Security and data

Security and your data

Plain answers to what a careful trader asks before connecting a funded account: where your journal is stored, how sign-in works, what the sync EA can and cannot do, and how to take your data with you or delete it.

Every statement here was checked against the journal’s code on 9 October 2026.

Your device firstThe journal saves on your device, then syncs a private backup tied to your account.
No password to leakYou sign in with a 6-digit code sent to your email.
The EA cannot tradeThe sync EA only reads. It has no code that places, changes or closes a trade.
Cards stay with StripeCard details go to Stripe’s checkout and never touch our servers.

Where your journal lives

Every trade you log is saved first in your browser’s storage on the device you are using. That is why the journal opens fast and keeps working when your connection drops.

When you sign in, a copy syncs to a private backup on Netlify, our hosting provider, tied to your account. Clear your browser, lose a laptop or switch to your phone, and the journal comes back as you left it. A few details worth knowing:

  • Chart screenshots you paste into a trade stay on your device. The cloud copy leaves them out.
  • The backup keeps up to 12 restore points, and it always takes one before any change that would shrink your journal, so a bad sync or an accidental wipe can be rolled back.
  • The backup only answers to a signed-in session for your account. Knowing someone’s email address gets you nothing.
  • On the device itself, the journal also keeps its last 5 automatic snapshots, which you can restore from Settings.
What it is not: end-to-end encrypted. Your backup travels over HTTPS and sits in private, access-controlled storage, but it is not locked with a key only you hold. That is how our servers can build your Monday report email and check your prop limits for live alerts. If you need zero-knowledge storage, the journal does not offer it today, and we would rather say so than imply it.

How sign-in works

There is no password to choose, reuse or leak. To sign in on a new device you enter your email and we send you a 6-digit code.

  • A code works once, for 10 minutes, and allows 5 tries.
  • At most 3 codes an hour can be sent to one email, and the sign-in screen never reveals whether an account exists.
  • We store each code only as a keyed hash, never the code itself.
  • Once the code checks out, that device gets its own device token so you are not asked again every day. Tokens are also stored only as a hash, a device left idle for 60 days has to sign in fresh, and one email can hold 10 devices at most.

Your plan is re-checked every day, so a cancelled or refunded subscription stops being Pro on every device. Lost a phone? Email journal@rbtrading.site and we can sign your email out of every device.

The sync EA reads. It never trades.

Live sync uses a small file you add to your own platform: the RBSync Expert Advisor for MetaTrader 4 and MetaTrader 5, and the RBSync cBot for cTrader. We read the source of all three for this page.

  • It reads three things: your open positions, your closed history, and your balance and equity.
  • None of the files contains an order function. The MetaTrader files have no OrderSend, OrderModify or OrderClose call and the MT5 file never loads the trade library. The cBot never calls ExecuteMarketOrder, ModifyPosition or ClosePosition. There is no path in the code to place, change or close a trade.
  • It never asks for your trading password or investor password. It runs inside a terminal you are already logged into.
  • You download it as plain source code (.mq4, .mq5 or .cs). Open it in MetaEditor or cTrader and read it before you run it.

Two setup prompts can look alarming, so here is why they appear. MetaTrader only runs an EA with Algo Trading switched on, even one that only reads. cTrader asks for full access because a cBot needs it to reach the internet and send your snapshot to the journal.

What it sends, every few seconds and on each trade event: your account number, server name, currency, balance, equity and net deposits, plus each position’s symbol, side, lots, prices, stop, target, profit, commission, swap, times and order comment. We keep the latest snapshot and up to 1,000 closed trades per synced account, filed under your sync code. That code is 18 random characters made on your device, so treat it like a key and keep it out of screenshots.

How live sync works

What the AI sees when you ask for a review

AI only runs when you press a button for it. Nothing is sent to an AI model in the background.

  • A trade review sends that one trade as text: symbol, direction, prices, size, R, setup, tags, emotions, mistakes and your notes.
  • An account review sends your account stats and a one-line summary of each trade.
  • Ask RB sends your question and a short summary of the current account, worked out on your device. Never the raw journal.
  • Screenshots are never part of a prompt, and neither is your email address.

The request goes to Anthropic, the company behind Claude, through their API, for one purpose: to write your answer. Our servers do not save the question or the reply. We keep only a count of how many you have used and what each one cost, so the daily limits and the monthly fair-use cap work.

Payments run on Stripe

When you upgrade, checkout happens on Stripe’s own hosted page. Your card number goes to Stripe and never touches our servers; we store only your plan and whether it is active. If you subscribe through Whop instead, Whop takes the payment.

Cancelling, pausing for two months or switching to annual all happen inside the journal under Settings. Card changes and invoices live in Stripe’s customer portal. Prices and the 30-day guarantee are on the pricing page.

Take your data with you

  • Export CSV: every trade in your current view with date, symbol, market, direction, entry, exit, stop, target, size, P&L, commission, swap, net P&L, R, result, setup, tags, notes and mistakes. It opens in Excel or Google Sheets.
  • Download Backup: one JSON file with your trades, accounts, playbooks, plans, rules and settings. Restore it on any device from Settings.

Both are on the free plan. Your journal is never held behind an upgrade.

Deleting your data

On your device you are in control. Delete a single trade, delete a whole account, or use Clear All Journal Data in Settings, which asks twice and then wipes the journal from that browser.

Clearing a device does not delete your cloud backup, and that is on purpose: the backup refuses to be overwritten by an empty journal, so a wipe by mistake can still be restored. To delete the backup, your sync data and your account records, email journal@rbtrading.site from the address you sign in with. Our privacy policy commits us to act on verified requests within one month. Billing records we must keep for tax are the one exception.

Who handles what

NetlifyHosts the site and the journal, runs our server functions and stores the backup and sync data.
Stripe and WhopTake payments. Stripe for cards, Whop if you subscribe on Whop.
ResendSends your sign-in codes and product emails.
AnthropicWrites AI replies, only when you ask for one.

We never sell your data, and your trades never go to an advertiser. The site runs over HTTPS, and its pages refuse to be framed by other sites. On the public pages, visitors in the UK and EEA get analytics and ad measurement only after they accept the cookie banner. The journal app itself loads neither.

You will not find compliance badges on this page. It lists what the code does today, and when the code changes, this page changes with it.

Questions traders ask

Can RB Trading see my trades?

Your cloud backup is private but not end-to-end encrypted, so our systems can read it. They do so for two jobs you get from the product: the Monday report email and live prop alerts. We never sell your data, and your trades never go to an advertiser.

Can the RBSync EA place or close trades?

No. The MT4, MT5 and cTrader files contain no order functions at all. They read your positions, history and balance and send them to your journal. You download them as source code, so you can read every line before you install one.

Do I have to give you my broker password?

No. The EA runs inside a platform you are already logged into, and file imports use an export you download yourself. The journal never asks for a trading or investor password.

How do I export my journal?

Use Export CSV for a spreadsheet of your trades, or Download Backup in Settings for one JSON file with your whole journal. Both work on the free plan.

How do I delete my account and data?

Clear All Journal Data in Settings wipes the journal from that device. To delete your cloud backup, sync data and account records as well, email journal@rbtrading.site from the address you sign in with.

See it with your own trades

Log a few trades, export them, read the EA before you install it. The free plan covers your first 50 trades with no card and no time limit.

Start free, no card

Questions about your data? journal@rbtrading.site