Privacy Policy

Last updated: May 2026

1. What Cadence Is

Cadence is a trading performance and journaling platform. We collect data you provide to help you track, reflect on, and improve your trading practice.

2. What We Collect

  • Account info — name, email (via Clerk authentication)
  • Trading data — trade records uploaded via CSV or entered manually
  • Journal content — check-in responses, intentions, reflections, diary entries, notes
  • Habit data — daily habit selections
  • Health data — sleep, readiness, HRV, heart rate, stress, activity, resilience, and other biometric data from connected wearables (Oura Ring, Whoop, Apple Health, Garmin). This data is fetched only with your explicit OAuth consent or device permission and stored securely in your account.
  • Usage data — pages visited, features used (for improving the product, never for advertising)

3. What We Don’t Collect

  • We don’t collect broker credentials or passwords
  • We don’t access your brokerage accounts directly
  • We never sell, license, lease, or rent your data to outside parties — not advertisers, not data brokers, not third parties. Our wearable partners’ API agreements prohibit it too. (Sharing specific entries with your own mentor or buddies is different — that only ever happens when you choose to.)
  • We don’t use cookies for tracking or advertising — authentication cookies only

4. How We Use Your Data

  • Your entries, intentions, and reflections are private to you by default — other members never see them unless you explicitly share a category or grant journal access (controlled per-category in Settings)
  • Display your trading journal, analytics, and health metrics to you
  • Run pattern detection to surface insights about your performance
  • Correlate health metrics with trading performance (only visible to you)
  • Send notifications you’ve opted into
  • Improve the product using anonymized, aggregated usage data

5. Health Data (Wearables) — General

  • Health data from any wearable provider is only accessed after your explicit OAuth consent or device-level permission
  • Your health data is stored in your account and only visible to you
  • Health data is never used for advertising, marketing, data mining, or sold to any third party under any circumstances
  • You can disconnect any wearable at any time in Settings, which immediately stops all future syncing and permanently deletes all health data from that provider in your account
  • We do not share your health data with other users — your buddy, pod, or Pit connections cannot see your wearable data
  • Health metrics are displayed as raw numerical data only. We do not diagnose, interpret, or draw clinical conclusions about your health status
  • Correlations between health metrics and trading performance (e.g. “days after good sleep you averaged +$380”) are observational and informational, not medical or clinical advice
  • Your wearable data may require an active subscription with the wearable provider for API access to function (e.g. Oura Membership for Gen3/Ring 4 users)

6. Health Data — Provider-Specific Requirements

Oura Ring

  • Oura health data is cached for a maximum of 59 days per the Oura API Agreement Section 7. Data older than 59 days is automatically purged from our database via a daily cleanup process.
  • If you disconnect your Oura account, all Oura-sourced data is immediately and permanently deleted.
  • In the event of a security breach involving Oura data, we will notify Oura within 24 hours and affected users promptly.
  • We comply with all terms of the Oura API Agreement.

Apple HealthKit

  • Each health data type requires separate explicit consent. We request only the minimum data types needed to provide the service (sleep, heart rate, activity).
  • Health data accessed through HealthKit is never used for advertising, marketing, or data mining.
  • We comply with Apple App Review Guideline 5.1.3 and all HealthKit developer requirements.
  • If you revoke HealthKit permissions in your device’s Privacy & Security settings, we can no longer read your health data.

Whoop

  • Our integration is subject to Whoop’s review and approval process.
  • Health data accessed through the Whoop API is never sold, licensed, or leased to any third party, even with user consent. This is explicitly prohibited by Whoop’s API Terms of Use.
  • Developer credentials are stored server-side only, never in client code or open source.
  • We comply with all terms of the Whoop API Terms of Use.

Future Wearable Integrations (Garmin, etc.)

Any future wearable integrations will follow the same principles: explicit consent, no selling or sharing, delete on disconnect, comply with provider terms.

7. Data Storage & Security

  • Data stored on Convex (database) and Vercel (hosting), both SOC 2 compliant
  • Authentication handled by Clerk
  • All connections encrypted via HTTPS/TLS
  • OAuth tokens stored server-side only, encrypted at rest
  • Your journal entries are stored as text so Cadence can power the features you rely on — search, pattern insights, and (when you opt in) mentor review — rather than being end-to-end encrypted. They’re encrypted in transit and at rest at the infrastructure level, kept private to you, and never shown to other members unless you choose to share them.
  • We are not a covered entity under HIPAA — wearable health data stored in Cadence does not receive HIPAA protection. However, we treat all health data as sensitive and follow GDPR-aligned practices regardless of jurisdiction.

8. Your Rights

  • View all your data within the app
  • Export your data (CSV export of trades)
  • Delete your account and all associated data by contacting us
  • Disconnect any wearable at any time — all data from that provider is immediately deleted
  • Opt out of any notifications
  • Request a copy of your stored data

9. Third-Party Services

  • Clerk (authentication)
  • Convex (database)
  • Vercel (hosting, plus cookieless usage & performance analytics)
  • Oura (health data, only when connected by you)
  • Whoop (health data, only when connected by you)
  • Apple HealthKit (health data, only when permitted by you)
  • Stripe (payments, when active)

None of these services receive your health data for their own advertising or marketing purposes.

10. Cookies

Authentication cookies only (Clerk session). No tracking cookies, no advertising cookies, no third-party analytics cookies. We use Vercel’s privacy-friendly analytics to measure page views and loading performance — it is cookieless and collects no personally identifying information.

11. Data Retention

  • Account data — retained while your account is active. Deleted upon account deletion request.
  • Trading data — retained while your account is active.
  • Journal content — retained while your account is active.
  • Oura health data — automatically purged after 59 days per Oura API Agreement.
  • Other wearable health data — retained while your account is active and the wearable is connected. Deleted immediately on disconnect or account deletion.
  • Usage & performance analytics — aggregated, cookieless page-view and loading-speed metrics processed by Vercel. Contains no personally identifying information.
  • Error logs — diagnostic crash reports used to fix bugs, automatically deleted after 30 days, and erased on account deletion.

12. Security Breaches

In the event of a data breach, we will notify affected wearable providers within 24 hours (per Oura API Agreement and as best practice for all providers) and notify affected users promptly with details about the breach and steps taken.

13. Changes

We may update this policy. Changes posted here with updated date. Continued use after changes constitutes acceptance.

14. Contact

Questions? Email privacy@cadence.trade