Privacy Policy

Privacy Policy

This Privacy Policy explains how FXOptimize, operated by Frederik Baunsøe ("we", "us", "our"), a private individual based in Denmark, collects, uses, and protects your information. We believe in transparency — especially when it comes to your trading data.

Last updated: 2026-08-16

The short version: Your backtest files are parsed entirely in your browser — the raw files are never uploaded to our servers. The same applies to the Pass Lab propfirm calculator: all Monte Carlo, walk-forward, and bootstrap computation happens locally in WebAssembly. We do collect anonymized portfolio-level metrics (EA names, performance statistics) to improve the service. We never see your individual trades, prices, lot sizes, or account balances.

Contact

1. Data Controller

The data controller responsible for your personal data under the General Data Protection Regulation (GDPR) is:

Collection

2. What We Collect

Account Information

When you sign up via Supabase (our authentication provider), we collect:

  • Email address and name (from email signup or Google login)
  • Authentication tokens managed by Supabase

Saved Sessions

If you choose to save a portfolio session, the session data (EA configurations, portfolio settings, optimization results) is stored on our servers. This is opt-in — you control when and what you save.

Anonymous Portfolio Analytics

After each analysis, we automatically collect anonymized performance data to improve our service. This includes:

  • EA names and currency pairs — as detected from your backtest report headers (e.g., "FXHexaFlow 8", "EURUSD")
  • Portfolio-level metrics — return %, max drawdown, Calmar ratio, Sortino ratio, win rate, and other aggregate statistics
  • Portfolio compositions — which combinations of EAs appeared in top-performing portfolios
  • Backtest date ranges — the start and end dates of your backtests
  • Verdict outcomes — when you run the propfirm pass-rate calculator: the firms compared, the primary backtest match firm and its 95% CI, top failure modes, and the worst-EA-contributor ranking. We never receive your trades or balance — only the aggregated per-firm pass-probability summary.

This data helps us build EA performance rankings and identify which EA combinations work well together. It is anonymized — it cannot be traced back to individual users or their trading accounts.

What we do NOT collect: individual trade entries/exits, prices, lot sizes, account balances, commission details, or the raw backtest file content. Pass Lab is no exception — the Monte Carlo simulation runs entirely in your browser via WebAssembly.

Payment Information

Payments are processed entirely by Stripe. We never see, store, or have access to your full card number. We only receive confirmation of payment status and subscription details from Stripe.

Verified Badge

The Pass Lab propfirm calculator can produce a Verified Badge share link of the form /pass-lab/badge#v=…. The badge encodes only the high-level summary you see on the results page (primary backtest match firm, 95% CI bounds, match strength, top failure mode, badge timestamp). It does not contain your trades, your balance, your EA names, or any account identifier. The badge data lives entirely in the URL fragment (the part after #), which is never sent to our servers — browsers do not transmit URL fragments in HTTP requests. The badge includes a non-cryptographic checksum (FNV-1a) so the page can detect tampering and warn the viewer; this is integrity-only, not encryption.

Collection

3. What We Don't Collect

Backtest files — Your MT4/MT5 HTML files are parsed entirely in your browser. They are never uploaded to or processed by our servers.

Individual trade data — We don't see your specific trades, entry/exit prices, lot sizes, or account balances. Only aggregated portfolio-level metrics are used for anonymous analytics.

Tracking cookies — We do not use advertising cookies, tracking pixels, or any form of cross-site tracking.

Browsing history — We don't track what pages you visit outside of FXOptimize.

Collection

4. How We Use Your Data & Legal Bases

We process your personal data on the following legal bases under GDPR Art. 6:

  • Contract (Art. 6(1)(b)) — Account management, service delivery, storing and retrieving your saved sessions, and payment processing. Required to provide the Service you signed up for.
  • Legitimate interest (Art. 6(1)(f)) — Product improvement via anonymized portfolio metrics; security, fraud prevention, and abuse mitigation (including per-device quota enforcement for the free tier).
  • Legal obligation (Art. 6(1)(c)) — Retention of payment records for tax and accounting purposes under Danish bogføringsloven.
  • Communication — Service-related emails (billing, important updates). No marketing spam.
Sharing

5. Sub-Processors

We use the following sub-processors that may process some of your data. Where data is transferred outside the EU/EEA, transfers rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs):

