Skip to content

RuleCord · Last updated 6 October 2026

Privacy Policy

This Policy explains information handling in RuleCord. Shazil Saif, operating RuleCord, is responsible for the application’s information handling. Contact support@rulecord.com for privacy questions or requests. Business/contact address: pending confirmation.

1. Information we handle

Account information includes email, authentication identifiers, profile/display information, verification state, preferences and recorded disclaimer acknowledgments. Supabase Auth handles credentials, sessions, verification and password-reset flows; passwords are not stored in RuleCord application profile rows.

Trading information includes the profiles, plans, strategies, rules, trades, recorded outcomes, journal entries and reflections you provide, together with derived adherence metrics and analytics. Chart evidence includes uploaded images, annotations/coordinates, associated trading context and generated chart interpretations.

Solis information includes selected trading context, prompts, journal/reflection content used for feedback, AI responses, job status/history and usage/quota accounting. Billing information includes checkout attempts, mapped customer/subscription/payment identifiers, payment amounts/statuses, verified period dates, cancellation/failure state and retained webhook/correlation evidence. RuleCord does not receive or store your full card number or card security code; Dodo handles payment details.

Technical information can include request times, IP addresses and device/browser information handled by hosting/auth/payment services, session cookies, security/error classifications and operational identifiers. Support emails contain the address and information you choose to share. Do not send passwords, card data or broker credentials to support or put them in chart/journal content.

2. Why information is used

We use information to create and authenticate accounts, provide journaling/rule tracking/analytics, generate requested or in-product AI feedback, manage subscription access, answer support requests, prevent abuse, troubleshoot and meet applicable financial/legal obligations. We process service data to perform our agreement with you, protect legitimate security/operational interests, comply with applicable obligations, and obtain consent where required by law.

RuleCord is not designed to sell personal information or deliver targeted advertising. We do not use journal content for advertising. Authentication/session cookies and local appearance preferences support the service; they are not a claim that third-party providers collect no technical data.

3. AI processing and your trading content

Production Solis currently uses OpenAI through a server-side API. Relevant trading/rule context, supplied chart images and reflection content may be sent to OpenAI to generate feedback. Some review paths use limited recent excerpts; other paths use the full reflection for the reviewed trade or previous day. Do not assume that only short excerpts are processed. Normal prompts do not intentionally include your account email or payment credentials, but personal information you put in free text or images can be included.

AI processing is part of the current service, not controlled by the one-time disclosure acknowledgment. There is no separate in-app AI-processing opt-out setting at present. Avoid submitting content you do not want processed this way, and contact support about your choices. Provider retention and processing are also governed by its API terms and your applicable rights; we do not promise zero retention, specific training treatment or a particular processing location without a verified applicable arrangement.

4. Service providers and disclosures

Supabase provides authentication, the application database and private chart storage. Vercel hosts the application, durable Solis Workflows and scheduled recovery/housekeeping. OpenAI processes Solis inputs to produce AI feedback. GoDaddy/Titan email infrastructure supports support correspondence and transactional email delivery, with Supabase initiating authentication emails. Error monitoring, when configured, uses Sentry with sanitized application context.

Dodo Payments is Merchant of Record and independently handles payment collection, transaction taxes, fraud/compliance checks, billing documents and payment disputes. Its own privacy/purchase terms apply to information it collects. We share the account/billing information needed to establish and manage your purchase, not your trading journal for payment processing.

We may disclose information when legally required, to protect security or legal rights, or to providers performing the functions above. Providers may process information in countries other than yours. Applicable transfers require appropriate legal safeguards; we do not promise all data stays in India or any particular region. Contact support for information about applicable arrangements.

5. Retention and account requests

Account and trading/journal records generally remain available while the account is maintained; cancellation of renewal does not erase them. There is no universal automatic deletion deadline for all account data. Billing/payment/checkout/webhook evidence is retained for ownership, financial audit, dispute handling and applicable obligations. Account retirement can preserve the application user and its billing history rather than hard-delete those relationships.

Uploaded chart evidence is marked to expire after 24 hours. Scheduled housekeeping subsequently removes expired chart files and post-trade coordinates; this is not a guarantee of deletion at the exact 24-hour instant. Temporary post-trade chart-review history is eligible for retirement after seven days. Other trading records, generated reviews, operational metadata, backups and provider-held records can have different retention. Failed cleanup is retried; provider backups and legally retained records are not erased merely because a file expires.

Contact support@rulecord.com to request access, correction, account retirement/deletion or other applicable privacy rights. We verify ownership before acting, explain records that must be retained and handle requests subject to applicable law. There is no public one-click deletion tool or guaranteed instant erasure. Do not send identity documents unless we establish a necessary secure verification process with you.

6. Security, choices and updates

We use server-side authentication and ownership checks, restricted database/browser access, private chart storage, HTTPS and scoped server credentials. No system is guaranteed secure. Protect your account and promptly report suspected misuse. You can update supported preferences, reset your password and manage your subscription through the application. Any applicable access, deletion, objection, portability or complaint rights can be raised with support or the relevant authority.

RuleCord is intended for adults, not children under 18. Contact support if you believe a child has submitted personal information. We update this Policy as the service changes and provide notice of material changes where appropriate. Operator address and jurisdiction-specific privacy disclosures should be completed before broader public launch.

Questions? support@rulecord.com