data. Deleting its cloud data removes only provenance owned by that connection, and a canonical trade is preserved while another source still owns it.
Optional Rithmic Sync
Rithmic Sync is an optional Pro feature. When you enable it, you provide your Rithmic system, username, and password. Those credentials are sent over TLS to the Journalit backend, verified against Rithmic, and stored encrypted at rest. They are used solely to sign in to Rithmic to retrieve trade and fill data. They are never exposed back to the browser or plugin, and they are deleted when you disconnect the connection. Rithmic (rithmic.com) processes the login and trade data under its own terms.
Optional cTrader Sync
cTrader Sync is an optional Pro integration. You authorise read-only access on cTrader, operated by Spotware. Journalit never requests trading permission. Access and refresh tokens are encrypted on the backend and are not returned to the website UI or plugin.
The backend stores encrypted account-history checkpoints containing provider deal identifiers, position relationships, executions, realised monetary amounts, and account and instrument metadata. These checkpoints support incremental synchronisation and replay. It also stores account selections and display labels, normalised execution evidence, canonical trades, delivery state, sync jobs, and operational records. The plugin sends random vault and device identifiers, its version, account mappings, and acknowledgements containing canonical trade identifiers, versions, local note paths, and delivery results. Journal note text and local annotations are not uploaded by this integration.
Disconnecting deletes that connection's OAuth tokens but preserves its cloud history and your Obsidian notes. History checkpoints have no automatic expiry: they are retained until the connection's cloud data or the Journalit account is deleted. Deleting connection cloud data also removes its selections and projection sources; trades with another active source are preserved. Shared canonical execution evidence and account identity records can remain after a connection is deleted and are retained until Journalit account deletion. Security, operational, and deletion-audit records follow their separate retention rules. Removing cloud data never removes notes from your vault.
Optional Trade Import
Trade Import is an optional Pro feature that processes selected broker exports on Journalit backend servers. It is not part of the offline manual journalling workflow.
- Uploaded Files - When you choose to import a broker export, the selected CSV, XLSX, XLS, HTML, or broker statement file is uploaded for processing.
- Possible File Contents - Broker exports may contain account identifiers, trade history, symbols, timestamps, prices, quantities, fees, balances, and P&L.
- Import Context - The plugin may send the selected account name, broker/file/mapping choices, custom field definitions and saved options, and limited local open-trade context needed for broker-specific matching such as IBKR open-position matching.
- Processing Behaviour - Raw files are processed for the requested import and are not stored by default. The backend returns preview data; final note creation remains local in your Obsidian vault.
- Control - Trade Import requires sign-in and an active Pro subscription before upload. The plugin shows an upload acknowledgement before processing each view session.
Optional Prop-Firm Profiles
When you are signed in, the plugin can download prop-firm profiles to prefill challenge rules. These are read-only requests that send only standard request headers, your authentication token, and a cache validator. Your challenge settings, accounts, trades, and vault data are never sent.
- Firm Index - Any signed-in user can receive a names-only list of supported firms, used to show when a firm you type has a profile available.
- Firm Profiles - Pro users can receive the rules, phases, and payout conditions for each supported firm challenge.
- Control - Both responses are cached in plugin settings so challenge setup works offline. You can always enter challenge rules by hand without downloading any profile.
What We Do NOT Collect
- Manual trades you create in Obsidian
- Trade notes or personal analysis
- Screenshots or attachments
- Contents of your Obsidian vault
- Third-party advertising trackers or ad-network profiles
- Your trading journal content for marketing analytics
- Trading account passwords or API keys, other than the optional Rithmic Sync credentials described above
- General plugin usage analytics or behavioural telemetry unrelated to the operational diagnostics disclosed above
How We Use Your Data
- Authentication - To verify your identity and maintain your session
- Trade Synchronization - To process MetaTrader, Tradovate, Rithmic, and cTrader records and project synchronized trades into your Obsidian vault
- Trade Import Processing - To analyse selected broker exports, generate import previews, apply broker-specific matching logic, and return structured preview data to the plugin
- Subscription Management - To manage your premium subscription status
- Security - FTP login attempts are logged for abuse prevention
- Referral Attribution and Fraud Prevention - To understand which referral link led to a subscription sign-up or subscription checkout, enforce affiliate program rules such as self-referral blocking, and reconcile internal commission records
Data Security
- All network communications use HTTPS (TLS 1.2+)
- Authentication tokens encrypted locally with AES-256-GCM
- Passwords hashed with bcrypt
- Database protected by Row-Level Security - users can only access their own data
Third-Party Services
OAuth Providers
We use Google, GitHub, and Discord for authentication. Their privacy policies apply to data they collect during sign-in.
Stripe (Payments)
Subscription and one-time payments are processed by Stripe. We receive billing and subscription status updates but never see your full payment details.
Email Delivery
We use an email service provider for verification codes, essential account and billing messages, lifecycle guidance, and selected product update announcements. The provider receives the recipient email address and message content needed to deliver the email.
