Privacy Policy
Last updated:
Effective September 18, 2026. Tick LLC, a Florida limited liability company, operates Tick at tick.so. Questions: matteo@pitline.to.
1. What we collect
Account information you give us. Email address, username, display name, password (stored hashed, never in plain text), and anything you add to your profile.
Trading data from your broker. When you connect a brokerage account, we receive your order and fill history: instrument, direction, quantity, entry and exit prices, timestamps, and account identifiers. We receive this directly from your broker. You never type it in and you cannot edit it.
Content you create. Posts, comments, theses, thesis annotations, community messages, and any media you upload.
Technical data. IP address, browser and device type, and pages visited, used to operate and secure the service.
2. What we do not do
We never place, modify, or cancel trades. Our access to your brokerage account is read-only, enforced by the permissions your broker grants us, not only by our own code.
We never receive or store your brokerage username or password. You authenticate directly with your broker, which issues us an access token instead.
We do not sell your personal information.
3. How your broker connection works
Connecting a broker uses OAuth. You are sent to your broker's own login page, you authenticate there, and you approve the specific permissions we request. Your broker then issues us an access token scoped to your account.
We store that token encrypted. You can revoke it at any time, either in Tick or through your broker. Revoking stops all future data import; trade data already imported remains in your account until you delete it.
4. What is public, and what is not
This section matters more than any other. Read it before connecting an account.
Always public, regardless of your settings. Your coverage percentage — the share of your verified trades that you have posted to the feed. This is public whether your journal is public, private, or paid. It is what makes a private journal trustworthy from the outside, and it cannot be hidden.
Public when you choose. Any trade you post to the feed, along with its verified data and your commentary. Posts, comments, and community messages in public communities.
Public after release. Theses submitted during the submission window are sealed, then published in full at 4:00 PM Eastern on the same trading day. This is automatic and cannot be undone. Do not put anything in a thesis you are not willing to publish. Your Mentor Round votes are also published at that time, with your name, as comments on the theses you voted on.
Private by default. Your full journal, if set to private or paid. Trades you have not posted to the feed. Your email address. Direct messages.
Visible to subscribers. If you paywall your journal or run a paid community, the people who pay see what that subscription covers.
5. Who else sees your data
We use third parties to run the service. They process data on our behalf and only for that purpose: Supabase (database, authentication, encrypted token storage), Vercel (application hosting), NinjaTrader and Tradovate (your brokerage connection and trade data), and Stripe (subscription billing).
We may disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger or sale of the business.
6. Retention and deletion
We keep your data while your account is active. You can delete individual posts at any time, and you can delete your account entirely, which removes your profile, imported trade data, posts, and journal.
Two exceptions. Content others have interacted with may persist in their view of a thread. Released theses remain part of the public record of that trading day, because other traders' votes and comments are attached to them.
We retain what we must for legal, tax, and accounting purposes.
7. Your choices
You can disconnect a broker, change your journal's access mode, delete individual posts, delete your account, and request a copy of your data by emailing matteo@pitline.to.
Depending on where you live, you may have additional rights over your personal information, including access, correction, deletion, and portability. Contact us and we will respond.
8. Security
Access tokens are stored encrypted. Database access is governed by row-level security policies so that users can only reach their own data and what has been made public. No system is completely secure, and we cannot guarantee absolute security.
9. Children
Tick is not for anyone under 18. We do not knowingly collect information from minors. If we learn we have, we delete it.
10. Changes
We will post any changes here and update the effective date. Material changes affecting how your data is used or displayed will be notified in the application before taking effect.