Legal
Privacy Policy
Last updated: 21 August 2026
This policy explains how we collect, use, share and protect personal data when you visit candelajournal.com, create a Candela account, or use the Candela trading journal. It is written to satisfy Articles 13 and 14 of the UK GDPR, and it describes what our systems actually do — no more and no less. Please read it alongside our Terms of Service.
1. Who we are
Candela is a trading name of Ryrex Finance Ltd, a company registered in England and Wales (company number 14500886) with its registered office at 13 Whitchurch Lane, Edgware, HA8 6JZ, United Kingdom. Ryrex Finance Ltd is the controller of the personal data described in this policy — that is, we decide why and how it is processed. We are registered with the UK Information Commissioner's Office as a data controller under registration reference ZC228212.
If you have any question about this policy, or want to exercise any of the rights described in section 9, contact us at support@candelajournal.com. We have not appointed a Data Protection Officer, as we are not required to; privacy queries are handled by the company directly.
Candela is a journaling and analytics tool for retail traders. It is not a broker, does not execute trades, and does not provide investment advice.
2. The data we collect
Almost everything Candela holds is data you deliberately put into your journal. We group it as follows.
Account data
When you sign up with email and password we collect your first and last name (combined into a display name), your email address, and your password. Your password is handled by our authentication provider, Supabase Auth; it is never stored in readable form by our application. The interface language you were using at signup is saved as your preferred language. If you sign in with Google instead, we receive your email address and profile name from Google via the sign-in handshake (see section 5); we do not import your Google profile photo.
From your settings you may add or change: display name, first and last name, time zone, display currency, markets traded, interface language, notification preferences, and an optional profile picture. Please note that profile pictures are stored in a publicly readablestorage location — anyone with the file's address can view the image, so upload only an image you are comfortable being public. You can also maintain personal tag vocabularies (setup tags, mistake tags, indicators, symbols, timeframes, markets — names and colours only).
We keep an activity logof significant actions on your account (for example “trade logged”, “journal exported”, “settings updated”). This log is append-only, visible to you in your settings, and exists so you can see what has happened on your account.
Trading journal data
The core of the product is content you author: trades (symbol, instrument type, direction, prices, size, fees, stop loss, target, risk amount, profit or loss, open/close times, broker reference, source platform), the journaling detail you attach to them (timeframe, setup and mistake tags, indicators, news-event annotations, playbook notes, whether you followed your plan), trading accounts (name, currency, broker, platform) and their deposits and withdrawals, strategies (rules, markets, timeframes, notes), and optional chart screenshots and hindsight images, which are stored in a private storage bucket accessible only to you via time-limited signed links.
If you import a broker statement (currently MT5), the file is parsed in memory and the file itself is not stored. What persists is the parsed result: the trades, any deposits or withdrawals it contained, and an import record holding the platform, the file name and the trade count.
Psychology and wellbeing journal
Candela lets you journal the human side of trading, and we want to be explicit about what that involves. Entirely at your option, you can record:
- per-trade emotional state before and after (1–5 scales) and free-text thoughts before and after;
- daily check-ins: hours and quality of sleep, whether you exercised, units of alcohol, cups of caffeine, whether you ate, stress level, energy level, where you were trading, whether you were distracted, and free-text notes;
- weekly and monthly mind goals.
Every one of these fields is optional and can be left blank. This is self-reported lifestyle and wellbeing information; some of it (sleep, alcohol, stress) is health-adjacent, and we treat all of it with heightened care: it is protected by per-user database access rules, it is never used for advertising or for any profiling beyond the analytics you see in your own dashboard, it is not displayed in our administrative tools, and it is shared with a third party only when you use the AI coach (section 4).
We ask before we store any of it. The first time you open the daily check-in, Candela shows a notice explaining what the questions cover, that answering is optional, and that your recent check-ins are sent to our AI provider if you use the coach — and asks you to agree in as many words. Nothing from the check-in is stored until you do, and declining leaves the rest of the Mind Journal working normally. That agreement is the explicit consent on which we rely for this data to the extent it constitutes health data under the UK GDPR, and we record when it was given and which version of the notice you saw. If we ever materially change what we collect or why, we ask again rather than carrying the old consent forward.
Withdrawing is straightforward and it means something.Settings → Data & privacy has a Withdraw consent control: it stops us processing this data and permanently deletes every daily check-in you have recorded, including the daily thoughts written in the Mind Journal, which are part of the same check-in. Your trades and the rest of your journal are untouched, and withdrawal does not affect the lawfulness of what we did beforehand. You can also overwrite any day's answers by filling the check-in in again, or ask us to erase specific days (section 9).
