Legal

Privacy Policy

This policy explains how Lone Wolf Journal collects, uses, stores, shares, and protects personal data. Last updated 2 August 2026.

1. Introduction

This Privacy Policy explains how Lone Wolf Journal ("Lone Wolf Journal", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit the public website, apply to participate in the beta programme, create or use an account, upload content, or otherwise interact with the service.

Lone Wolf Journal is a trading journal application designed to help users record trading activity, notes, screenshots, account information, rules, and performance-related observations. This Privacy Policy applies to the website and web application available through https://lonewolfjournal.com.

A separate Cookie Policy provides more detailed information about cookies and similar browser technologies.

2. Data Controller and Contact Details

The controller responsible for the processing described in this Privacy Policy is:

No Data Protection Officer has been appointed because, based on the current nature and scale of the service, the appointment of a Data Protection Officer is not considered legally required.

3. Personal Data We Collect

Depending on how you use the service, we may collect the following categories of personal data:

  • Identity and contact data, such as name and email address.
  • Account and authentication data, including an internal user identifier, user role, securely hashed password, email-verification timestamp, last successful login timestamp, persistent login token, password-reset information, and encrypted two-factor authentication information where these features are used.
  • Trading journal data, including trading accounts, trade records, symbols, trade direction and outcome, entry and exit information, profit or loss figures, grades, rules, notes, daily summaries, and other information entered by the user.
  • Uploaded content, including trade screenshots, their original filenames, generated file identifiers, storage paths, and relationships connecting files to the relevant user and trade.
  • Beta application data, including name, email address, IP address, user-agent, and creation and modification timestamps.
  • Consent records, including the Privacy Policy version accepted, the acceptance timestamp, the optional newsletter and marketing choice, the consent timestamp, and any later withdrawal timestamp.
  • Session, security, and technical data, including session identifier, linked user identifier, IP address, user-agent, last activity timestamp, authentication state, temporary form state, rate-limit identifiers, failed login counters, and security-event information.
  • Cookie and analytics data, but only where the user has consented to analytics cookies.
  • Contact and privacy-request data submitted through the contact method made available in this policy.

4. How We Collect Personal Data

We collect personal data:

  • directly from you when you register, apply for beta access, enter journal data, upload images, configure security settings, request a password reset, contact us, or exercise a privacy right;
  • automatically when the website or application creates sessions, security records, technical logs, cookies, and similar records necessary for operation and protection;
  • from Google Analytics on public website pages only, after you have consented to analytics cookies; and
  • from service providers where necessary to provide hosting, security, or other technical services.

6. Account and Authentication Data

When an account is created, the application stores an internal user identifier, email address, user role, timestamps associated with the account, and authentication information needed to provide secure access.

Passwords are stored only in securely hashed form. We do not store passwords in their original readable form.

Where the relevant functions are used, the application may also store an email-verification timestamp, last successful login timestamp, a "Remember me" token, password-reset token information, and an encrypted two-factor authentication secret together with its activation timestamp.

The persistent login cookie may remain for up to 400 days if the user actively selects the persistent login function. Users can remove persistent login data by signing out, clearing browser storage, or changing relevant account credentials.

7. Trading Journal Data and Uploaded Images

Users decide what trading journal data to enter. The service may store trading account details, trade records, performance data, rules, grades, notes, reviews, and other user-created journal content.

Trade screenshots are optimised and stored as WebP or JPEG files. The service stores the image content, the original filename supplied during upload, a generated random file identifier and storage path, and the relationship between the image, the user, and the relevant trade. The original filename is retained only as display metadata and is not used as the public storage path.

Users should avoid uploading information about other identifiable individuals unless they have a lawful reason to do so. Lone Wolf Journal is intended as a personal trading journal and should not be used to store unnecessary third-party personal data.

8. Beta Tester Sign-up and Beta Data

The beta sign-up form stores the applicant's name, email address, IP address, user-agent, application timestamps, the accepted Privacy Policy version, and the time of acceptance. A hidden anti-spam field may be used, but its content is not stored permanently.

