Last updated: 2026-05-13

Privacy Notice

Plain language. What we collect, why we collect it, who can see it, and how to make us forget you.

What Wedge actually is

Wedge is a structured-friction journaling tool for futures traders. We read trade data from your broker via a read-only OAuth connection and from a desktop plugin you install on your own machine. We do not place trades, modify orders, or transfer funds. We never will.

What we collect

  • Account data: email, password hash (managed by Supabase Auth), full name (optional), trading handle (optional), prop firm (optional), broker (optional).
  • Trade data:fills, positions, order timestamps, contract names, prices, quantities, and account-level P&L — fetched via read-only broker API.
  • Pattern detection events: when our software observes a pattern (e.g., consecutive losses, position-size doubling), we record the event and your response to it (paused / proceeded / cancelled).
  • OAuth tokens: access and refresh tokens for your broker, stored encrypted at the column level via Supabase Vault (pgsodium). We never see your broker password.
  • Operational logs: minimal request logs for debugging — no full request bodies, no PII in logs.
  • Usage analytics:pageviews, referrers, approximate region (derived from IP, not stored as IP), and Core Web Vitals performance metrics. Collected via Vercel Analytics and Vercel Speed Insights — cookie-less, no cross-site tracking. See “Sub-processors” below.

We do not collect facial images, voice recordings, biometric identifiers, location data, contacts, or device IDs. We do not run microphone or webcam access on any surface, ever.

GLBA — Why this is a financial-aggregator notice

Wedge connects to your prop-firm or broker account in a read-only capacity. We are functionally a financial data aggregatorunder the Gramm-Leach-Bliley Act (GLBA) for US users. This notice describes what we share and why. You can opt out of non-required sharing at any time by emailing us (see “Your rights” below).

GDPR / international users

For users in the EU/UK/EEA, we operate under Standard Contractual Clauses (SCCs) plus a Data Processing Agreement (DPA), not residency in the EU. If you need a copy of our DPA before signing up, email us. We honor data subject access requests (DSARs) within 30 days, or 72 hours for verified deletion requests.

CCPA — California residents

You have the right to know what personal information we collect, to delete it, to correct it, and to opt out of sale or sharing. Wedge does not sell personal information, period. To exercise any CCPA right, email us at privacy@wedge.app (or whatever the live contact channel is). We will not charge you, and we will not discriminate.

Do Not Sell My Data

We do not sell or license data — including anonymized or aggregated data — to anyone. This is a permanent covenant, not a current policy. If we ever changed this, every user would receive 60-day notice and the right to delete before any sharing began.

Data retention + deletion

  • Active accounts: we keep your data as long as your account is active.
  • Soft delete (30 days): if you delete your account or close your subscription, data is marked for deletion and recoverable for 30 days.
  • Archive (60 days after soft delete): data moves to encrypted cold storage and is not accessible to product systems.
  • Permanent deletion: 90 days after soft delete, all archived data is destroyed.
  • Hard delete on request: on a verified deletion request, we destroy your data within 72 hours and confirm in writing.

Your rights

You can, at any time:

  • Request a copy of your data (machine-readable export).
  • Correct any field on your account.
  • Delete your account (soft, then permanent — see above).
  • Revoke broker OAuth access from this app, or from inside your broker portal.
  • Opt out of any marketing emails (transactional emails like password reset are required for service).

Security

OAuth tokens are encrypted at the column level via Supabase Vault (pgsodium). All traffic uses TLS 1.2+. Database access is restricted to the application service role and a small number of named operators. Row-level security policies ensure your data is only readable by you and mentors you explicitly invite (and only in read-only mode, with the scope you grant).

Sub-processors

We use a small number of vendors to operate Wedge. Each one is bound by a Data Processing Agreement (or equivalent) and only receives the data needed for its function.

  • Supabase (database, auth, encrypted token storage) — account data, trade data, pattern events, OAuth tokens. Hosted in the US.
  • Vercel(application hosting + edge runtime) — request routing, TLS, static assets. Hosted globally via Vercel's edge network.
  • Vercel Analytics (product analytics) — pageviews, referrers, approximate region. Cookie-less, no cross-site tracking, no advertising identifiers.
  • Vercel Speed Insights (performance telemetry) — Core Web Vitals (LCP, FID, CLS) sampled per visit. No personal data.
  • Your broker / prop firm(Tradovate, Topstep, Apex, etc.) — the source of your trade data, accessed via read-only OAuth. We don't share data back; we only read.

We will give 30 days' notice on this page before adding any new sub-processor that receives identifiable user data.

Contact

Questions, requests, or complaints: privacy@wedge.app. We will respond within 5 business days for inquiries and within the regulatory window for any rights request.