Privacy Policy
Scope. This policy covers the TradeRange website at traderange.net, the share host at trge.link, and the TradeRange apps distributed through the Google Play Store, the Apple App Store, and as a direct-download Android APK. Each app is a bundled version of the same website and follows the same practices described here, connecting to the same API (api.traderange.net). Points that are specific to the app are collected in Section 7. Where we store data — including on servers in the United Kingdom, the EEA, and the United States — is in Section 8.
Who operates TradeRange. The TradeRange service — the website, the API at api.traderange.net, and the account, settings, and gameplay data described in this policy — is operated by the TradeRange maintainers under the tradely.dev community. The TradeRange apps are distributed through the Google Play Store, the Apple App Store, and as a direct-download Android APK. The terms “we,” “us,” and “TradeRange” in this policy mean those operators.
1. What We Collect
Discord, Google, and GitHub OAuth2 identifiers (pseudonymous) – When you log in using Discord, Google, or GitHub, we receive provider identifiers needed to recognise you across sessions. For Discord: Discord ID, username, and avatar URL. For Google (OAuth 2.0): Google ID (sub), public profile name, and profile picture URL. For GitHub (OAuth 2.0): GitHub numeric user ID, public login (handle), and avatar URL. We explicitly do NOT request or store your email address, phone number, real name, birthday, or any other personal data from these providers. Google’s email scope is never requested; if Google provides email by default in the ID token, we discard it immediately and do not write it to disk or logs. GitHub is requested with the identify-only read:user scope — we do not request user:email, and we do not store a GitHub email if one is present on the profile object. Each provider ID acts as a pseudonymous key.
Profile pictures are served only from TradeRange. Provider avatar URLs are stored privately on our servers and fetched once by our backend proxy. Every profile picture you see on the site — leaderboards, public profiles, your account page — is served from api.traderange.net/api/avatar/… as a cached WebP on our domain. We never expose the original Discord, Google, or GitHub CDN link to your browser.
Cookies and localStorage – Essential browser storage: we store a session token (expires after 30 days) and a CSRF protection token. No third-party tracking cookies are placed without explicit consent. These mechanisms are strictly necessary for authentication and game functionality. If you open an article while signed out, we also keep a compact reading list in localStorage (tr_lesson_reads) so catalogs can mark what you have already opened and surface the next unread piece. That list stays on your device until you sign in (when it is merged into your account) or you clear site data.
Campaign landing – If you arrive through a campaign link such as /ad/?src=… (for example from Reddit), we store a short source label on your device (localStorage key tr_ad_attr and a first-party cookie) and, if you then sign in, on your account as signup_source. We use this only to see which channels bring players. It is first-touch (a later visit does not overwrite it), is not used for advertising targeting, is included in Settings → Your data, and is deleted with your account. The /ad/ page itself is excluded from search indexes and from our sitemap.
Share-link attribution – Copied links include a share_id query parameter that identifies the person or campaign who shared the URL. Opening one stores that identifier on your device (first-party cookies named tr_share_id and tr_share_vid, plus a localStorage record). If you then create an account, we send you through /botcheck/ (a Cloudflare challenge) on that first sign-in so we can tell a person from an automated script, and we record the referral on your account. We use this to see which links bring players, to prevent self-referral and duplicate conversion, and to review abuse. It is first-touch (a later share link does not overwrite it), is not used for advertising targeting, is included in Settings → Your data, and is deleted with your account. /botcheck/ is excluded from search indexes and from our sitemap.
Article reading progress (signed-in) – When you are signed in and open a Learn, Analysis, or Blog article, we record that you opened it, roughly how far you scrolled, time spent on the page, and whether you finished it (scrolling most of the way through, or an explicit completion). We use this only to order unread and in-progress articles ahead of ones you have already finished. Pins set by editors always stay first. We also keep anonymous pair counts — that article A and article B were both read, with no user identifier on that table — so related articles can surface. This data is included in Settings → Your data, is merged if you link Discord, Google, and/or GitHub, stays on this profile if you later unlink a sign-in method, and is deleted with your account. It is never used for advertising.
Recommendation quality (signed-in) – When you are signed in, we also record that a catalog or next-up list was shown, and whether you opened a recommended article from it (or went on to a second article shortly afterwards). We use this only to measure whether those recommendations were useful, on an aggregate admin screen with no account identifiers. These events are kept for 90 days, then deleted, and they are deleted with your account. They are not used for advertising.
Google Analytics (optional, consent-based) – Only after you accept the cookie consent banner, we load Google Analytics 4 (GA4). GA4 collects anonymised usage data (page visits, time on site, game interaction events). No Discord ID, Google ID, GitHub ID, or any OAuth identifier is ever sent to Google. You may reject the banner, and GA will never load or transmit data. Withdraw consent: on the website, open Settings → Ads & analytics (from your profile) to change or fully withdraw your analytics and advertising consent at any time, or use the “Show the consent banner again” reset there. Clearing your browser cookies and localStorage also resets your preference and re-shows the banner.
Advertising (Google AdSense — website only) – The TradeRange website displays advertisements served by Google AdSense to keep TradeRange free and fund its continued development. To do this, Google and its advertising partners use cookies, device identifiers, and similar technologies, and may collect information such as your IP address, approximate location, browser and device characteristics, the pages you view, and your interactions with ads. Depending on your consent choice, ads may be personalised (based on this data and your prior activity) or non-personalised (based only on general context such as the page content and coarse location). We do not share your Discord ID, Google ID, GitHub ID, username, or gameplay records with Google for advertising. Details, the legal basis, and how to opt out are in Section 6. The apps show no third-party ads — AdSense is not loaded inside the Android or the iOS app.
