Privacy Policy - TraderKit One

Privacy Policy - TraderKit One

Last Updated: 20 September 2026 Effective Date: 10 September 2026

TraderKit One ("TraderKit", "we", "us", "our") is dedicated to protecting your privacy. This Privacy Policy explains our data practices, detailing what information is processed, where it is stored, and how we handle telemetry and crash reporting.


1. Zero-Server Storage Architecture

We do NOT store your trading data, account credentials, balances, or transaction history on any TraderKit servers.

TraderKit One is built with a decentralized, client-side first architecture:

  • Direct-to-Deriv Communication: All trading actions, account authentications, tick subscriptions, contract purchases, and balance updates stream directly between your device and Deriv's official servers via encrypted Secure WebSockets (wss://) and HTTPS.
  • No Intermediary Database: We do not operate cloud databases that harvest, log, or store your private trading records, personal identity, or financial balances.
  • Local Storage Only: Bot configurations, money management rules, custom parameters, active symbol preferences, and session statistics are saved locally on your device via encrypted local device storage.

2. Information Handled Locally On Your Device

The following data remains exclusively on your device:

  • Account Tokens & IDs: OAuth session tokens and login IDs used to authenticate your direct WebSocket connection with Deriv;
  • Bot Configurations: Strategy parameters, stake amounts, Take Profit / Stop Loss thresholds, and Martingale multipliers;
  • Local Session History: In-memory bot run trades and realized P&L counters accumulated during your active session.

Clearing app storage or uninstalling the app permanently deletes all locally stored preferences and configurations.


3. Anonymous Analytics, Crashlytics & Diagnostics

To maintain app stability, detect performance regressions, monitor feature health, and troubleshoot bugs, we collect minimal, anonymized technical telemetry using Google Firebase Analytics and Firebase Crashlytics:

  • Anonymous Device Identifier & Analytics: We generate an anonymous, non-reversible device UUID stored in local SecureStore to attribute application events (e.g. app launches, authentication events, and feature navigation) consistently across sessions without identifying you personally;
  • Crash Reports & Error Diagnostics (Crashlytics): Stack traces, unhandled exceptions, operating system logs at time of crash, and WebSocket disconnection error codes to fix software bugs and improve app reliability;
  • Aggregated Device Diagnostics: Device model, operating system version, app release version, and general network type (e.g., WiFi vs. Cellular) to optimize chart rendering and low-latency performance.

What We NEVER Collect:

  • We never collect your trading passwords, API secrets, financial balances, account balances, or personal identification details;
  • We never track, sell, or share your trading activity, strategy choices, or trading performance to third parties, data brokers, or advertising networks.

4. Device Permissions Requested

TraderKit One requests only the permissions necessary for trading operations:

  • Internet Access (INTERNET): Required to establish direct Secure WebSocket connections with Deriv for live prices and trade execution;
  • Keep Screen Awake (WAKE_LOCK): Optional, activated solely during live bot runs to prevent your device from sleeping while an automated strategy is actively executing trades;
  • Audio Output: Used locally to play sound cues for trade settlements (win/loss audio effects).

We do not access your contacts, SMS messages, photo library, camera, microphone, or GPS location.


5. Third-Party Services

  • Deriv API & OAuth: When you log in and trade via TraderKit One, your trading interactions and authentication are governed by Deriv's Privacy Policy and Security Terms.
  • Google Firebase (Analytics & Crashlytics): We use Google Firebase services solely for anonymized analytics, usage metrics, and crash diagnostics. Firebase processes telemetry in accordance with Google's Privacy Policy.

6. Data Security

We adhere to best security practices to safeguard your local data:

  • Encrypted In-Transit: 100% of data transmitted to and from Deriv is encrypted using industry-standard TLS 1.2 / TLS 1.3 over WSS/HTTPS.
  • Encrypted At-Rest: Local configurations and session keys are secured inside the application's private, sandbox-protected storage directory on iOS and Android.

7. Children's Privacy

TraderKit One is strictly intended for individuals who are at least 18 years of age (or the legal age for financial trading in their jurisdiction). We do not knowingly collect information from children under 18.


8. Changes to This Privacy Policy

We may periodically update this Privacy Policy to reflect app updates or regulatory standards. Any changes will be indicated with an updated "Last Updated" date at the top of this document.


9. Contact Us

If you have any questions or concerns regarding this Privacy Policy or our data practices, please contact us.