The short version
- We keep your email address, your simulations and your API keys (as hashes, never the keys). We don't store IP addresses: our rate limits keep a scrambled form that changes every day.
- Vercel, Neon, Amazon SES, Cloudflare and Sentry help run the service. Anthropic sees your question and your simulation's numbers, and only when you ask for an AI answer.
- Your data is stored in the United States.
- No advertising, no tracking cookies, and we don't sell data.
- On the account page you can download your data, change your email address, see where you're signed in, and delete your account.
- We delete accounts nobody has used for 24 months, after an email warning.
- tradefloor is not for anyone under 16.
Who we are
tradefloor is run by Simon Coombes, of the United States ("we"). We decide how the personal data described here is used, so we are its controller under data protection law. Our contact details are at the end of this page.
This policy covers app.tradefloor.dev, its HTTP API, its MCP server and the emails it sends. The website, tradefloor.dev, and the documentation, docs.tradefloor.dev, are separate.
What we collect
- Your account: your email address, when you signed up and were last seen, your plan (with its end date and a history of the plans we granted or withdrew, if any), whether the account is suspended, any note we add to it (such as why we granted a plan), the version of the terms and this policy you accepted and when, whether you want news emails, and when we warned you that an unused account would be deleted.
- Sign-in records. Each sign-in link and its 6-digit code are stored as hashes, never as the link or code. If you ask for a link and never use it, no account is made. Each browser sign-in is stored as a hash of its cookie, with a label naming the browser and system (such as "Firefox on macOS"), when it signed in and when it was last seen. We don't store its IP address or the rest of what your browser sends. You can see the list on the account page.
- Account links: the links we email to confirm a new email address or a deletion, stored as hashes, with the new address until the link is used or expires.
- API keys: each key's id, a salted hash of its secret, the name you gave it, its scope (full, trader or read-only), and when it was made, last used and revoked. We can't show a key again after it's made.
- Connected apps: when you connect an app such as claude.ai over OAuth, its name and web address, the scope you gave it, when you connected it and last used it, and its tokens, stored as hashes.
- Your simulations: the settings you chose (preset, seed, companies, starting prices, scenarios), the names you give simulations and branches, your orders and any notes on them, fills, the simulated market's history, and figures we compute from them, such as report cards and behavior metrics. Also the custom scenarios you save, your saved strategies with every version, and your benchmark runs: the strategies you submit and their results.
- Teams: the teams you make or join, your role in each, and the invitations you send. An invitation holds the address it went to, the role and who sent it, and its code as a hash. It works for 14 days.
- Shares: who you shared a simulation or benchmark run with (a person, a team or a class) and what they may do with it. A share sent to an address with no account waits for that address to sign in, for up to 30 days.
- Replay links: for each one you turn on, the link's code and what it shows, until you turn it off.
- Shared markets: the markets you run, the seats in them with each seat's name and email address, and seat invitations. For a seat you hold, the name you chose and your trades.
- Notifications: the messages in the bell (such as a finished benchmark run, something shared with you, or a problem with your agent) and whether you've read them.
- Your address when someone else types it. When a person invites you to a team, shares something with you or offers you a seat, we store your email address with that invitation and email you, whether or not you have an account.
- Usage: for your account and each key, daily counts of calls, simulated days, compute seconds and refused calls. They apply your plan's limits and show your usage.
- Runs on our servers: for each time you run your code on our servers, the line and strategy version it ran, when it started and ended and why, the CPU time it used, and the last 32 KB of what it printed. Also a daily count of the CPU time you used there, which applies your plan's limit.
- An audit log, with a line for each call that changes a simulation: the call, the time, your account id, the key id (never the key), the simulation, the result and how long it took. A failed attempt to use a key also records a scrambled form of the IP address it came from, which changes every day, never the address itself.
- Rate-limit counters: an IP address, email address or account id, stored as a keyed hash (HMAC-SHA256 under a secret key kept outside the database, and a new key every day), with a count of requests in the current window. Without the key a hash can't be matched to an address, and hashes from different days can't be matched to each other. We still treat them as personal data.
- AI answers. We don't store the questions you type. We keep the answers for 14 days so that asking the same question about the same state costs nothing, and a record of each AI call (your account id, the simulation, the model, the tokens used and the cost) for 90 days.
- Contact messages: what you write on the contact page, emailed to us with your account's email address, account id, plan and sign-up date. They go to our email inbox, not the app's database.
- Notices: which of our notices we emailed you, and when.
- Deleted accounts: one line for each, with the date, whether the owner or our inactivity rule deleted it, how many records went, and a keyed hash of its account id. It names no one: only someone who already knows the id and our secret key could match it.
