Privacy Policy

Last updated: 18 August 2026

This Privacy Policy explains how Monitron (“Monitron”, “we”, “us”) collects, uses, and protects your personal data when you use monitron.co.uk and the associated services (the “Service”). Monitron is operated by Justin Sutherland, a sole trader based in the United Kingdom, at Flat 12 Aspire Residence, Union Grove, Aberdeen, AB10 6TH, United Kingdom (“the data controller” for the purposes of UK GDPR).

1. What we collect

  • Account data: name, email address, hashed password, tier/subscription status.
  • Fitness & wellness data: workouts, training plans, mobility sessions, nutrition and sleep logs, wearable data synced from connected integrations.
  • Trading data: trade logs you enter (pairs/instruments, direction, entry/exit, P&L, notes, screenshots), and TradingView indicator access status.
  • AI analysis outputs: narrative summaries and confluence/quiz results generated from your trade and lesson data.
  • Payment metadata: subscription/purchase status, price paid, and billing history. We do not collect or store your card details — these are handled entirely by Stripe (see §3).
  • Integration data: data and access tokens from any third-party account you choose to connect (Strava, Spotify, Garmin, Whoop, Oura, Gmail, Outlook), scoped to what each integration needs to function.
  • Technical data: IP address, device/browser information, and error/crash reports (via Sentry).

2. Why we process your data, and our lawful basis

  • Providing the Service (contract) — creating your account, storing your logs, generating dashboards and analysis, granting access to purchased content.
  • Payments (contract / legal obligation) — processing purchases and subscriptions via Stripe, and keeping records required by UK tax law.
  • Product improvement and error monitoring (legitimate interests) — using Sentry to detect and fix bugs.
  • Communicating with you (contract / consent) — service emails (verification, password reset, receipts) and, where you’ve opted in, product updates.
  • AI-assisted analysis (consent / contract) — sending your trade data to our AI provider to generate the analysis you’ve requested.

3. Who we share data with (sub-processors)

We use the following third parties to run the Service. Each only receives the data it needs to perform its function:

  • Stripe — payment processing. Stripe receives your payment details directly; Monitron never sees your full card number.
  • Anthropic — processes your trade data and lesson activity to generate AI narrative analysis and quiz/signal parsing, under Anthropic’s commercial API terms.
  • Sentry — error monitoring. Request data is scrubbed of sensitive fields before being sent.
  • Resend — sends transactional email (verification, password reset, receipts).
  • Cloudinary — stores images/media you upload (e.g. trade screenshots).
  • Railway and Vercel — hosting infrastructure for our backend and frontend respectively.
  • Strava, Spotify, Garmin, Whoop, Oura, Google (Gmail/Calendar), Microsoft (Outlook) — only if you explicitly connect these integrations, to sync the specific data each integration provides.

We do not sell your personal data.

4. International transfers

Some of our sub-processors (including Anthropic, Stripe, and Sentry) may process data outside the UK/EEA, including in the United States. Where this happens, we rely on appropriate safeguards such as Standard Contractual Clauses or the provider’s own adequacy certifications.

5. How long we keep your data, and how deletion works

We retain account and trading data for as long as your account is active. You can delete your account at any time from Profile → Danger Zone by re-entering your password to confirm. This schedules permanent deletion of your account and all associated data in 30 days — long enough to recover from an accidental or impulsive request. Simply logging back in during that 30-day window automatically cancels the pending deletion. After 30 days, deletion is permanent and cannot be undone, except where we’re required to retain certain records for longer (e.g. financial records for tax purposes, typically 6 years).

6. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure of your data
  • Object to or restrict certain processing
  • Request a portable copy of your data
  • Withdraw consent at any time where processing is based on consent

Most of these are self-service: edit your details directly in your Profile settings to correct inaccurate data, use Profile → Export My Data to download a complete, portable copy of everything we hold on you as a JSON file, and use Profile → Danger Zone → Delete Account to request erasure (see §5 above for how that works). For anything else — objecting to processing, withdrawing consent, or any question about your data — contact us at support@monitron.co.uk. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.

7. Cookies

We use essential cookies/local storage only, to keep you signed in and remember your preferences. We do not currently use analytics or marketing cookies. If that changes, this policy and a cookie consent banner will be updated before any non-essential cookies are introduced.

8. Security

We use industry-standard measures — encrypted connections (HTTPS), hashed passwords, and access controls — to protect your data. No system is 100% secure, and we encourage you to use a strong, unique password.

9. Contact

Questions about this policy or your data: support@monitron.co.uk.