AI coach conversations
If you use the AI coach, we store the textof your messages and the assistant's replies as conversations in your account, so you can return to them. Images and PDFs you attach to a coach message are sent to the AI model to answer that conversation but are not saved to our database or storage. We also keep a per-message usage ledger (model used, token counts, number of images, credits charged and our cost) for billing and abuse prevention; this ledger contains no message content. Section 4 describes exactly what is sent to our AI provider.
Payments and billing
Checkout and payment are handled by Whop, which acts as the merchant of record — the legal seller of the subscription, responsible for taking payment and accounting for UK VAT. Your card details, billing address and Whop account are collected by Whop on whop.com and never touch our systems. What we hold is entitlement data: your plan, subscription status, a Whop membership identifier, and AI credit balances. When Whop notifies us of billing events by webhook (an automated server-to-server notification), we receive and retain the event data Whop sends — which includes the buyer's email address, membership and plan details — and we store the raw event record for audit and reconciliation. When you open the AI credit-pack checkout, your Candela account identifier (a random code, not your name or email) is included in the checkout link so the purchase can be matched back to your account.
Partner programme
If you join our affiliate programme, we send your Candela account email address to Whop to create your Whop affiliate account, and we receive back and store your Whop affiliate ID, Whop username, share links, and performance statistics (earnings, referral counts, active members, retention rates), refreshed periodically. Clicks on your referral link are logged with the short code, the referring site's hostname and the destination — no IP address, device identifier or visitor identityis recorded. Visitors arriving via a referral link are asked for cookie consent like everyone else; only if they choose “Accept all” is a first-party attribution cookie set (see section 7). If they later sign up, the referral is recorded against their profile so your commission can be attributed at checkout.
Please note: the partner leaderboard shows your rank, your Whop username and your earnings to every other signed-in partner. It is not visible to the public or to ordinary Candela users. If you have not set a Whop username, the leaderboard falls back to your referral short code, which is derived from the part of your email address before the @ — join the programme with this in mind.
Support and communications
If you raise a support ticket we collect your email address, the subject and message you write, and the page you were on. If you opt in to our Sunday newsletter (an unticked checkbox at signup, or the footer form), we record your email address, optionally your first name, your interface language, and where you signed up, and we share those with our newsletter delivery provider, Kit (section 5). We send transactional emails — subscription confirmations, credit-purchase receipts, and partner-programme notifications — as a consequence of your actions, not as marketing.
Technical data
We deliberately run no third-party analytics, advertising or session-recording tools. The technical data we process is limited to: the cookies and browser storage described in section 7; your IP address, used transiently to rate-limit a small number of endpoints (newsletter signup, statement parsing, support tickets, and the referral-cookie consent claim) — these rate-limit records are not linked to your profile and are purged after approximately one day; and standard server-side error logs. Our hosting providers (Vercel, Supabase) generate their own infrastructure logs, including request IP addresses, as part of operating the platform; we do not use these to identify or profile visitors.
3. How we use your data and our lawful bases
Under the UK GDPR we need a lawful basis for each purpose. They are:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and operating your account and journal — authentication, storing and displaying your trades, images, strategies, check-ins, goals and settings; statement imports; the analytics in your own dashboard | Account data; trading journal data; psychology and wellbeing data | Contract — providing the service you signed up for. For health-adjacent wellbeing fields, additionally your explicit consent, given through the notice shown before your first daily check-in and withdrawable at any time in Settings → Data & privacy (sections 2 and 9) |
| Providing the AI coach when you send a message | Coach conversation, attachments, and the journal context described in section 4 | Contract — you request the feature each time you use it; wellbeing context rests on the consent above |
| Billing, entitlements and receipts | Plan, entitlement and webhook data; email | Contract; retention of billing records also serves our legal obligations (tax and accounting) |
| Transactional emails (subscription activated, credits purchased, partner notifications) | Email address, plan/credit/earnings details, preferred language | Contract — service communications resulting from your actions |
| Sunday newsletter | Email, optional first name, language | Consent — opt-in only, withdraw at any time |
| Whop marketing pixel and Trustpilot review widget | Whatever those scripts collect in your browser (section 7) | Consent— loaded only if you choose “Accept all” |
| Running the partner programme, attributing referrals and paying commissions | Partner email, Whop username and stats; referral cookie and click log; referral marker on referred accounts | Contract (with partners); consentfor storing the referral cookie on a visitor's device (set only on “Accept all”); legitimate interests (attributing referrals accurately so partners are paid correctly) for the click log and the attribution itself |
| Support | Ticket contents, email | Contract and our legitimate interest in resolving your issues |
| Security: session management, optional two-factor authentication, rate limiting, webhook verification, the account activity log | Session cookies, IP addresses (transient), audit events | Legitimate interests — keeping the service and your account secure and preventing abuse |
| AI usage metering and abuse prevention | Usage ledger (tokens, credits, cost — no content) | Legitimate interests — fair metering, cost control and abuse prevention |
| Remembering interface preferences (language, selected account, log view, display mode) | Preference cookies and browser storage (section 7) | Legitimate interests — a functioning interface; these are strictly first-party functional preferences |
We do not use your data for automated decision-making producing legal or similarly significant effects, and we do not build advertising profiles.
