Privacy Policy

Effective date: 28 July 2026 · Version 2.0
This English text is a translation provided for convenience. In case of discrepancy, the German Datenschutzerklärung prevails.

0. Scope of this policy

This policy explains how we process personal data in two distinct contexts:

  • Part A — the website www.tradelics.com, including the shop, contact form and newsletter.
  • Part B — the Tradelics desktop application for Windows and macOS, however obtained (direct download or Microsoft Store).

Part C contains the rules that apply to both.

Please read the part relevant to you. Where the app behaves differently from the website, Part B governs.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Mauricio Wells
Hollerstr. 6
80995 Munich
Germany

Phone: +49 (0) 8664 3182612
Email: legal@tradelics.com

We are not legally required to appoint a Data Protection Officer. For all data protection matters, please use the contact details above.

2. Principles

  • We process personal data only where a legal basis under Art. 6 GDPR applies.
  • We do not sell personal data.
  • We do not use advertising networks, cross-site tracking, ad IDs or data brokers.
  • We do not carry out profiling or automated decision-making within the meaning of Art. 22 GDPR.
  • The Tradelics application contains no analytics, telemetry or usage tracking of any kind. Your trades, notes and screenshots never leave your device (see B.1).

Part A — The website www.tradelics.com

A.1 Hosting

Our website is hosted by an external service provider. When you visit the site, the provider processes personal data on our behalf — in particular IP addresses and access data — in order to deliver the site.

  • Provider: STRATO AG, Pascalstraße 10, 10587 Berlin, Germany.
  • Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure and efficient presentation of our website.
  • Processing agreement: We have concluded a data processing agreement pursuant to Art. 28 GDPR with STRATO AG.
  • Server location: Germany. No data is transferred to a third country in connection with hosting.

A.2 Server log files

Each time the website is accessed, the server automatically records:

  • the pages requested and the volume of data transferred
  • date and time of the request
  • browser type and version
  • operating system
  • referrer URL
  • IP address

Purpose: technical delivery of the site, stability, security, and defence against attacks and abuse.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional, secure website).
Retention: log data is deleted or anonymised after 7 days, unless a specific incident requires longer retention as evidence.

This data is not merged with other data sources and is not used to identify individual visitors.

A.3 Cookies and consent management

We use cookies — small text files stored on your device.

  • Strictly necessary cookies (session handling, security, storing your consent decision) are set without consent, on the basis of § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR.
  • All other cookies and comparable technologies (in particular analytics) are only set after your express consent, on the basis of § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.

Consent is collected and documented using the consent management tool Complianz, which runs on our own website; the tool stores your consent decision (including timestamp and scope) so that we can demonstrate consent as required by Art. 7(1) GDPR.

You may withdraw or change your consent at any time with effect for the future via the cookie banner / privacy settings link on our site. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

You can also configure your browser to refuse or delete cookies. Doing so may limit the functionality of the site.

A.4 Web analytics with Matomo (self-hosted)

We use Matomo, an open-source analytics tool, to understand how our website is used and to improve it.

  • Hosting: Matomo runs on our own servers within the EU. No analytics data is transmitted to Matomo or any other third party.
  • Data processed: anonymised IP address, pages visited, time on page, referrer URL, approximate region derived from the truncated IP, device type, operating system, browser.
  • IP anonymisation: IP addresses are truncated before storage, so no complete IP address is retained.
  • Cookies: Matomo sets cookies only after you have consented via the consent banner.
  • Legal basis: Art. 6(1)(a) GDPR (consent) — and, for the storage of and access to information on your device, § 25(1) TDDDG.
  • Retention: raw analytics data is deleted automatically after 12 months; only aggregated, non-personal statistics are retained beyond that.

Objection / opt-out. You may withdraw your consent at any time via the cookie banner, or use the opt-out below. The opt-out is stored in a cookie on your device — if you clear your cookies, change browser or change device, you will need to opt out again.

