UP JOURNAL

Privacy Policy

Last updated September 17, 2026

This policy explains what personal data UP Journal collects, why, and what rights you have. UP Journal is operated by its founder, a natural person established in Romania ("we", "us", "our"). We collect the minimum data needed to run a trading journal — we do not sell personal data and we do not run advertising trackers.

1. Data we collect

  • Account data: email address, display name, authentication identifiers (managed by our authentication provider), and optional profile details you choose to add.
  • Journal data: the trading records, plans, analyses, notes, images and templates you create — this is the content of the service.
  • Billing data: Paddle (our Merchant of Record) processes payments and shares with us the subscription status, plan, billing country and receipt identifiers. We never see or store your full card details.
  • Technical data: server logs (IP address, timestamps, user agent) kept for security and abuse prevention.

2. Why we process it (legal bases)

  • To provide the service you signed up for — performance of contract (account, journal storage, sync across devices).
  • To process payments and comply with accounting obligations — contract and legal obligation (handled primarily by Paddle as Merchant of Record).
  • To secure the service and prevent abuse — our legitimate interest.
  • To send service messages (invites, security notices, billing receipts) — performance of contract. We do not send marketing emails without your consent.

3. Processors we share data with

  • Paddle.com Market Ltd — Merchant of Record for payments, tax and invoices (data: email, purchase and subscription details).
  • Resend — email delivery for service messages such as address verification and security notices (data: email address and message content).
  • OVH — hosting provider for the application servers and database (European data centres).
  • Cloudflare — DNS and edge protection for up-journal.com.

Processors are bound by contract to process data only on our instructions.

4. Retention

Journal data is kept while your account exists. If you delete your account or ask us to erase your data, we delete your journal content and personal data, except the minimum records we must keep for accounting (billing records processed by Paddle follow Paddle’s retention duties) and short-lived security logs.

5. Your rights

Under the EU General Data Protection Regulation (GDPR), which applies directly in Romania, together with Romanian implementing legislation (Law No. 190/2018 and Law No. 363/2007) — you can request access, rectification, erasure, restriction, portability of your personal data, and object to processing based on legitimate interests. Requests go to [email protected] or through the support section inside the application; we answer within 30 days.

You also have the right to lodge a complaint with the Romanian supervisory authority — ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) — or, if you are in another EU member state, with the supervisory authority of your country of residence.

6. Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted, SSH-key-based, and monitored. We back up the database nightly and test restores as part of normal operations.

7. Contact

You can reach us at [email protected] or through the support section inside the UP Journal application (available after signing in). Questions about a payment, invoice or refund can also be raised with Paddle buyer support — the details are included in every Paddle receipt.

© 2026 UP Journal · Built for traders who measure.