Privacy
Effective 26 September 2026
This describes what Taba collects about you, what it does not, where it goes and how to get rid of it. It covers taba.trade, app.taba.trade and this documentation.
In short. Taba collects what it needs to sign you in, connect your venues and show you your own trading — an email or social identifier, wallet addresses, encrypted venue credentials, and the trades it reads back from venues. It asks for no identity documents, runs no advertising and no third-party analytics, and sells nothing to anyone. Most of what you write in the journal never leaves your browser. This summary is not the policy; the sections below are.
1 · What is collected
| What | Why it exists |
|---|---|
| Account identifier Email address, social login identifier, or wallet address |
To sign you in and to attach your settings and connections to you. Handled by our authentication provider. |
| Wallet addresses Ethereum and Solana addresses you use or that are created for you |
To connect venues, sign approvals, and read your positions back. |
| Venue credentials Delegated trading keys and API keys you provide |
To place and cancel the orders you ask for. Stored encrypted; see section 8. |
| Trading records Orders sent, their outcome, and the fills, positions, balances and funding read back from venues |
To show your positions, to build the journal, and to keep an audit trail of what was sent on your behalf. |
| Social content Username, display name, avatar, posts, follows |
Only if you use Social. Posts you publish are public by design. |
| Technical logs IP address, request time and path, user agent, errors |
To keep the service running, apply rate limits and diagnose faults. |
2 · What is not collected
- No identity documents. No passport, ID card, selfie, proof of address or date of birth. Taba runs no KYC process. Where a venue requires verification, you do that with the venue — those documents go to them and never through us.
- No advertising or tracking. No ad networks, no third-party analytics, no behavioural profiling, no cross-site tracking, no fingerprinting, no tracking pixels, no data brokers.
- No selling. Your personal data is not sold, rented or traded, and it is not shared for anyone else's marketing.
- No private keys in the clear. The private key of a wallet created for you is managed by the authentication provider's key infrastructure and is not readable by us. Your own external wallet's key never reaches us at all.
3 · Why
Data is used to operate the service you asked for, and for nothing else: to sign you in, to hold your venue connections, to route and record your orders, to build your journal, to run Social if you use it, and to keep the service secure and available. Aggregate, non-identifying counts may be used to understand load and decide what to build.
Where the law requires a legal basis, the basis is the performance of the agreement between us for everything needed to run the service, and our legitimate interest in security, abuse prevention and service reliability for logs.
4 · What stays in your browser
A fair amount of Taba is deliberately local. The following never reaches the server:
- trade notes, observations and rules you write in the journal;
- workspace layouts, saved chart templates, favourites and preferences;
- cached market and account data held in IndexedDB so the app opens quickly.
That means it is per-browser: it does not follow you to another device, and clearing site data deletes it permanently with no copy anywhere.
Taba sets no advertising cookies. Storage is used for your session and for the preferences above.
5 · Who else sees it
Taba is run on a single server by one person. Data is shared only with the parties needed to make it work:
| Who | What they receive |
|---|---|
| Privy Authentication and wallet infrastructure |
Your email or social identifier and wallet addresses. They hold the key material for wallets created at sign-in, under their own privacy policy. |
| Trading venues The venues you choose to connect |
Your orders, and whatever your credentials identify you as there. Each venue has its own privacy policy and its own verification requirements. |
| Market data providers | Nothing about you. News and economic calendar data is fetched by our server, not your browser, so these providers never see your address or IP. |
| Hosting and network | The server host and the reverse proxy in front of it process traffic, including IP addresses, as part of delivering the service. |
| Google Fonts | Font files are requested by your browser from Google's CDN when you load a page, which discloses your IP address to Google. |
Data may also be disclosed where the law validly requires it. Given that no entity stands behind Taba, the practical position is that there is very little to disclose: no identity documents, no payment records, and no custody of funds.
6 · The public chain
Blockchain transactions are public and permanent. Deposits, withdrawals, approvals and on-chain trades are visible to anyone, are linked to your wallet address forever, and cannot be deleted by us or by you. Anyone who can connect that address to your identity can see everything it has ever done. This is a property of the chain, not a choice Taba makes.
Trading on a venue also exposes information to that venue and, on some venues, to the public — Taba's own Whales page is built from exactly that kind of public venue data.
7 · How long it is kept
- Account and connections — while your account exists.
- Venue credentials — until you revoke them or delete your account, whichever is first.
- Order and audit records — kept as a record of what was sent on your behalf, because that is what makes a dispute about an order resolvable.
- Technical logs — a short rolling window, then overwritten.
- Social posts — until you delete them or your account.
- Browser-local data — until you clear it.
8 · How it is protected
Traffic is encrypted in transit with TLS. Venue credentials and delegated trading keys are encrypted at rest in an envelope scheme whose master key lives only on the server and is never in the repository, in a backup you receive, or in any log.
Delegated trading keys are deliberately limited: they can place and cancel orders and cannot withdraw or transfer funds. That is the single most important protection here — it bounds what a breach could cost you to bad orders rather than to a drained account.
No system is perfectly secure, and this one is run by one person on one server. Judge it accordingly, keep withdrawal permission off any API key you create, and revoke anything you are not using.
9 · Your choices
You can, at any time and without asking anyone:
- revoke a venue connection, from Taba or from the venue;
- export your wallet key from Settings;
- delete your Social posts;
- clear browser storage, which erases your notes, layouts and caches.
To see what is held about you, correct it, or have your account and its server-side data deleted, write to the address in section 12. Deletion removes your account, connections and stored credentials. It cannot remove anything already written to a blockchain, and it does not close positions or touch funds held at a venue — do that with the venue first.
Depending on where you live you may have further rights — access, rectification, erasure, portability, objection, or complaint to a supervisory authority. Those rights are honoured on request to the same address.
10 · Children
Taba is not for anyone under 18 and is not directed at children. If you believe a minor has an account, write to us and it will be removed.
11 · Changes
This policy may change. The effective date at the top will move, and continuing to use Taba after that means accepting the revision.
12 · Contact
Privacy questions, data requests and deletion requests go to contact@taba.trade.
Effective 26 September 2026