Operational logs (security & anti-abuse) – We log core interactions with the Service: games played, answers submitted, leaderboard updates, API calls, page requests, and significant in-app actions. A log entry may include the timestamp, your OAuth identifier (Discord ID, Google ID, or GitHub ID) where you are signed in, your IP address, and request metadata (user agent, accept-language, and the viewport your browser reports). We use these logs to detect cheating, brute-force attempts, scraping, and other abuse, and to keep the Service available and fair. IP handling: an IP address is held in readable form for up to 7 days, the window in which an attack is still worth investigating; after that it is replaced by a salted, keyed SHA-256 hash that lets us recognise repeat abuse without recovering the address. Some records — short-link visitor counts, for example — never store an IP at all, only such a hash from the outset. The whole log record, hashed IP included, is deleted after 90 days. All retention periods are collected in Section 9.
Data stored on your device (app) – The app — on both Android and iOS — additionally keeps data locally on your device for offline use and preferences: a cache of already-viewed articles and images; articles you explicitly download for offline reading (a complete copy of the article — its text, images, and the market data behind its charts — kept on your device for up to 7 days and then cleared automatically); your cookie-consent choice; and your notification settings. This stays on your device, is not transmitted to us as a separate collection, and is removed when you uninstall the app or clear its storage. See Section 7.
Device push token (app, optional) – If you enable notifications in the app, we collect and store a push notification token issued for your device/install by the push notification service used to deliver them, solely to send you the notifications you asked for. It is a pseudonymous device identifier, is not linked to your real-world identity, and is deleted when you disable notifications or uninstall the app.
Authenticator (optional TOTP) – You may turn on an authenticator app from Settings. We store an encrypted copy of the authenticator secret. We never store the 6-digit codes you type. After you confirm a code, later sign-ins ask for a fresh code from the app. Optional. If you lose the device, an administrator can remove the authenticator so you can sign in with Discord, Google, or GitHub again. Enabling it signs other sessions out. It is included as an on/off flag in Settings → Your data (not the secret) and is deleted with your account.
RSS and Atom feeds – The public feeds at /rss/ are static files. We do not require an account to subscribe, we do not put tracking pixels or unique identifiers in the feed files, and we do not know who subscribed. Fetching a feed is an ordinary HTTP request for a public file; like any other page, that request may appear in operational and CDN logs as described above and in Section 6 (Cloudflare). Those logs are not a subscriber list. Your feed reader is a third party with its own privacy policy. See Section 16.
Share links (trge.link) – When you share a multiplayer room, a scheduled lobby, an article, a game, or a calculator, the copied URL is on trge.link (for example https://trge.link/p/… or https://trge.link/t/…) and includes the share_id described above. Opening that URL records that the link was used, then redirects you to the matching page on traderange.net with the share id still on the query string. We store a visitor identifier — a first-party cookie named trge_vid on trge.link, or, on a first visit with no cookie, a hash derived from your IP address and browser user-agent so the same client still counts as one visitor. We do not store the IP itself, we do not use the short-link hit identifier for advertising, and we do not treat a crawler unfurl as a referred visit. Known automated crawlers (for example link-preview bots) still follow the redirect so a shared link can unfurl, but they are not counted as visitors. The person-check at /botcheck/ runs only after a referred visitor signs in for the first time, not when the share link is opened. Short-link hit records are kept for 90 days, then deleted, the same retention as other interaction logs. The trge_vid cookie lives only on trge.link; it is not set on traderange.net.
2. How We Use & Protect Information
- Operate the leaderboard, persist game progress, keep your reading list, and personalise which unread articles surface next.
- Detect and block automated scripts, multiple-account abuse, and score manipulation using heuristic analysis on logged actions.
- Attribute a new account to the person or campaign whose shared link you opened, after a successful person-check, so we can see which links bring players and review abuse.
- Debug performance, improve game designs, and understand aggregate usage (with anonymized analytics only after consent).
- Enforce Terms of Service (e.g., suspend accounts that violate fair play or API abuse).
- Security protections: All data transmitted via TLS 1.3 (HTTPS). The SQLite database is encrypted at rest (SQLCipher) and stored files — avatars, uploads, private configs, backups — are encrypted with AES-256-GCM. Live operational log files remain plaintext so they can be tailed. Access to the hosts is restricted to the core maintainers. Those hosts may be in the United Kingdom, the EEA, or the United States (see Section 8). API endpoints implement strict rate limiting, brute-force protection, and request signing where appropriate. No OAuth tokens are retained after session termination; we store only the opaque reference to your Discord/Google/GitHub ID, not the access tokens themselves. No service can promise perfect security. These are the measures we take and keep current; they reduce risk but cannot eliminate it, and nothing in this policy is a warranty or guarantee that our systems, or the third parties in Section 6, will never be compromised. Section 11 describes what we do if a breach occurs.
Advertising supports the free service. TradeRange is provided free of charge and is funded in part by advertising. We do not share your OAuth ID (Discord ID, Google ID, or GitHub ID), username, or gameplay logs with advertisers or data brokers. However, to show ads, our advertising partner (Google) and the vendors it works with set cookies and process device and usage data as described in Sections 1 and 6. Under some privacy laws (for example, the California CPRA), enabling interest-based advertising may be considered a “sale” or “sharing” of personal information. You control this: declining our consent banner (or opting out through the Google controls linked in Section 6) limits ads to non-personalised. Separately, we may disclose information (a) as required by law; (b) to protect the rights, safety, or property of TradeRange and its users; or (c) with your explicit consent.
