1.Who we are and what this covers
TradeMirrorly provides the service described in this policy and is responsible for the personal information described here. We are based in United States, at 604 C. Hoare, San Juan, Puerto Rico, 00907, United States. Contact: support@trademirrorly.com.
This policy covers the TradeMirrorly account portal, licensing and account APIs, desktop service integrations, inbound webhooks, downloads, billing integration and remote support. It does not replace the policies of your broker, Telegram, Google, Whop or a separately operated website you visit. Information reaches us from you, your connected desktop app, your configured webhook senders, Google when you choose Google sign-in, and Whop when you pay.
2.Local credentials and server-held information
In normal desktop operation, your Telegram sign-in/session credentials and broker login credentials are kept on the computer or VPS where you run the desktop app and trading terminal. The TradeMirrorly licensing API does not request or store these credentials.
Local credential storage does not mean TradeMirrorly holds no personal information. Our servers store your TradeMirrorly account profile and password hash where set, license and device records, trading-account identifiers, signal commands, webhook message bodies, billing records and support records. Optional remote-support recordings are stored on our support infrastructure. The sections below explain these records and their retention.
Google handles your Google authentication, and Whop and its payment providers handle checkout payment credentials. Neither is a credential stored only in the desktop app. If you put a secret into a webhook message, send it to support or display it during recorded remote support, it can become part of those server-held records.
Keeping trading credentials on your device reduces central credential collection; it does not make a device or service completely secure. Protect your computer or VPS, its backups and account access. The security measures and choices below still apply.
3.Information we process
Account and identity. Your name, email, customer ID, email-verification status, password hash if you set a password, account dates and sign-in records. We also keep verification and reset-code hashes and account preferences such as dismissed release announcements.
Google profile. When supplied by Google: a unique Google account identifier, verified email, full/given/family name, profile-picture URL, language or locale, organization domain and the time the profile was refreshed. The next section explains this optional connection.
Licenses and devices. Plan, license status and expiry, license-key records, activated device identifiers, computer name, operating system, app version, last contact and IP address. We use these to provide access and enforce purchased device and account limits.
Trading-account details. Account number, broker server, MT4/MT5 platform, your label and account-addition/removal dates. The licensing API does not ask for or store your broker password. Trading-account identifiers are still personal information when linked to you.
Channels and signal history. Selected channel identifiers/names, linked accounts, signal times, command type, instrument, side, parsed EA command and blocked reasons. This history does not store the original Telegram message text. It records reported commands, not a verified record of fills, balances, profit or loss.
Webhook content. Your webhook name, URL token, authentication settings and secret hashes; accepted message bodies, content type, sender IP and time; and acceptance/rejection counters. Unlike signal history, the webhook service stores the incoming message body so the desktop app can retrieve it. Do not put passwords or unnecessary personal information in messages.
Purchases. Whop customer, plan and membership identifiers, subscription status, billing periods, cancellation and access dates, and payment-event payloads sent by Whop. Those events can include customer and transaction details. Checkout payment credentials are collected by Whop and its payment providers, not by a card-entry form on this portal.
Support and security. Correspondence, diagnostics you choose to provide, support permissions and connection records, screen recordings as described below, license audit events, IP addresses, request/browser metadata and download records.
4.Signing in with Google
Google sign-in is optional; email registration is also available. We request identity, email and basic profile scopes to create or authenticate your account, link a Google identity to an existing account, show your profile picture and help secure sign-in. We do not request access to Gmail, Drive, contacts, calendars or your Google password.
The profile information above is stored with your account and refreshed when you sign in with Google. Google access and refresh tokens are not persisted in our account database. Your browser may contact Google to load your profile picture. We do not use Google profile data for advertising, sell it, or use it to train general-purpose AI models. If your Google email becomes your account email, it is also used for account messages, support and the Whop checkout you initiate.
You can remove TradeMirrorly access in your Google Account connections settings. This does not delete the TradeMirrorly profile already stored. Contact us to request deletion or disconnection; establish an email/password sign-in method first if you want to keep using your account. Google separately controls information it processes for its own services.
5.How and why we use information
We use the information needed to operate your account, activate licenses, synchronize permitted accounts and sources, deliver webhooks, show your history, provide installers and updates, reconcile payments, communicate about your service and answer support requests.
Where data-protection law requires a legal basis, processing necessary to provide the service you request relies on our contract with you or steps taken at your request before a contract. Security, abuse prevention, troubleshooting and defending claims rely on our legitimate interests, balanced against your rights. Required accounting, regulatory and legal records rely on legal obligations. Where consent is required for optional access or recording, we seek that consent and you can withdraw it for future processing.
Required account and licensing information is necessary to supply the corresponding service; without it we may be unable to create an account, activate a device or provide paid access. Optional Google sign-in and remote support are not required to buy a plan. Reading this policy is not consent to unrelated marketing or optional tracking.
6.Remote support and recordings
You enable remote support in the desktop app for a particular computer. While enabled, authorized support staff can connect to view your screen and use support chat. Remote control, clipboard sharing and file transfers depend on the permissions you grant and the staff member's permissions. Access remains enabled until you turn it off or the session is ended; a fresh approval is not requested for every staff connection.
