Security
How the trading journal handles your exchange keys and your data. Last updated: October 2026
The journal exists to read your trading history. It has no way to place an order, cancel one, move money or withdraw, and it is built so that it never needs the right to. This page says exactly what that means.
Read-only keys, checked
- When you connect an exchange you create an API key on the exchange yourself, with only reading switched on: no trading, no withdrawals, no transfers.
- Where the exchange lets us ask what a key is allowed to do, we ask before keeping it. A key the exchange says can trade or withdraw is refused and never stored. Today that check runs for Binance, Bybit and OKX, and the same check is repeated once a day on keys already stored. If a stored key is later changed on the exchange to allow trading or withdrawal, the Exchanges page shows it in red and we email you.
- Some exchanges cannot tell us what a key may do. For those the Exchanges page says not verified and you should check on the exchange that trading, withdrawals and transfers are off. We never describe a key as read-only unless the exchange confirmed it.
- The journal's code asks exchanges only for your trades, orders, positions and balance history. It contains no order, cancel, transfer or withdrawal request. (A few exchanges require reading requests to be sent as POST; they are still reads.)
- Where the exchange allows it, restrict the key to our server's IP address as well. It is optional and extra protection.
How keys are stored
- Your API secret, key and any passphrase are encrypted before they reach the database (authenticated encryption: libsodium, or AES-256-GCM where that is not available). The encryption key lives in a file outside the public web folder and never in the database or in a release package, so a copy of the database alone cannot be used to sign requests.
- After you save a key we show only its last four characters. We cannot show you the secret again, and neither can anyone using your account.
- Keys for the AI you choose for Ask are stored the same way and are used only to answer your own questions.
Your data stays yours
- Every journal row belongs to your account and is only read for you. Ask works over your own rows only, with read-only queries, and shows each query it ran.
- You can disconnect an exchange at any time from the Exchanges page; the stored key is erased from our database at that moment. Also delete the key on the exchange itself.
- You can download everything we hold about you, or ask for erasure, from My Account.
- Passwords are not used for the site: you sign in with a one-time code sent to your email.
What we cannot promise
No system is perfectly secure. We keep the software up to date, limit what each part can do, and log failures, but we cannot guarantee that nothing will ever go wrong, and the journal and Ask are provided as analysis tools, not as financial advice (see our Terms). The most protective thing you can do is also the simplest: use a read-only key, and delete it on the exchange when you stop using the journal.
Report a problem
If you believe you have found a security issue, please tell us privately through our contact page before sharing it publicly, and we will respond as quickly as we can. If you ever suspect a key has been exposed, delete it on the exchange first, then tell us.