3. OAuth Provider Disclosures
TradeRange offers sign-in with Discord, Google, and GitHub solely for authentication and identification. Administrators can turn any of these methods off from the admin panel; a method that is off will not appear on the login page and will refuse new OAuth attempts, while existing sessions remain valid until they expire.
TradeRange’s usage of Google OAuth 2.0 adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request only the
profilescope (Google ID, name, profile picture). No email, Google Drive, Calendar, Contacts, or any other scope is requested. - Google user data (your Google ID, public profile info) is never transferred to third parties, used for advertising, or stored longer than necessary.
- You can revoke TradeRange’s access to your Google account at any time via your Google Account permissions page. Revocation will prevent future sign-ins, but your existing gameplay data remains associated with the Google ID; to delete that data completely, please request deletion as described in Section 12.
- We DO NOT combine Google authentication data with any external database for targeting or enrichment.
TradeRange’s usage of GitHub OAuth is likewise identify-only:
- We request only the
read:userscope (GitHub numeric ID, public login, avatar). We do not requestuser:email, repository access, or any organization permission. - GitHub user data is never transferred to third parties, used for advertising, or stored longer than necessary. We do not store your GitHub access token after the login handshake.
- You can revoke TradeRange’s access at any time from your GitHub Authorized OAuth Apps (or GitHub App installations) page. Revocation will prevent future sign-ins; existing gameplay data remains associated with the GitHub ID until you delete the TradeRange account as described in Section 12.
- We DO NOT combine GitHub authentication data with any external database for targeting or enrichment.
If you sign in with one provider and later link another from Settings, those logins become one account: the same public profile, combined scores, and one display name. Linking asks you to confirm both sessions. Until you link them, separate Discord, Google, and GitHub sessions stay distinct accounts.
4. Your OAuth Identifier Is Your Account Key
Your Discord ID, Google ID, or GitHub ID is the sole binding key to your TradeRange account: it ties together scores, settings, and history. If you delete that provider account or permanently lose access, you will not be able to recover your TradeRange progress unless you can re-authenticate with the exact same identifier, or with another provider after you have linked it in Settings. We strongly recommend linking the methods you use from Settings – but due to pseudonymous design, no password recovery exists.
5. Cookies, Local Storage & Consent Banner (Enhanced Transparency)
Strictly necessary storage: a session token (localStorage) and CSRF cookie. These do not require consent because the service cannot function without them. Opening a share URL on trge.link may also set a first-party cookie named trge_vid on that host only, used solely to count distinct visitors to that link as described in Section 1. It is not an advertising cookie and is not set on traderange.net.
Consent banner (analytics & advertising): On first visit, the website asks whether you allow analytics and personalised advertising. Your choice is recorded (localStorage key tr_analytics_consent) and applied via Google Consent Mode. If you accept, we load Google Analytics 4 and allow personalised ads. If you decline, no analytics scripts load and no analytics data is sent; ads may still appear on the website but are limited to non-personalised ones. You may change or withdraw your choice at any time from Settings → Ads & analytics on the website (separate toggles for personalised ads and for analytics, plus a button to re-open the banner); clearing your browser cookies and localStorage also resets it, and an administrator can re-prompt everyone. Essential OAuth session storage remains until expiry (30 days) unless you manually log out. Ad and analytics cookies set by Google are governed by Google’s policies and expire per Google’s retention.
Advertising cookies: When ads are shown, Google and its partners may place cookies/identifiers on your device to measure performance, cap frequency, and (with consent) personalise ads. You can manage these through the controls listed in Section 6.
Do Not Track (DNT): Nothing is loaded before you choose — analytics and advertising storage both start denied for every visitor, so a browser sending DNT is already in the declined state and no GA4 tag loads until you accept. If DNT is on, the banner says so. DNT is a preference rather than a legal signal, so an explicit Accept from you still overrides it.
Global Privacy Control (GPC): We honour the GPC signal. Where your browser or extension sends GPC, we treat it as a valid opt-out of personalised advertising and of any “sale” or “sharing” of personal information as those terms are used in California and other US state privacy laws. Unlike DNT, GPC is not overridden by the banner or by the Settings toggles: while it is asserted, advertising consent stays denied whichever button you press, and the banner says so. Analytics remains your choice. See Section 19.
6. Third-Party Services & Infrastructure
Google AdSense (advertising — website only) – We use Google AdSense to display ads on the TradeRange website, which helps keep the service free and fund future development. When you visit a page that contains an ad slot, Google — acting as an independent third party under its own Advertising and Privacy policies — and its ad-technology partners may set and read cookies and similar identifiers and process data such as your IP address, approximate (non-precise) location, device and browser information, and ad interactions.
- Personalised vs non-personalised ads. If you accept our consent banner, ads may be personalised using the data above and your prior activity. If you decline (or are in a region where we do not have consent), we instruct Google to serve non-personalised ads, which rely only on general context like the current page and coarse location. We implement Google Consent Mode so your choice is passed to Google automatically.
- Legal basis. In the EEA/UK, personalised advertising and non-essential ad cookies are used only with your consent (GDPR Art. 6(1)(a)); you may withdraw consent at any time (see below). Elsewhere, advertising supports our legitimate interest in funding a free service, subject to your opt-out choices.