Tracking status: checking …

A.5 YouTube videos

On our video tutorials page we embed videos hosted by YouTube, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

  • How it works: videos are only loaded after you actively click a preview to consent to the embed. Until then, only a placeholder image is shown and no connection to YouTube’s or Google’s servers is made.
  • Data processed: once you consent, your browser transmits your IP address and device/browser information to Google; Google may also set cookies to recognise you and for its own purposes (e.g. reach measurement, personalisation).
  • Cookies: set only after your consent via the cookie banner.
  • Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TDDDG.
  • Third-country transfer: Google also processes data in the United States. Where applicable, this transfer relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) or the EU-U.S. Data Privacy Framework, to the extent Google is certified under it.
  • More information: Google’s privacy policy.

You can withdraw your consent at any time, with effect for the future, via the cookie banner or the privacy settings link; this does not retroactively affect videos already loaded.

A.6 Contacting us

If you contact us by email, via the contact form or by telephone, we process the data you provide (typically name, email address, and the content of your message) in order to handle your enquiry.

  • Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or pre-contractual steps; otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
  • Retention: we delete enquiries once they have been fully dealt with and no retention obligation applies. Business correspondence may be subject to statutory retention periods of up to 6 or 10 years (§ 257 HGB, § 147 AO).

A.7 Newsletter

If you subscribe to our newsletter, we process your email address and, where provided, your name, together with the date, time and IP address of your sign-up and confirmation (double opt-in log).

  • Purpose: sending product news, release information and related updates; documenting your consent.
  • Legal basis: Art. 6(1)(a) GDPR (consent). The double opt-in log is kept on the basis of Art. 6(1)(c) and (f) GDPR in order to prove consent.
  • Procedure: we use the double opt-in procedure. Your subscription only becomes active once you confirm it via the link in the confirmation email.
  • Processor: Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany — part of Brevo SAS, 106 Boulevard Haussmann, 75008 Paris, France). Newsletter data is stored on servers within the European Union. We have concluded a data processing agreement pursuant to Art. 28 GDPR with Brevo.
  • Success measurement: we do not analyse the behaviour of individual recipients. Open and click measurement is configured in anonymised form, so that opens and clicks are recorded only as aggregate totals and are not attributed to individual contacts or email addresses. In addition, open tracking is limited to contacts who have expressly consented; we do not record any such consent. We therefore only see aggregate dispatch statistics (deliveries, opens, clicks, bounces, unsubscribes) without any personal reference.
  • Withdrawal: you may unsubscribe at any time via the link in every newsletter, or by emailing legal@tradelics.com. After unsubscribing, your address is deleted from the distribution list; we may retain it on a suppression list solely to ensure you receive no further mailings (Art. 6(1)(f) GDPR).

A.8 Purchase of a licence — Lemon Squeezy

Licences for Tradelics are sold through Lemon Squeezy.

Lemon Squeezy acts as reseller and Merchant of Record: it is the seller and your contracting party for the transaction, and handles payment processing, invoicing and sales tax/VAT. When you click “Buy”, you are taken to a checkout page operated by Lemon Squeezy.

Its role under data protection law is twofold. In respect of the order data it processes for us, it acts as our processor on the basis of its Data Processing Agreement. In respect of its own purposes — in particular operating its platform, fraud prevention and its own customer relationships — it acts as an independent controller under its own privacy policy.

  • Provider: Sold through Link, LLC (formerly Lemon Squeezy LLC), trading as Lemon Squeezy, 222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA — a Stripe company.
  • Data processed by Lemon Squeezy: name, email address, billing address and country, tax/VAT identifiers where applicable, payment method details, transaction amount and currency, IP address and fraud-prevention signals.
  • Data we receive: we receive order and customer records (name, email address, billing country, product, amount, order ID) and payout reports. We never receive or store your full card number, bank details or other payment credentials.
  • Our purpose and legal basis: performing the licence agreement and providing support (Art. 6(1)(b) GDPR), and complying with commercial and tax retention obligations (Art. 6(1)(c) GDPR).
  • Third-country transfer: processing takes place in the USA. The transfer is safeguarded by the Standard Contractual Clauses of the European Commission pursuant to Art. 46(2)(c) GDPR, as set out in the Lemon Squeezy Data Processing Agreement (lemonsqueezy.com/dpa). Please note that US authorities may have access rights that do not fully correspond to the EU standard.
  • Lemon Squeezy privacy policy: lemonsqueezy.com/privacy
  • Retention: order and invoice data is retained for the statutory periods of up to 10 years (§ 147 AO, § 257 HGB).

