SpiceLog

Privacy Policy

Last updated 2026-09-08

This Privacy Policy explains what SpiceLog LLC, a Utah limited liability company ("SpiceLog," "we," "us"), collects when you use the SpiceLog website, application, and related services (the "Service"), why we collect it, and the choices and rights you have. It's part of the same agreement as our Terms of Service — read together, not separately.

What we collect

SpiceLog is a trading journal: what it collects follows directly from what the product does.

  • Account and authentication data — your email address, display name, a securely hashed password (we never store the password itself) or a Google account link, and session identifiers that keep you signed in.
  • Financial data you import or enter — trades, executions, profit-and-loss figures, and broker or account labels from files or connections you choose to import. This is the core of the product: without it, there's nothing to journal.
  • Content you create — journal entries (plans, reviews, lessons), tags, and any images you attach to an entry.
  • Technical and security metadata — IP address and browser user-agent at sign-in, and a log of security-relevant account events (sign-ins, password changes, exports, deletions). We use this to keep accounts secure and to investigate abuse, not to track you across the web.
  • What you send us directly — anything you include in a bug report or a message to monte@spicelog.com, including attachments you choose to add.

We do not collect government IDs, payment card numbers, or health information — SpiceLog has no billing today and never asks for these.

How we use it, and why we're allowed to

Everything above is used to operate the Service you signed up for: authenticating you, storing and displaying your own trade and journal data back to you, computing the statistics and charts the Service shows, and keeping the account secure. We do not sell your data, and we do not use your trades or journal entries to train models offered to other customers.

For anyone in the UK, EU, or a similar jurisdiction: our legal basis for almost everything here is that it's necessary to perform the contract you agreed to by using the Service (GDPR Art. 6(1)(b)). Security and abuse-monitoring metadata is processed on the basis of our legitimate interest in keeping the Service working and secure, balanced against your privacy. Nothing today is processed on the basis of your consent, because SpiceLog runs no marketing, analytics, advertising, or profiling of any kind.

Who else sees it

We use a small number of service providers to run the Service. None of them is permitted to use your data for their own purposes.

  • DigitalOcean — hosts the production server and its backups.
  • Resend — delivers transactional email (password resets, verification links, account notices). Bug reports you submit are delivered to a Google Workspace inbox we monitor.
  • Google — provides "Sign in with Google" if you choose it (we receive only your email, name, and a Google account identifier, never your Google password), and hosts the Google Workspace mailbox that receives your bug reports and any message you send to monte@spicelog.com.
  • Yahoo Finance — if you choose to load a price chart on a trade, our server requests that symbol and time range from Yahoo's public data feed. No information about you or your account is sent.

We do not use any analytics, advertising, or session-recording vendor. Beyond the providers above, we disclose account information only when required by law, to protect the rights or safety of SpiceLog or our users, or with your direction.

SpiceLog is based in and operates from the United States, and every provider above is a US company. If you use the Service from outside the United States, your information is transferred to, stored, and processed in the United States. For anyone in the UK, EU, or Switzerland: each of these providers has signed a data processing agreement with us that incorporates the European Commission's Standard Contractual Clauses (and the UK Addendum) for that transfer, and DigitalOcean and Google are additionally certified under the EU-U.S. Data Privacy Framework.

Who at SpiceLog can see it

Access inside SpiceLog is need-to-know, not open by default. Support and administrative work happens through a separate staff tool with its own sign-in and multi-factor authentication, and every look at a customer account through it is written to a permanent audit log. Today that tool shows account-level information only (your email, sign-up and verification status, whether an import succeeded); it has no way to open your trades or journal entries. Staff never copy customer data to personal devices, email, or tools outside that audited system.

Two things sit outside that tool, and we'd rather say so than imply otherwise. First, the owner operates the servers and can reach the database directly for maintenance, backups, and recovery; that access is used for operations, not for reading individual accounts. Second, a bug report you send us, with any screenshot or file you attach, lands in the Google Workspace mailbox named above; we delete those attachments 90 days after the report is resolved. We use AI-assisted engineering tools to build and maintain the Service, and they are barred from reading customer records.

How long we keep it

Your account and trading data is kept for as long as your account is active — this is a journal product, and the value is in the history it builds. Some narrower categories are kept for a shorter, fixed window: password-reset and email-verification links expire and are deleted within 30 days; a security audit log entry is kept for 24 months; the raw broker file data behind an import is reduced to just enough to detect duplicates 90 days after the import finishes, since nothing in the app reads the full raw row back after that. If you delete your account, your trades, journal entries, and profile are deleted immediately; encrypted backups taken before that point age out on our standard backup schedule.

Your rights and how to exercise them

You can export a full copy of your account and trading data at any time from within the app, and delete your account and all of its data yourself from Settings — both take effect immediately, with no need to contact us first.

Depending on where you live, you may also have the right to request access to, correction of, or deletion of your personal information, or to object to certain processing, through a channel other than the app itself. To do that, email monte@spicelog.com. We verify a request comes from the account it concerns before acting on it, and we respond within 30 days (GDPR/UK GDPR) or 45 days (CCPA/CPRA), whichever applies to you — there's never a fee for the first copy of your own data in a rolling 12 months.

Cookies

SpiceLog uses only the cookies the Service needs to function: a signed session cookie that keeps you logged in, and a short-lived cookie used only during Google sign-in. We use no advertising, analytics, or tracking cookies, and no cookie consent banner is shown because nothing here is optional or used to track you elsewhere.

Children

The Service is not directed to, and is not knowingly used by, anyone under 18 — see the eligibility requirement in our Terms of Service.

Changes to this policy

We may update this policy from time to time, for example to reflect a new feature or a change in law. If a change is material, we'll make reasonable efforts to tell you, such as an in-app notice, before it takes effect.

Contact

Questions about this policy, or a privacy request of any kind, can be sent to monte@spicelog.com.

Back to SpiceLog