- What we do not share. We never provide Google or advertisers with your Discord ID, Google ID, GitHub ID, username, email (we hold none), or your gameplay/leaderboard records for ad targeting.
- Your controls & opt-out. You can decline our banner or toggle personalised ads off under Settings → Ads & analytics; manage or turn off ad personalisation in your Google Ad Center / Ads Settings; opt out of third-party vendor cookies at aboutads.info/choices and youronlinechoices.eu; and see Google’s list of ad-technology providers here. Administrators can also disable ads platform-wide.
- App exclusion. The TradeRange apps (both Android and iOS) do not load AdSense or show third-party ads; this section applies to the website only.
Cloudflare (network proxy & CDN) – All traffic to traderange.net and trge.link passes through Cloudflare’s reverse proxy and CDN network before reaching our servers. Cloudflare operates points of presence in many countries, including the United States, the United Kingdom, and the EEA. This means Cloudflare processes every HTTP request you make, including your IP address, request headers, and response metadata, in order to provide DDoS mitigation, TLS termination, and caching. Cloudflare operates under its own Privacy Policy. We do not control what Cloudflare logs or retains at the network layer. We encourage you to review Cloudflare’s policies if you have concerns about edge-network data handling. Storage on our own servers is described in Section 8.
Video embeds – The Learn & Analysis section may embed videos in article content. For YouTube we embed through youtube-nocookie.com, Google’s privacy-enhanced host, so advertising and profiling cookies are not placed when the page loads. Loading an embed still discloses your IP address and basic request metadata to Google (or, for a Vimeo embed, to Vimeo), because your browser has to fetch the player from them, and pressing play causes the provider to set playback storage. That processing is governed by Google’s Privacy Policy or Vimeo’s, not ours. If you would rather no request reached them at all, a browser extension that blocks third-party frames stops the embed loading; the rest of the article still works.
Market data – TradeRange games, charts, and calculators use market data we obtain from third-party sources. Those requests are made by our servers, not by your browser: we fetch the data, cache it, and serve it to every player from traderange.net. This means:
- Your IP address is not exposed to any of those sources by playing a game or opening a chart. They see our server, not you.
- We never share your Discord ID, Google ID, GitHub ID, username, or any TradeRange account data with a data source.
- No personal identifier is appended to any market-data request we make.
- We do not list our data sources here, and we may add, drop, or change them at any time. Because nothing about you is sent to them, which ones we use does not affect your privacy.
- Requests your browser does make to third parties are the ones described elsewhere in this section — advertising, analytics, video embeds, and the charting library we load from a public CDN (jsDelivr / unpkg).
Google Play (Android app distribution) – The TradeRange Android app is distributed through the Google Play Store. Downloading, installing, and updating the app is handled by Google Play under Google’s Privacy Policy. We do not receive your Google Play account details; we only receive the pseudonymous OAuth identifier described above if you choose to sign in.
Apple App Store (iOS app distribution) – The TradeRange iOS app is distributed through the Apple App Store. Downloading, installing, and updating the app is handled by Apple under Apple’s Privacy Policy. We do not receive your Apple ID or App Store account details; we only receive the pseudonymous OAuth identifier described above if you choose to sign in.
Push notification delivery – If you enable notifications in the app, we use a push notification service to deliver them. On Android this is carried over the operating system’s messaging service (operated by Google); on iOS it is carried over the Apple Push Notification service (APNs) (operated by Apple). We may also use a third-party push provider to send messages on our behalf. The provider we use may change over time. Whichever service is used issues a per-install device token and relays the messages we send to your device, under its own privacy terms. We share only the push token and the notification content with that service — never your OAuth identifier, gameplay data, or any other account information.
7. Mobile App: On-Device Storage, Notifications & Permissions
The TradeRange apps for Android and iOS are bundled versions of the website and follow the same data practices as the rest of this policy, with the app-specific additions noted below. Except where a point is called out as platform-specific, these apply to both platforms:
- On-device storage. To support offline use, the app keeps a local cache on your device of its interface and of content you have already opened (articles and their images), plus small preference values (your cookie-consent choice and notification settings). This data stays on your device, is not sent to us as a separate collection, and is cleared when you uninstall the app or clear its storage.
- Downloaded articles (offline reading). When you tap Download on an article, the app saves a complete offline copy of it on your device — the article’s text, its images, and the market data behind its price charts — in the app’s local database, so you can read it fully without a connection. These downloads are limited in number and each one auto-clears about 7 days after you save it; you can also remove a saved article at any time from within the app. This content stays on your device, is not sent to us as a separate collection, and is cleared when you uninstall the app or clear its storage. Re-opening a downloaded article while online fetches the latest version over the network as usual.
- Notifications. If you allow it, the app can show you notifications — both reminders scheduled on your device (for example, the daily-reset reminder) and push notifications we send from our servers (for example, announcements or new content). To deliver push notifications we register your device with a push notification service — this is the platform’s messaging service (Google’s on Android, Apple’s APNs on iOS) and may involve a third-party push provider we use to send messages — and store the resulting device push token so we can reach your device. The token is a pseudonymous per-install identifier, is not linked to your real-world identity, and is removed when you disable notifications or uninstall the app. Both Android and iOS ask for your permission before any notification is shown, and you can turn notifications off in the app’s Settings or in your device settings.