Support connections are configured to be screen-recorded for accountability and support review. Recordings may contain anything visible on your screen, including messages or financial information. Close unrelated windows and hide sensitive information before enabling support. Turn support off in the app to end access. Ordinary email support remains available without granting remote access.
We keep the device/session identifiers, permitted actions, staff identity, connection times, IP/network details and event metadata. File-transfer events can include a filename, size and outcome. Screen recordings are stored by our separate support infrastructure; access to recordings is permission-controlled and recorded. We do not promise that every connection will produce a complete recording if the connection or upload fails.
7.Who receives information
Authorized personnel and providers supporting hosting, network security, email delivery, payments and support infrastructure receive information needed for those purposes. Whop receives your account email and purchase-linking metadata when you start checkout and sends us membership/payment updates. Google handles the sign-in you choose.
The portal loads fonts or icon styles from Fontshare and jsDelivr, and Google-hosted profile images when used. These services can receive your IP address and browser/request metadata. Network-security providers such as Cloudflare may process requests and technical identifiers. Telegram, your broker and any webhook sender process the information you send through their services under their own policies.
We may disclose relevant records where legally required, to address abuse or defend legal claims, or in a business transfer subject to applicable safeguards and notice requirements. We do not sell personal information or share it for cross-context behavioral advertising.
8.Cookies and browser features
The account portal uses cookies needed to keep you signed in, protect forms against forged requests and display account messages. The sessionid cookie normally lasts up to 14 days; csrftoken normally lasts up to 364 days and may be renewed. Temporary message cookies clear after the message is read. Signing out ends your portal session. Blocking these cookies can prevent sign-in, checkout initiation or form submission.
We do not currently add advertising pixels or audience-tracking scripts to the account portal. Security providers may use additional cookies to prevent abuse, and Google or Whop may use their own cookies on their services. The time-savings calculator runs in your browser: its assumptions are not saved or sent to us. Cookie settings can be managed in your browser. Any future optional tracking will need its own disclosure and any consent required by law.
9.How long information is kept
Scheduled deletion is not instantaneous at the stated cutoff. We assess other retained records by purpose and legal need when handling a deletion request. We do not promise that closing an account immediately removes every payment, support or backup record.
Signal history. Events older than 365 days are removed by the scheduled daily cleanup. Selected-source snapshots are updated as the app reports its configuration.
Webhook messages. Messages older than 7 days are removed by the scheduled daily cleanup. Removing a webhook also removes its stored messages.
Support recordings and events. Recordings are scheduled for deletion after 30 days. Detailed support events older than 365 days are cleaned up daily. Session and connection summary records are retained separately for accountability and disputes; they are not subject to that event-cleanup deadline.
Account, license and billing records. These do not have a single automatic expiry. Retention depends on active access, required financial records, security and dispute needs, applicable limitation periods and valid deletion requests. Canceling a plan does not by itself delete the account or its records.
Authentication, correspondence and backups. Verification/reset codes expire after 10 minutes; expired code records and expired login sessions are cleaned up daily. Correspondence, technical logs and backups follow their operational retention cycles. Information needed for a specific legal obligation or dispute may need to be preserved longer; restricted backup copies can remain until their normal replacement cycle.
10.Security and international processing
We use HTTPS for public service connections, hashed passwords and authentication secrets, access controls and signed license tokens. These measures reduce risk but cannot guarantee absolute security. Tell us promptly if you believe your account or webhook URL has been compromised. Never send us passwords, one-time codes, private signing keys or complete payment-card details in a support request.
Our infrastructure and providers may process information outside your country, where legal protections can differ. A transfer requiring additional legal protection must use an applicable lawful mechanism, such as an adequacy decision or appropriate contractual safeguards. Contact us for information about locations and safeguards relevant to your data. We do not represent that every provider stores data in your home country.
11.Your choices and privacy rights
You can edit supported profile details in the portal, stop a configured signal source, remove a webhook, cancel a subscription or turn off remote support. For access, correction, deletion, a portable copy, restriction or an objection to processing, contact support@trademirrorly.com. Your available rights depend on applicable law. You may also withdraw consent where we rely on it, without affecting processing already lawfully carried out.
We may need proportionate verification of your identity before acting. Explain the request and use your account email where possible; do not include your password. We will respond within the applicable legal deadline and explain any lawful restriction or extension. You may complain to the data-protection authority responsible for your location. We will not penalize you for exercising privacy rights.
License limits, abuse checks and payment updates can automatically restrict access. Contact us for review if you think a restriction is wrong. We do not use portal activity to provide investment advice or make trading decisions for you.
12.Age requirements and policy changes
TradeMirrorly is intended for adults aged 18 or older who can enter a binding contract. We do not knowingly offer the service to children. Contact us if you believe a child has provided personal information so we can investigate and take appropriate action.
We will update the effective date when this policy changes and provide appropriate notice of material changes. If a new use requires consent, publication alone will not replace that consent. Questions about this policy can be sent to support@trademirrorly.com.
Contact
TradeMirrorly
604 C. Hoare, San Juan, Puerto Rico 00907, United States
support@trademirrorly.com