Effective July 10, 2026
Fulcrum ("Fulcrum", "we", "us") is a trading journal and market-scanning application operated at fulcrumtrade.io. This policy explains what data we collect, why we collect it, how it is protected, and the choices you have. It applies to the Fulcrum web application and its API.
Account data. Your email address and, for password accounts, a salted bcrypt hash of your password (we never store the password itself). If you sign in with Google, we store your Google account identifier and email address (see section 2).
Trading journal data you provide. Trades you log (ticker, direction, quantity, prices, dates), your written theses and exit rationales, and settings you choose. This is the core content of the product and it belongs to you.
Derived analysis. Market context and Anchored VWAP analysis computed for your trades and scans (prices, volumes, patterns, scores), and AI-generated audit and strategy text (see section 4).
Security records. Short-lived, single-use security tokens (email-verification links, password-reset links, sign-in codes) stored only as SHA-256 hashes, together with issue/expiry timestamps and attempt counters.
Billing data. If you subscribe, payment is processed entirely by Stripe on Stripe's hosted pages. We never see or store card numbers; we store only your plan tier.
What we deliberately do not collect. No advertising identifiers, no third-party analytics or tracking pixels, no behavioral profiles, no brokerage credentials — Fulcrum never connects to your broker.
If you choose "Continue with Google", we request the minimal OAuth scopes openid, email and profile. From these we access and store exactly two values: your Google account ID and your email address. They are used solely to create your Fulcrum account, sign you in, and link Google sign-in to an existing account with the same email address.
Fulcrum's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not transfer Google user data to third parties except as necessary to provide the service, with your consent, or for legal reasons; we do not use it for advertising; we do not sell it; and no human reads it except for security, abuse investigation, legal compliance, or with your explicit permission for support.
You can revoke Fulcrum's access at any time at myaccount.google.com/permissions. Revoking access does not delete your Fulcrum account (see section 8).
Only to operate Fulcrum:
Authentication and security — signing you in, emailing single-use sign-in codes (two-step verification for password accounts), verification links, and password-reset links.
The product itself — storing your journal, running market scans, computing AVWAP analysis, generating AI audits and strategy synthesis from your own trading history, and showing your analytics back to you.
Billing — managing your subscription tier via Stripe.
We do not use your data for advertising, we do not sell it, and we do not share it with data brokers. We send no marketing email — only the transactional messages listed above.
Fulcrum's scoring, trade audits, and strategy synthesis are produced by Anthropic's Claude models via the Anthropic API. To generate them we send: market statistics for scanned tickers, the details of trades you ask to be analyzed (ticker, prices, dates, pattern data), your written thesis for those trades, and aggregate statistics of your closed trades. We do not send your email address, password data, or payment information to Anthropic. Anthropic processes this data as a service provider under its commercial API terms; API inputs and outputs are not used to train Anthropic's models under those terms.
We share data only with the processors required to run the service:
Tiingo (market data) — receives ticker symbols and date ranges we query. No personal data is sent.
Anthropic (AI) — as described in section 4.
Stripe (payments) — receives your email and payment details when you subscribe, directly on Stripe's pages.
AhaSend (transactional email) — receives your email address and the content of the security emails we send you (verification links, reset links, sign-in codes).
DigitalOcean (hosting) — the servers and database run in DigitalOcean data centers.
Beyond these, we disclose data only if required by law, or to protect the security and integrity of the service.
Fulcrum sets exactly one cookie: an HTTP-only, secure session cookie that keeps you signed in. It contains no tracking information and expires after 7 days. There are no analytics, advertising, or third-party cookies.
All traffic is encrypted in transit (TLS). Passwords are hashed with bcrypt; security tokens and sign-in codes are stored only as SHA-256 hashes, are single-use, and expire quickly (codes in 10 minutes, reset links in 1 hour). Password sign-ins require a second factor: a one-time code sent to your email. Access to production systems is limited to the operator.
We keep your data for as long as your account exists. Trades you delete in the app are soft-deleted (recoverable by you) rather than destroyed, so you can restore them; security tokens expire automatically and are retired after use.
To permanently delete your account and all associated data — including Google account data, journal entries, analysis, and AI-generated text — email privacy@fulcrumtrade.io from your account address. We complete deletion within 30 days and will confirm when it is done. Backups age out within a further 30 days.
Depending on where you live (e.g. GDPR in the EU/UK, CCPA in California), you may have rights to access, correct, export, restrict, or delete your personal data, and to object to processing. Contact us at the address below and we will honor these requests for all users regardless of location. You also have the right to complain to your local data-protection authority.
Fulcrum is a financial tool for adults. It is not directed at children under 18, and we do not knowingly collect data from them. If you believe a minor has created an account, contact us and we will delete it.
If we make material changes, we will update this page, change the effective date above, and notify signed-in users in the app before the changes take effect.
Data controller: Fulcrum (fulcrumtrade.io). For any privacy question or request: privacy@fulcrumtrade.io.