Legal

Privacy Policy

This policy explains how Sourcr, LLC, operating Trade Echo, handles information when you use the Trade Echo website and iOS application.

Last updated October 7, 2026

Information we collect

  • Account information, including your email address, account identifier, name or display name when provided, authentication records, language, theme, and app preferences.
  • Profile photos you choose to upload. Photos are stored with your account using a publicly accessible image URL; anyone with that URL may view the image. Do not upload an image you intend to keep private.
  • Trading and financial information, including watchlists, journal entries, risk limits, account-size settings, simulated trades, automation settings, and exchange-confirmed orders, fills, positions, entry and exit prices, fees, and profit or loss. Connected-exchange features may also retrieve balances, equity, margin, and unrealized profit or loss.
  • Exchange connection information you provide, including API credentials and connection settings. Secret credentials are encrypted for storage, used to provide requested exchange features, and are not displayed back in full. Trade Echo does not need your exchange password or withdrawal permission.
  • User content, including questions, messages, chart screenshots, notes, and context you submit to Ask or other app tools, and information you send when contacting customer support.
  • Device identifiers and service tokens, including push-notification and Live Activity tokens associated with your account, plus app version, operating system, device type, crash reports, performance information, and diagnostic logs used to operate and troubleshoot the service.
  • For signed-in members, coarse app-section visits, session timestamps, active duration, and whether the app is visible. This supports owner-only service administration and product improvement. We do not record screens, typed content, URL query parameters, or IP addresses for this feature. We honor browser Do Not Track and Global Privacy Control signals.
  • Aggregated web analytics, including page views, event timestamps, referring sites, device and browser information, and approximate country, region, or city derived by our analytics provider. This is not precise GPS location. Vercel Web Analytics uses aggregated information and a short-lived visitor identifier rather than advertising cookies.
  • Purchase history and subscription information, including product identifiers, transaction records, entitlement status, and renewal or expiration information associated with your account. Payment card details are processed by payment providers and are not stored by Trade Echo.

How we use information

  • Provide authentication, account profiles, market tools, alerts, journals, performance reports, simulated trading, connected-exchange features, and user-requested trading automation.
  • Personalize your workspace using your saved preferences, watchlists, risk settings, and content you submit.
  • Answer Ask requests and analyze chart screenshots using an AI-processing provider. The messages, images, and context needed for the requested feature are sent to that provider. Avoid submitting credentials or sensitive information that is not needed for the request.
  • Deliver push notifications, home-screen widgets, and Live Activities. Trade information shown in notifications or Live Activities may be visible on your lock screen, Dynamic Island, or other system surfaces according to your device settings.
  • Evaluate app-section usage and aggregated analytics to understand feature reliability, improve the product, and support owner-only service administration.
  • Maintain security, prevent abuse, troubleshoot errors, and improve reliability and usability.
  • Manage subscriptions, respond to support requests, and send service-related notices.
  • Comply with legal obligations and enforce our terms.

Sharing and processors

We do not sell personal information or use account and trading records for targeted advertising. We share information with service providers needed to operate Trade Echo, when you direct us to connect an exchange, or when required by law.

Providers include Vercel for hosting and web analytics, Supabase for authentication, database and uploaded-image storage, Apple for purchases, notifications and system integrations, and Anthropic for AI processing. An exchange you connect receives the authenticated requests and trading instructions needed for the features you enable. Provider retention and handling are also governed by their applicable privacy policies and service terms.

Market and liquidation data shown in the app are reference market information, not information about your personal account. Embedded TradingView charts and third-party pages opened from news links may receive connection information such as your IP address and browser or device details directly, and may use their own cookies or similar technologies. Their privacy policies apply to that processing; Trade Echo does not control those sites.

Data retention

Identifiable section-visit and presence records are retained for up to 30 days and removed by a daily retention sweep. These records are also deleted when the underlying account is deleted.

We retain account and product data while your account is active and as reasonably needed to provide the service, meet legal obligations, resolve disputes, and protect the service. Retention periods vary by data type. We may retain de-identified or aggregated information that no longer identifies you.

Uploaded profile photos remain in storage until removed or deleted as part of an account-deletion request. Copies already downloaded by others or retained in caches may persist. Financial and purchase records may be retained where required for accounting, security, or legal obligations. AI requests and other processor records may be retained under the applicable provider terms.

Your choices

You may update app preferences, disconnect exchange access, disable notifications in device settings, or request access, correction, export, or deletion of your personal information. To request account deletion, email dev@tradeecho.io from the address associated with your account. We may need to verify your identity before completing a request.

You can revoke exchange API credentials directly with your exchange. Removing a connection does not cancel exchange orders or close positions; review and manage them on the exchange. You can control notification previews and Live Activities in iOS settings and remove home-screen widgets. Face ID authentication is performed by the device; Trade Echo does not receive or store your biometric template.

Security

We use administrative, technical, and organizational safeguards designed to protect information. No network or storage system can be guaranteed completely secure, so you should use a unique password and protect your devices and exchange credentials.

International use

Trade Echo and its service providers may process information in the United States and other countries. Where required, we use appropriate safeguards for international transfers.

Children

Trade Echo is not directed to children under 18, and we do not knowingly collect personal information from children.

Contact

For privacy questions or requests, contact Sourcr, LLC at dev@tradeecho.io.