4. The AI coach
The AI coach is powered by models from Anthropic(the maker of Claude), called through Anthropic's commercial API. Anthropic acts as our processor for this feature — a provider that handles data only on our instructions. Under the commercial API terms we rely on, Anthropic does not use data submitted through the API to train its models.
We think you should know exactly what is sent. When you send a coach message, the request to Anthropic includes:
- your message, the full history of that conversation (each prior turn is re-sent with every request), and any images or PDFs you attach;
- summary statistics for your trading accounts (account name as you named it, currency, trade counts, win rate, net P&L);
- your strategies in full (rules, notes, news stance);
- your last 50 trades, including setup and mistake tags, P&L, emotions before and after, and excerpts of your free-text thoughts;
- your last 60 daily check-ins, including the sleep, alcohol, caffeine, exercise, stress, energy, location and notes fields you filled in.
We do not attach your name, email address or Candela account identifier to these requests — they are made under Candela's own API key. However, any text you have written yourself — account names, strategy notes, journal thoughts — is sent as you wrote it, so if it contains your name or other identifying details, those reach the model.
Afterwards, Candela stores the conversation text (your messages and the replies) in your account — you can delete any conversation, which also deletes its messages — and a usage-ledger row containing token counts, image count, credits and cost, but no content. Attachments are not stored by Candela at all.
The coach produces suggestions and analysis for you to read; it does not make any automated decision about you, and nothing it produces has legal or similarly significant effects.
The coach sends data to Anthropic only when you send a message. Because coach requests include your recent check-ins, using the coach is also the moment your wellbeing entries are shared with Anthropic on our behalf; if you would rather your journal context — including wellbeing data — never reach the AI provider, do not use the coach, and nothing will be sent.
6. International transfers
Our database, authentication and file storage are hosted by Supabase. Several of our providers are, or process data in, the United States — including Vercel, Anthropic, Resend, Kit, Whop, Google and Trustpilot — so depending on the provider, personal data may be processed in the United Kingdom, the European Union and the United States.
Where personal data is transferred outside the UK, we rely on safeguards recognised by UK law: the UK Extension to the EU–US Data Privacy Framework where the provider is certified, and otherwise the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, as incorporated in each provider's data processing terms, together with any UK adequacy regulations that apply. You can ask us at support@candelajournal.com for more information about the safeguard applied to a particular transfer.
8. How long we keep your data
Our default is simple: your journal is yours, and we keep it until you delete it. Specifically:
- Journal content (trades, images, strategies, check-ins, goals, coach conversations): kept until you delete the individual items or your account. Deleting a trade also deletes its chart images from storage; deleting a coach conversation deletes its messages; clearing or deleting a trading account removes its trades and their images.
- Account and settings data: kept for the life of your account.
- Activity log: append-only for the life of your account; deleted with the account.
- Billing webhook records: raw payment and membership event records are retained for audit, reconciliation and dispute handling for six years from the end of the financial year in which the event occurred, in line with UK tax record-keeping, then deleted.
- AI usage ledger: retained for billing integrity and abuse prevention for the life of your account; deleted with the account.
- Support tickets: retained so we can handle follow-ups for up to 24 months after closure, then deleted; deleted earlier if you delete your account.
- Newsletter subscription: kept until you unsubscribe; it is independent of your account (see below).
- Rate-limit records containing IP addresses: purged after approximately one day.
- Consent record: 180 days, then we ask again.
What happens when you delete your account
You can delete your account yourself at Settings → Data & privacy (a typed confirmation is required). Deletion is immediate: your profile, trading accounts, trades and all journal text, image records and the stored image files themselves (chart screenshots, hindsight images and your avatar), imports, strategies, daily check-ins, mind goals, coach conversations and messages, AI usage records, support tickets, activity log, tag vocabularies, partner records and entitlements are all deleted. There is no soft-delete or grace period.