Sub-ProcessorPurposeData ProcessedRegion
SupabaseAuthentication & databaseEmail, name, hashed credentials, OAuth tokens, saved sessionsEU (configured)
StripePayment processingPayment method, billing address, subscription statusUS (SCCs / DPF)
ResendTransactional and drift-alert email deliveryEmail address, message content of the emails we send youUS (SCCs / DPF)
CloudflareCDN, DDoS protection, DNSIP address, request metadataGlobal edge
HetznerServer hostingApplication data at restGermany (EU)
Cloudflare Web AnalyticsCookieless pageview/traffic analytics (server-side)Aggregated page views, referrers (no PII, no cookies, no fingerprinting)Global edge
Umami (self-hosted — first-party, not a third party)In-app product analytics, runs on our own Hetzner server. Loaded only with your analytics consent.Aggregated in-app events (which features/steps were used) + a cookieless localStorage visitor count. No PII, no cross-site tracking, no backtest data.Germany (EU)

Each sub-processor has its own privacy policy. We recommend reviewing them if you have specific concerns.

Retention

6. Data Retention

  • Account data — Retained while your account is active, plus up to 90 days after deletion for operational wind-down
  • Saved sessions — Retained until you delete them or close your account
  • Anonymous analytics — Retained indefinitely (cannot be linked back to you)
  • Payment records — Retained for 5 years after transaction as required by Danish bogføringsloven
  • Broker-sync data — Retained only while the broker account is connected. Hard deletion immediately upon disconnect (trades, EA mappings, account snapshot)
Collection

7. Synchronization (Optional Feature)

If you opt into the Synchronization feature (available on the Solo and Studio plans), we process additional data necessary to maintain a read-only connection to your MetaTrader 4 or MetaTrader 5 brokerage account. This section applies only to users who explicitly connect a broker account via the /app/connect flow. It does not apply to backtest analysis, Pass Lab, or any other Service feature.

What we collect for broker sync

  • No broker credentials. We do not ask for, receive, or store your investor password, your trading password, or any broker API key. Sync works the other way round: the FXOptimize Tracker Expert Advisor, which you install in your own MetaTrader terminal, pushes data out to us. Nothing connects to your broker from our side, and the link carries no instructions back.
  • Broker server name and account number — used to route sync requests to the correct broker.
  • Trade history — closed trades and currently-open positions retrieved from your account, normalized to UTC.
  • Per-trade metadata — symbol, lots, open/close price, profit, swap, commission, magic number, comment.
  • Account snapshot — current balance, equity, margin level, currency. Updated on each 5-minute sync cycle.

What broker sync allows us to do

  • Retrieve your read-only trade history and account statistics for display in your dashboard.
  • Compute drift detection metrics comparing your live trades to a backtest baseline you previously uploaded (Pass Lab flow).
  • Group trades by EA (using the magic number assigned by your EA, which you can override or rename).

What broker sync does NOT allow us to do

The tracker EA only ever sends data outward, and we send no instructions back. We cannot, and will never:

  • Place, modify, or close trades on your account
  • Deposit funds, withdraw funds, or change your balance
  • Modify your account settings, leverage, or risk parameters
  • Access your trading password, full broker portal, or any funds-movement capability
  • Access your personal banking, payment methods, or KYC documentation held by your broker

Where Sync is available

Sync is available worldwide, including to residents of the European Economic Area and the United Kingdom. An earlier version of this policy restricted it pending a GDPR review of credential-storage processing. That processing no longer exists: the current design stores no broker credential of any kind, so the basis for the restriction is gone.

The whole of FXOptimize — backtest analysis, Pass Lab, and Sync — is available to all users on the same terms.

Sub-processor for broker connections

There isn't one. Earlier versions of Sync brokered the connection through MetaApi (Agile Trading B.V., Netherlands). The current design has no connection to broker — your own terminal pushes the data — so no third party sits between us and your account. See §5 Sub-Processors for the services we do use.

Retention

All broker-sync data is retained until you disconnect the account. When you click "Disconnect" in your settings, we perform a hard delete immediately:

  • All synced trades — deleted
  • EA mappings — deleted
  • Account snapshot — deleted

Records we are required to keep for accounting purposes under the Danish bogføringslov are retained for the statutory period. They contain no trade data and no broker information.

