The short version
- We keep your email address, your simulated sessions and your API keys (as hashes, never the keys). We don't store IP addresses: our rate limits keep a scrambled form that changes every day.
- Vercel, Neon, Amazon SES and Cloudflare help run the service. Anthropic sees your question and your session's numbers, and only when you ask for an AI answer.
- Your data is stored in the United States.
- No advertising, no tracking cookies, and we don't sell data.
- On the account page you can download your data, change your email address, see where you're signed in, and delete your account.
- We delete accounts nobody has used for 24 months, after an email warning.
- tradefloor is not for anyone under 16.
Who we are
tradefloor is run by Simon Coombes, of the United States ("we"). We decide how the personal data described here is used, so we are its controller under data protection law. Our contact details are at the end of this page.
This policy covers app.tradefloor.dev, its HTTP API, its MCP server and the emails it sends. The documentation site, tradefloor.dev, is separate.
What we collect
- Your account: your email address, when you signed up and were last seen, your plan (with its end date and a history of the plans we granted or withdrew, if any), whether the account is suspended, any note we add to it (such as why we granted a plan), the version of the terms and this policy you accepted and when, whether you want news emails, and when we warned you that an unused account would be deleted.
- Sign-in records. Each sign-in link and its 6-digit code are stored as hashes, never as the link or code. If you ask for a link and never use it, no account is made. Each browser sign-in is stored as a hash of its cookie, with a label naming the browser and system (such as "Firefox on macOS"), when it signed in and when it was last seen. We don't store its IP address or the rest of what your browser sends. You can see the list on the account page.
- Account links: the links we email to confirm a new email address or a deletion, stored as hashes, with the new address until the link is used or expires.
- API keys: each key's id, a salted hash of its secret, the name you gave it, its scope (full, trader or read-only), and when it was made, last used and revoked. We can't show a key again after it's made.
- Connected apps: when you connect an app such as claude.ai over OAuth, its name and web address, the scope you gave it, when you connected it and last used it, and its tokens, stored as hashes.
- Your sessions: the settings you chose (preset, seed, companies, starting prices, scenarios), the names you give sessions and branches, your orders and any notes on them, fills, the simulated market's history, and figures we compute from them, such as report cards and behaviour metrics. Also the custom scenarios you save, and your suite runs: the strategies you submit and their results.
- Usage: for your account and each key, daily counts of calls, simulated days, compute seconds and refused calls. They apply your plan's limits and show your usage.
- An audit log, with a line for each call that changes a session: the call, the time, your account id, the key id (never the key), the session, the result and how long it took. A failed attempt to use a key also records a scrambled form of the IP address it came from, which changes every day, never the address itself.
- Rate-limit counters: an IP address, email address or account id, stored as a keyed hash (HMAC-SHA256 under a secret key kept outside the database, and a new key every day), with a count of requests in the current window. Without the key a hash can't be matched to an address, and hashes from different days can't be matched to each other. We still treat them as personal data.
- AI answers. We don't store the questions you type. We keep the answers for 14 days so that asking the same question about the same state costs nothing, and a record of each AI call (your account id, the session, the model, the tokens used and the cost) for 90 days.
- Contact messages: what you write on the contact page, emailed to us with your account's email address, account id, plan and sign-up date. They go to our email inbox, not the app's database.
- Notices: which of our notices we emailed you, and when.
- Deleted accounts: one line for each, with the date, whether the owner or our inactivity rule deleted it, how many records went, and a keyed hash of its account id. It names no one: only someone who already knows the id and our secret key could match it.
- Class mode: the classes you teach or have joined, the name you asked a class to call you (optional), your work for them, and whether the Simulator's simple view is on (see Class mode below).
- Logs: the app writes a log line for some requests and errors. Log lines name your account id and session ids, never your email address.
We don't ask for your name (a class may ask what to call you, which is optional), a password, a postal address or payment details. Please don't put personal information in session names, key names, order notes, questions or custom scenarios.
