Privacy Policy
Birhana is a trading journal. Its whole philosophy is telling you the truth about your trading — so this page tells you the truth about your data: what we collect, why, where it lives, and what you control.
1. What we collect
Account
- Email address and password (password stored as a hash by our authentication provider — we never see it), or your Google identity if you sign in with Google.
- A display name and avatar if you set one.
Your journal
- Everything you log: trades, P&L, accounts, notes, screenshots, emotions, checklists, backtests, achievements, giveaway entries, and community posts you choose to publish.
- This is your data. We store and process it only to run the journal for you. We do not sell it, share it with advertisers, or train anything on it.
Payments (CBE & crypto)
- When you upgrade, you pay by CBE transfer or in crypto (USDT on BNB Smart Chain) — telebirr is coming soon but not yet live. For a CBE payment, you paste the receipt number or receipt link and we verify it against the bank's own public receipt page, storing the receipt number, amount, date, the payer name and masked phone shown on the receipt, and the plan we granted. For a crypto payment, you paste the transaction ID (hash) and we read that transfer from the public BNB Smart Chain blockchain, storing the transaction ID, the USDT amount, the sending wallet address, the date, and the plan we granted. Blockchain transfers are public by design — anyone can look them up on the chain. (If you paid by Binance Pay before we switched, that payment's Order ID is still checked against Binance's own record.)
- The payment helper ("Shemsu") uses an outside AI service for CBE payments. If you paste a bank SMS or ask it a question on the pay page, that text — which may include a payer name or phone number — is sent to an AI model hosted by NVIDIA to pull out the receipt number and answer you. It is not stored by us afterwards, and nothing the AI says can approve a payment: only the bank's receipt page does that. Crypto payments are checked directly against the blockchain — no AI reads that text. If you'd rather not use the AI helper for a CBE payment, paste the receipt number straight into the box instead.
- We never see or ask for your CBE password, your Binance or wallet password, your wallet's recovery phrase or private keys, or full card details. Never share those with anyone claiming to be us.
Technical & analytics
- A first-party, anonymous event beacon on the landing page (page view, button clicks) tied to a random session id — only if you choose "Accept all" in the cookie banner. It contains no name, no email.
- Vercel Web Analytics and Speed Insights, on every page. These count page views and measure how fast pages load. They set no cookie, store nothing on your device, and create no identifier that follows you between visits or between sites — so there is nothing in them that points back to you. Vercel, who already hosts the site, is the only recipient.
- IP addresses and basic device info, used for security, rate-limiting, and enforcing bans after abuse. Alongside server logs, we keep a record of the IP addresses your account has signed in from, tied to your account, so that a banned account can't simply be recreated. It's removed when your account is deleted.
- If you arrive through a partner link, the referral code, so the partner can be credited.
Integrations you connect (optional)
- Notion: if you connect it, we store the access token Notion gives us and read only the database you pick, to import rows as trades. Revoke any time in Notion's settings or by disconnecting in Birhana.
- MetaTrader 5: if you connect an account, you give us your account number, broker server and investor password — the read-only one, which can view trades but can never place, change or close them. We pass those to MetaApi, the third-party service that talks to your broker on our behalf, and from it we receive your fills (symbol, size, price, time, profit) to journal them automatically. Disconnecting in Birhana removes the account from MetaApi.
- Web push: if you enable notifications, we store the push subscription your browser issues. Turn it off any time in Settings → Notifications or in your browser.
2. Where it lives
Data is stored with Supabase (database & authentication) and served through Vercel (hosting/CDN). Every table is protected with row-level security so your rows are readable by your account only. Backups of your journal are also kept locally on your own device so a bad connection can't erase your work.
3. Cookies & local storage
Birhana does not use advertising or cross-site tracking cookies. We use your browser's local storage for things the product needs to function:
| Key | Purpose | Type |
|---|---|---|
| Auth session (Supabase) | Keeps you signed in | Essential |
| Journal cache & backups | Your trades work offline and survive bad connections | Essential |
| Preferences (theme, notification toggles, calendar options) | Remembers your settings | Essential |
| bh:consent | Remembers your cookie choice | Essential |
| birhana:ref | Credits the partner who referred you | Essential |
| bh:sid + analytics beacon | Anonymous landing-page analytics | Optional — off unless you Accept all |
| Vercel Web Analytics / Speed Insights | Page counts and load times — stores nothing on your device | No cookie, no stored id |
The landing page also loads scripts from public CDNs and small brand icons from Google's favicon service; those requests reach the respective providers like any image or script on the web.
4. What we never do
- No selling or renting your data. No ads. No data brokers.
- No reading your journal for any purpose other than running the service or investigating abuse with cause.
- No asking for your CBE password, your Binance or wallet password, your wallet's recovery phrase, or your broker's trading password — ever. The MT5 link uses only the read-only investor password, which cannot trade.
5. Retention & deletion
Your journal is kept for as long as your account exists. You can export your trades as CSV from the app at any time.
You can delete your account yourself from Settings; it takes effect immediately. Your journal, profile, sign-in record, saved IP addresses, notification subscriptions and community posts are erased. Two kinds of record are kept, with your name and contact details removed from them: payment receipts (so the same receipt can't be reused to unlock another account, and so our books balance), and — if you were a partner or had an invite code — the record of commissions earned and paid, because other people's money depends on it. If you'd rather we do it for you, message Support on Telegram from the account's email.
6. Security
Row-level security on every table, hashed passwords, HTTPS everywhere, and self-healing local backups. Honest note: no system on earth is unbreakable — if a breach ever affects your data, we will tell you plainly and quickly.
7. Who can use Birhana
Birhana is for adults aged 18 and over. We do not knowingly collect data from anyone under 18.
8. Your rights
You can access and export your data, correct it, delete it, withdraw consent for optional analytics (choose "Essentials only", or clear the choice and pick again), and complain to your local data authority. We honor these requests for every user regardless of country.
9. Changes
If this policy changes in a way that matters, we'll say so in the app before it takes effect. The date at the top always tells you the current version.
10. Contact
BONTrades · Addis Ababa, Ethiopia · t.me/birhanasupport