Two caveats:
- Billing event records: raw Whop webhook records are retained (no longer linked to any account) for audit and financial reconciliation on the six-year schedule above; these can include the email address Whop sent us.
- Newsletter: your newsletter subscription is keyed to your email address, not your account, and survives account deletion; unsubscribe via the link in any newsletter or by emailing us, and we will also remove you from our delivery provider, Kit.
Backups maintained by our database provider may retain deleted data for a limited period (currently around seven days) before cycling out.
9. Your rights
Under the UK GDPR you have the right to: access your personal data; rectify inaccurate data; erase data; restrict processing; object to processing based on legitimate interests; data portability for data you provided under contract or consent; and to withdraw consentat any time, without affecting processing before withdrawal — for cookies via the footer “Cookie settings” link, for the newsletter via the unsubscribe link, and for wellbeing data via the Withdraw consent control in Settings → Data & privacy, which also deletes every check-in you have recorded.
Self-service tools cover most of this:
- Export: Settings → Data & privacy offers a download of your trade journal as CSV or JSON. This export covers your trades (including tags, emotions and journal text); it does not yet include strategies, check-ins, images or coach conversations — email us and we will provide the rest as part of an access or portability request.
- Rectification: everything in your journal and settings is directly editable in the app.
- Erasure: delete individual items in-app at any time, or delete your entire account at Settings → Data & privacy (section 8).
For anything the tools do not cover, email support@candelajournal.com from the address on your account. We will respond within one month; if a request is complex we may extend by up to two further months, and we will tell you if so. We may need to verify your identity before acting. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk (helpline 0303 123 1113). We would appreciate the chance to resolve the issue first. If you are in the EEA, you may also complain to your local supervisory authority.
You are under no statutory obligation to provide personal data, but without an email address we cannot create an account, and the journal only works with the content you choose to put in it.
10. Security
We take proportionate technical and organisational measures, including:
- Encryption: all traffic is served over TLS, with HTTP Strict Transport Security enforced; data is encrypted at rest by our database and storage provider.
- Per-user database isolation: the tables holding your journal and account data are protected by row-level security, so each account can read and write only its own rows — enforced in the database itself, not just the application.
- Authentication: passwords are handled and hashed by Supabase Auth, with a minimum-strength policy at signup; sign-in with Google is available; optional two-factor authentication (authenticator-app codes) is available to every account and, once enrolled, is enforced server-side on every sign-in — including on the administrator and partner areas.
- Private storage: chart and hindsight images live in a private bucket, readable only via short-lived signed links scoped to your account. (Avatars are intentionally public — see section 2.)
- Least-privilege administration: admin access is role-based, limited to a separate admin host, and — as described in section 5 — excludes journal text, coach conversations and wellbeing data from the admin interface, with database-level access rules keeping coach and check-in data owner-only.
- Abuse controls: rate limiting on sensitive endpoints; billing webhooks are verified with cryptographic signatures and a freshness check before being trusted.
- Standard hardening: security headers on every response (frame-embedding denied, MIME sniffing disabled, restrictive referrer and permissions policies).
- Accountability: an append-only activity log on every account; sign-out from one device or all devices.
No internet service can promise absolute security, and we do not claim it. If we become aware of a personal data breach likely to result in a risk to you, we will notify the ICO and, where required, affected users, in accordance with our legal obligations.
11. Children
Candela is a tool for trading contracts for difference and similar leveraged products, and is intended for adults only. You must be at least 18 years old (or the age of majority where you live, if higher) to use Candela. The service is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact support@candelajournal.com and we will delete it.
12. Changes to this policy
We will update this policy as the product and the law evolve. The “Last updated” date at the top always reflects the current version. For material changes — new categories of data, new recipients, or a new purpose — we will give you reasonable advance notice by email or an in-product notice before the change takes effect. Where a change relies on your consent (for example a new consent-based purpose, or a wider use of wellbeing data), we will ask for that consent afresh rather than treating continued use as agreement. Otherwise, continued use after the effective date constitutes acceptance of the updated policy; if you do not agree, you can export your journal and delete your account at any time.
13. Contact
Ryrex Finance Ltd (trading as Candela)
Registered in England and Wales, company number 14500886
Registered office: 13 Whitchurch Lane, Edgware, HA8 6JZ, United Kingdom
ICO data protection register reference: ZC228212
Email: support@candelajournal.com
For complaints about our handling of personal data, you may also contact the Information Commissioner's Office: ico.org.uk.