Why we use it
Data protection law requires a lawful basis for each use of personal data. Ours are:
- To provide the service you signed up for: your account, sign-in, keys, sessions, usage limits, class mode, and AI answers when you ask for them. The basis is our contract with you, the terms of service.
- To keep the service secure and working, and to stop abuse: sign-in records, rate limits, the audit log, the Turnstile check, logs and the deletion log. The basis is our legitimate interest in protecting the service and the people who use it. Most of these records are deleted within days (see How long we keep it).
- To answer messages you send us. The basis is our legitimate interest in replying, or steps you asked for before a contract, such as asking for a larger plan.
- To send occasional news about tradefloor. The basis is our legitimate interest in telling people who use it about it. Each news email has a link to stop them, and you can switch them off on the account page.
- To meet legal obligations, such as answering a lawful request from an authority. The basis is legal obligation.
We email you sign-in links, links that confirm a change you asked for, a receipt when your account is deleted, a warning before we delete an account nobody has used for 24 months, notices we must send (a change to the terms or this policy, or the service ending), replies to messages you send us and, unless you switch them off, occasional news. We don't use your data for advertising, we don't sell it, and we make no decisions about you by purely automated means that have legal or similarly significant effects. Deleting an unused account follows a fixed rule, is announced by email 30 days before, and is stopped by signing in.
Who else handles it
These companies process personal data for us, under their data processing terms, and only for their part of the service:
- Vercel (United States) hosts the app. Every request passes through Vercel, including your IP address and browser details. The app runs in Vercel's Washington, D.C. region.
- Neon (United States) hosts the database that holds everything listed above, in the AWS us-east-1 region in Virginia.
- Amazon Web Services (United States) sends email through Amazon SES: your sign-in links, the other account emails and notices above, and contact messages on their way to us. It handles your email address and the message.
- Cloudflare (United States, with servers worldwide) runs Turnstile, the check on the sign-in page that you're a person. Its script reads signals from your browser, and we send Cloudflare the token it produces and your IP address to confirm the check. Cloudflare's Turnstile privacy addendum says it uses these signals to detect bots and to improve that detection.
- Anthropic writes AI answers, and nothing else. See the next section.
The site's fonts are served from our own site, so no page makes your browser contact Google or any other font service.
If you connect an AI app, an agent or a bot to tradefloor, it reads what it asks for under its own terms, which we don't control. We will also disclose data when the law requires it, for example under a court order.
When you share a simulation, the people and teams you share it with see the simulation and its branches, the notes ("Why") on its trades, your name, your email address and the names of the keys that trade in it. Your name is the one you gave, or the part of your email address before the @. A teammate's branch keeps your notes up to the day it splits from yours. The members of a team see each other's email addresses and how many simulated days each member has used, and a teacher sees the work their students hand in.
A replay link lets anyone who has it watch one simulation or benchmark run, read only, until you turn the link off. It shows none of those: no notes, Why, names, email addresses or key names, and no code, agent instructions or report cards.
AI answers and Anthropic
Anthropic writes the AI answers in the Simulator's Ask panel and from POST /v1/sessions/{id}/ask. When you ask for one, your question and facts about that session are sent to it:
- your question, if you typed one (up to 500 characters);
- facts our server computes about that session: its settings, prices, your orders, fills and positions, profit and loss, and events;
- text typed into that session: its name and its branches' names, the names of the keys that traded in it, and order notes.
We don't send your email address or account id. Quick answers and report cards are computed on our server and send nothing to Anthropic, and neither do the MCP tools report_card and explain_session_move. If you'd rather nothing about a session goes to Anthropic, use the quick answers.
Anthropic's Commercial Terms of Service (effective 17 June 2025) say "Anthropic may not train models on Customer Content from Services", and its Data Processing Addendum makes it our processor. Anthropic says it deletes API inputs and outputs within 30 days, but keeps them longer where it must to enforce its Usage Policy (up to 2 years for content flagged as a violation) or to comply with the law. Those are Anthropic's commitments as we read them on 24 September 2026, and Anthropic can change them.
