Privacy Policy

Last updated: 11 August 2026 (draft aligned to current LoJoRi mobile app behavior).

1. Who we are

LoJoRi (“we”, “us”) is a mobile journaling and decision-support product for traders. This policy describes categories of information the current product processes.

Legal entity name, registered address, and a dedicated Data Protection Officer (if any) are not yet formally designated in this draft. A dedicated privacy@ address is not published; use the support contact below for privacy questions until a separate alias exists.

2. Contact

3. Information we process

3.1 Account authentication

LoJoRi uses Firebase Authentication (email/password). We process authentication identifiers such as your account email and Firebase user id to create and secure your account.

3.2 Profile

Profile fields stored in cloud data (Firestore) may include email, first name, account currency, experience level, markets, trading style, preferred session, starting balance, default risk percentage, account type, onboarding status, checklist preference, and related timestamps.

3.3 Journal and trading records

When you use the product, we store user-owned journal data under your account, including trades (and nested review/checklist content), notes, tags, goals, challenges, and import batch history associated with broker file imports.

3.4 Learning records

Learning commit records associated with your account may be stored in cloud data. Client apps create these records; trusted server deletion removes them with your account tree.

3.5 Import and export

Import flows read broker files you select on device and may create import history and trades in your account. Export flows generate PDF/CSV reports on device for sharing via the operating system share sheet. Exported files leave LoJoRi when you choose to share them.

3.6 Local device data

Some data stays on your device, including:

3.7 Crash diagnostics (Sentry)

When crash reporting is enabled for a build, technical crash and error diagnostics may be sent to Sentry. LoJoRi configures privacy-oriented defaults (for example, default PII sending disabled and message/context sanitization). Crash reporting is separate from the in-app product-analytics toggle.

3.8 Product analytics (PostHog)

When product analytics is enabled for a build and you have not opted out, LoJoRi may send a strict allowlist of anonymous product-usage events (for example screen/feature opens) to PostHog. Journal text, coach conversations, AI content, and trading results are not intended to be sent as telemetry content. You can turn off product analytics in Settings. Missing preference defaults to sharing on; a read failure fails closed to off.

3.9 Production AI backend

The production AI backend capability is currently disabled. Local coach behavior and mock AI modes may still operate without a production AI backend transport. This policy will need updating if a production AI backend is enabled later.

4. Processors / service providers

LoJoRi uses third-party processors to operate the product. Current processors reflected in the implementation include:

These providers process data on our behalf as part of providing the service. This draft does not claim absence of third-party processing.

5. Purposes

6. Security

Access to cloud user data is gated by authentication and Firestore security rules that restrict user documents to the signed-in owner. Sensitive account deletion requires recent reauthentication. This draft does not claim SOC/ISO certifications or specific encryption-at-rest guarantees beyond what the underlying providers document.

7. Retention

Account-associated cloud data is retained while your account exists. After a successful account deletion, Firebase Authentication and the account’s Firestore user tree are removed by the trusted deletion backend. Some device-level preferences and device-global coach history may remain on the device after account deletion. Crash and analytics systems retain data according to those providers’ retention settings and our project configuration.

8. Account deletion

You can delete your account:

Successful deletion removes, in particular:

Typically retained on device after deletion:

9. International processing

Firebase, Sentry, and PostHog may process data in regions configured for the LoJoRi project (for example Cloud Functions in europe-west4; PostHog host configuration may target EU or US ingest). Exact residency depends on project and provider settings and should be confirmed in operations configuration before making stronger residency claims.

10. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. You can export journal data from the app, adjust analytics sharing in Settings, and request deletion as described above. This section is not legal advice and does not assert a specific statutory legal basis or GDPR certification.

11. Children

LoJoRi is intended for adults who trade or journal trading activity. It is not directed to children.

12. Changes

We may update this draft as the product or processors change. Material changes should be reflected on this page with an updated date.

13. Contact for privacy questions

Email support@lojori.com (support inbox; no separate privacy@ alias yet) or use Support.