Privacy
Last updated: July 2026
A trading journal holds two sensitive things at once: your money and your state of mind. This page says plainly what Kaizen stores, who touches it, and what control you keep. The short version: your journal is yours, nobody at Kaizen can read it, and you can take it or delete it whenever you want.
What we store
- Account data: email, optional username and name, hashed password (we never see the password itself), sign-in method.
- Journal data: daily sessions (including emotional-state entries and notes), trades and their rule checkboxes, chart screenshots you paste, weekly/monthly reviews, patterns and touches.
- Product data: plan and subscription status, AI-coach usage counts and token totals (never the content of coach conversations beyond your journal itself), support tickets you file, and coarse activity timestamps (e.g. "last seen" to the hour).
Who can read your journal
Only you. Kaizen's administrative tools operate on account metadata — email, plan, activity dates, usage counts. The permission to open a user's journal does not exist in the system, and an automated test fails our builds if anyone tries to add one. Support staff answering your ticket see the ticket, not your journal.
The one exception is the one you create: you can invite a mentor to view your journal, read-only. That access exists only while your explicit grant is active — you can revoke it at any moment, the change is immediate, and every view your mentor makes is logged where you can see it. Mentors can never write to your journal, never use AI features on your data, and staff roles gain nothing from the feature: without your grant, there is no door.
Processors we use
- Anthropic (Claude API) — only when you use an AI coach feature: the relevant slice of your journal is sent for that request, used to generate the response, and not used to train models (per Anthropic's commercial terms).
- Revolut — payments. Your card details go to Revolut directly; Kaizen never sees or stores them.
- Resend — transactional email (verification, password reset, ticket replies, billing notices). Your email address only.
- Hosting — the application and its database run on our own servers in a datacenter; screenshots are stored on encrypted disks there.
Bring-your-own-Notion
If you connect your own Notion workspace, your journal lives in your Notion, under your account, and Kaizen reads and writes it through the token you grant. That token is stored encrypted (AES-256-GCM) and can be disconnected anytime from Settings. Notion's own privacy policy applies to data stored there.
Your rights (GDPR and common sense)
- Export: Settings → Danger zone → export gives you everything we hold about you, in machine-readable form, self-serve.
- Deletion: Settings → Danger zone → delete removes your account with a 7-day grace period (sign back in within 7 days to undo); after that, journal, screenshots, and account data are purged. Financial records Revolut requires us to keep are retained per their terms.
- Correction: everything in the journal is yours to edit at will.
What we don't do
- No selling data, no ad networks. Analytics is privacy-first and cookieless (self-hosted Umami) — page views and anonymous usage only, never personal data, cross-site tracking, or your journal content.
- No training AI models on your journal.
- No reading your journal for "quality" or "moderation."
Contact
Privacy questions: file a ticket from Settings → Help, or write to the address on the site footer of your instance.