Cookies and browser storage
| Name | What it's for | How long |
|---|---|---|
| tf_session (cookie) | Keeps you signed in. Page scripts can't read it. | 30 days after your last visit, or until you sign out |
| tf_next (cookie) | Remembers what asked you to sign in, such as an app you're connecting, so you land back there. Set only when a sign-in starts from somewhere other than the sign-in page. | 15 minutes, or until you sign in |
| tf-app-theme (local storage) | Your light or dark choice. Set only when you use the toggle. | Until you clear your browser's storage |
The sign-in page also loads Cloudflare's Turnstile script, described above. There are no analytics, advertising or tracking cookies.
How long we keep it
| Data | How long |
|---|---|
| Your account, custom scenarios, suite runs and their results, and sessions you haven't deleted | Until you delete them or your account, or until we delete an account nobody has used for 24 months (next row) |
| An account with no sign-in and no use of its keys or connected apps for 24 months | We email a warning. If it's still unused 30 days later, we delete it as if you had. Signing in keeps it. Suspended accounts are kept to stop abuse. |
| API keys and connected apps | Until you revoke or disconnect them, then 30 days |
| Usage counts, per account and per key | 13 months |
| A session you delete | Removed at once with its history. The audit log and cached AI answers about it expire on their own schedule, below. |
| Sessions a suite run opens for an agent | Deleted 7 days after the run ends. The results stay with the run. |
| Sign-in links and codes | About a day: they expire 15 minutes after we send them and are deleted 24 hours after that |
| Account links (a new email address, a deletion) | They expire an hour after we send them and are deleted a day after that |
| Browser sign-ins, with the browser's label | Until you sign out (one browser, or everywhere at once), or 30 days after that browser's last visit |
| OAuth codes and tokens | Codes 10 minutes, access tokens 1 hour, refresh tokens 30 days. An app registration with no connection is deleted after 30 days. |
| Rate-limit counters | Until their window ends, from 1 minute to 1 day |
| Retry records (idempotency keys) and the responses they replay | 24 hours |
| Audit log | 90 days |
| Cached AI answers and session facts | 14 days |
| Record of AI calls | 90 days |
| Which notices we emailed you | 13 months |
| The line saying an account was deleted | 2 years |
| App logs at Vercel | 1 day |
| Contact messages | In our email inbox, not the app. Nothing deletes them automatically, so ask and we'll delete yours. |
| What Anthropic receives | Anthropic's policy: within 30 days, with the exceptions above |
Hourly and daily jobs delete each item when its time is up, so an item can last up to a day longer than shown. Deleted data also stays in our database provider's restore history for up to 7 days before it's gone for good.
Where your data is
Your data is stored and processed in the United States: the app in Vercel's Washington, D.C. region, and the database and email in AWS's us-east-1 region in Virginia. Cloudflare and Anthropic may also handle it in other countries. If you're in the UK or the European Economic Area, that is a transfer outside it. We rely on the safeguards in each provider's data processing terms: the EU Standard Contractual Clauses with the UK's addendum to them, or the provider's certification under the EU-US Data Privacy Framework and its UK extension. Ask us for a copy of the safeguards that apply.
Your rights
Depending on where you live, you can ask us to:
- give you a copy of your data, including in a machine-readable form you can take elsewhere;
- correct it, for example to change your email address;
- delete it;
- restrict how we use it, or object to a use based on our legitimate interests.
Most of this you can do yourself, at once:
- download all your data, as JSON or as CSV files, on the account page or with GET /v1/account/export. It's made when you ask, and holds your account, keys (names and dates, never the keys), connected apps, sessions with their settings, orders and fills, usage, suite runs and the rest listed above. Your AI questions aren't in it, because we don't store them;
- change your email address on the account page. We email a link to the new address, and tell the old one once it's changed;
- delete your account on the account page, by typing its email address or by a link we email you. POST /v1/account/delete emails that link too;
- see the browsers where you're signed in, and sign out of one or all of them, and optionally disconnect every app, on the account page;
- delete a session on the Dashboard, with DELETE /v1/sessions/{id}, or with the delete_session tool;
- revoke a key or a connected app on the Keys page;
- switch off news emails on the account page or with the link in any of them.
