Privacy Policy
Birhana is a trading journal. Its whole philosophy is telling you the truth about your trading — so this page tells you the truth about your data: what we collect, why, where it lives, and what you control.
1. What we collect
Account
- Email address and password (password stored as a hash by our authentication provider — we never see it), or your Google identity if you sign in with Google.
- A display name and avatar if you set one.
Your journal
- Everything you log: trades, P&L, accounts, notes, screenshots, emotions, checklists, backtests, achievements, giveaway entries, and community posts you choose to publish.
- This is your data. We store and process it only to run the journal for you. We do not sell it, share it with advertisers, or train anything on it.
Payments (Telebirr)
- When you upgrade, you send payment through telebirr and paste the receipt number. We verify it against ethiotelecom's public receipt page and store: the receipt number, amount, date, the receipt's masked payer phone, and the plan we granted.
- We never see or ask for your telebirr PIN, password, or full card details. Never share those with anyone claiming to be us.
Technical & analytics
- A first-party, anonymous event beacon on the landing page (page view, button clicks) tied to a random session id — only if you choose "Accept all" in the cookie banner. It contains no name, no email.
- IP addresses and basic device info in server logs, used for security, rate-limiting, and enforcing bans after abuse.
- If you arrive through a partner link, the referral code, so the partner can be credited.
Integrations you connect (optional)
- Notion: if you connect it, we store the access token Notion gives us and read only the database you pick, to import rows as trades. Revoke any time in Notion's settings or by disconnecting in Birhana.
- MetaTrader 5: if you connect an account, we receive your fills (symbol, size, price, time, profit) to journal them automatically.
- Web push: if you enable notifications, we store the push subscription your browser issues. Turn it off any time in Settings → Notifications or in your browser.
2. Where it lives
Data is stored with Supabase (database & authentication) and served through Vercel (hosting/CDN). Every table is protected with row-level security so your rows are readable by your account only. Backups of your journal are also kept locally on your own device so a bad connection can't erase your work.
3. Cookies & local storage
Birhana does not use advertising or cross-site tracking cookies. We use your browser's local storage for things the product needs to function:
| Key | Purpose | Type |
|---|---|---|
| Auth session (Supabase) | Keeps you signed in | Essential |
| Journal cache & backups | Your trades work offline and survive bad connections | Essential |
| Preferences (theme, notification toggles, calendar options) | Remembers your settings | Essential |
| bh:consent | Remembers your cookie choice | Essential |
| birhana:ref | Credits the partner who referred you | Essential |
| bh:sid + analytics beacon | Anonymous landing-page analytics | Optional — off unless you Accept all |
The landing page also loads scripts from public CDNs and small brand icons from Google's favicon service; those requests reach the respective providers like any image or script on the web.
4. What we never do
- No selling or renting your data. No ads. No data brokers.
- No reading your journal for any purpose other than running the service or investigating abuse with cause.
- No asking for your telebirr PIN, bank passwords, or broker passwords — ever.
5. Retention & deletion
Your journal is kept for as long as your account exists. You can export your trades as CSV from the app at any time. To delete your account and its data, message @BONTradesSupport on Telegram from the account's email and we'll erase it within 30 days, except minimal payment records we must keep for accounting and fraud prevention.
6. Security
Row-level security on every table, hashed passwords, HTTPS everywhere, and self-healing local backups. Honest note: no system on earth is unbreakable — if a breach ever affects your data, we will tell you plainly and quickly.
7. Who can use Birhana
Birhana is for adults aged 18 and over. We do not knowingly collect data from anyone under 18.
8. Your rights
You can access and export your data, correct it, delete it, withdraw consent for optional analytics (choose "Essentials only", or clear the choice and pick again), and complain to your local data authority. We honor these requests for every user regardless of country.
9. Changes
If this policy changes in a way that matters, we'll say so in the app before it takes effect. The date at the top always tells you the current version.
10. Contact
BONTrades · Addis Ababa, Ethiopia · t.me/BONTradesSupport