- Class mode: the classes you teach or have joined, the name you asked a class to call you (optional), your work for them, and whether the Simulator's simple view is on (see Class mode below).
- Logs: the app writes a log line for some requests and errors. Log lines name your account id and simulation ids, never your email address.
We don't ask for your name (a class may ask what to call you, which is optional), a password, a postal address or payment details. Please don't put personal information in simulation names, key names, order notes, questions or custom scenarios.
Why we use it
Where the law asks for a lawful basis for each use of personal data, ours are:
- To provide the service you signed up for: your account, sign-in, keys, simulations, teams and sharing, usage limits, class mode, and AI answers when you ask for them. The basis is our contract with you, the terms of service.
- To keep the service secure and working, and to stop abuse: sign-in records, rate limits, the audit log, the Turnstile check, logs and the deletion log. The basis is our legitimate interest in protecting the service and the people who use it. Most of these records are deleted within days (see How long we keep it).
- To answer messages you send us. The basis is our legitimate interest in replying, or steps you asked for before a contract, such as asking for a larger plan.
- To send occasional news about tradefloor. The basis is our legitimate interest in telling people who use it about it. Each news email has a link to stop them, and you can switch them off on the account page.
- To meet legal obligations, such as answering a lawful request from an authority. The basis is legal obligation.
We email you sign-in links, links that confirm a change you asked for, a receipt when your account is deleted, a warning before we delete an account nobody has used for 24 months, notices we must send (a change to the terms or this policy, or the service ending), replies to messages you send us and, unless you switch them off, occasional news. We don't use your data for advertising, we don't sell it, and we make no decisions about you by purely automated means that have legal or similarly significant effects. Deleting an unused account follows a fixed rule, is announced by email 30 days before, and is stopped by signing in.
Who else handles it
These companies process personal data for us, under their data processing terms, and only for their part of the service:
- Vercel (United States) hosts the app. Every request passes through Vercel, including your IP address and browser details. The app runs in Vercel's Washington, D.C. region. Vercel also counts page views for us (Web Analytics): the page's address with any link, code or id removed, the site you came from, and your browser, device type, operating system and rough location. It sets no cookies and stores no IP address, and it tells visitors apart only by a code made from the request, which it discards after 24 hours. When you run your code on our servers, it runs in a Vercel Sandbox, a separate virtual machine in the same region. The sandbox gets your strategy's code (already kept with your simulation) and the line it trades. It is deleted after the run ends, within minutes. What your code prints passes through Vercel's logging on its way to us.
- Neon (United States) hosts the database that holds everything listed above, in the AWS us-east-1 region in Virginia.
- Amazon Web Services (United States) sends email through Amazon SES: your sign-in links, the other account emails and notices above, and contact messages on their way to us. It handles your email address and the message.
- Cloudflare (United States, with servers worldwide) runs Turnstile, the check on the sign-in page that you're a person. Its script reads signals from your browser, and we send Cloudflare the token it produces and your IP address to confirm the check. Cloudflare's Turnstile privacy addendum says it uses these signals to detect bots and to improve that detection.
- Sentry (United States) receives a report when the app hits an error: what went wrong, where in our code, and the address of the page, with any email address or link token removed. A report carries no IP address, cookies, account details or anything you typed.
- Anthropic writes AI answers, and nothing else. See the next section.
The site's fonts are served from our own site, so no page makes your browser contact Google or any other font service.
When you run your code in the browser, your browser downloads Python from jsDelivr, a public file service, which sees your IP address and browser details as any website does; your code and your data aren't sent there.
If you connect an AI app, an agent or a bot to tradefloor, it reads what it asks for under its own terms, which we don't control. We will also disclose data when the law requires it, for example under a court order.
When you share a simulation, the people and teams you share it with see the simulation and its branches, the notes ("Why") on its trades, your name, your email address and the names of the keys that trade in it. Your name is the one you gave, or the part of your email address before the @. A teammate's branch keeps your notes up to the day it splits from yours. The members of a team see each other's email addresses and how many simulated days each member has used, and a teacher sees the work their students hand in.
A replay link lets anyone who has it watch one simulation or benchmark run, read only, until you turn the link off. It shows none of those: no notes, Why, names, email addresses or key names, and no code, agent instructions or report cards.
AI answers and Anthropic
Anthropic writes the AI answers in the Simulator's Ask panel and from POST /v1/sessions/{id}/ask. When you ask for one, your question and facts about that simulation are sent to it:
- your question, if you typed one (up to 500 characters);
- facts our server computes about that simulation: its settings, prices, your orders, fills and positions, profit and loss, and events;
- text typed into that simulation: its name and its branches' names, the names of the keys that traded in it, and order notes.