For anything else, email the address at the end of this page from your account's email address, or use the contact page while signed in. We'll answer within one month, and may ask you to confirm the request from your account's email address first.
Deleting your account removes your email address, sign-ins, account links, keys, connected apps, sessions, custom scenarios, suite runs, class memberships and hand-ins, usage per key, audit lines and cached AI answers, and it emails a receipt to the old address. Two records stay without your id, so the service's daily totals stay right: the daily usage counts (13 months) and the record of AI calls (90 days). We keep the one line saying an account was deleted (above). Logs at Vercel, the restore history and what Anthropic holds expire on the schedules above. Custom scenarios you shared stay in the sessions other people already ran with them.
You can also complain to a data protection authority: in the UK the Information Commissioner's Office, and in the EU the authority where you live. We'd like the chance to sort it out first.
Class mode
A teacher can set up a class with assignments, and students join it with a code. If you join a class as a student, its teacher can see:
- your email address, the name you gave the class (if any), and when you joined;
- which of the class's assignments you have started and handed in, and when;
- the sessions you open for the class's assignments, and every branch you fork from them, with their prices, events, orders, fills, positions and results, read only;
- the report card of each session you hand in, and your answers.
The teacher can't see your other sessions, your keys, your connected apps, your usage or anything else in your account. The teacher, or the school they teach for, decides how to use what they see for the class and is responsible for that use, and a school's own privacy notice may also apply. You can leave a class on its page, and the teacher can remove you: either way your answers for that class are deleted and the teacher can no longer see your sessions, which stay yours. Deleting your account does the same for every class you're in.
If you teach, tell your students what you'll see, invite only people aged 16 or over, and use what you see only for the class. If you delete your account, your classes go with it, with their assignments and your students' hand-ins; your students keep their own sessions. The account page warns you first. Tell your students before you do it, so they can keep what they need.
Children
tradefloor is not for anyone under 16, and you must be 16 or over to make an account. The sign-in page says so. We don't ask for a date of birth or check ages. If we learn that an account belongs to someone under 16, we'll delete it.
Security
- Traffic to the app uses HTTPS.
- Sign-in links, codes, browser sign-ins, OAuth tokens and API keys are stored only as hashes. API keys use a salted hash with a secret key kept outside the database, and sign-in codes use a keyed hash.
- A sign-in link works once and lasts 15 minutes, and asking for a new one cancels the old one.
- Page scripts can't read the sign-in cookie, and every signed-in form or browser call carries a token that other sites can't get.
- Sign-ins, failed keys, AI answers, API calls, data downloads and account emails are rate limited. Rate-limit keys, and the addresses of failed key checks, are kept only as keyed hashes that change every day.
- You can see every browser signed in to your account, and sign any of them out, on the account page.
- A change of email address or a deletion by link needs a link sent to the address in question, which works once and lasts an hour.
- An account sees its own simulations and the ones shared with it, by a person, a team or a class, and a replay link shows only what is described above. A request for anything else gets the same answer as one for something that doesn't exist.
- The AI model gets only the facts for one of your sessions and has no tools, so it can't trade, call the API or see other accounts.
No system is perfectly secure. If a breach puts your personal data at risk, we'll tell you and the regulator as the law requires.
Changes to this policy
We'll post changes here and update the date at the top. When this policy or the terms change, signed-in users see a one-line notice on every page until they press OK, and we record which version each account accepted and when. If a change affects how we use data you've already given us, we'll email every account before it takes effect.
Contact
Email info@tradefloor.dev with any question about this policy or your data. When you're signed in, you can also use the contact page.