Your email address from the purchase is also used to deliver your licence key and to contact you about licence-related matters (e.g. device transfers). This is contract performance under Art. 6(1)(b) GDPR and is not a newsletter subscription.

Part B — The Tradelics desktop application

B.1 What stays on your device — and does not

Tradelics is a local desktop application. The following data is created and stored exclusively on your own device and is never transmitted to us or to any third party:

  • your trades, orders, accounts and balances
  • journal entries, notes, comments, tags, strategies and review answers
  • chart screenshots and any other images you attach
  • the SQLite journal files themselves, and your workspace folders
  • your broker credentials and API keys (encrypted at rest — see B.5)
  • application log files

We have no server-side copy of your trading data, no cloud sync and no backup on our systems. If you delete these files locally, they are gone; we cannot restore them.

The application contains no analytics, no telemetry, no crash reporting to us, no advertising and no tracking identifiers.

The app makes network connections only in the specific, limited cases described in B.2 to B.7 below.

B.2 Licence activation and free trial

To activate a licence or start a free trial, the application contacts our licence server at tradelics.com.

Data transmitted by the application:

DataNotes
Licence keyOn activation and licence checks
Device identifierA random UUID generated on first start and stored locally
Windows MachineGuidA device-level identifier read from the operating system
Email addressOptional when starting a trial; provided by you when activating a licence
IP address, request time, app versionRecorded automatically by the server, as with any web request

Purposes:

  1. Verifying that a licence key is valid and issuing a signed licence/trial token to your device.
  2. Binding a licence to a limited number of devices, as provided for in our licence terms.
  3. Preventing repeated use of the free trial on the same device — this is why the device identifier and MachineGuid are processed.
  4. Enabling the device-transfer procedure (see B.3).

Legal bases:

  • Art. 6(1)(b) GDPR — performance of the licence agreement and pre-contractual measures (trial). Without a device identifier, licence enforcement and the trial are technically impossible.
  • Art. 6(1)(f) GDPR — our legitimate interest in preventing licence abuse and repeated trials.
  • Where you voluntarily supply an email address for a trial, Art. 6(1)(a) GDPR additionally applies to its use for contact purposes; you may withdraw at any time.

Necessity. The email address is optional for the trial. Device and machine identifiers are technically necessary: without them the application cannot verify entitlement and cannot be used.

Retention:

  • Licence records (key, bound device identifiers, email, activation history): for the duration of the licence and thereafter for the statutory retention periods; entries no longer required for accounting are deleted 24 months after the licence ends.
  • Trial records (device identifiers, optional email, trial start/end): deleted 24 months after the trial expires, as this is the period for which abuse prevention remains meaningful.
  • Licence server access logs: 30 days. The longer period compared with the website (A.2) is justified by the need to detect and investigate systematic attempts at licence and trial abuse, which typically only become apparent over several weeks.

No hidden checks. The licence token is stored locally on your device (Windows Registry / macOS Keychain / application preferences) and validated offline. The application does not phone home continuously.

B.3 Device transfer

If a licence key is already bound to another device, you can request a transfer from within the application. The application transmits the licence key and the new device identifier; our server then sends a confirmation link to the email address registered with that licence. Within the app, the address is only shown to you in masked form (e.g. j***@gmail.com).

  • Purpose: confirming that the transfer request comes from the legitimate licence holder.
  • Legal basis: Art. 6(1)(b) GDPR (performance of the licence agreement) and Art. 6(1)(f) GDPR (legitimate interest in preventing unauthorised transfers).

B.4 Update check

The application checks at most once every 24 hours whether a newer version is available, by sending a request to tradelics.com.

