Legal
Privacy Policy
Last updated 1 September 2026
TradePilot AI is a browser-based backtesting tool for Gold, Forex and Crypto strategies, with an optional live-trading side you switch on yourself. This page says exactly what it stores, where that data sits, and who else can see it.
The short version: almost everything the app produces — your strategies, your AI memory, your demo account, your journal, your cached candles — is written to your own browser. An account exists so that work can follow you to another device, so that a plan can be attached to you, and — if you turn it on — so that a standing rule can run on our server while your browser is closed.
01Who is responsible
TradePilot AI is operated by its owner as an independent product, based in India. For any question about this policy or about your data, write to mahidaammar1@gmail.com.
02What stays in your browser
These are stored on your device by the app and are never transmitted to us. Clearing your browser data for this site deletes all of them.
- Working session — the market, timeframe, strategy settings and last screen you had open, so a reload does not lose your place.
- Saved strategies — a copy on the device is kept even when you are logged out, so pressing Save never throws work away.
- AI memory and lessons — the champions the Autopilot found on each market, and the logic that kept failing there.
- Demo account, paper trades and journal — the sleeves you armed, their trades, and anything you wrote about them.
- Your data-provider API key — if you paste a Twelve Data key, it is kept in this browser only and used to call Twelve Data directly from it. It is never sent to our servers.
- Cached candles — downloaded price history, in IndexedDB, so the same range is not re-downloaded on every visit.
- Preferences — light/dark theme and whether you have already seen the walkthrough.
03What an account stores
Accounts and storage run on Supabase. If you sign up, these rows exist and are readable only by you — every table has row-level security, and the policy is scoped to your own user id:
- Your email address and account id, plus sign-in timestamps, handled by Supabase Auth.
- Strategies you chose to save — the name, the settings, and the summary numbers of the last backtest you ran on them.
- Your plan — free, pro or elite, and its expiry date. How you paid is not here; see clause 5.
- Terminals you created for live trading — the label you gave it, which broker platform it is, when it last checked in, and whether it is switched on. The terminal's token is stored only as a hash, so it cannot be read back out of the database — not by us either. Your broker login and password are never sent to us at all.
- Standing rules — for a live or alert rule: the strategy settings, the symbol, the timeframe, the risk percentage, and the last candle it evaluated.
- Queued orders — the order intents a rule produced (side, symbol, stop, target, risk) and what your terminal reported back about them. This is the audit trail of the automation; it does not include anything from your broker account beyond that report.
- Alert destinations, if you set one up — your Telegram chat id, so the server knows where to send a signal.
- Optional cached candles — the same price history as above, so a second device does not have to download it again. Market data, not personal data.
Backtest results are computed in your browser. We do not receive a copy of a run unless you save the strategy, or unless a standing rule you switched on evaluates it on our server.
04Who else sees your requests
Price data is fetched by your browser, directly from the provider. The provider therefore sees that request and your IP address, and its own privacy policy applies to it:
- Binance public market data — for crypto symbols. No key, no account.
- Twelve Data — for Gold and Forex, using the key you supply.
- Supabase — authentication and the rows listed above.
- Vercel — hosting. It serves the pages and keeps standard server logs.
- Razorpay — only if you buy a plan, and only on their own payment page. See clause 5.
- Telegram — only if you set up alerts, and only for the messages we send to the chat id you gave us.
That is the entire list. There is no analytics script, no advertising network, no tracking pixel and no session recorder in this app — you can confirm it by viewing the page source.
05Payments
Subscriptions are taken through Razorpay. The payment page is theirs, and your card number, UPI id or netbanking login is entered there — it never reaches this app or its database, so there is nothing of it here to leak or to hand over. Razorpay is the data controller for that step and its own privacy policy applies to it.
What comes back to us is only what is needed to switch the plan on and to answer a billing question: the payment and order id, the amount, whether it succeeded, and the resulting plan and expiry date on your account. Refunds are issued back to the same method for the same reason — we could not send money anywhere else even if you asked, because we do not have the details. See Refunds & Cancellation.
06Cookies and similar storage
The app uses browser storage for the two purposes described above: keeping you signed in (Supabase Auth) and remembering your own work and preferences. There are no advertising or cross-site tracking cookies, so there is nothing here to consent to for marketing purposes.
07How long it is kept, and how to delete it
- Browser data — until you clear it. Deleting a strategy in My Strategies removes the device copy immediately.
- Saved strategies in your account — until you delete them, which the same button does.
- Terminals, rules and queued orders — until you delete the terminal, which takes its rules and their order history with it. Deleting is never gated by a plan.
- Payment records — the id, amount and plan of each charge are kept for as long as tax and accounting law requires, even after the account is deleted. That is the one thing an erasure request cannot remove.
- The account itself — email mahidaammar1@gmail.com from the address you signed up with and it will be deleted, with everything attached to it, within 30 days.
08Your rights
You can ask for a copy of what the account holds, ask for it to be corrected, or ask for it to be erased. Write to mahidaammar1@gmail.com and expect a reply within 30 days. If you are in the EU or UK, the lawful basis for holding your email is the contract to provide you the service; for everything else it is your own instruction to save it.
09Children
This is a financial-analysis tool and is not intended for anyone under 18. We do not knowingly create accounts for minors. If you believe one exists, write to us and it will be removed.
10Security
The site is served only over HTTPS. Database access uses a public, restricted key together with row-level security, so one account cannot read another's rows; the privileged service key exists only in the server environment and is never shipped to the browser. No system is perfect, and nothing here should be read as a guarantee against a breach — but the smaller the pile of data, the smaller the loss, which is why so much of this product keeps its data on your own machine.
11Changes
If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and the new version replaces this page. Continuing to use the app after that means the new version applies.
12Contact
mahidaammar1@gmail.com — for privacy questions, deletion requests, or anything on this page that is not clear. See also the Terms of Service and the contact page.