Legal
Privacy Policy
This policy explains how Lone Wolf Journal collects, uses, stores, shares, and protects personal data. Last updated 2 August 2026.
1. Introduction
This Privacy Policy explains how Lone Wolf Journal ("Lone Wolf Journal", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit the public website, apply to participate in the beta programme, create or use an account, upload content, or otherwise interact with the service.
Lone Wolf Journal is a trading journal application designed to help users record trading activity, notes, screenshots, account information, rules, and performance-related observations. This Privacy Policy applies to the website and web application available through https://lonewolfjournal.com.
A separate Cookie Policy provides more detailed information about cookies and similar browser technologies.
2. Data Controller and Contact Details
The controller responsible for the processing described in this Privacy Policy is:
- Controller
- Deák Zsolt, sole proprietor
- Registered office
- 2080 Pilisjászfalu, Pipacs utca 4., Hungary
- Sole proprietor registration number
- 56837041
- Tax number
- 58191668-2-33
- Website
- https://lonewolfjournal.com
- Privacy contact
- Written privacy requests may be sent to the registered office above.
No Data Protection Officer has been appointed because, based on the current nature and scale of the service, the appointment of a Data Protection Officer is not considered legally required.
3. Personal Data We Collect
Depending on how you use the service, we may collect the following categories of personal data:
- Identity and contact data, such as name and email address.
- Account and authentication data, including an internal user identifier, user role, securely hashed password, email-verification timestamp, last successful login timestamp, persistent login token, password-reset information, and encrypted two-factor authentication information where these features are used.
- Trading journal data, including trading accounts, trade records, symbols, trade direction and outcome, entry and exit information, profit or loss figures, grades, rules, notes, daily summaries, and other information entered by the user.
- Uploaded content, including trade screenshots, their original filenames, generated file identifiers, storage paths, and relationships connecting files to the relevant user and trade.
- Beta application data, including name, email address, IP address, user-agent, and creation and modification timestamps.
- Consent records, including the Privacy Policy version accepted, the acceptance timestamp, the optional newsletter and marketing choice, the consent timestamp, and any later withdrawal timestamp.
- Session, security, and technical data, including session identifier, linked user identifier, IP address, user-agent, last activity timestamp, authentication state, temporary form state, rate-limit identifiers, failed login counters, and security-event information.
- Cookie and analytics data, but only where the user has consented to analytics cookies.
- Contact and privacy-request data submitted through the contact method made available in this policy.
4. How We Collect Personal Data
We collect personal data:
- directly from you when you register, apply for beta access, enter journal data, upload images, configure security settings, request a password reset, contact us, or exercise a privacy right;
- automatically when the website or application creates sessions, security records, technical logs, cookies, and similar records necessary for operation and protection;
- from Google Analytics on public website pages only, after you have consented to analytics cookies; and
- from service providers where necessary to provide hosting, security, or other technical services.
5. Purposes and Legal Bases of Processing
We process personal data only where a legal basis under the General Data Protection Regulation (GDPR) applies. The main processing activities are summarised below.
| Data / activity | Purpose | GDPR legal basis | Retention | Recipients / processors |
|---|---|---|---|---|
| Account and authentication data | Create and administer accounts, authenticate users, and provide login, persistent login, password-reset, and two-factor authentication functions. | Article 6(1)(b) GDPR. Security-related processing may also rely on Article 6(1)(f) GDPR. | For the lifetime of the account. Deleted from active systems normally immediately when the account is deleted, subject to limited legal or security exceptions. | Hetzner Online GmbH and authorised personnel. |
| Trading journal records and uploaded screenshots | Provide the journal service, store user-entered records, display results, and enable review, export, and restore functions. | Article 6(1)(b) GDPR. | For the lifetime of the account or until deleted by the user. Beta data may also be removed under the beta retention rules. | Hetzner Online GmbH. |
| Beta application data | Manage beta applications, invitations, eligibility, testing communications, and participation. | Article 6(1)(b) GDPR for requested beta access and Article 6(1)(f) GDPR for managing and securing the beta programme. | While the person participates in or remains eligible for the beta. Inactive beta data may be deleted after 30 consecutive days of inactivity. | Hetzner Online GmbH and authorised personnel. |
| Privacy Policy acceptance record | Record that the beta applicant accepted the Privacy Policy that applied when the form was submitted. | Articles 6(1)(c) and 6(1)(f) GDPR - compliance and the legitimate interest in demonstrating transparent processing. | For the duration of the beta relationship and afterwards for as long as reasonably necessary to demonstrate compliance or resolve a legal claim. | Hetzner Online GmbH and authorised personnel. |
| Newsletter and marketing consent record | Record the optional request to receive product updates, news, and occasional marketing emails, and any later withdrawal. | Article 6(1)(a) GDPR - consent. | Until consent is withdrawn. A limited record of the consent and withdrawal may be retained afterwards where necessary to demonstrate compliance. | Hetzner Online GmbH and authorised personnel. Any future email delivery provider will be identified before it begins processing this data. |
