Privacy Policy

Last updated: 30 September 2026

This Privacy Policy explains how Monitron (“Monitron”, “we”, “us”) collects, uses, and protects your personal data when you use monitron.co.uk and the associated services (the “Service”). Monitron is operated by Justin Sutherland, a sole trader based in the United Kingdom, at Flat 12 Aspire Residence, Union Grove, Aberdeen, AB10 6TH, United Kingdom (“the data controller” for the purposes of UK GDPR).

1. What we collect

  • Account data: name, email address, hashed password, tier/subscription status.
  • Fitness & wellness data: workouts, training plans, mobility sessions, nutrition and sleep logs, wearable data synced from connected integrations.
  • Trading data: trade logs you enter (pairs/instruments, direction, entry/exit, P&L, notes, screenshots), and TradingView indicator access status.
  • AI analysis outputs: narrative summaries and confluence/quiz results generated from your trade and lesson data.
  • Payment metadata: subscription/purchase status, price paid, and billing history. We do not collect or store your card details — these are handled entirely by Stripe (see §3).
  • Integration data: data and access tokens from any third-party account you choose to connect (Strava, Spotify, Garmin, Whoop, Oura, Gmail, Outlook), scoped to what each integration needs to function.
  • Technical data: IP address, device/browser information, and error/crash reports (via Sentry).
  • Messages you send us: feedback and support requests, with the page you sent them from and your screen size and browser attached so we can reproduce any problem.
  • Visit statistics: the page you viewed, the site that linked you here, any campaign tag in the link (such as utm_source), whether you were signed in, and whether you used a phone. No cookies are used and nothing is stored on your device. To count each visitor once per day, we combine your IP address and browser details with a random value that we replace and delete every day, and keep only the resulting code; your IP address itself is not stored, and visits can’t be linked across days or to your account. We keep these statistics for about 13 months.

2. Why we process your data, and our lawful basis

  • Providing the Service (contract) — creating your account, storing your logs, generating dashboards and analysis, granting access to purchased content.
  • Payments (contract / legal obligation) — processing purchases and subscriptions via Stripe, and keeping records required by UK tax law.
  • Product improvement and error monitoring (legitimate interests) — using Sentry to detect and fix bugs, and counting visits and sign-ups (the visit statistics above) to understand which pages and campaigns work.
  • Communicating with you (contract / consent) — service emails (verification, password reset, receipts) and, where you’ve opted in, product updates.
  • AI-assisted features (consent / contract) — sending the relevant data to our AI provider to generate the analysis, reflection, or briefing you’ve requested.

3. Who we share data with (sub-processors)

We use the following third parties to run the Service. Each only receives the data it needs to perform its function:

  • Stripe — payment processing. Stripe receives your payment details directly; Monitron never sees your full card number.
  • Anthropic — processes data to generate the AI features you use, under Anthropic’s commercial API terms: trade data and lesson activity for narrative analysis and quiz/signal parsing; journal entries for the daily reflection feature; and, if you generate a Morning Briefing or use its chat assistant, the context that feature is built from — emails and calendar events (only if you’ve connected Gmail/Outlook), tasks, readiness/wellness data (sleep, mood, stress, training desire), and trading/news data for that day.
  • Sentry — error monitoring. Request data is scrubbed of sensitive fields before being sent.
  • Resend — sends transactional email (verification, password reset, receipts).
  • Cloudinary — stores images/media you upload (e.g. trade screenshots).
  • Railway and Vercel — hosting infrastructure for our backend and frontend respectively.
  • Strava, Spotify, Garmin, Whoop, Oura, Google (Gmail/Calendar), Microsoft (Outlook) — only if you explicitly connect these integrations, to sync the specific data each integration provides.

We do not sell your personal data.

4. International transfers

Some of our sub-processors (including Anthropic, Stripe, and Sentry) may process data outside the UK/EEA, including in the United States. Where this happens, we rely on appropriate safeguards such as Standard Contractual Clauses or the provider’s own adequacy certifications.

5. How long we keep your data, and how deletion works

We retain account and trading data for as long as your account is active. You can delete your account at any time from Profile → Danger Zone by re-entering your password to confirm. This schedules permanent deletion of your account and all associated data in 30 days — long enough to recover from an accidental or impulsive request. Simply logging back in during that 30-day window automatically cancels the pending deletion. After 30 days, deletion is permanent and cannot be undone — this includes your trading journal and account data in full. We do not retain a copy of your data after your account is purged.

6. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure of your data
  • Object to or restrict certain processing
  • Request a portable copy of your data
  • Withdraw consent at any time where processing is based on consent

Most of these are self-service: edit your details directly in your Profile settings to correct inaccurate data, use Profile → Export My Data to download a complete, portable copy of everything we hold on you as a JSON file, and use Profile → Danger Zone → Delete Account to request erasure (see §5 above for how that works). For anything else — objecting to processing, withdrawing consent, or any question about your data — contact us at support@monitron.co.uk. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.

7. Cookies

We use essential local storage only, to keep you signed in. We do not currently use analytics or marketing cookies. See our Cookie Policy for full detail, including the third-party cookies set by Stripe during checkout.

8. Security

We use industry-standard measures — encrypted connections (HTTPS), hashed passwords, and access controls — to protect your data. No system is 100% secure, and we encourage you to use a strong, unique password.

9. Contact

Questions about this policy or your data: support@monitron.co.uk.