Effective October 1, 2026
Candlefolio is currently a closed, invite-only beta. Candlefolio is independently operated from San Diego, California, United States. There is no registered company. This policy explains what information Candlefolio collects while you use the beta, why, who can see it, and how to ask for it to be deleted.
To create an account, Candlefolio collects the email address and password you provide. Password authentication is handled by Supabase Auth, the authentication component of Candlefolio's own service infrastructure — the Candlefolio application itself does not receive or store a plaintext password in its application database; Supabase Auth stores the provider-managed, securely hashed password record as part of operating Candlefolio's authentication system. During the closed beta, account creation is also checked against a private list of approved email addresses; that list is not visible to any user and is managed only by the operator.
Your username, display name, and any bio, location, market focus, experience level, or trading-style tags you choose to add to your profile are stored and shown to other users according to the visibility rules described below. A profile photo you upload is stored and served from a public image address — like most consumer apps, anyone who already has that exact address can view the image file itself, even though your profile page follows its own separate visibility rules.
The trading day, your written reflection, self-ratings, and "tomorrow's focus" you enter when completing a journal entry are stored so the entry can be shown back to you, and — for a limited subset, automatically, once a friendship is accepted, with no separate per-entry choice — to your accepted friends, as described under "Friends-only journal visibility" below.
A chart or trade screenshot you attach to a journal entry is stored in a private file location — it is never given a permanent public address, unlike a profile photo. You can always view your own screenshot. If an accepted friend is authorized to view that specific journal entry (see "Friends-only journal visibility" below), they may also be given a short-lived, individually authorized link to view the same screenshot; a non-friend or a stranger can never receive a link to it. Removing that friend connection or blocking the user ends their ability to receive a new link to it going forward. Candlefolio cannot detect or redact information you place inside a screenshot's own image content — please review a screenshot yourself before uploading it if it might contain something you wouldn't want an accepted friend to see.
Fields in the "Private Trading Summary" area of a journal entry — daily P&L, account size, trades taken, and your best/worst trade for the day — along with any private notes you write, are visible only to you. There is no setting, role, or feature anywhere in Candlefolio that can make these fields visible to another user, including an accepted friend.
When you search for, request, accept, or remove a friend connection, Candlefolio stores that relationship and its current state (pending, accepted, or removed) so both accounts can see accurate friend lists and requests. If you block another user, that action is stored too, and is never disclosed to the person you blocked.
By default, a journal entry is visible only to you. Once another user becomes an accepted friend, a limited, non-financial subset of your journal entries (excluding every field listed above under "Private journal and performance fields") automatically becomes visible to that friend — there is no separate, per-entry sharing step. Removing a friend connection or blocking a user immediately ends that visibility, and a non-friend or stranger can never see your journals at all.
Messages you send through Candlefolio's chat feature are stored so they can be delivered and displayed in your conversation history. Chat is limited to accepted friends, one-to-one — there are no group conversations and no message visibility beyond the two people in the conversation.
If you comment, reply, or react with an emoji on a journal entry you have permission to view, that comment, reply, or reaction is stored and shown to everyone who can already view that entry — never more broadly than that.
Like any web application, operating Candlefolio naturally produces technical records — for example, sign-in timestamps, basic request metadata, and error logs generated by our infrastructure providers while serving the application. This information is used only to operate, secure, and troubleshoot the service, never to build an advertising profile.
Candlefolio uses only the essential cookies and browser session storage that Supabase Auth needs to keep you signed in — confirmed by a direct audit of this codebase's own dependencies, Candlefolio currently has no advertising cookie, no cross-site tracking pixel, and no behavioral-advertising or cross-site analytics tracker of any kind. Candlefolio does not track you across other, unrelated websites or services, and has no mechanism to do so today. Because Candlefolio doesn't perform that kind of cross-site tracking, a browser's "Do Not Track" signal doesn't change how the application behaves — there is no different tracking behavior for it to turn off. Supabase and Vercel, the infrastructure providers named above, process the technical information described under "Technical and security information" only to operate, secure, and troubleshoot Candlefolio itself, as part of providing that infrastructure — not for their own advertising purposes. Candlefolio does not knowingly permit any third party to collect personal information over time across unrelated sites through Candlefolio for advertising purposes.
Each category above is collected for one practical reason: account information to let you sign in securely; profile and journal content to provide the actual journaling and reflection features you use; friend, chat, comment, and reaction data to provide the optional social features you choose to use; and technical information to keep the beta running and secure. Candlefolio does not use your information for advertising, and does not sell your personal information to anyone.
