Privacy policy.
FX Patrol is a solo personal project. The data collection here is the minimum needed for the service to work — there is no analytics platform, no advertising network, no third-party data sharing for marketing. This page describes what's actually collected and why.
1 · What we collect
- Email address — required to identify your account across sessions, and used to send password-reset links and any account or billing notices.
- Display name — what we greet you with in the app and on your account page. Optional if you sign in with Google (we use the name your Google account provides).
- Password (hashed) — stored as a bcrypt hash if you sign up with email/password. The plaintext is never stored. If you only ever sign in with Google, no password is stored at all.
- Google account identifier — if you sign in via Google, we store the unique account ID Google provides (the "sub" claim) so future Google sign-ins resolve to the same account.
- Display preferences — which panels and central banks you've hidden and how you've ordered them. Saved per account so the terminal looks the same on next login.
- Push subscription details — if you previously turned on browser notifications, the endpoint URL + keys your browser provided are stored on your account. The alerts they carried were tied to the retired AI engine, so nothing is sent to them now.
- Trade Journal entries — only if you use it: the trades you record or import, including entry/exit, size and P&L, plus (optionally) an encrypted OANDA read-only API token used to import closed trades. Deleting the account or the connection removes them.
- Replay sessions, lesson progress and pair notes — if you use the replay, learning or notes features, the sessions, progress and notes you create are saved to your account.
- Server logs — our host (Oracle Cloud, London region) records HTTP request logs for ~7 days for debugging and abuse prevention. Standard practice; we don't have a separate analytics layer.
2 · What we don't collect
- Broker logins or anything that can move money. There is no execution layer. The only broker-related item we ever hold is an optional OANDA read-only token for the Trade Journal import, stored encrypted and removable at any time.
- Bank or card details. We don't ask for, store, or process bank details or card numbers. (If you use the optional Trade Journal, the profit/loss figures of the trades you import or enter are stored on your account — see section 1 — but nothing that could move money.)
- Behavioural analytics. No Google Analytics, no Hotjar, no Mixpanel, no advertising pixels, no remarketing tags.
- Your conversations with anyone else. We read no messages you exchange outside FX Patrol — no inbox access, no DMs, no monitoring of any other service.
- Anything sent to an AI model. The in-app AI assistant and the AI engine behind the old directional views were retired in September 2026, and nothing you do in the app is sent to a model provider any more. Conversation records written while the assistant existed remain on the account until you ask for them to be deleted — see section 3.
3 · How long we keep it
Account data stays for as long as your account exists. If you ask for your account to be deleted, we erase your user row and any data tied to it (preferences, push subscriptions, etc.) within 30 days. To request deletion, email help@fxpatrol.com.
Market data — prices, calendar releases, news headlines, indicator readings and the rest of what the terminal displays — is kept indefinitely so that historical charts and series stay complete. None of it is personal data and none of it links back to your account.
4 · Third parties
The minimum third-party services involved are:
- Oracle Cloud Infrastructure — our hosting provider. Sees the same server-log data we do.
- Market data and news providers — the exchanges, statistics offices, central banks, newswires and publications the app pulls from. We fetch their public feeds from our own server; your browser is not sent to them and they receive nothing about you.
- Google — only if you choose to sign in with Google. Google handles authentication; we receive your verified email + name. See Google's own privacy policy for what they hold.
- Web Push services (Mozilla / Apple / Google) — only if you opt into browser notifications. They relay the notification to your device; we don't share the message content with them beyond what's needed to deliver it.
- Resend — used to send password-reset emails on the rare occasion you request one. Stores the recipient email + the message it sent for delivery logs.
5 · Your rights
Under UK GDPR you have the right to access, correct, or delete the personal data we hold about you, and to object to processing or request data portability. Email help@fxpatrol.com and we'll handle it within 30 days. If we ever process anything in a way you think violates your rights, you also have the right to complain to the UK Information Commissioner's Office (ICO).
6 · Changes to this policy
If the policy materially changes — e.g. if a new analytics layer gets added, or a new third party processes your data — we'll update this page. You're encouraged to check it occasionally. There's no email blast when it changes; this is a small enough operation that flooding inboxes would feel disproportionate.