We don't send your email address or account id. Quick answers and report cards are computed on our server and send nothing to Anthropic, and neither do the MCP tools report_card and explain_session_move. If you'd rather nothing about a simulation goes to Anthropic, use the quick answers.
Anthropic's Commercial Terms of Service (effective 17 Jun 2025) say "Anthropic may not train models on Customer Content from Services", and its Data Processing Addendum makes it our processor. Anthropic says it deletes API inputs and outputs within 30 days, but keeps them longer where it must to enforce its Usage Policy (up to 2 years for content flagged as a violation) or to comply with the law. Those are Anthropic's commitments as we read them on 24 Sep 2026, and Anthropic can change them.
Cookies and browser storage
| Name | What it's for | How long |
|---|---|---|
| tf_session (cookie) | Keeps you signed in. Page scripts can't read it. | 30 days after your last visit, or until you sign out |
| tf_next (cookie) | Remembers what asked you to sign in, such as an app you're connecting, so you land back there. Set only when a sign-in starts from somewhere other than the sign-in page. | 15 minutes, or until you sign in |
| tf-app-theme (local storage) | Your light or dark choice. Set only when you pick Light or Dark on the account page, under Appearance. | Until you clear your browser's storage |
| tf-allowance-80 (local storage) | The day you were last told you'd used 80% of today's simulated days, so you're told once a day. It holds your account id and a date. | Until you clear your browser's storage |
| tf.sim.tab and tf-sim-hidden-groups (session storage) | The Simulator tab you had open on a phone, and the groups of branches you hid. | Until you close the tab |
The sign-in page also loads Cloudflare's Turnstile script, described above. When you run code in a browser tab, your browser keeps the Python files it downloaded from jsDelivr in its normal cache. There are no analytics, advertising or tracking cookies.
How long we keep it
| Data | How long |
|---|---|
| Your account, custom scenarios, strategies, benchmark runs and their results, teams, and simulations you haven't deleted | Until you delete them or your account, or until we delete an account nobody has used for 24 months (next row) |
| An account with no sign-in and no use of its keys or connected apps for 24 months | We email a warning. If it's still unused 30 days later, we delete it as if you had. Signing in keeps it. Suspended accounts are kept to stop abuse. |
| API keys and connected apps | Until you revoke or disconnect them, then 30 days |
| Usage counts, per account and per key | 13 months |
| What your code printed when it ran on our servers | 30 days after the run ends. The record of each run (when, why it ended, the CPU time it used) is kept 13 months. |
| A simulation you delete | Removed at once with its history. The audit log and cached AI answers about it expire on their own schedule, below. |
| Simulations a benchmark run opens for an agent | Deleted 7 days after the run ends. The results stay with the run. |
| Team invitations | Until they're used or canceled, or 14 days |
| Shares waiting for an address to sign in | Until that address signs in, or 30 days |
| Sign-in links and codes | About a day: they expire 15 minutes after we send them and are deleted 24 hours after that |
| Account links (a new email address, a deletion) | They expire an hour after we send them and are deleted a day after that |
| Browser sign-ins, with the browser's label | Until you sign out (one browser, or everywhere at once), or 30 days after that browser's last visit |
| OAuth codes and tokens | Codes 10 minutes, access tokens 1 hour, refresh tokens 30 days. An app registration with no connection is deleted after 30 days. |
| Rate-limit counters | Until their window ends, from 1 minute to 1 day |
| Retry records (idempotency keys) and the responses they replay | 24 hours |
| Audit log | 90 days |
| Cached AI answers and simulation facts | 14 days |
| Record of AI calls | 90 days |
| Which notices we emailed you | 13 months |
| The line saying an account was deleted | 2 years |
| App logs at Vercel | 1 day |
| Page view counts at Vercel | At least 12 months, by Vercel's policy. They hold no IP address, cookie or account. |
| Error reports at Sentry | 30 days |
| Contact messages | In our email inbox, not the app. Nothing deletes them automatically, so ask and we'll delete yours. |
| What Anthropic receives | Anthropic's policy: within 30 days, with the exceptions above |
Hourly and daily jobs delete each item when its time is up, so an item can last up to a day longer than shown. Deleted data also stays in our database provider's restore history for up to 7 days before it's gone for good.
Where your data is
Your data is stored and processed in the United States: the app in Vercel's Washington, D.C. region, the database and email in AWS's us-east-1 region in Virginia, and error reports at Sentry in the United States. Cloudflare and Anthropic may also handle it in other countries. If you use tradefloor from outside the United States, your data goes to the United States. Where the law of your country asks for safeguards for that, we rely on those in each provider's data processing terms. Ask us for a copy.
Your rights
Depending on where you live, you can ask us to:
- give you a copy of your data, including in a machine-readable form you can take elsewhere;
- correct it, for example to change your email address;
- delete it;
- restrict how we use it, or object to a use based on our legitimate interests.