| Session data | Maintain secure login state, temporary application state, form messages, and temporary two-factor authentication setup information. | Articles 6(1)(b) and 6(1)(f) GDPR. | Normally 2 hours after the last activity, unless the optional persistent login feature is selected. | Hetzner Online GmbH. |
| Login and two-factor authentication rate-limit data | Prevent brute-force attacks, abuse, and unauthorised access. | Article 6(1)(f) GDPR - legitimate interests in service and account security. | Up to 1 hour under the current configuration. | Hetzner Online GmbH. |
| Server access, error, and security logs | Operate the service, diagnose errors, prevent abuse, investigate incidents, and establish, exercise, or defend legal claims. | Article 6(1)(f) GDPR. | Up to 12 months. Incident-specific records may be kept longer where necessary to investigate an incident or establish, exercise, or defend legal claims. | Hetzner Online GmbH and authorised technical personnel. |
| Analytics data on public pages | Understand use of public pages and improve website performance and usability. | Article 6(1)(a) GDPR - consent. | According to the retention settings configured for the Google Analytics property and Google policies. Analytics cookies may remain on the device for up to 2 years. | Google Ireland Limited and relevant Google group entities. |
| Cookie preference | Remember whether analytics cookies were accepted or rejected. | Article 6(1)(f) GDPR and applicable cookie rules, as necessary to record and respect the choice. | 6 months under the current configuration. | Hetzner Online GmbH. |
| Contact messages and GDPR requests | Respond to enquiries, facilitate privacy rights, and demonstrate compliance. | Articles 6(1)(c) and 6(1)(f) GDPR and, where applicable, Article 6(1)(b) GDPR. | For as long as necessary to respond, comply with legal obligations, or establish, exercise, or defend legal claims. | Authorised personnel and Hetzner Online GmbH. |
6. Account and Authentication Data
When an account is created, the application stores an internal user identifier, email address, user role, timestamps associated with the account, and authentication information needed to provide secure access.
Passwords are stored only in securely hashed form. We do not store passwords in their original readable form.
Where the relevant functions are used, the application may also store an email-verification timestamp, last successful login timestamp, a "Remember me" token, password-reset token information, and an encrypted two-factor authentication secret together with its activation timestamp.
The persistent login cookie may remain for up to 400 days if the user actively selects the persistent login function. Users can remove persistent login data by signing out, clearing browser storage, or changing relevant account credentials.
7. Trading Journal Data and Uploaded Images
Users decide what trading journal data to enter. The service may store trading account details, trade records, performance data, rules, grades, notes, reviews, and other user-created journal content.
Trade screenshots are optimised and stored as WebP or JPEG files. The service stores the image content, the original filename supplied during upload, a generated random file identifier and storage path, and the relationship between the image, the user, and the relevant trade. The original filename is retained only as display metadata and is not used as the public storage path.
Users should avoid uploading information about other identifiable individuals unless they have a lawful reason to do so. Lone Wolf Journal is intended as a personal trading journal and should not be used to store unnecessary third-party personal data.
8. Beta Tester Sign-up and Beta Data
The beta sign-up form stores the applicant's name, email address, IP address, user-agent, application timestamps, the accepted Privacy Policy version, and the time of acceptance. A hidden anti-spam field may be used, but its content is not stored permanently.
Beta contact details are used to administer beta access, communicate about testing, request feedback, and send service-related beta notices. Agreeing to the Privacy Policy is required to submit the form, but it is not consent to marketing.
A separate, optional checkbox allows applicants to request product updates, news, and occasional marketing emails. This choice is not required for beta registration. Where selected, we record the time of consent. Consent can be withdrawn at any time by following the unsubscribe instructions provided with a marketing communication or by sending a written request using the contact details in this policy. Withdrawal does not affect processing carried out before it was withdrawn.
During the beta period, permanent storage and uninterrupted availability are not guaranteed. We may delete beta accounts and associated data where reasonably necessary for testing, maintenance, security, database restructuring, or further development of the service.
Inactive beta accounts and their associated data may be deleted after at least 30 consecutive days of inactivity. Where reasonably practicable, affected users may be notified before deletion. Users should export data they wish to retain.
10. Server Logs and Security
The hosting environment and application may generate access, error, authentication, and security logs. These records may include IP address, requested URL, request time, HTTP status, referring page, user-agent, failed login activity, rate-limit events, application errors, and security blocks.
We use these records to keep the service operational, diagnose errors, detect abuse, protect accounts, investigate incidents, and establish, exercise, or defend legal claims. Server and security logs are retained for no longer than 12 months unless a longer period is necessary for a specific security incident or legal claim.
11. Service Providers and Data Recipients
11.1 Hosting
The service is hosted by Hetzner Online GmbH. The current server location is Falkenstein, Germany, within the European Economic Area. Hetzner may process data stored on the server and technical data necessary to provide and secure the hosting service. More information is available in the Hetzner Privacy Policy.
11.2 Google Analytics
Google Analytics is provided by Google Ireland Limited. Google and relevant group entities may process analytics information as described in Google's terms and privacy documentation, subject to the visitor's analytics consent. More information is available in the Google Privacy Policy.