- App updates (Android direct-download version only). The Google Play and Apple App Store builds are updated through their respective stores; the iOS app has no self-update mechanism and no direct-download version. Only the Android build downloaded directly from traderange.net (rather than Google Play) keeps itself up to date. It periodically asks our servers for the latest published build; that request sends only the app’s installed version number and the standard request metadata described elsewhere in this policy — no additional personal data. If you choose to update, the new signed APK is downloaded from our servers over HTTPS through Android’s download manager and installed by the system installer with your explicit confirmation. Updates are never silent: installing them relies on Android’s “install unknown apps” permission, which you grant to the app and can revoke at any time in your device settings. We keep an aggregate count of how many times each build is downloaded; this number is not linked to you or your account.
- Permissions. The app requests only network access and, optionally, permission to post notifications. It does not request location, contacts, camera, microphone, or file access.
- In-app browser. Sign-in and external links open in a secure system in-app browser (a Custom Tab on Android, a Safari-based view /
SFSafariViewControlleron iOS). Pages you open there are subject to their own privacy policies, and sign-in is subject to Discord’s, Google’s, or GitHub’s policies.
8. Where We Store and Process Data
Our servers. Account, gameplay, reading, portfolio, session, and operational data we hold is stored on virtual private servers we operate. Those servers may be located in the United Kingdom, the European Economic Area (EEA), and/or the United States. We may add, replace, or move servers among those regions as we operate the service. A signed-in account is homed on one of those servers; we may later move that home to another server in any of the same regions, including from Europe to the United States or the other way, so the fleet can stay available.
Encryption does not depend on location. Regardless of which country a server sits in, the SQLite database is encrypted at rest (SQLCipher) and stored files are encrypted with AES-256-GCM, as described in Section 2. Live operational log files remain plaintext so they can be tailed.
International transfers. If you use TradeRange from the EEA, the United Kingdom, or Switzerland, some of the processing described in this policy involves transferring personal data to the United States (and, for some subprocessors, other countries). That includes (a) storage on a United States server when your home box, a replica, or a backup sits there; (b) traffic that passes through Cloudflare’s global network, which includes points of presence in the United States; and (c) processing by the third parties in Section 6 (for example Google, Discord, GitHub, Apple, and Cloudflare), which operate in the United States and elsewhere. By using the Service you understand and agree that your data may be stored and processed in the United Kingdom, the EEA, and the United States.
Safeguards for those transfers. Where a destination is not covered by an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, and on the EU–US / UK–US Data Privacy Framework for organisations that participate in it (including Cloudflare and Google where they certify). You may contact us (Section 15) if you want more detail about those safeguards. Objecting to a transfer is only practical by stopping use of the Service and requesting deletion as described in Section 12.
Data on your device. The apps also keep a local copy on the device you use, wherever you are. That copy is described in Section 7. It is not moved onto our servers as a separate collection.
9. Data Retention & Deletion Improvements
Log retention: Interaction logs (including IP addresses and OAuth identifiers) are kept for a maximum of 90 days, after which the record is permanently deleted. Aggregated, non-identifiable statistics (for example “daily active players”) contain no user-specific detail and may be retained indefinitely.
At a glance. Where a period below and a period elsewhere in this policy differ, the shorter one is the one we apply.
| What | How long we keep it |
|---|---|
| Account record, scores, gameplay history, portfolios, settings | Until you delete the account, or until the inactivity rule below applies |
| IP address in readable form | Up to 7 days, then replaced by a salted keyed hash |
| Interaction and operational logs (including the hashed IP) | 90 days |
| Short-link (trge.link) hit records | 90 days |
| Recommendation-quality events | 90 days |
| Sessions | 30 days from issue, or until you sign out |
| Deleted account, during the grace period | 14 days frozen, then permanently erased |
| Analytics (GA4), if you consented | 14 months (Google’s retention, not ours) |
| Backups | Rolling; older backups are superseded and destroyed as newer ones are taken |
| Aggregated, non-identifying statistics | Indefinitely |
Backups. Deleting your account removes it from the live systems straight away. Encrypted backups taken before that point are not individually edited; they are superseded and destroyed on a rolling basis as newer backups are taken, and we do not restore a deleted account from one.
Inactive accounts. We may delete an account, and the data associated with it, after a prolonged period with no sign-in. Because we hold no email address, we cannot warn you first, and signing in at any point resets the clock. We do not currently run an automatic inactivity purge; this reserves the ability to introduce one rather than describing something already running.
Gameplay and reading data: Scores, leaderboard entries, and article reading progress are stored until you request deletion. When you request account deletion, we will remove your OAuth identifier, all scores, game history, article reads, and associated metadata within 30 days. Anonymised leaderboard entries (without identifier) and anonymous article-pair counts may remain for historical integrity but will not be linkable to you.
Google Analytics data (if consented): Retained in accordance with GA4’s default 14-month retention period. No OAuth identifiers are included. You may also request deletion of your GA4 event data by clearing consent (clearing cookies) and contacting us, but GA4 data is aggregated and not personally attributable.
10. Your Privacy Controls
Your privacy choices, in one place. To opt out of personalised advertising and of any “sale” or “sharing” of personal information, decline the consent banner, turn personalised ads off under Settings → Ads & analytics, or browse with Global Privacy Control enabled (Section 5) — any one of those is enough, and GPC needs no further action from you. To withdraw analytics consent, use the same Settings panel. To export or erase everything we hold, use Settings → Your data and the deletion control below. Section 19 sets out the US state-law versions of these rights.
TradeRange provides the following privacy controls, accessible from your profile page (labelled Settings in the app):
- Hide profile picture: Your avatar will not appear on leaderboards, public profiles, or anywhere else on the site. The image remains stored privately on our servers (sourced once from Discord, Google, or GitHub by our proxy) but is not displayed publicly.
