Vienne is a personal trading journal operated from Estonia, European Union. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Estonian Personal Data Protection Act, the operator of Vienne is the data controller of the personal data described in this policy.
Contact for all privacy matters, including requests to exercise your rights:
truevienne@gmail.com
We have not appointed a Data Protection Officer, as we are not required to under GDPR Article 37. Privacy requests are handled directly by the operator at the address above.
This policy covers the Vienne web application and the account system behind it. It does not cover third-party services you choose to connect or visit, such as an AI provider or our community chat — those are governed by their own policies.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Email address, username, display name, password stored only as a bcrypt hash, role, registration date, last login | You, at sign-up |
| Journal content | Trading days, profit and loss figures, trade counts, symbols, sessions, direction, your written notes on reasoning, mistakes and improvements, discipline ratings, and any screenshots you attach | You, as you use the app |
| Accounts and expenses | Names, sizes, currencies and types of the trading accounts you create, plus the fees, payouts and costs you record | You, as you use the app |
| Licence data | Licence key, plan, activation and expiry dates | Generated by us when a key is issued |
| Device identifier | A hash derived from your browser and device characteristics, used to bind one account to one device and prevent abuse of free accounts | Computed in your browser at login |
| Technical logs | IP address, timestamp, requested endpoint, and error information | Automatically, when your browser contacts our server |
| Preferences | Theme, accent colour, layout and other interface settings | You, in Settings |
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and maintaining your account, authenticating you | Account data, device identifier | Art. 6(1)(b) — performance of a contract |
| Storing, syncing and displaying your journal and calculating your statistics | Journal content, accounts and expenses | Art. 6(1)(b) — performance of a contract |
| Sending password-reset and essential service emails | Email address | Art. 6(1)(b) — performance of a contract |
| Issuing and validating licence keys | Licence data, account data | Art. 6(1)(b) — performance of a contract |
| Keeping the service secure, preventing abuse and duplicate free accounts | Technical logs, device identifier | Art. 6(1)(f) — legitimate interests in protecting the service; balanced against your rights, using the least identifying data that works |
| Sending your journal data to an AI provider for analysis | The filtered journal data you select | Art. 6(1)(a) — your consent, given by enabling the feature and entering your own key |
| Complying with legal obligations and defending legal claims | Whatever is strictly relevant | Art. 6(1)(c) and Art. 6(1)(f) |
Where we rely on consent, you may withdraw it at any time by turning the relevant feature off; this does not affect the lawfulness of processing carried out before withdrawal.
Vienne uses no advertising, analytics or tracking cookies, and therefore does not display a cookie consent banner — under the ePrivacy Directive, consent is not required for storage that is strictly necessary to deliver a service the user has requested.
We store the following in your browser:
| Key | Purpose | Lifetime |
|---|---|---|
| Authentication token | Keeps you signed in between visits | Until you log out or it expires |
| Device identifier | Binds your account to this device | Until browser storage is cleared |
| Journal cache | A local copy of your trades, accounts and expenses so the app works instantly and offline | Until you log out or clear it |
| Preferences | Theme, accent, layout and feature toggles | Until you reset them |
| AI provider key | Stored locally so AI requests can be made from your browser | Until you remove it |
Clearing your browser storage will sign you out and remove the local copy; your server-side journal is unaffected.
Your data lives in exactly three places: a managed Neon PostgreSQL database, which is where the account and journal records themselves are stored and which runs on Amazon Web Services infrastructure; the Render platform, which runs the application server and receives the request logs it writes to its standard output; and Resend, which delivers the occasional service email. We operate no servers of our own and keep no copies of your data on local machines.
We do not sell, rent or trade personal data, and we do not share it for anyone else's marketing. These three processors act only on our instructions under GDPR Article 28 agreements:
| Processor | Role | Data involved |
|---|---|---|
| Neon | Managed database hosting | All account, journal, accounts, expenses and licence data |
| Render | Application hosting | Technical logs and data in transit |
| Resend | Transactional email delivery | Email address and the content of service emails |
We may also disclose data where we are legally required to do so, for example in response to a valid order from a competent authority, or where it is necessary to establish, exercise or defend legal claims. If Vienne is ever transferred to another operator, your data may transfer with it; you would be notified in advance and could delete your account first.
