Privacy Policy
How Peritum collects, uses and protects your data
Controller
Peritum is operated by Marvin Singer, Kampstr. 7, 49832 Freren, Germany ("Peritum", "we", "us"). You can reach us at admin@peritumfx.com. This policy explains what personal data we process, why, and the rights you have over it.
Legal Basis for Processing
We process your personal data on the following legal bases:
Contract fulfillment
Account data, trading data, and subscription information are processed to deliver the services you have requested under our contract (e.g., journaling, analytics, and account sync). This is the legal basis for the core processing of your account and journal data.
Legitimate interest
We process usage data in aggregated, anonymised form to understand which features are useful and to improve the platform. This is based on our legitimate interest in improving our services.
Consent
When you use AI-powered features, you provide content that is sent to our AI provider. Using these features constitutes your consent to that processing. You can withdraw consent at any time by simply not using the AI features.
Legal obligation
We retain certain records — such as payment and tax records — to comply with legal regulatory obligations, even after you request deletion of your account.
Data We Collect
Account data
When you create an account we store your email address, an optional display nickname, and a hashed password managed by our authentication provider. We also store subscription, billing, credit balance, tier and role information linked to your account.
Usage data
We record which pages and features you use and how long you spend on them, in aggregated and anonymised form, to understand which parts of the platform are useful and to improve them. No personal usage profiles are sold or shared with third parties.
Trading data
Trade history, journal entries, notes, screenshots you upload, daily session notes, settings and statistical calculations you generate are stored linked to your account so that your journal and analytics function correctly.
Account Creation & User Profiles
You create an account with an email and password (or via Google sign-in). Your profile is limited to an email and an optional nickname. You can edit or delete your account data at any time from Settings or by contacting us.
Payment Processing
Stripe
Card payments are processed by Stripe. Stripe receives your card details directly — we never see or store full card numbers. Stripe may pass back a customer identifier and the outcome of the payment so we can activate your subscription or purchase.
PayPal (where available)
PayPal payments are offered through Stripe's payment method configuration. When you pay with PayPal, PayPal handles the authentication and authorisation; we only receive a confirmation that the payment succeeded.
Apple Pay & Google Pay (where available)
Apple Pay and Google Pay are wallet payment methods offered through Stripe. Your device handles the authentication (Face ID, Touch ID, or device PIN); the wallet passes a tokenised payment to Stripe. We do not receive or store your wallet credentials or card details.
Cookies & Analytics
We use essential cookies and local storage to keep you logged in, remember your preferences (such as theme and journal settings), and keep the app working. We use analytics to track aggregate usage in our own database; we do not use advertising networks or third-party tracking pixels that profile you across the web.
Email Notifications
We may send you emails about your account: payment receipts, security notices, login alerts, and messages from the Peritum team. You can opt out of non-essential emails from your settings or by following the unsubscribe instructions. Transactional emails about your account and payments cannot be disabled.
AI Features
Peritum offers AI-powered analysis and support assistants. When you use these features, the data you provide (such as your aggregated journal statistics or the question you ask) is sent to our AI provider to generate a response. This data may be processed by servers located outside the European Union (for example in the US), where different data protection rules apply. By using AI features, you agree to this transfer. AI outputs are analytical observations only and are never investment advice. Do not enter sensitive personal data you would not want processed by our AI provider into AI features.
Trading Account Connections
You can optionally connect external trading accounts to sync your trade history into your journal. We support several connection methods:
MetaTrader EA
A lightweight Expert Advisor runs on your own MT5 terminal and submits your closed trades to us using an API key you generate. We never receive your MT password in this mode.
TradeLocker
Cloud sync through the TradeLocker backend API. You provide your TradeLocker email, password, server and account ID. These are used to authenticate with TradeLocker and stored by us so we can keep your journal up to date.
cTrader
Secure OAuth connection through the Spotware Open API. You authorise Peritum to read your cTrader account; we store an access and refresh token (no password). You can revoke access at any time from your cTrader account settings or from our app.
Binance
Cloud sync through the Binance public API. You provide a read-only API key and secret (no withdrawal permissions) and select which trading pairs to monitor. Your API key and secret are stored by us so we can periodically fetch your closed trades. We only read your trade history — we never place, modify or close orders.
Tradovate
Cloud sync through the Tradovate REST API. You provide your Tradovate username and password; these are stored by us so we can authenticate and periodically fetch your closed futures trades. We only read your trade history — we never place, modify or close orders.
Third-Party APIs
We rely on third-party services to provide trading-account sync and market data, including the TradeLocker API, the Spotware cTrader Open API, Binance, Tradovate, and data providers such as Finnhub. These providers process the data you send them (for example your MT credentials or instrument requests) according to their own terms and privacy policies. We are not responsible for how third parties handle your data once it leaves our systems.
Credential Storage
For cloud-sync connections (TradeLocker, Tradovate and Binance) we store your credentials or API keys so we can re-sync your account without you re-entering them each time. These credentials are stored within our database, are restricted to the sync process, and are never used to place, modify or close trades — we only read your closed trade history. We do not store your full card numbers or wallet credentials at any time; payment details are handled entirely by Stripe and the respective wallet providers.
How to Disconnect an Account
You can disconnect any connected trading account at any time. In the Journal page, open the account switcher, select the account, and choose delete/disconnect. Disconnecting removes the stored credentials and stops all future syncing for that account; your already-imported trade history remains in your journal unless you choose to delete it. For cTrader, you can also revoke access from your Spotware/cTrader account settings.
Data Sharing & Sub-Processors
We only share your data with the service providers we need to run the platform: our hosting and database provider, our authentication provider, Stripe and the wallet providers for payments, and the trading-account and market-data APIs listed above when you choose to use them. We never sell your personal data.
Data Retention
We keep your account and journal data for as long as your account is active. When you delete your account, we remove your personal data within a reasonable period, except where we are legally required to retain records (for example tax and payment records).
Age Requirement
Peritum is not directed at individuals under the age of 18. You must be at least 18 years old, or of the minimum age required to enter into a binding contract in your jurisdiction, whichever is higher. If your jurisdiction requires a higher minimum age (for example 21), you are responsible for ensuring you meet that threshold before using the platform. We do not knowingly collect personal data from individuals under the applicable minimum age. If you believe a child or young person under the applicable age limit has provided personal data to us, please contact us so we can investigate and delete it.
Your Rights (GDPR)
Depending on where you live, you may have the right to access, correct, delete, export or restrict the processing of your personal data, and to object to or withdraw consent for certain processing. To exercise these rights, contact us at admin@peritumfx.com. You can also lodge a complaint with your local data protection authority.
Security
We apply reasonable technical and organisational measures to protect your data, including access controls and encrypted transit. No method of transmission or storage is completely secure, but we work to protect your data and act promptly if an issue is identified.
Contact
For any privacy questions or requests, email admin@peritumfx.com.
Last updated: 29 July 2026