TradeItAll

Privacy and security

Plain answers to the questions that matter when software can touch your trading accounts.

What we store

Your email, a one-way hash of your password (we can't read it), your broker username, your broker API key encrypted with a key that never leaves our server environment, the accounts and copy groups you set up, and a log of every order the copier sent or skipped and why.

We also keep an activity log of sign-ups, logins, failed logins, and changes to your connections and groups, with the IP address they came from. That log is how we spot someone trying to get into your account.

What we never do

We don't sell or share your data. We don't show your API key to anyone, including our own staff. We never copy another person's trades into your account, and we never copy yours into anyone else's.

How the site defends itself

Every form is protected against cross-site forgery. Login attempts are rate-limited per connection and locked per account after repeated failures. Broker connections are rate-limited so keys can't be sprayed at the form. Sessions expire, cookies are HTTP-only and secure, and pages refuse to load inside other sites. Backups are taken daily.

If we go down while you're in a trade

TradeItAll never stands between you and your broker. Your broker platform keeps working, and you can always close positions there. Each group has a kill switch, the dashboard has a stop-everything button, and a flatten button closes follower positions when the platform is up. Copies that were not sent are never sent later; you decide.

Deleting your account

Delete my account on the dashboard removes your account, connections, encrypted keys, groups, and copy log immediately. Backups holding that data expire on their own within 60 days.

Questions: support@tradeitall.io