11.3 Email delivery
No external email delivery provider is currently confirmed. Before an external provider begins processing personal data for account verification, password resets, security notices, beta messages, newsletters, or other email delivery, this Privacy Policy and the relevant contractual documentation will be updated.
11.4 Other disclosures
We may disclose personal data where required by law, court order, or a competent authority, or where reasonably necessary to protect the service, users, or legal rights. We do not sell personal data and do not share personal data for third-party advertising.
12. International Data Transfers
The primary hosting location is in Germany within the European Economic Area. Google Analytics or future service providers may involve processing outside the EEA. Where personal data is transferred outside the EEA, we will rely on a legally recognised transfer mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard, where required.
13. Data Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, subject to legal, security, and dispute-resolution requirements. The main retention rules are:
- Account and journal data: for the lifetime of the account, unless deleted earlier by the user or under the beta rules.
- Inactive beta accounts and associated beta data: may be deleted after at least 30 consecutive days of inactivity.
- Newsletter and marketing consent: until withdrawn; a limited consent and withdrawal record may be retained afterwards where necessary to demonstrate compliance.
- Server-side sessions: normally 2 hours after the last activity.
- Login and two-factor authentication rate-limit data: up to 1 hour.
- Cookie consent preference: 6 months.
- Optional persistent login cookie: up to 400 days.
- Google Analytics cookies: up to 2 years; Google-hosted analytics data according to the configured property retention and Google policies.
- Server, access, error, and security logs: up to 12 months, except incident-specific or legal-claim records that reasonably require longer retention.
- Temporary backup-import ZIP files: deleted after the import process whether it succeeds or fails.
- Temporary export ZIP files: deleted after download.
- Contact and privacy-request records: for as long as needed to answer the request, comply with law, and establish, exercise, or defend legal claims.
14. Data Security
We apply technical and organisational measures intended to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include password hashing, encrypted storage of two-factor authentication secrets, access restrictions, session controls, rate limiting, server security controls, and secure hosting configurations.
No online service or storage system can be guaranteed to be completely secure. Users are responsible for choosing a strong and unique password, protecting their login credentials, enabling available security features, and keeping exported data secure.
15. Data Exports, Temporary Files, Backups and Account Deletion
Users may be able to export journal data or restore a supported export. ZIP files uploaded for restoration are stored temporarily in private storage and deleted after the import process, whether the import succeeds or fails. Temporary ZIP archives created for export are deleted after download.
When a user deletes an account, the account, associated journal records, and uploaded files are deleted from the active database and active file storage without undue delay, normally immediately as part of the deletion process.
A separate long-term backup system containing deleted user accounts is not currently maintained. If backup functionality is introduced, this Privacy Policy will be updated before or when that backup system begins processing personal data, including the backup location, retention period, and deletion process.
16. User Rights under the GDPR
Subject to the conditions and limitations of applicable law, users may have the right to:
- request access to personal data and receive information about its processing;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive personal data in a structured, commonly used, and machine-readable format and, where applicable, request data portability;
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal; and
- lodge a complaint with a competent supervisory authority.
The availability of a particular right depends on the relevant legal basis, circumstances, and applicable legal exceptions.
17. How to Exercise Privacy Rights
To exercise a privacy right or ask a privacy question, send a written request to the registered office listed in Section 2 and Section 22.
We may request information reasonably necessary to verify identity before acting on a request. We normally respond without undue delay and within one month, subject to any extension permitted by the GDPR for complex or numerous requests.
18. Right to Lodge a Complaint
You may lodge a complaint with the supervisory authority in the country of your habitual residence, place of work, or the place of the alleged infringement. As the controller is established in Hungary, you may also contact:
National Authority for Data Protection and Freedom of InformationNemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Email: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu
You are encouraged to contact us first so that we have an opportunity to address the concern directly.
19. Children's Privacy
The service is not designed specifically for children, but no general age restriction is currently imposed. Where consent is relied upon for an information-society service and applicable law requires consent or authorisation from a person with parental responsibility, that consent or authorisation must be obtained.
We do not knowingly seek to collect unnecessary personal data from children. A parent or legal guardian who believes that a child has provided personal data unlawfully may contact us using the privacy contact method above and request appropriate action.
20. Automated Decision-Making
Lone Wolf Journal does not currently use personal data for automated decision-making, including profiling, that produces legal effects or similarly significant effects concerning users. Grades, statistics, summaries, and other journal outputs are tools based on information entered or selected by the user and do not constitute automated decisions about the user.
21. Changes to This Privacy Policy
We may update this Privacy Policy when the service, legal requirements, processing activities, retention periods, or service providers change. The latest version will be published on the website with an updated effective date. Material changes may also be communicated through the service or another appropriate channel.
22. Contact Details
Privacy questions and requests may be sent in writing to the registered office below.
2080 Pilisjászfalu, Pipacs utca 4., Hungary
Website: https://lonewolfjournal.com