TradeNovaPRIVATE BETAEffective August 1, 2026
Privacy Policy
This policy explains how TradeNova, operated by KZ Operations LLC, handles information for the TradeNova private beta, including its read-only AI connector.
Information we handle
- Account information: email address, username, password verifier, approval status, profile image, MFA configuration, session records, and account-recovery records.
- User content: journal text, screenshots, videos, habits, trading accounts, account groups, RuleGuard settings, payout-tracking information, notes, imports, and other information you choose to save.
- Trading records: manually entered or authorized imported P&L, trade dates, symbols, side, quantity, prices, and account labels.
- Connector information: registered AI-client name and redirect addresses, approved read scopes, hashed OAuth tokens, token status, connection dates, and tool names used.
- Security and technical information: hashed network and user-agent identifiers, security-event type and outcome, rate-limit records, and error details that do not intentionally include journal contents.
How we use information
We use this information to provide and secure TradeNova, authenticate users, save and restore user content, display trading history and analytics, operate user-requested connector tools, prevent abuse, investigate failures, respond to support and privacy requests, and improve beta reliability. We do not sell personal information or use connector data to advertise to you.
AI connector disclosures
The connector is read-only. It returns only the requested TradeNova journal, historical trading, account, or RuleGuard fields to the AI provider you authorize. It does not return TradeNova passwords, MFA codes, OAuth tokens, journal media bytes, internal user IDs, connection IDs, diagnostic IDs, or security logs. Credential-like text found inside journal text is filtered where practicable, but you should never save passwords, API keys, access tokens, or MFA codes in TradeNova.
Recipients and service providers
Information may be processed by Cloudflare for application hosting, database, storage, security, and operational delivery. If you connect an AI provider such as OpenAI or Anthropic, requested connector results are sent to that provider at your direction and are then governed by that provider's terms and privacy policy. Authorized support personnel may access the minimum information needed to address a request or security issue. We may disclose information when legally required or necessary to protect users and the service.
Retention
- Account information and saved TradeNova content are retained while the private-beta account remains active and until an account-deletion request is completed, subject to necessary security, legal, and backup exceptions.
- OAuth authorization codes and approval pages expire after 10 minutes. Access tokens expire after one hour. Refresh tokens expire after 30 days and rotate when used. Expired authorization codes and hashed token records are pruned; grant records may remain with the account for revocation and security auditing.
- Rate-limit records are pruned after approximately seven days. Security-event records may be retained for up to 12 months, or longer when reasonably necessary to investigate abuse, preserve account security, or meet a legal obligation.
- When deletion is requested, we aim to remove or deidentify eligible account information and content from active systems within 30 days. Residual encrypted backups may persist for a limited recovery cycle before being overwritten.
Your controls
You can disconnect an AI provider from TradeNova's AI Connections page to revoke its connector tokens. You may request access, correction, export, or deletion of your information by emailing tradernovadev@outlook.com. We may need to verify that the request belongs to the account holder.
Security
TradeNova uses account-scoped database queries, password hashing, optional MFA, short-lived sessions and access tokens, rotating refresh tokens, PKCE, token hashing, encryption for configured provider secrets, input limits, rate limits, security headers, and audit events. No security method is perfect, so keep your own backup of important trading records and report suspected account compromise promptly.
Children and changes
TradeNova is not directed to children under 13. A minor who may legally use TradeNova must have any consent required from a parent or guardian. TradeNova does not enable brokerage activity. We may update this policy as the private beta changes; the effective date above will be updated when material changes are published.