  • Data transmitted: your IP address (unavoidably, as with any HTTP request) and the app version in the user-agent header (e.g. Tradelics/1.0.1-beta). No licence key, no device identifier and no personal data are sent with this request.
  • Purpose: informing you about updates, including security-relevant ones.
  • Legal basis: Art. 6(1)(f) GDPR — legitimate interest in keeping installations up to date and secure.
  • Control: the update check can be disabled at any time in the application’s preferences.

B.5 Broker connections and credentials

Tradelics can import your trades from brokers. How this works depends on the broker:

Local bridge (MetaTrader 5, cTrader, NinjaTrader, MetaTrader 4).
Data is read from the trading platform running on your own computer, via a local component that communicates only over 127.0.0.1 (localhost) using an encrypted, certificate-pinned connection. This data never leaves your device and never reaches us.

Direct API connections (exchanges and brokers).
If you configure such a connection, the application connects directly from your device to that provider in order to retrieve your own trade history. Currently supported:

  • Kraken — api.kraken.com (Payward Ltd. / Payward Inc.)
  • Binance — fapi.binance.com, dapi.binance.com (Binance group)

We expect to add further exchanges and brokers over time. The description in this section applies to each of them equally, without requiring an update to this policy: the connection is always configured and initiated by you, the application never mediates it, and we never receive the transmitted data.

In doing so, your API key and signature, and unavoidably your IP address, are transmitted to that provider. These providers are independent controllers and process this data under their own privacy policies and terms. Servers may be located outside the EU/EEA, including in third countries without an adequacy decision; in that case the transfer is based on Art. 49(1)(b) GDPR, since it is necessary for the performance of the contract you have with that provider and which you initiate yourself by configuring the connection.

We are not involved in these connections and receive none of this data.

  • Legal basis for the processing within the app: Art. 6(1)(b) GDPR (provision of the functionality you have requested).

Storage of credentials. Broker credentials and API keys are stored encrypted on your device. The encryption key is held in the operating system’s protected storage (Windows DPAPI, macOS Keychain, or libsecret on Linux). We have no access to it and cannot recover your credentials.

Our recommendation: create API keys with read-only permissions wherever your broker supports it.

B.6 Exchange rates

To convert values in multi-currency journals, the application retrieves exchange rates from public services:

  • api.frankfurter.app (based on European Central Bank reference rates)
  • api.exchangerate-api.com

Only the currency pair concerned is requested. No trade data, account data, licence data or personal identifiers are transmitted. Technically unavoidable is the transmission of your IP address to the operator of the respective service; for exchangerate-api.com this may involve a transfer to a third country.

  • Legal basis: Art. 6(1)(b) GDPR — providing the currency conversion functionality that is part of the product.

B.7 External links

The application contains links which open in your default browser (for example our website, the user guide, or TradingView). Once you follow such a link, the privacy policy of the operator of the target site applies. We have no influence on their processing.

B.8 Local log files

The application writes log files to your own device (%APPDATA%Tradelicslogs on Windows, ~/Library/Logs/Tradelics on macOS). They may contain file paths, account names and error details.

These logs remain on your device and are never transmitted automatically. They are only shared with us if you deliberately attach them to a support request — in which case we process them solely to resolve your issue (Art. 6(1)(b) / Art. 6(1)(f) GDPR) and delete them once the case is closed.

B.9 Distribution via the Microsoft Store

If you install Tradelics from the Microsoft Store, Microsoft processes data relating to the download, installation, licensing and, where applicable, in-store purchase as an independent controller under its own privacy statement (privacy.microsoft.com/privacystatement). We receive from Microsoft only aggregated, non-personal statistics (for example the number of installations and crash counts) in the Partner Center. We cannot identify individual users from this.

Part C — Provisions applying to both

C.1 Recipients and processors

We disclose personal data only where necessary and lawful. Categories of recipients:

RecipientRolePurposeLocation
STRATO AG, BerlinProcessor (Art. 28)Website and licence server hostingGermany
BrevoProcessor (Art. 28)Newsletter dispatchEU (Germany/France)
Sold through Link, LLC (Lemon Squeezy)Processor and, for its own purposes, independent controller (Merchant of Record)Sale, payment, invoicingUSA
Microsoft CorporationIndependent controllerStore distribution and licensingUSA / global
Exchanges and brokers you connect directlyIndependent controllersOnly if you configure a direct connection to that providerVaries by provider; may include third countries
Tax advisor, auditors, authoritiesRecipients under statutory dutyAccounting, legal obligationsGermany

Beyond this, data is transferred only where you have consented, where it is necessary to perform a contract, or where we are legally obliged to do so.

