Privacy Policy

Last updated: September 9, 2026

This Privacy Policy explains what information Choptick collects, how we use it, and the choices you have. Choptick is operated by Innovizea LLC, an Idaho limited liability company ("Innovizea," "we," "us"), which is responsible for the personal information described here. This Policy covers the Choptick website at choptick.app and the Choptick mobile app for Android and iOS (together, the "Service"). By using the Service, you agree to this Policy.

We built Choptick to hold sensitive trading records, so the short version is simple: your data is yours, we don't sell it, we don't run ads, and every account's data is isolated from every other account's.

1. Information we collect

2. How we use your information

3. How your data is protected

Passwords are hashed with bcrypt. Authenticated requests use signed tokens, and every database query is scoped to your account so one user cannot access another's data. The Service runs over encrypted HTTPS on infrastructure with an encrypted data volume, and we keep encrypted backups, on and off the server, to prevent data loss (see section 4a). No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of trading records.

4. Service providers

We rely on a small number of third parties to run Choptick. They process data only to perform services for us, under contract, and are not permitted to use it for their own purposes. We do not sell your personal information or your trading content to anyone, and we do not share it for advertising.

ProviderWhat it doesWhat it receives
Fly.io Hosting. The Service and its database run on Fly.io infrastructure in the United States. Everything you store in Choptick, because the database itself lives there.
Cloudflare R2 Off-site backup storage. A complete encrypted copy of the database, uploaded daily — see “Backups” below.
Stripe Payments, subscriptions and billing-related tax calculation for paid plans. Your name, email address, billing address and payment details. Card numbers go directly to Stripe and never reach Choptick's servers — we store only a customer and subscription reference.
Resend Delivery of transactional email (verification, password reset, and alerts you have enabled). Your email address and the contents of those messages.

If we add or change a provider that receives your personal information, we will update this section and the “Last updated” date.

4a. Backups, and where your data is copied

We state this separately because it is the one place your information routinely leaves the machine that serves the Service. A complete copy of the Choptick database — which includes every user's account record and trading content — is made automatically each day and uploaded to encrypted off-site object storage (Cloudflare R2). Backups exist so that a hardware or hosting failure cannot destroy your trading history, and they are the reason a lost server does not mean a lost journal.

Off-site copies are encrypted at rest, are accessible only to Choptick's operator, and are automatically deleted on a rolling schedule (currently 90 days). A copy is also kept on the server's own storage volume, retained for the most recent 30 backups.

5. Third-party platforms you connect

If you connect a platform such as TradingView or NinjaTrader, data flows from that platform into Choptick through a tool you install. Those platforms have their own privacy practices, which we do not control. You can revoke a connection token at any time from the Connections page, which stops further syncing.

6. Your choices and rights

To make a request, contact us at the address below.

7. Data retention

We keep your information for as long as your account is active or as needed to provide the Service. Deleting your account removes your personal information and trading content from the live Service immediately. Copies inside existing backups are not individually erased — a backup that could be edited would not be a reliable backup — but they age out automatically on the rotation described in section 4a, currently within 90 days. We may retain limited records where required for legal, tax, or security purposes.

8. The mobile app, cookies, and local storage

On the website, Choptick uses your browser's local storage to keep you signed in (an authentication token) and to remember your theme preference. The Choptick mobile app stores your sign-in token and basic profile on your device using the operating system's secure storage, so you stay signed in between sessions.

The mobile app contains no advertising and no third-party analytics, tracking, or advertising SDKs. We do not use cross-site or cross-app tracking, and we do not track you across other apps or websites. The app communicates only with Choptick's own servers over encrypted HTTPS, and we do not sell or share your personal information or trading content for advertising.

9. Children

Choptick is not directed to anyone under 18, and we do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date and, where appropriate, communicated to you. Your continued use of the Service after an update constitutes acceptance of the revised Policy.

11. Contact

Questions or privacy requests? Contact Innovizea LLC at support@innovizea.com. We are the operator of Choptick and the party responsible for the personal information described in this Policy.