Table of contents
Privacy Policy
How RuleGate processes account, trading, integration, billing, technical, and consent data.
Who controls your data
The data controller is Andrey Boyukliev, Independent developer and operator of RuleGate, Burgas, Bulgaria. RuleGate determines why and how personal data is processed for the Service.
Privacy requests may be sent through Contact or to privacy@rulegate.app.
Data map and lawful bases
Account and access
- Data:
- Supabase user ID, email, display name, role, plan, access source, and account timestamps.
- Purpose:
- Create and secure accounts, provide features, support users, and enforce access.
- Legal basis:
- Contract; legitimate interests in security and support; legal obligation where applicable.
- Recipients:
- Supabase, Vercel, and authorized support or administrative personnel.
Trading and journal
- Data:
- Symbols, direction, quantity, entry/exit, PnL, fees, timestamps, sessions, plans, Gate Checks, journal notes, reviews, emotions, mistakes, discipline labels, and screenshots.
- Purpose:
- Provide journaling, review, statistics, discipline scoring, calendar history, and user-requested analysis.
- Legal basis:
- Contract; legitimate interests in improving and securing the Service.
- Recipients:
- Supabase, Vercel, and integration providers only where needed for a user-authorized workflow.
Integrations
- Data:
- Platform, connection ID, account label, masked identifier, status, permission summary, encrypted credentials or tokens, sync timestamps, provider metadata, and imported trade IDs.
- Purpose:
- Connect authorized accounts, import history, prevent duplicates, troubleshoot, and secure synchronization.
- Legal basis:
- Contract; legitimate interests in reliability, fraud prevention, and security.
- Recipients:
- The chosen broker, exchange, MetaApi, Supabase, and Vercel as applicable.
Billing
- Data:
- Stripe customer/subscription/Price IDs, plan, billing status, period dates, cancellation state, invoices, and payment status.
- Purpose:
- Run subscriptions, provide access, handle billing support, disputes, accounting, and fraud controls.
- Legal basis:
- Contract; legal obligation; legitimate interests in preventing fraud and resolving disputes.
- Recipients:
- Stripe, Supabase, Vercel, and professional advisers where legally necessary.
Administration
- Data:
- Complimentary grants, reasons, internal support notes, role changes, and audit logs.
- Purpose:
- Provide support, manage access, investigate incidents, and preserve accountability.
- Legal basis:
- Legitimate interests; contract; legal obligation where applicable.
- Recipients:
- Authorized owner/admin personnel and infrastructure providers.
Technical and security
- Data:
- IP address received by infrastructure, browser/device details, request and error logs, security events, cookie IDs, consent choices, and timestamps.
- Purpose:
- Deliver and protect the Service, diagnose faults, prevent abuse, and preserve consent evidence.
- Legal basis:
- Legitimate interests; legal obligation; consent for optional cookies.
- Recipients:
- Vercel, Supabase, Stripe for checkout security, and relevant security providers if later configured.
Future analytics and marketing
- Data:
- Page views, usage and conversion events, referrals, affiliate attribution, campaign data, and advertising identifiers.
- Purpose:
- Measure product performance and campaigns or provide consented marketing.
- Legal basis:
- Consent where required. Optional providers remain disabled until the relevant consent is given.
- Recipients:
- Only providers listed in the Cookie Policy or Subprocessors page when actually configured.
Payments and card data
Stripe hosts Checkout and Customer Portal. RuleGate receives billing identifiers, subscription state, invoice or payment status, and period dates needed to provide access. RuleGate does not receive or store full card numbers, CVCs, or complete payment credentials.
Security and minimisation
RuleGate limits collection to information needed for the Service and uses safeguards appropriate to the type of data.
- Supabase Row Level Security limits browser database access to authorized rows.
- Service-role keys, Stripe secrets, integration tokens, and encryption keys remain server-side.
- Integration credentials and OAuth tokens are encrypted at rest before database storage.
- Private screenshot storage uses user-scoped paths and signed access.