C.2 Transfers to third countries

Some of the recipients above are located outside the EU/EEA. Such transfers only take place where one of the following applies:

  • an adequacy decision of the European Commission (Art. 45 GDPR), including certification under the EU–U.S. Data Privacy Framework;
  • Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, supplemented where necessary by additional protective measures;
  • your express consent (Art. 49(1)(a) GDPR);
  • the transfer being necessary for the performance of a contract that you have initiated (Art. 49(1)(b) GDPR) — this applies in particular to direct broker connections you configure yourself in the app.

We point out that in third countries, and in the USA in particular, a level of data protection equivalent to that of the EU cannot be guaranteed in every respect, and that authorities may be granted access rights. You can request a copy of the safeguards in place from us at any time.

C.3 Retention and erasure

We store personal data only for as long as is necessary for the purposes described, or for as long as statutory retention obligations require. Specific periods are stated in the sections above. In particular:

  • Commercial and tax-relevant records: 6 or 10 years (§ 257 HGB, § 147 AO).
  • Where deletion conflicts with a retention obligation, the data is restricted (blocked) instead of deleted and is not processed for any other purpose.

C.4 Data security

We use TLS/SSL encryption for all connections to our servers, and the connection between the application and the local broker bridge is TLS-encrypted with certificate pinning. Licence tokens are cryptographically signed (RSA-SHA256) and verified by the application. Broker credentials are encrypted at rest using keys held in the operating system’s protected storage. We apply appropriate technical and organisational measures in accordance with Art. 32 GDPR and review them regularly.

No method of transmission over the internet is completely secure. Please protect your own device, since your trading data is stored locally and unencrypted backups of it are your responsibility.

C.5 Your rights

You have the following rights in respect of your personal data:

  • Access (Art. 15 GDPR) — confirmation as to whether we process your data, and a copy of it.
  • Rectification (Art. 16 GDPR) — correction of inaccurate or incomplete data.
  • Erasure (Art. 17 GDPR) — deletion, provided no retention obligation applies.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR) — receipt of your data in a structured, machine-readable format.
  • Objection (Art. 21 GDPR) — see the separate notice in C.6.
  • Withdrawal of consent (Art. 7(3) GDPR) — at any time with effect for the future, without affecting the lawfulness of prior processing.
  • Complaint to a supervisory authority (Art. 77 GDPR).

To exercise your rights, contact legal@tradelics.com. We respond within one month; where a request is complex, this period may be extended by a further two months, and we will inform you accordingly.

A note specific to the app: because your trading data is stored solely on your device, a request for access, portability or erasure of that data cannot be fulfilled by us — you have direct and exclusive control over it. Our disclosure obligations extend to the licence, trial, order and newsletter data described above.

Competent supervisory authority for us:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
www.lda.bayern.de

You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.

C.6 Right to object — Art. 21 GDPR

Where we process your data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to that processing.

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where data is processed for direct marketing purposes, you may object at any time without giving reasons; we will then cease that processing entirely.

An objection can be sent informally to legal@tradelics.com.

C.7 Obligation to provide data

You are under no statutory or contractual obligation to provide personal data. However, certain data is necessary in order to conclude and perform a contract: without a device identifier the licence cannot be validated and the application cannot be used, and without an email address we cannot deliver a licence key or process a device transfer. Providing an email address for the free trial is voluntary.

C.8 No automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22(1) and (4) GDPR.

C.9 Changes to this policy

We will amend this policy where changes to our services, or to the legal position, make it necessary. The current version always applies and is available at tradelics.com/legal/privacy-policy/. Where changes materially affect processing based on your consent, we will obtain fresh consent.

Version 2.0 — 28 July 2026. Previous version: April 2026.