Privacy Policy

Tilt Blocker Privacy Policy

Last updated: July 25, 2026

Summary

Tilt Blocker: Trade Diary HD is a local-first Chrome extension for prop futures traders. It stores session plans, protection state, replay metadata, and reviews in Chrome local storage; syncs the trader's protection settings across licensed browsers; checks paid access through Tilt Blocker billing endpoints; offers optional user-initiated Grok trade review and private YouTube backup; and does not sell personal data, transmit broker credentials, place trades, cancel broker orders, or modify positions.

Information Stored Locally

The extension stores the checkout email, a random installation identity, signed access token, trader-configured profit and loss limits, exact commitments, optional dashboard URL, cached billing status, pending checkout reference, session plan, consent state, recording and execution markers, lockout state, realized-P&L boundary metadata, review answers, diary exports, optional ETH reflection note, and next-session lesson using Chrome local storage. The protection settings are also the offline copy of the licensed-browser sync described below. Customer-facing license keys are redeemed for signed access tokens; the extension does not need broker credentials to verify access. Local export redacts the signed access token, and the user can disconnect and clear the trader data stored by the extension.

Billing Information

Paid access is processed by Stripe. The pricing page sends visitors to Stripe Checkout, where Stripe collects the receipt email and payment details. After Checkout, Tilt Blocker shows a license key and Chrome Web Store install link; the extension can redeem the checkout email and license key for a signed expiring access token. The extension can send that token to Tilt Blocker billing endpoints to open Stripe Customer Portal sessions and confirm whether an active lifetime purchase exists. Payment card details are handled by Stripe, not stored by the extension.

Stripe Checkout may ask for promotional email consent where supported so Tilt Blocker can follow local marketing rules before sending product or recovery emails.

Tilt Blocker stores the normalized receipt email, Stripe customer and purchase references, license status, an HMAC of the random installation identity, activation timestamps, the versioned protection-settings profile described below, Stripe webhook processing IDs, and short-lived API rate-limit records in Neon Postgres. This supports a two-installation license limit, settings sync, device deactivation, duplicate-event protection, and automatic refund or dispute revocation. It does not store payment card details, broker credentials, recordings, or diary entries in that database.

Protection Settings Sync

When an active license is connected, Tilt Blocker sends the configured profit and loss limits, trading days and hours, safeguard choices, exact session commitments, session duration, exit window, market-holiday preference, and optional dashboard URL to a license-protected Tilt Blocker endpoint over HTTPS. Neon Postgres stores one versioned protection profile per license so another licensed Chrome installation can retrieve it. Each update includes the last known revision; if two browsers change different copies, Tilt Blocker asks which copy to keep rather than silently overwriting one.

Session plans, recordings, execution markers, realized P&L, reviews, diary entries, access tokens, and temporary lock state are not included in protection-settings sync.

Trading Activity

On Tradovate, the extension passively observes sanitized order, position, fill, and cashBalance messages after the platform processes them. It uses those local events for execution markers, the first-fill Settings lock, and the trader-configured per-account profit and loss boundaries. It does not send, change, delay, or cancel orders. On TradingView and TopstepX, interaction timestamps are used as replay-marker fallbacks. Session records remain local unless the user explicitly downloads them, imports diary JSON into a dashboard they configured, consents to Grok review, or chooses private YouTube upload. The separate protection-settings sync does not include trading activity.

Calendar and Private Video Upload

The extension fetches the public Fair Economy weekly calendar feed and retains only the high-impact event fields needed for the planning screen. If the user explicitly chooses private YouTube backup, Chrome requests the narrow youtube.upload OAuth scope and sends the selected replay to Google APIs. The resulting video ID may be stored with the local session record; the OAuth token is not written into the diary record.

Optional Grok Trade Review

After a session is saved, the user may explicitly consent to an AI review. Tilt Blocker then extracts five chronological JPEG still frames from the replay in the browser and sends those frames, together with the session plan, self-review, realized P&L, account count, and available execution markers, through a license-protected Tilt Blocker endpoint to the xAI API. The raw replay video, Google OAuth token, license key, and broker credentials are not sent to xAI. The returned feedback, model name, timestamp, and data-retention status are stored with the local diary record.

Tilt Blocker requests stateless processing with store: false. xAI states that API inputs and outputs may still be retained for up to 30 days for abuse monitoring unless Zero Data Retention is enabled for the API account. AI feedback can be incomplete or wrong and is presented as a discipline review, not financial advice.

Website Analytics

The marketing website uses Google Analytics to understand page views and non-sensitive product interactions such as checkout clicks, form views, form starts, form submission outcomes, guide filtering, and calculator use. Analytics events are configured to avoid sending early-access email addresses, notes, broker credentials, trade diary content, or payment card details.

Permissions

The extension requests storage, unlimitedStorage, identity, and sidePanel. These permissions support local session records, opt-in YouTube authorization, and the activation panel. Replay and diary files use ordinary user-initiated browser downloads rather than Chrome's broad downloads API permission. Network and content access is limited to Tilt Blocker billing and opt-in Grok review, the Fair Economy calendar, Google upload APIs, supported topstepx, tradovate, and TradingView chart hosts, and the named prop-firm sites protected during RTH.

Future Changes

If session or trade-history sync, extension telemetry, or additional remote trade reporting is added later, this policy should be updated before those features ship. Any future networked feature should be clearly separated from trade execution and should explain what data is transmitted and why.