- Administrative and billing actions are checked server-side and recorded where appropriate.
- Stripe webhook signatures are verified before subscription access is updated.
- No analytics, advertising, or affiliate script is installed globally by this release.
No method of storage or transmission is completely secure. Users should protect account credentials and avoid putting unnecessary personal or broker-security information in notes and screenshots.
Retention
Retention depends on the purpose, account status, security needs, provider capabilities, and applicable legal obligations. RuleGate does not publish an exact period until it can be operationally enforced.
Account profile
Kept while the account is active. After a verified deletion request, account data is deleted or anonymized unless a legal or security reason requires limited retention.
Journal and trading data
Kept while the account is active so the Service can provide journals, plans, reviews, statistics, and history. Users may request export or deletion.
Trade screenshots
Kept with the associated account and journal content until removed or the related account data is deleted, subject to limited backup retention.
Integration metadata
Kept while an integration is connected and as needed to preserve imported trade provenance, troubleshoot synchronization, and protect the Service.
Encrypted integration credentials
Kept only while required to operate an authorized connection. Credentials are invalidated or deleted when the connection is disconnected or the account is deleted.
Temporary OAuth sessions
Used only to complete and secure an authorization flow and retained no longer than operationally necessary.
Billing records
Subscription and transaction records are kept for billing administration, dispute handling, fraud prevention, and applicable accounting or legal obligations.
Security logs
Kept for a limited period proportionate to detecting abuse, investigating incidents, and protecting accounts and infrastructure.
Operational and error logs
Kept for a limited period needed to diagnose errors, maintain reliability, and prevent repeated failures.
Administrative audit logs
Kept as needed to preserve the integrity of access grants, role changes, support actions, and account-security investigations.
Legal and consent records
Kept as evidence of the version, time, source, and choices associated with an account or browser consent decision.
Marketing consent
Kept until consent is withdrawn and afterwards only as needed to record and respect the withdrawal.
Deleted-account backups
Residual copies may remain in restricted backups for a limited recovery period and are not restored for normal product use.
Processors and international transfers
RuleGate uses service providers for hosting, authentication, storage, billing, and user-authorized integrations. Some may process data outside Bulgaria or the European Economic Area. Depending on the provider and route, transfers may rely on adequacy decisions, standard contractual clauses, or another lawful safeguard.
See the Subprocessors page for current provider categories, purposes, and links. RuleGate does not invent guarantees beyond each provider's actual arrangements.
Your data-protection rights
Subject to applicable GDPR conditions and exceptions, you may request:
- access to personal data and information about its processing;
- correction of inaccurate or incomplete data;
- deletion of data;
- restriction of processing;
- portability of data you provided in a structured, commonly used format;
- objection to processing based on legitimate interests or direct marketing; and
- withdrawal of consent at any time, without affecting earlier lawful processing.
RuleGate may need to verify identity and may retain limited information where law, billing, fraud prevention, security, or legal claims require it. You may complain to the Bulgarian Commission for Personal Data Protection or another competent supervisory authority. The Bulgarian authority provides complaint information at cpdp.bg.
Analysis and profiling
RuleGate may calculate discipline scores, summaries, statistics, classifications, and future behavioural Insights from account and trading data. These tools are intended to help users reflect on execution quality. They may be incomplete, delayed, or incorrect.
RuleGate does not currently make solely automated decisions that produce legal or similarly significant effects. Users remain responsible for trading and account decisions.
Export and account deletion
Signed-in users can download a copy of core user-owned data from Settings. To request correction or deletion, use the Privacy & Data section or email privacy@rulegate.app.
Before deletion, resolve any active subscription. A verified request will address the profile, application state, journal and imported data, integration credentials and metadata, and screenshots. Limited billing, fraud, consent, security, or audit records may remain when law or legitimate protection requires. Restricted backup copies may remain until their normal expiry.
Changes and contact
Material policy changes will be communicated appropriately and may require a new acknowledgement or consent. Cosmetic edits do not automatically trigger a new consent request. Contact RuleGate through the Contact page.