Most of this you can do yourself, at once:
- download all your data, as JSON or as CSV files, on the account page or with GET /v1/account/export. It's made when you ask, and holds your account, keys (names and dates, never the keys), connected apps, simulations with their settings, orders and fills, usage, benchmark runs and the rest listed above. Your AI questions aren't in it, because we don't store them;
- change your email address on the account page. We email a link to the new address, and tell the old one once it's changed;
- delete your account on the account page, by typing its email address or by a link we email you. POST /v1/account/delete emails that link too;
- see the browsers where you're signed in, and sign out of one or all of them, and optionally disconnect every app, on the account page;
- delete a simulation on the Dashboard, with DELETE /v1/sessions/{id}, or with the delete_session tool;
- revoke a key or a connected app on Connect;
- switch off news emails on the account page or with the link in any of them.
For anything else, email info@tradefloor.dev from your account's email address, or use the contact page while signed in. We'll answer within one month, and may ask you to confirm the request from your account's email address first.
Deleting your account removes your email address, sign-ins, account links, keys, connected apps, simulations, custom scenarios, strategies, benchmark runs, runs on our servers (any still going is stopped first), shares you made, team memberships, class memberships and hand-ins, notifications, usage per key, audit lines and cached AI answers, and it emails a receipt to the old address. A team you own passes to one of its other members, and a team with nobody else in it is deleted. The account page lists these teams before you delete. People you shared simulations with can no longer open them. Two records stay without your id, so the service's daily totals stay right: the daily usage counts (13 months) and the record of AI calls (90 days). We keep the one line saying an account was deleted (above). Logs at Vercel, error reports at Sentry, the restore history and what Anthropic holds expire on the schedules above. Custom scenarios you shared stay in the simulations other people already ran with them.
If you think we've mishandled your data, tell us first and we'll try to put it right. Depending on where you live, you may also be able to complain to a data protection authority.
Class mode
A teacher can set up a class with assignments, and students join it with a code. If you join a class as a student, its teacher can see:
- your email address, the name you gave the class (if any), and when you joined;
- which of the class's assignments you have started and handed in, and when;
- the simulations you open for the class's assignments, and every branch you make from them, with their prices, events, orders, fills, positions and results, read only;
- the report card of each simulation you hand in, and your answers.
The teacher can't see your other simulations, your keys, your connected apps, your usage or anything else in your account. The teacher, or the school they teach for, decides how to use what they see for the class and is responsible for that use, and a school's own privacy notice may also apply. You can leave a class on its page, and the teacher can remove you: either way your answers for that class are deleted and the teacher can no longer see your simulations, which stay yours. Deleting your account does the same for every class you're in.
If you teach, tell your students what you'll see, invite only people aged 16 or over, and use what you see only for the class. If you delete your account, your classes go with it, with their assignments and your students' hand-ins; your students keep their own simulations. The account page warns you first. Tell your students before you do it, so they can keep what they need.
Children
tradefloor is not for anyone under 16, and you must be 16 or over to make an account. The sign-in page says so. We don't ask for a date of birth or check ages. If we learn that an account belongs to someone under 16, we'll delete it.
Security
- Traffic to the app uses HTTPS.
- Sign-in links, codes, browser sign-ins, OAuth tokens and API keys are stored only as hashes. API keys use a salted hash with a secret key kept outside the database, and sign-in codes use a keyed hash.
- A sign-in link works once and lasts 15 minutes, and asking for a new one cancels the old one.
- Page scripts can't read the sign-in cookie, and every signed-in form or browser call carries a token that other sites can't get.
- Sign-ins, failed keys, AI answers, API calls, data downloads and account emails are rate limited. Rate-limit keys, and the addresses of failed key checks, are kept only as keyed hashes that change every day.
- You can see every browser signed in to your account, and sign any of them out, on the account page.
- A change of email address or a deletion by link needs a link sent to the address in question, which works once and lasts an hour.
- An account sees its own simulations and the ones shared with it, by a person, a team or a class, and a replay link shows only what is described above. A request for anything else gets the same answer as one for something that doesn't exist.
- The AI model gets only the facts for one of your simulations and has no tools, so it can't trade, call the API or see other accounts.
No system is perfectly secure. If a breach puts your personal data at risk, we'll tell you and the regulator as the law requires.
Changes to this policy
We'll post changes here and update the date at the top. When this policy or the terms change, signed-in users see a one-line notice on every page until they press OK, and we record which version each account accepted and when. If a change affects how we use data you've already given us, we'll email every account before it takes effect.
Contact
Email info@tradefloor.dev with any question about this policy or your data. When you're signed in, you can also use the contact page.