← Back to home

Security & Privacy Commitments

Last updated: September 2, 2026

🔒 Your trades are yours

Every trade you log, every journal entry, and every emotion note is protected by database-level access controls that prevent anyone else from reading your data — even other paying Grabbovoi users. Below is exactly how that works, so you don't have to take our word for it.

1. How your data is isolated (the technical guarantee)

Grabbovoi runs on Postgres, hosted by Supabase (SOC 2 Type II certified). Every table containing user data — trades, journal_entries, emotion_entries, practice_trades, film_room_trades — is protected by Row-Level Security policies that enforce two rules on every read:

  1. The row's user_id must equal the signed-in user's ID
  2. The signed-in user must be a paid member

These rules live in the database, not in the app code. That means even if a bug slipped into a route somewhere, the database itself will refuse to hand back rows that don't belong to you. A signed-in paying user asking for "all trades" only ever gets back their own.

2. Who has administrative access

Exactly one person — the founder, DaViana — has administrative access to the Grabbovoi infrastructure (Supabase, Vercel, the code repository). Every admin-only route in the application checks a single hardcoded email before granting access.

Support contributors (if any) hold read-only access to the code repository so they can review pull requests, but they have zero access to the production database, production environment variables, or any user data.

3. Our access policy

The founder could, in principle, query the database and read any user's trades — administrative access implies technical capability. We commit as a matter of policy to never access individual users' trading data or journal entries, with two narrow exceptions:

  1. To resolve a specific support ticket you have opened, when it's impossible to help without looking
  2. To respond to a valid legal request we're legally required to comply with

Any such access is a manual, deliberate action — not an automated process — and would be documented in the resulting support ticket.

4. What we send to third parties (and don't)

Grabbovoi integrates with a small number of vendors to run the product. Here's exactly what each one sees:

  • Supabase — the database host. Holds your data at rest, encrypted, subject to the RLS rules above.
  • Vercel — the web host. Sees traffic but not database contents.
  • Whop — payment processing. Sees your email + subscription status. Does not see any trade data.
  • Resend — transactional email delivery (welcome + access-link emails). Sees your email and the email content sent to you. Does not see trade data.
  • Kit (ConvertKit) — Academy visitor mailing list only. Sees the email you optionally submit at the free Academy overlay. Does not see any account or trade data.

We do not use analytics vendors that would relay your trading behavior. No Google Analytics, no Mixpanel, no Segment on user-data pages. No third-party session recorders.

5. What we don't collect

  • Your broker credentials, API keys, or trading passwords — CSV uploads are the only way trades enter the system
  • Your credit card number or billing address — Whop handles all payment info
  • Your Discord messages, servers, or friends list
  • Your location, device fingerprint, or IP address (beyond standard server access logs)

6. Deleting your data

You can delete every trade, every journal entry, every emotion note, and your account itself from the Settings page inside the dashboard at any time. Deletion is immediate and permanent — there is no soft-delete window.

7. Reporting a security concern

If you discover a vulnerability or have a security concern about how your data is being handled, email support@grabbovoi.com directly. We'll respond within one business day.

This page is meant to be honest and specific, not marketing copy. If any claim here is unclear or feels overstated to you, tell us — we'll fix it.