Candlefolio uses Resend to deliver account and security emails — for example the message that confirms a new account and the message that lets you reset a password. These are sent when you take the action that needs them, such as signing up or asking for a password reset, and your optional email preferences do not affect them. Resend receives your email address and the content of each message in order to deliver it.
Candlefolio has also prepared an optional daily email digest, but it is not yet active: Candlefolio is not sending it to members, and Settings says the same. What follows describes how it is designed to work if and when it is turned on.
The digest is one combined email a day, scheduled for 4:00 p.m. New York time, sent to the email address on your account only when optional email is turned on and there is something to share. It can include a journaling reminder (the journal date and your time zone) and, for the categories you have enabled, a summary of unread activity: friend requests and acceptances, comments and replies on journals you can view, the people you have unread chat conversations with (shown by display name, or by username if they have no display name — never the message text), and new Challenge announcements, each with a link back into Candlefolio. It does not include journal text, chat message text, or any private trading or performance figure.
In Settings you can turn optional email off entirely, choose which categories you want, and pick reminder days. Until you save your own choices, some optional email types are on by default — Settings shows the current setting for each, so please review them. Every digest includes an unsubscribe link (and the one-click unsubscribe that mail apps offer) that turns off optional email while keeping your other choices; it does not affect account and security email.
To send and manage the digest, Candlefolio would keep: a delivery record (the date, its status, and the provider's response); the prepared email itself, which contains your address and the email content and is kept only so a delivery can be retried safely; the identifiers — not the text — of the activity already included, so the same activity is not emailed twice; a one-way fingerprint of each unsubscribe link; and status notices from Resend (delivered, bounced, marked as spam, or suppressed), which record the type of event and a link to the delivery record but not the subject or body.
Resend also keeps its own suppression list, which is separate from Candlefolio's handling. According to Resend's documentation, it automatically adds an address after a permanent bounce or a spam complaint, and then skips later email to that address across its whole account — which can include account and security email — until the address is removed; it also notes that not every mailbox provider reports spam complaints. Resend can tell Candlefolio about these events. When Candlefolio receives one and can match it to your account, Candlefolio stops sending optional email to that address and leaves your saved preferences unchanged. If an event is not received or cannot be matched — for example, one that arrives long after the related delivery record has been removed — Candlefolio's own handling may not apply, so Candlefolio does not promise that every bounce, complaint, or suppression will stop its digest attempts.
Candlefolio's own retention for these records is designed as follows: the prepared email is deleted when that day's sending has been closed out by Candlefolio's scheduled cleanup (or, failing that, by the cleanup once it has expired, about 26 hours after it was prepared); delivery records are removed 90 days after that day's sending closes; Resend status notices are kept for one year; a suppression stays until it is cleared or the account is deleted; and the unsubscribe-link fingerprints stay as long as the account exists. These periods depend on that scheduled cleanup running, which belongs to the digest launch and is not running yet, so they describe the intended behavior rather than a guarantee. Resend keeps its own records of the messages it delivers under its own policies, which Candlefolio does not control and this policy does not state — see Resend's privacy policy.
Candlefolio keeps your information for as long as your account remains open, so the product can keep working the way you expect. Candlefolio does not currently enforce a fixed, automatic deletion schedule for any category of data — if you would like your account or specific content deleted, see "Your rights and account deletion" below. Records created by the optional daily email, if it is turned on, are described separately under "Email" above.
You can review and correct your own editable profile information — username, display name, bio, location, market focus, experience level, trading-style tags, and profile photo — at any time through Edit Profile. For any other question about what information Candlefolio holds about you, or to request a correction Edit Profile doesn't cover, email support@candlefolio.com.
You can request deletion of your account and associated data, or ask what information Candlefolio holds about you, at any time by emailing support@candlefolio.com. Candlefolio will respond to a deletion request within 30 days.
Candlefolio protects your information with the specific controls actually in place: provider-managed authentication through Supabase Auth, private Storage authorization for journal screenshots (never a permanent public address), and row-level database access rules that scope every query to the right account or authorized relationship. Candlefolio has not undergone an independent security compliance assessment, and does not claim to meet any named security or compliance standard. Candlefolio takes reasonable steps to keep your information secure, but no online service can guarantee perfect security, and Candlefolio cannot promise that either.
Candlefolio may update this policy as the beta evolves. If changes are made, this page's effective date will be updated. Continued use of Candlefolio after a change means you accept the updated policy.
Questions about this policy can be sent to support@candlefolio.com. Candlefolio is independently operated from San Diego, California, United States.
This is a practical policy for Candlefolio's closed beta, written to accurately describe what the product actually does today. It has not been reviewed by professional legal counsel. See also our Terms of Service.