Neon, Render and Resend are all United States companies, and the Neon database runs on Amazon Web Services in the region chosen for our project. Where personal data leaves the European Economic Area, the transfer is protected by an appropriate safeguard under GDPR Chapter V — in practice the European Commission's Standard Contractual Clauses, and, where the provider is certified, the EU–U.S. Data Privacy Framework. You may request a copy of the relevant safeguards by emailing us.
AI Analysis is optional and off by default. When you enable it, you choose a provider (Anthropic Claude, OpenAI ChatGPT, DeepSeek, xAI Grok or Groq) and supply your own API key.
| Data | Where it sits | How long we keep it |
|---|---|---|
| Account, journal, accounts, expenses, preferences, licence links | Neon PostgreSQL database | For as long as your account exists |
| The same data, after you delete your account | Neon PostgreSQL database | Deleted immediately. Deleting your account issues a real DELETE on your user record, and every related row — journal, accounts, expenses, settings, device binding, read receipts — is removed with it by database cascade. There is no soft-delete flag and no archive copy. |
| Residual copies in database recovery history | Neon point-in-time recovery | Neon automatically retains a short window of database history so a database can be restored after an accident. Deleted rows can survive inside that window and then become permanently unrecoverable. The window is set by our Neon plan and is currently 24 hours. We do not read from this history except to recover from a genuine incident. |
| Server request logs (timestamp, IP address, method, path, status code, response time) | Render log stream | Written to the application's standard output and held by Render under its own log retention, currently 7 days, then discarded. These logs are never written into the database and are not backed up. |
| Password-reset tokens | Neon PostgreSQL database | Valid for 30 minutes, and cleared the moment the password is changed |
| Licence records (key, plan, dates) | Neon PostgreSQL database | Kept for the life of the key. When you delete your account the link between the key and you is severed, so what remains is an anonymous record of a key with no personal data attached to it. |
| Emails we send you | Resend | Held by Resend under its own delivery-log retention; we do not archive sent mail ourselves |
We keep no manual backups, no exports and no separate archive of the database. Apart from the automatic recovery window described above, deletion is final — which is also why we suggest exporting your journal from Settings → Data before you close your account.
If you are in the EEA or the United Kingdom, GDPR gives you the following rights. We honour them for every user regardless of location.
Two of these are built into the product and need no request at all:
For anything else, email truevienne@gmail.com from the address registered to your account. We will respond within one month as required by GDPR Article 12(3), and may extend by two further months for complex requests, telling you why. Exercising your rights is free; we may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive. If we cannot verify that a request comes from you, we may ask for further information before acting.
If you believe we have mishandled your data, please contact us first — we would rather fix it. You also have the right to lodge a complaint with a supervisory authority, in particular the one in your country of residence or workplace. Our lead authority is:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
www.aki.ee/en
We do not carry out automated decision-making that produces legal or similarly significant effects on you within the meaning of GDPR Article 22. Statistics and AI commentary are informational summaries of data you entered; they make no decision about you and have no effect on your access to the service.
No system can be guaranteed completely secure. You help by using a strong, unique password and by keeping your device and browser up to date.
If a personal data breach occurs, we will notify the Estonian Data Protection Inspectorate without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly and without undue delay, as required by Article 34.
Vienne is not directed at children. You must be at least 16 years old to create an account, or older if your country sets a higher age of digital consent. If we learn that we hold data from a child below that age without valid parental authorisation, we will delete it promptly. Parents and guardians may contact us at the address below.
We may update this policy as the service evolves or the law changes. The version number and date at the top always reflect the current text. For material changes we will notify registered users by email or an in-app notice at least 30 days before they take effect, so you can review them or close your account.
Privacy questions, rights requests and anything else covered by this policy:
truevienne@gmail.com
See also our Terms of Service.