Privacy Policy
This policy explains what personal data we collect, why we process it, who we share it with, and how to ask for deletion or an export.
Last updated September 27, 2026. Chapi Labs operates Trade Desky.
Chapi Labs (“we”) provides Trade Desky. This policy covers the website, the Trade Desky Watcher desktop app, and the receiver API. It does not cover Tradier, Schwab, Discord, or Whop’s own sites. Whop’s privacy notice is at whop.com/privacy.
1. Data we collect
Account
Name, email, password hash, and whether the email is verified. We do not store your password in plain text.
Session and device
Sign-in session cookie, IP address and user agent associated with the session, and a hashed device API key issued for the desktop app. The website also writes a local theme preference in the browser.
Broker connections
Broker name, connection status, account id, environment (paper/live where applicable), and encrypted OAuth or API credentials you provide for Tradier or Schwab.
Alerts, settings, and trades
Notification text the desktop app forwards while you are signed in; normalized parse output; sizing and risk settings; inbound alert records; and trade execution records (including broker responses we store to show history).
Billing
Subscription status, plan name, renewal/end dates, and Whop membership identifiers when present. We do not receive or store full card numbers. Whop processes the payment.
Support
Emails you send to [email protected], including the address you write from.
2. How we use data
- Create and authenticate your account
- Parse alerts and submit or skip broker orders according to your settings
- Show dashboards, connections, and billing status
- Prevent abuse, debug failures, and meet legal requests we are required to honor
- Email you about the account, billing, or material product changes
We do not sell personal data. We do not use advertising cookies or sell data to ad networks.
3. Alert text and AI
When the desktop app is signed in, notification bodies are sent to our ingest API and may be sent to a third-party AI inference provider to extract a structured order intent. Treat alert text as content we will process. Do not expect notification banners that contain passwords or unrelated secrets to stay only on your machine.
4. Processors and sharing
We share data only as needed to run the product:
- Infrastructure and database hosting (including PostgreSQL and the server that runs the API)
- Tradier and Charles Schwab, after you connect them, to authorize and place orders
- The AI inference provider configured for parsing
- Authorities if the law requires it
5. Location
We operate from Chapi Labs and store application data with providers that currently host in the United States. If you use the service from another country, you transfer data to the United States to receive it.
6. Cookies
We use a session cookie that is required to keep you signed in (HttpOnly session). Without it, the product cannot authenticate the browser. We do not use analytics pixels or advertising cookies. You can block cookies in the browser; you will be signed out.
7. Retention
We keep account, trade, and alert records while the account exists and for a reasonable period afterward if we need them for billing disputes, security, or law. You can disconnect a broker at any time from Connections, which removes stored credentials for that broker. To delete the account or request an export, email [email protected] from the registered address.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Email [email protected]. We may need to verify the account. We will not discriminate against you for exercising a privacy right the law gives you.
If you are in the EEA or UK and we process data to perform the contract (providing the software you signed up for) or for legitimate interests (security and abuse prevention), those are the grounds we rely on. You may lodge a complaint with your local data authority.
9. Children
The service is for adults who can legally trade. We do not knowingly collect personal data from children. If you believe we have, email [email protected] and we will delete it.
10. Security
Broker tokens are encrypted at rest. No method of transmission or storage is completely secure. You still control broker-side permissions and can revoke OAuth or rotate API tokens at the broker.
11. Changes
We will post updates on this page with a new “last updated” date. If we materially expand how we use personal data, we will also note it in the product or by email when practical.
Questions: [email protected]