Privacy Policy
Last updated: August 19, 2026
1. Who we are
Tiders is an independent product operated by its founder from Chile and offered to users worldwide. Tiders is the data controller for the personal information described in this policy. For any question about it, or to exercise any of the rights in section 9, contact hello@tiders.ai.
2. What this policy covers
This policy describes how Tiders ("we", "us") collects, uses, and protects personal information when you use the Tiders website and the Tiders application.
3. Information we collect
- Account information: your email address, name, and profile picture as provided through our identity provider when you sign up or sign in. We never receive or store your password.
- Content you create: your accounts, your watchlist, your trade journal (rides, actions, fill prices, share counts, and the notes and trade reasoning you write), and your settings.
- Subscription email: if you subscribe to updates, the email address you submit, stored only after you confirm via the double opt-in email. Subscribing is not an account and gives no access to the application.
- Automatic information: standard technical data such as IP address, browser type, and pages visited. Our website analytics are cookieless and privacy-preserving: we do not use tracking cookies or advertising pixels.
4. How we use it, and on what basis
Where data protection law requires us to identify a legal basis for each use, these are ours:
| What we do | Why | Legal basis |
|---|---|---|
| Create and secure your account | So you can sign in and only you can reach your data | Performance of a contract |
| Store and process your journal, watchlist and settings | This is the service you asked for | Performance of a contract |
| Send account and service emails | To operate your account and answer you | Performance of a contract |
| Send update emails | You asked to hear from us: product updates, new features, and occasional educational pieces | Consent, which you can withdraw at any time |
| Keep the service available and prevent abuse | To protect the service and its users | Legitimate interests |
| Measure aggregate website usage without cookies | To understand what visitors find useful | Legitimate interests |
We do not sell your personal information. Tiders keeps a record of what its strategy engine observed in the market each day so that the engine can be studied and improved. That record is about market data rather than about you (see section 10). If we ever want to use your own journal to improve the engine, we will say so here first and give you a choice about it.
5. Service providers
We use a small set of processors to run Tiders. Each receives only what its function requires:
| Provider | Purpose | Location |
|---|---|---|
| Auth0 (Okta) | Identity and sign-in | United States |
| Supabase | Database and storage | United States (AWS us-west-2) |
| Resend | Email delivery (updates, service emails) | United States |
| Vercel | Website hosting and cookieless analytics | United States |
| Railway | Application hosting, and the Redis instance holding short-lived request counters and live update delivery | United States |
Market data and options-activity data shown in Tiders come from third-party data providers. Those providers receive the ticker symbols the application asks about and never receive any information identifying you.
To keep the service available to everyone, we count how many requests each signed-in account makes over the preceding minute. That counter holds your account identifier. For requests that are not signed in, it holds the network address our hosting provider reports, which is their own proxy rather than your address. Either way it expires within minutes and is never used to build a profile of you.
We will update this table before any new processor begins handling your information, and note the change under section 12.
6. International transfers
Tiders is operated from Chile and its processors are located in the United States, so your information is transferred to, stored in, and processed in those countries. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
7. Cookies
Signing in sets one encrypted, strictly necessary session cookie so the application knows you are signed in. It carries no advertising or cross-site tracking, and the service cannot work without it. Our website analytics set no cookies at all, and we use no advertising pixels and no third-party trackers.
8. Security
Traffic is encrypted in transit. Credentials are handled entirely by our identity provider, so Tiders never sees or stores your password. Your session cookie is encrypted and HTTP-only. Data is stored with managed providers that encrypt it at rest, and access to production data is limited to the operator of the service. No service can promise perfect security, and we do not claim to hold any security certification.
If a breach affects your personal information and is likely to put you at risk, we will tell you and the relevant supervisory authority without undue delay, and within 72 hours of becoming aware of it where that deadline applies to us.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal information, to withdraw consent where processing is based on consent, and not to be discriminated against for exercising any of them.
Two of these are built into the application and need no request: you can download a complete JSON archive of your data at any time, and you can delete your account, which downloads that archive first and then permanently removes your accounts, watchlist, journal, and trade reasoning. For anything else, contact hello@tiders.ai. We reply within 30 days, and we may need to confirm your identity before acting on a request. You can also complain to your local data protection authority.
10. Data retention
We keep your information for as long as your account is active. When you delete your account, your profile, accounts, watchlist, journal, and trade reasoning are permanently deleted at that moment. Automated backups held by our database provider age out on that provider's own schedule, after which the deleted data is gone from those too.
Subscription emails are kept until you unsubscribe or the list is retired. Addresses collected earlier, when the list was an announcement waitlist for the beta, are not used for these updates: that consent was given for a different purpose, so those addresses are kept only as a record and are not mailed.
Tiders also keeps a record of what its own strategy engine observed in the market on each trading day. That record is about market data and the engine, contains no information about you or anyone else, and is unaffected by account deletion.
11. Children
Tiders is not directed at children and may not be used by anyone under 18. We do not knowingly collect information from children.
12. Changes
We may update this policy as the service evolves. Material changes will be announced on this page with a new "last updated" date.
13. Contact
Questions about privacy: hello@tiders.ai.