Storage

8. Cookies & Session Storage

FXOptimize uses only strictly necessary cookies and session storage required for the Service to function. No consent banner is required because no optional tracking cookies are used.

  • fxo_anon_session — HttpOnly, Secure, 1-year Max-Age. A pseudonymous per-device identifier (non-PII) used to enforce the free-tier monthly analysis quota. Legal basis: ePrivacy Directive Art. 5(3) "strictly necessary for a service the user has explicitly requested."
  • Supabase authentication tokens — Stored in the browser's sessionStorage (cleared when you close the tab). Required to keep you signed in during a session.
  • Stripe cookies — Set by Stripe during checkout, governed by Stripe's privacy policy.

We do not use any advertising, cross-site tracking, or third-party marketing cookies. Our analytics — Cloudflare (pageviews, server-side) and self-hosted Umami (in-app usage) — set no advertising or cross-site cookies; Umami stores only a single first-party localStorage value to count unique visitors, and is loaded only after you consent.

Cookies & analytics consent

FXOptimize uses two privacy-first analytics layers, both free of advertising and cross-site tracking. Cloudflare measures aggregated pageviews and traffic server-side — no client-side script, cookies, or fingerprinting. Umami, which we self-host on our own server (no third-party analytics vendor), measures how the in-app tool is used — which features and funnel steps people reach — so we can improve it. It never receives your backtest data.

Umami is cookieless and does not fingerprint. It stores a single first-party localStorage value to count unique visitors without a cookie. Because that touches client-side storage, we load Umami only after you accept analytics in the cookie banner, and you can withdraw consent any time via Manage cookies, which stops it immediately. Cloudflare, being server-side and identifier-free, needs no consent.

What we collect: aggregated pageviews, country (from IP, not stored), browser + OS family, the referrer URL, and — once you consent — aggregated in-app events (which features and funnel steps were reached, never your backtest data). What we do NOT collect: your email, name, raw IP address (Cloudflare anonymizes it at ingest), specific URLs of authenticated app pages (those are blocked from analytics in robots.txt), device fingerprints, or behavioral profiles.

We also receive minimal HTTP server logs (IP + URL + timestamp) for security and rate-limiting purposes — these are deleted after 14 days and never linked to user identity.

Storage

9. Data Security

We take reasonable measures to protect your data, including:

  • Encrypted data transmission (HTTPS/TLS 1.3 with HSTS preload)
  • Secure authentication through Supabase
  • Cloudflare protection against DDoS and malicious traffic
  • Regular security audits
  • No broker credentials to protect — Sync is push-only from an EA you install, so there is no password, key, or token of your broker's on our systems at all
  • Row-Level Security (RLS) policies on Supabase enforce per-user isolation: a user cannot read another user's broker credentials or trade history even with direct database access

No method of transmission or storage is 100% secure. If you discover a security vulnerability, please contact us immediately at [email protected].

Rights

10. Data Breach Notification

In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Danish Data Protection Authority (Datatilsynet) within 72 hours, and affected users without undue delay, in accordance with GDPR Articles 33 and 34.

Rights

11. Your Rights (GDPR)

As we are based in Denmark (EU), you have the following rights under GDPR:

  • Access (Art. 15) — Request a copy of all personal data we hold about you. Available self-service in your account settings as "Download my data".
  • Rectification (Art. 16) — Correct inaccurate personal data
  • Erasure / Right to be forgotten (Art. 17) — Request deletion of your account and personal data. Available self-service in your account settings as "Delete my account". Note: payment records are retained for 5 years under bogføringsloven but are disassociated from your identity.
  • Portability (Art. 20) — Receive your data in a structured, machine-readable format (JSON export via "Download my data")
  • Objection (Art. 21) — Object to processing of your data for specific purposes
  • Restriction (Art. 18) — Request limited processing of your data
  • Lodge a complaint — You have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk if you believe your data is being processed unlawfully

To exercise any of these rights, use the self-service options in your account settings or contact us at [email protected]. We will respond within 30 days.

Rights

12. Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Collection

13. Children's Privacy

FXOptimize is not directed at anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us.

Rights

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Service. The "Last updated" date at the top reflects the most recent revision.

Contact

15. Contact

For privacy-related questions, data requests, or concerns:

Privacy contact: [email protected]

General support: [email protected]

Frederik Baunsøe · Denmark