We store delivery records such as provider message identifiers, delivery status, failures, bounces, and complaints. These records help us prevent repeated delivery attempts to invalid addresses and investigate email problems. Open and click tracking are disabled on our current sending domain.
Product updates and lifecycle guidance have separate preferences. You can change them from your account dashboard or use the unsubscribe link in a marketing email. Unsubscribing from these categories does not stop essential billing, security, verification, or account service messages.
Tradovate
If you connect one or more Tradovate identities, Journalit communicates with Tradovate to authorize each connection and retrieve the account and trading data needed for synchronization. Tradovate's privacy policy applies to its services.
Rithmic
If you connect a Rithmic account, Journalit communicates with Rithmic to verify your login and retrieve the trade and fill data needed for synchronization. Rithmic's privacy policy applies to its services.
cTrader / Spotware
If you connect a cTrader account, Journalit communicates with cTrader, operated by Spotware, to authorize read-only access and retrieve the account and trading data needed for synchronization. Spotware's privacy policy applies to its services.
Website Analytics
We use Google Analytics on public website and documentation pages to understand page visits and selected actions such as starting signup or opening a download link. In the UK, EEA, Switzerland, and locations we cannot classify, Google Analytics does not load unless you allow it. It does not run on login, checkout, billing, or authenticated application pages. We do not send account, trading, or payment data to Google.
When website analytics is allowed and a page URL contains campaign parameters, we keep those allowlisted parameters in session storage for the current browser tab. This lets a later sign-in or upgrade in the same tab retain the campaign context. The stored values expire when the tab session ends and are not created when website analytics is declined.
When you deliberately start signup, download, or installation, we temporarily store the current page, a source category, the referring hostname, and allowlisted campaign fields. The anonymous attempt expires after 30 minutes. If a new account is created, that limited context is attached to the account so we can measure signup, trial, activation, and subscription cohorts using our own records. This is signup-origin measurement, not first-website-visit tracking.
Data Retention
- Account Data - Stored until you request deletion
- Synced Trades - Stored until account deletion
- Tradovate Synchronization Data - Connected OAuth connections, account configuration, normalized source records, canonical trades, jobs, reconciliation state, and projection state are stored until you delete the relevant connection data or your Journalit account. Connection-scoped deletion preserves canonical trades that still have another source.
- Tradovate Diagnostic Evidence - Encrypted replay bundles and privacy-safe client and job events expire after 14 days. Diagnostic access is restricted and audited.
- Trade Import Files - Processed for the requested import and not stored by default
- Session Tokens - Expire after 30 days
- Authentication Codes - Deleted within 24 hours
- Uncompleted Signup Attempts - Deleted after 30 minutes
- Aggregate Billing and Upgrade Attribution - Commercial event amounts, Stripe correlation identifiers, and first-party campaign context may be retained after account deletion with the Journalit user identifier removed, for financial and aggregate funnel reporting
- Security Logs - Older entries periodically cleaned
- Referral Attribution Records - Kept only as long as reasonably necessary to reconcile affiliate referrals, investigate abuse, and maintain accounting records
Your Rights
Data Access
All your local data is accessible in your Obsidian vault. For backend data, contact us for an export.
Data Deletion
- Local Data - Delete by removing the plugin or deleting files
- Backend Data - Contact contact@journalit.co for account deletion. Aggregate billing and upgrade attribution records, with the Journalit user identifier removed, may remain as described under Data Retention above.
Opt-Out
You can use the plugin 100% offline with no network features. Disable network-backed features and disconnect broker integrations to stop their data transmission.
Cookies and Browser Storage
We use a small number of first-party cookies and storage entries:
- Session Cookie - Maintains your login state (expires when you sign out or after 30 days)
- Referral Attribution Cookie - Set for 30 days only after you allow it in the on-page cookie notice when arriving through a partner link. It lets us attribute a later subscription to that partner and does not change your price. You can browse without making a choice; we create no individual affiliate click or referral cookie unless you allow it.
- Analytics Preference Cookie - Remembers whether you allowed or declined website analytics for up to 180 days
- Google Analytics Cookies - Set only when website analytics is allowed; these distinguish website visits and can be removed by switching analytics off above
- Campaign Session Storage - Keeps allowlisted UTM campaign fields for the current tab only when website analytics is allowed, so sign-in and upgrade steps can retain their source
We do not use third-party advertising cookies, retargeting cookies, or ad-network trackers.
Children's Privacy
Journalit is not intended for users under 18 years of age. We do not knowingly collect data from minors.
Changes to This Policy
We will notify users of material changes through:
- Plugin update notes
- Product update emails, when you are subscribed
- Discord community announcements
- GitHub release notes
Contact
Privacy questions or concerns:
- Email: contact@journalit.co
- Discord: Join our server
Compliance
This service adheres to:
- Obsidian Developer Policies
- Obsidian Plugin Guidelines
- GDPR principles (data minimization, purpose limitation, transparency)