- Anonymous mode: Your username is replaced with anon on leaderboards and public profiles. Your scores are still counted and contribute to game statistics, but cannot be linked to your identity by other users. Live multiplayer still shows your display name. You can disable anonymous mode at any time, unless an administrator has locked it on the account.
- Home server: You may pick one Discord community you share with the bot as your TradeRange home server (from your profile page). You can switch to a different community at most once every 7 days. Clearing your home server does not reset that wait. When you set a home server, that community may be notified in its TradeRange channel; creating a TradeRange account is never announced.
- Authenticator (optional): From Settings you can add an authenticator app so sign-in also asks for a 6-digit code. You can turn it off with a code from the app. If you lose the phone, contact an administrator to remove it from the account.
- Account deletion (14-day grace period): You may delete your account from your profile page. When you confirm, your account is immediately frozen – it becomes unusable, is hidden from leaderboards and public profiles, and all sessions on other devices are signed out – and a 14-day countdown to permanent deletion begins. During those 14 days you may restore your account at any time simply by signing in again and selecting “Restore my account”, which fully reactivates it with your data intact. If you do not restore it, then when the countdown ends your account and all associated data (OAuth identifier, avatar, scores, gameplay records, article reads, portfolios, sessions, authenticator enrollment, and settings) are permanently and irreversibly deleted from our systems by an automated process. This deletion cannot be undone once the grace period has elapsed.
Discord server opt-out: Server administrators may run the /settings bot command and use the Hide from directory button to hide their server from the public TradeRange server directory. The bot remains active in the server; only the public listing is affected. To reverse an opt-out, server administrators must contact TradeRange maintainers via the tradely.dev server.
11. Improved Protections Against Abuse & Data Minimisation
- Data minimisation by design: We never collect email addresses, even if Google provides them via ID token (we discard). No “forgot password” or marketing lists.
- IP masking: In analytics and long-term logs, IP addresses are hashed after 7 days using a salted SHA-256 to prevent reconstruction while still allowing abuse detection.
- Rate limiting and anomaly detection: Our API tracks request patterns per OAuth identifier and IP. Suspicious behaviours (automated score submission, extreme request rates) trigger temporary blocks and manual review.
- Access controls: Access to production logs and databases is limited to a small number of core maintainers who need it to run the Service, and is reviewed as the team changes. Access is logged. We use environment-specific secrets and do not hardcode credentials.
- Incident response: If we become aware of a personal data breach, we will notify the competent supervisory authority where the law requires it — under the UK and EU GDPR, without undue delay and, where feasible, within 72 hours of becoming aware of it — and we will inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Because we hold no email addresses, we will give that notice through a prominent notice on traderange.net and in the app, and an announcement on the tradely.dev Discord. The 72-hour figure is the regulator deadline, not a promise of a completed public post-mortem in that time.
12. Your Rights (GDPR / CCPA Aligned)
Because we intentionally collect no real-world personal data (only pseudonymous OAuth identifiers and gameplay logs), traditional access/correction rights have limited scope. However, we fully honour:
- Right to deletion: Email [email protected] from any address or contact a maintainer on our Discord (tradely.dev). We will delete your OAuth ID and all associated gameplay data within 30 days. Confirmation provided.
- Right to object / restrict processing: You may stop using TradeRange at any time. Request that we cease processing your new logs (only possible by account deletion). You may also object to analytics by rejecting the consent banner.
- Right to withdraw consent (analytics & ads): On the website, use Settings → Ads & analytics to change or withdraw your analytics and advertising consent independently, or reset it there to re-show the banner. Clearing browser cookies and localStorage also brings the banner back.
- Right to opt out of personalised advertising / “sale” or “sharing”: Decline the consent banner to keep ads non-personalised, and/or use the Google and industry opt-out controls in Section 6 (Google Ads Settings, aboutads.info, youronlinechoices.eu). California residents may treat this as a request to opt out of the “sale”/“sharing” of personal information for cross-context behavioural advertising.
- Right to data portability: Download a JSON copy of your scores, streak, play dates, privacy flags, whether an authenticator is enabled, article reads, and portfolios from Settings → Your data. Session rows in that file include device and country, not IP addresses. You may also email us if you need help.
- Right to lodge a complaint: Supervisory authority (e.g., ICO for UK or local DPA). We will assist.
- International transfers: Data may be stored in the United Kingdom, the EEA, and the United States as described in Section 8. You may ask us for more detail about the safeguards we use. Stopping use and deleting your account (this section and Section 10) is the practical way to end further transfers of your account data.
13. Children
TradeRange is a general-audience service and is not directed to children. You must be at least 13 years old, or the minimum age of digital consent in your country if that is higher (in parts of the EEA it is 14, 15, or 16), to use the Service. This matches Section 2 of the Terms of Service.
We do not knowingly collect personal data from anyone below that age, and we do not knowingly serve personalised advertising to them. We do not ask for a date of birth, so we cannot verify age ourselves; Discord, Google, and GitHub enforce their own minimum ages at sign-in.
If you are a parent or guardian and believe a child below the applicable age has created an account, email [email protected] with enough detail to identify the account (the display name shown on the profile or leaderboard is usually enough). You do not need an account to make that report. We will verify what we reasonably can, delete the account and the data associated with it, and confirm to you when it is done. If we otherwise become aware of such an account, we delete it on the same basis without waiting for a report.
