No trading, transfer or withdrawal permissions.
Privacy and security
This policy explains which data PnLFlow needs to operate the trading journal, how it is used and how the service protects it.
Last updated: September 13, 2026API credentials are encrypted before storage.
You can disconnect an exchange and request data deletion.
1. Scope
This policy applies to pnl-flow.com, its language subdomains and the PnLFlow dashboard. By creating an account or using the service, you acknowledge this policy.
2. Data we process
- Account data: email, user identifier, language and subscription status.
- Journal data: trades, fees, PnL, balances, positions, strategies, notes and risk settings.
- Connection data: exchange, synchronization status, update time and error messages.
- Payment and referral data: plan, amount, payment status and identifier, referral attribution and payout details.
3. How data is used
Data is needed for registration and sign-in, exchange synchronization, analytics calculations, saving settings, processing payments, operating the referral program, support and abuse prevention.
PnLFlow does not sell personal data and does not use API keys to execute trades.
4. Exchange API keys and security
Create a separate API key with read permissions only. Trading, transfers and withdrawals must remain disabled.
- The service may reject a connection when trading permissions are detected.
- The secret portion of a key is encrypted before storage and is not returned to the browser after connection.
- PnLFlow never asks for a seed phrase, wallet private key or two-factor authentication code.
- You can revoke an API key in your exchange account at any time.
5. Payments and external providers
Authentication and database services are provided through Supabase. Cryptocurrency invoices and payment confirmations are handled by NOWPayments. Exchanges provide data under their own API terms. These providers may process necessary technical data under their own policies.
PnLFlow receives the payment status, amount and identifier required to activate a plan and record referral commission. The service does not request card details or wallet private keys.
6. Cookies and local storage
Necessary cookies and local storage preserve the session, language, theme, interface preview and referral attribution. Referral attribution is stored for up to 30 days. Disabling required cookies may prevent sign-in and dashboard functionality.
7. Storage, deletion and your rights
Data is retained while your account is used and as needed to operate the service, maintain security and account for payments. Some records may temporarily remain in backups or technical logs.
You may request access to your data, correction of inaccurate data or deletion of your account. Account ownership verification may be required to prevent unauthorized requests.
8. Responsibility and contact
No online service can guarantee absolute security. You are responsible for protecting your email, password, device and exchange account. If compromise is suspected, revoke the API key at the exchange immediately and contact support.
This policy may be updated when service features or legal requirements change. The current version is always published on this page.