This Privacy Policy explains what data Return Metrics collects when you use our web application at returnmetrics.co, how we use it, who we share it with, how long we keep it, and the rights you have over it. We keep this policy short, plain-spoken, and free of legalese wherever possible. If anything is unclear, email us and we will explain in your own language.
01Data we collect
Account data
When you register we collect your email address, display name, and — for password-based accounts — a bcrypt-hashed password (never the plain-text value). If you sign in with Google we additionally receive your Google profile ID, name, and (optionally) a profile picture. We never receive your Google password.
Trading data
Every trade, note, tag, reflection, screenshot, and CSV import you enter is stored in a private MongoDB instance and encrypted in transit. This data is only visible to you and to Return Metrics staff performing debugging or support with your explicit permission.
Public share cards
By default your account has a public share card at returnmetrics.co/u/{handle} showing aggregate statistics only (total P&L, win rate, best pair, equity sparkline). It never shows your notes, screenshots, entries, exits, or individual trade rows. You can flip this to private in Settings at any time.
Lead-magnet submissions
If you submit the Roast My Trades, Trading Style Diagnostic, Book a Demo, or newsletter opt-in form, we store your name, email, optional social handle, the answers you gave, and any notes. These entries flow into our admin lead inbox so a human can respond.
Payment data
Payments are processed by Stripe. We never see, transmit, or store your full card number. Stripe returns a customer identifier and a "last-four" preview to us for receipts, invoices, and refunds.
Usage & session data
We log basic technical information: IP address, browser type, request paths, response codes, and error events. For product improvement we also use PostHog for anonymised session replays and event analytics. IP addresses are used for rate limiting and fraud prevention and are truncated in long-term storage.
02How we use your data
- Run the Service — authenticate you, show your ledger, generate statistics, produce AI-powered auto-tags, reflections, and answers.
- Transactional email — via Resend: welcome, password resets, demo confirmations, admin lead notifications, weekly digests, trial nudges, and the Sunday tape.
- Payments & billing — via Stripe, to charge your card and manage subscriptions, refunds, and referral credits.
- Product improvement — anonymised or aggregated usage patterns, feature-flag experiments, and A/B tests.
- Security & fraud prevention — rate limiting, brute-force lockout, referral-abuse detection, and audit trails.
- Legal compliance — when required by law, court order, or lawful government request.
We do not use your data for behavioural advertising. We do not sell, rent, or share your data with data brokers, ad networks, or affiliate partners.
03Sub-processors
Return Metrics depends on a small number of infrastructure vendors to operate the Service:
- Emergent — application hosting, MongoDB, and object storage for screenshot uploads.
- OpenAI (via Emergent LLM) — powers Edge AI features (GPT-5.2). Prompts include your recent trades and the specific question asked, but no personal identifiers beyond your account context. OpenAI does not train on API traffic sent through this integration.
- Stripe — payment processing. Governed by Stripe's own privacy policy.
- Resend — transactional email delivery (welcome, password reset, receipts, digests, newsletter, lead notifications).
- Google (OAuth) — only if you choose to sign in with Google.
- PostHog — anonymised product analytics and session replays. Text is masked by default.
- Plausible — privacy-first, cookie-less page-view analytics for the marketing site.
- Frankfurter — public FX rates used to compose the Sunday tape newsletter. No personal data is sent.
We audit our sub-processor list regularly and will notify you of material changes.
04Cookies & tracking
We use two httpOnly cookies for authentication (a short-lived access token and a longer-lived refresh token). Both are marked Secure, HttpOnly, and SameSite=None so they only travel to our own API over HTTPS and cannot be read by JavaScript.
We do not use advertising cookies. Plausible is cookie-less. PostHog uses a first-party identifier for session continuity and can be reset from the client-side "Do Not Track" browser signal.
05Data retention
- Your trades, reflections, and account are kept for as long as your account is active.
- Individual trades you delete are removed immediately from the primary database.
- If you delete your account, we remove your trades, reflections, broker accounts, preferences, AI conversation history, and referral records within 30 days. Anonymised logs (with truncated IPs) may persist longer for security audits and legal compliance.
- Stripe retains payment records for legally required periods (typically 7 years) independent of your Return Metrics account status.
- Backups roll off within 30 days.
06Your rights
Depending on where you live (GDPR / UK GDPR / CCPA / other applicable law), you have the right to:
- Access the personal data we hold about you.
- Correct any inaccurate or incomplete data.
- Export your data in a machine-readable format (CSV / JSON).
- Delete your account and all associated Content.
- Object to certain kinds of processing, including analytics tracking.
- Withdraw consent for optional processing at any time.
- Lodge a complaint with your local data-protection authority if you believe we have mishandled your data.
To exercise any of these rights, email contactreturnmetrics@gmail.com from the address on file. We will respond within 30 days at no cost to you.
07Security
Return Metrics implements industry-standard technical and organisational measures to protect your data:
- Passwords stored as bcrypt hashes with a cost factor of 12.
- JWT session tokens delivered via HttpOnly, Secure cookies only.
- Brute-force lockout (5 failed attempts within 15 minutes) at the login endpoint.
- Rate limits on registration, password-reset, and public lead-magnet endpoints.
- All data in transit is encrypted with TLS 1.2+ (HSTS enabled).
- MongoDB is only accessible from our backend network — never exposed to the public internet.
- Least-privilege access controls on backend services and staff accounts.
No system is perfectly secure. If we ever suffer a data breach that affects your personal data, we will notify you and any required authorities within 72 hours as required by law.
08International transfers
Our primary infrastructure is hosted in the United States. If you access the Service from outside the US, your personal data may be transferred to, stored, and processed in the US and other countries where our sub-processors operate. Where required, we rely on Standard Contractual Clauses or equivalent legal mechanisms to protect these transfers.
09Changes to this policy
We may update this policy as the product evolves. Material changes will be announced at least 14 days in advance via email or an in-app notice. The "Last updated" date at the top always reflects the current version. Continued use of the Service after the change date constitutes acceptance of the updated policy.