14. Changes to This Privacy Policy
We may update this policy to reflect new features, new legal requirements, or improved protections. The Last updated date at the top of this page always reflects the current version.
Where a change materially reduces your rights or materially widens how we use your data, we will give notice before it takes effect — a prominent notice on the website and in the app, and an announcement on the tradely.dev Discord — and, where the change relies on your consent, we will ask for that consent rather than assume it from continued use. For other changes, continued use after the effective date indicates acceptance. If you do not accept a change, you may stop using the Service and delete your account (Sections 10 and 12). We keep prior versions and will send you one on request.
15. Contact & Data Protection Inquiries
TradeRange is maintained by volunteers under the tradely.dev community. For privacy questions, data requests, or security reports:
- Discord: discord.tradely.dev (preferred for quick responses)
- Email: [email protected] (for formal requests, deletion, or GDPR/CCPA inquiries)
- Mail (legal correspondence): available via email request
Our game website is traderange.net and our share host is trge.link; legal coordination and project governance operate under tradely.dev.
Who the controller is. For the processing described in this policy, the data controller is the group of TradeRange maintainers operating under the tradely.dev community, contactable at [email protected]. TradeRange is not an incorporated company (see Section 1 of the Terms of Service); the maintainers act jointly as controller. A postal address for formal legal or regulatory correspondence is provided on request to [email protected], and we will provide it to a supervisory authority on request without requiring one.
How quickly we answer. We aim to acknowledge privacy requests within a few working days and to answer them in full well inside the statutory deadline. Where the UK or EU GDPR applies, that deadline is one month from receipt, extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why. Where a US state privacy law applies, we answer within the period that law allows (generally 45 days, extendable once by a further 45 days). Requests are free unless they are manifestly unfounded or excessive.
Verifying a request. Because we hold no email address or real name, the reliable way for us to confirm that a deletion or export request is really yours is for you to make it from the signed-in account (Settings → Your data) or from the Discord, Google, or GitHub account the request concerns. If you email us instead, we may ask you to prove control of that provider account. We are not able to act on a request we cannot tie to an account, and we will say so rather than delete the wrong person’s data.
16. RSS and Atom feeds
TradeRange publishes public RSS 2.0 and Atom 1.0 feeds at traderange.net/rss/. They list titles, short summaries, cover images, and links to pages on our website. They do not contain full articles or the daily market brief itself.
- No subscriber account. You do not log in to subscribe. We do not issue a subscriber identifier, we do not embed tracking pixels or unique query strings in the feed files, and we do not operate a list of who is subscribed.
- What a fetch looks like to us. A reader polling a feed is requesting a public static file, the same as fetching any other page. That request may pass through Cloudflare (Section 6) and may appear in our short-lived operational logs (IP address, user agent, URL, timestamp) for security and abuse detection, then is deleted on the schedule in Section 9. We do not use those logs to profile reading habits or to advertise.
- Your reader is a third party. The app or service you use to subscribe (Feedly, Inoreader, NetNewsWire, a browser extension, an email-to-RSS gateway, and so on) is not TradeRange. It fetches our files on your behalf under its privacy policy. We do not control what it stores, how long it keeps a copy of an item after we unpublish it, or what it does with your identity.
- AI-generated items. Some feed items, including the daily market brief, are produced by artificial intelligence. That material may be inaccurate. It is the same content (in teaser form) described in the Terms of Service; it is not a personalised profile about you and it does not use your account data.
- No personal data in the files. Feed items are editorial (titles, summaries, public images, links). They do not include OAuth identifiers, emails (we hold none), IP addresses, or gameplay records.
Using a feed is optional. If you do not want a third-party reader to fetch TradeRange on your behalf, do not subscribe. The same articles remain available on the website.
17. Legal Bases for Processing (UK & EU GDPR)
Where the UK GDPR or the EU GDPR applies to you, we must have a lawful basis for each purpose. Ours are set out below. We do not process special-category data, and we do not ask for any.
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, saving scores and progress, leaderboards, portfolios | Performance of a contract (Art. 6(1)(b)) — this is the service you asked for |
| Linking Discord, Google, and GitHub logins into one account | Performance of a contract (Art. 6(1)(b)) |
| Article reading progress and ordering unread articles first | Legitimate interests (Art. 6(1)(f)) — making the catalogue usable. You can stop it by signing out or deleting the account |
| Operational logs, rate limiting, anti-cheat, anti-scraping, abuse investigation | Legitimate interests (Art. 6(1)(f)) — keeping the Service available, fair, and secure |
| Share-link and campaign attribution, and the person-check at /botcheck/ | Legitimate interests (Art. 6(1)(f)) — understanding which links bring players and preventing automated or self-referred sign-ups |
| Recommendation-quality measurement (aggregate, 90 days) | Legitimate interests (Art. 6(1)(f)) — checking a feature works |
| Google Analytics 4 | Consent (Art. 6(1)(a)), and consent under PECR / the ePrivacy Directive for the storage itself. Withdraw it at any time |
| Personalised advertising and non-essential advertising cookies | Consent (Art. 6(1)(a)) and ePrivacy consent. Withdraw it at any time; GPC is honoured as an opt-out |
| Push notification token | Consent (Art. 6(1)(a)) — you enable notifications, and disabling them deletes the token |
| Authenticator (TOTP) secret | Performance of a contract (Art. 6(1)(b)) at your request, and legitimate interests in account security |
| Session token and CSRF token | Performance of a contract (Art. 6(1)(b)); strictly necessary storage, which needs no ePrivacy consent |
| Responding to legal requests, defending legal claims, enforcing the Terms | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have limited the processing accordingly — short retention, pseudonymous identifiers, no advertising use, and no profiling of you as an individual beyond what Section 18 describes. You have the right to object to any of it (Section 12), and you can ask us for the balancing assessment behind a particular purpose.
