Last updated: June 16th, 2026
This Privacy Policy explains how StormLedge ("StormLedge," "we," "us," or "our"), collects, uses, and shares information when you use the StormLedge website and application (the "Service"). We are the data controller for the personal data described in this policy under the EU General Data Protection Regulation (GDPR).
StormLedge is an AI-assisted tool for building, backtesting, and simulating algorithmic trading strategies. It does not connect to any real brokerage or exchange account, and it does not execute real trades or move real money — see the Terms of Service for details.
Contact / Data Controller: StormLedge, privacy@stormledge.dev.
If you sign in with Google, we receive and store your Google account ID, email address, name, and profile picture URL. We do not receive or store your Google password. You can use most of the Service without signing in — an anonymous session is created automatically.
Every visit is associated with a session, identified by a random ID stored in an HTTP-only cookie in your browser. If you're not signed in, this session is anonymous; if you sign in, it becomes linked to your account.
This includes strategy descriptions and instructions you give the AI assistant, chat messages and conversation history, generated strategy code and files, backtest configurations, and backtest/simulated-live results. This content is stored so your projects persist across visits and can be retrieved, edited, and re-run.
We record metadata about each AI generation request and each sandboxed code execution: which session/project it belongs to, the model used, token counts, duration, approximate cost, and whether it succeeded or errored (including error details on failure). This is tied to your session ID and, if you're signed in, your account.
We also enforce daily usage limits (e.g., on messages/AI generations, backtests, and projects created) to keep the Service running reliably for everyone; signed-in accounts get a higher daily allowance than anonymous sessions. These limits reset automatically at midnight UTC, and reuse the same per-session/per-account usage data described above to determine how much of the daily allowance you've used. See the Terms of Service, Section 8, for more detail.
We use PostHog to understand how the Service is used (e.g., which features are used, example strategies selected). If you're signed in, analytics events are associated with your account ID, email, and name. If you're not signed in, analytics are tied to an anonymous identifier.
We use Sentry for two distinct purposes:
We use one essential cookie to maintain your session (required for the Service to function, exempt from consent under Art. 5(3) ePrivacy Directive). We also use PostHog for analytics and Sentry for session replay (see above), neither of which is essential — both only run if you accept them in the cookie banner shown on your first visit; no analytics events or session recordings are captured until you click "Accept." You can change your choice at any time by clearing your browser's local storage for this site (a dedicated settings control is not yet available).
We use the information above to: operate and provide the Service (including running your strategies through the AI assistant, the backtesting engine, and the sandboxed execution environment); maintain your session and account; monitor, debug, and improve the Service; understand feature usage and prioritize development; detect and prevent abuse; and comply with legal obligations.
Under GDPR, we rely on the following legal bases:
When you use the AI assistant — to generate strategy code, chat about a strategy, or get suggestions — your prompts, chat history, and relevant strategy context are sent to Anthropic's Claude API for processing. This content is subject to Anthropic's own privacy and data-handling terms. We do not use your content to train our own models.
Strategy code (whether AI-generated or written by you) and backtest runs are executed in an isolated sandbox environment hosted by Modal. Your strategy code and the resulting output pass through this third-party infrastructure to produce backtest and simulated-live results.
We share information with the following categories of service providers, only as needed to operate the Service:
We do not sell your personal information. We may disclose information if required by law, to protect the rights, property, or safety of StormLedge, our users, or others, or in connection with a merger, acquisition, or sale of assets (with notice to you where required by law).
A small number of internal operators can access aggregate and per-session/per-user usage statistics (token counts, cost, error rates) through an internal admin tool, gated by a shared access token. The same tool lets operators configure the daily usage limits described in Section 1 ("Usage and diagnostic data") and reset a specific account's or everyone's usage window early. This tool does not expose strategy content, chat messages, or account passwords (we don't have passwords).
We retain account information, projects, and associated content for as long as your account exists, so your strategies remain available to you. Anonymous session data persists until the session is deleted or expires. Usage/diagnostic data is retained for operational and analytics purposes.
If you delete your account (Section 7), your account and every project you own (including messages, files, and backtest results) are permanently and immediately deleted from our production database — this is not a soft-delete or a grace period, and we cannot recover it for you afterward. Your browser session itself is not deleted (it reverts to an anonymous session, consistent with signing out), and historical usage/diagnostic records tied to that session or account are anonymized (the account reference is cleared) rather than deleted outright, so aggregate operational reporting stays intact.
You can sign out at any time, which unlinks your Google account from your current session (your projects remain associated with your account for next time you sign in).
If you're signed in, you can permanently delete your account at any time from the Account page in the Service. This immediately and irreversibly deletes your account and every project you own, as described in Section 6 — there is no confirmation step beyond the one in the product itself, and no way for us to undo it once submitted.
Under GDPR, you have the right to: access the personal data we hold about you; rectify inaccurate data; request erasure of your data; restrict or object to certain processing (including processing based on legitimate interests, per Section 2); receive your data in a portable format; and withdraw consent at any time where processing is based on consent (e.g., analytics cookies), without affecting the lawfulness of processing before withdrawal. The self-service account deletion above satisfies the right to erasure for your account and projects; for anything it doesn't cover (e.g., data portability, or erasure of anonymous session/usage data you can't reach through the product), contact us at privacy@stormledge.dev. We'll respond within one month as required by Art. 12(3) GDPR. If you're not satisfied with our response, you have the right to lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi), or the supervisory authority in your own EU/EEA country of residence.
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18. If you believe a minor has provided us with personal information, contact us and we will delete it.
We use HTTP-only, signed session cookies, and isolate strategy code execution in a sandboxed environment. Internal admin tooling requires a separate access token. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
PostHog and Sentry process data on EU-based infrastructure. Anthropic, Modal, and Google are based in, or process data in, the United States, which is outside the European Economic Area. Where we transfer personal data to these providers, we rely on appropriate safeguards recognized under GDPR Chapter V, such as the European Commission's Standard Contractual Clauses, or the recipient's participation in a recognized data-transfer framework.
We may update this Privacy Policy from time to time. We'll update the "Last updated" date above when we do. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Questions about this Privacy Policy or your data can be sent to privacy@stormledge.dev.