Beta contact details are used to administer beta access, communicate about testing, request feedback, and send service-related beta notices. Agreeing to the Privacy Policy is required to submit the form, but it is not consent to marketing.

A separate, optional checkbox allows applicants to request product updates, news, and occasional marketing emails. This choice is not required for beta registration. Where selected, we record the time of consent. Consent can be withdrawn at any time by following the unsubscribe instructions provided with a marketing communication or by sending a written request using the contact details in this policy. Withdrawal does not affect processing carried out before it was withdrawn.

During the beta period, permanent storage and uninterrupted availability are not guaranteed. We may delete beta accounts and associated data where reasonably necessary for testing, maintenance, security, database restructuring, or further development of the service.

Inactive beta accounts and their associated data may be deleted after at least 30 consecutive days of inactivity. Where reasonably practicable, affected users may be notified before deletion. Users should export data they wish to retain.

9. Cookies and Google Analytics

The website uses strictly necessary browser storage for session management, cross-site request forgery protection, cookie preferences, optional persistent login, and theme preferences. More information is provided in the separate Cookie Policy.

Google Analytics 4 is used only on public frontend pages and not inside the authenticated application or administrative area. Google Analytics is loaded only after the visitor accepts analytics cookies. If analytics is rejected, Google Analytics is not loaded.

After consent, information sent to Google Analytics may include the public page visited, event time, browser and device type, operating system, screen and technical characteristics, referring page, approximate geographic information, analytics client and session identifiers, and basic page interactions.

Google Signals, advertising personalisation, and advertising data storage are disabled. We do not use Google Analytics for personalised advertising.

The analytics cookies currently include _ga and _ga_17YCCT4NRQ and may remain on the user's device for up to two years. Google Analytics event-level and user-level data are retained by Google according to the settings configured for our Google Analytics property and Google's applicable retention rules.

10. Server Logs and Security

The hosting environment and application may generate access, error, authentication, and security logs. These records may include IP address, requested URL, request time, HTTP status, referring page, user-agent, failed login activity, rate-limit events, application errors, and security blocks.

We use these records to keep the service operational, diagnose errors, detect abuse, protect accounts, investigate incidents, and establish, exercise, or defend legal claims. Server and security logs are retained for no longer than 12 months unless a longer period is necessary for a specific security incident or legal claim.

11. Service Providers and Data Recipients

11.1 Hosting

The service is hosted by Hetzner Online GmbH. The current server location is Falkenstein, Germany, within the European Economic Area. Hetzner may process data stored on the server and technical data necessary to provide and secure the hosting service. More information is available in the Hetzner Privacy Policy.

11.2 Google Analytics

Google Analytics is provided by Google Ireland Limited. Google and relevant group entities may process analytics information as described in Google's terms and privacy documentation, subject to the visitor's analytics consent. More information is available in the Google Privacy Policy.

11.3 Email delivery

No external email delivery provider is currently confirmed. Before an external provider begins processing personal data for account verification, password resets, security notices, beta messages, newsletters, or other email delivery, this Privacy Policy and the relevant contractual documentation will be updated.

11.4 Other disclosures

We may disclose personal data where required by law, court order, or a competent authority, or where reasonably necessary to protect the service, users, or legal rights. We do not sell personal data and do not share personal data for third-party advertising.

12. International Data Transfers

The primary hosting location is in Germany within the European Economic Area. Google Analytics or future service providers may involve processing outside the EEA. Where personal data is transferred outside the EEA, we will rely on a legally recognised transfer mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard, where required.

13. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, subject to legal, security, and dispute-resolution requirements. The main retention rules are:

  • Account and journal data: for the lifetime of the account, unless deleted earlier by the user or under the beta rules.
  • Inactive beta accounts and associated beta data: may be deleted after at least 30 consecutive days of inactivity.
  • Newsletter and marketing consent: until withdrawn; a limited consent and withdrawal record may be retained afterwards where necessary to demonstrate compliance.
  • Server-side sessions: normally 2 hours after the last activity.
  • Login and two-factor authentication rate-limit data: up to 1 hour.
  • Cookie consent preference: 6 months.
  • Optional persistent login cookie: up to 400 days.
  • Google Analytics cookies: up to 2 years; Google-hosted analytics data according to the configured property retention and Google policies.
  • Server, access, error, and security logs: up to 12 months, except incident-specific or legal-claim records that reasonably require longer retention.
  • Temporary backup-import ZIP files: deleted after the import process whether it succeeds or fails.
  • Temporary export ZIP files: deleted after download.
  • Contact and privacy-request records: for as long as needed to answer the request, comply with law, and establish, exercise, or defend legal claims.

14. Data Security

We apply technical and organisational measures intended to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include password hashing, encrypted storage of two-factor authentication secrets, access restrictions, session controls, rate limiting, server security controls, and secure hosting configurations.

No online service or storage system can be guaranteed to be completely secure. Users are responsible for choosing a strong and unique password, protecting their login credentials, enabling available security features, and keeping exported data secure.

15. Data Exports, Temporary Files, Backups and Account Deletion

Users may be able to export journal data or restore a supported export. ZIP files uploaded for restoration are stored temporarily in private storage and deleted after the import process, whether the import succeeds or fails. Temporary ZIP archives created for export are deleted after download.

When a user deletes an account, the account, associated journal records, and uploaded files are deleted from the active database and active file storage without undue delay, normally immediately as part of the deletion process.

A separate long-term backup system containing deleted user accounts is not currently maintained. If backup functionality is introduced, this Privacy Policy will be updated before or when that backup system begins processing personal data, including the backup location, retention period, and deletion process.

16. User Rights under the GDPR

Subject to the conditions and limitations of applicable law, users may have the right to:

  • request access to personal data and receive information about its processing;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive personal data in a structured, commonly used, and machine-readable format and, where applicable, request data portability;
  • withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal; and
  • lodge a complaint with a competent supervisory authority.

The availability of a particular right depends on the relevant legal basis, circumstances, and applicable legal exceptions.

17. How to Exercise Privacy Rights

To exercise a privacy right or ask a privacy question, send a written request to the registered office listed in Section 2 and Section 22.

We may request information reasonably necessary to verify identity before acting on a request. We normally respond without undue delay and within one month, subject to any extension permitted by the GDPR for complex or numerous requests.

18. Right to Lodge a Complaint

You may lodge a complaint with the supervisory authority in the country of your habitual residence, place of work, or the place of the alleged infringement. As the controller is established in Hungary, you may also contact:

You are encouraged to contact us first so that we have an opportunity to address the concern directly.

19. Children's Privacy

The service is not designed specifically for children, but no general age restriction is currently imposed. Where consent is relied upon for an information-society service and applicable law requires consent or authorisation from a person with parental responsibility, that consent or authorisation must be obtained.

We do not knowingly seek to collect unnecessary personal data from children. A parent or legal guardian who believes that a child has provided personal data unlawfully may contact us using the privacy contact method above and request appropriate action.

20. Automated Decision-Making

Lone Wolf Journal does not currently use personal data for automated decision-making, including profiling, that produces legal effects or similarly significant effects concerning users. Grades, statistics, summaries, and other journal outputs are tools based on information entered or selected by the user and do not constitute automated decisions about the user.

21. Changes to This Privacy Policy

We may update this Privacy Policy when the service, legal requirements, processing activities, retention periods, or service providers change. The latest version will be published on the website with an updated effective date. Material changes may also be communicated through the service or another appropriate channel.

22. Contact Details

Privacy questions and requests may be sent in writing to the registered office below.

Controller Deák Zsolt, sole proprietor
Registered office 2080 Pilisjászfalu, Pipacs utca 4., Hungary
Registration number 56837041
Tax number 58191668-2-33