Where we rely on consent, refusing or withdrawing it costs you nothing but the feature concerned: the Service works with analytics off, with personalised ads off, and with notifications off.
If you are in the EEA, the UK, or Switzerland, Section 8 explains the transfers involved and the safeguards we rely on.
18. Automated Processing and Profiling
We are required to be straight with you about decisions taken by software rather than a person.
- What is automated. Rate limiting, brute-force protection, and anti-abuse heuristics run automatically on the logs described in Section 1 and can temporarily block a request, a session, or an account from parts of the Service. The bot-check at
/botcheck/is also automated. The ordering of articles and recommendations is automated, but it only changes what surfaces first. - What is not. A permanent ban, a suspension, or the removal of an account is decided by a human maintainer, using the automated signals as evidence rather than as the verdict. We do not use automated decision-making to produce legal effects concerning you, and we do not sell or score you for anyone else.
- Your right to a human. If an automated block affects you and you think it is wrong, contact us (Section 15). You are entitled to have a person look at it, to be told the reason, and to contest the outcome. We will restore access where the block was mistaken.
- No advertising profiles. None of the above feeds advertising. We do not build an interest profile of you, and we do not share gameplay, reading, or log data with advertisers (Sections 2 and 6).
19. US State Privacy Rights (California and others)
This section applies if you are a resident of California or of another US state with a comprehensive privacy law (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana). It supplements, and does not replace, the rest of this policy.
Categories of personal information we collect. Using the California categories: identifiers (pseudonymous OAuth ID, device and visitor identifiers, IP address); internet or other network activity (pages requested, gameplay events, reading progress, ad and analytics interactions); geolocation only in the coarse, non-precise sense that an IP address implies a country or region — we do not collect precise location; commercial information only in the sense of which free features you use. We collect no sensitive personal information, no biometric data, no government identifiers, no financial account data, and no email addresses or real names. We do not collect the contents of your communications.
Sources. Directly from you and your device, from your OAuth provider at sign-in, and from our own logs and analytics.
Purposes. The purposes in Section 2 and Section 17 — operating the Service, security and anti-abuse, measurement, and advertising as described.
Disclosures. We disclose personal information to the service providers and third parties named in Section 6 for the purposes described there. We do not disclose your OAuth identifier, username, or gameplay records to advertisers or data brokers.
“Sale” and “sharing”. We do not sell personal information for money. However, when personalised advertising is enabled, the use of advertising cookies and identifiers by Google and its partners for cross-context behavioural advertising may qualify as a “sale” or “sharing” under the CPRA and as “targeted advertising” under other state laws. We treat it as such so that you get the opt-out either way. We do not sell or share the personal information of anyone we know to be under 16.
How to opt out. Any one of these is a complete opt-out, and none of them requires an account:
- Press Decline on the consent banner.
- Turn personalised ads off under Settings → Ads & analytics, reachable from the Your privacy choices link in the site footer.
- Browse with Global Privacy Control enabled. We honour GPC as a valid opt-out signal, it applies automatically on arrival, and it cannot be overridden by the banner (Section 5).
Your other rights. Subject to verification, you may request to know what we collect and why, to access a portable copy (Settings → Your data), to correct inaccurate information, to delete your information (Settings, or Section 12), and to limit the use of sensitive personal information — the last of which does not arise, because we collect none. Exercise any of them as described in Section 15.
Authorised agents. You may use an authorised agent to submit a request. We will ask for written proof of the agent’s authority and may ask you to confirm it directly, because the account identifier is the only thing tying a request to a person.
No retaliation. We will not deny you the Service, charge you a different price, or give you a lesser experience for exercising any of these rights. The Service is free and stays free either way; declining personalised ads does not remove features.
Appeals. If we refuse a request and your state gives you a right of appeal (as Colorado, Connecticut, Virginia, Texas, Oregon, and Montana do), reply to our refusal and say you are appealing. A maintainer who did not take the original decision will review it and answer within the period your state allows, and we will tell you how to contact your state Attorney General if you are still unsatisfied.
20. Complaints and Supervisory Authorities
If you think we have handled your data wrongly, please raise it with us first at [email protected] — it is usually the fastest way to get it fixed, and we would rather know.
You do not have to come to us first, and raising it with us does not affect your right to complain to a regulator:
- United Kingdom: the Information Commissioner’s Office (ICO), ico.org.uk/make-a-complaint, helpline 0303 123 1113.
- EEA: the data protection authority of the country where you live, work, or where you think the problem occurred. The list is at edpb.europa.eu.
- Switzerland: the Federal Data Protection and Information Commissioner (FDPIC).
- United States: your state Attorney General, and for California the California Privacy Protection Agency.
EU and UK representative. TradeRange is a small volunteer project that processes pseudonymous data only. Where Article 27 of the UK or EU GDPR requires a local representative and no exemption applies, we will appoint one and name them here. Until then, and in every case, [email protected] reaches the maintainers directly and we will engage with any supervisory authority that contacts us there.
© 2026 TradeRange · Terms · Privacy · No email at sign-up | Pseudonymous by design
We never ask for an email address to create or use an account. If you choose to email [email protected], that message and its address sit in our mailbox while we deal with it, like any correspondence.