Nexus Trader← Back to site

Privacy Policy

VERSION 1.2-ON (REVISED) · 2026-08-27

Privacy Policy — Nexus Trader

Nexus Trader (“Nexus”, “we”) · Effective date: 2026-08-27 · Contact: inquiries@nexustrader.app

Nexus Trader is software you install on your own PC that trades your own Interactive Brokers (IBKR) account. This policy tells you exactly what information leaves your computer, what we do with it, and what never leaves your computer at all. It is written to be read; the short version is: we collect what licensing, the status emails, and basic server security require — and this policy lists all of it. No analytics, no tracking, never your broker credentials.

1. What we collect, and when

When you get a license, we record your email address together with the license itself (key, tier, expiry). We use that address to deliver the license, send service notices, and answer your support requests.

When you activate a license, the Software sends us: your license key; a hardware fingerprint of your PC transmitted only as one-way hashes (computed from the Windows machine ID, system volume serial, and CPU identity — the raw identifiers never leave your machine; the hashes function as stable pseudonymous device identifiers); your Windows computer name; a pseudonymous account token for the IBKR account the license is bound to, together with the account number's last 4 characters; the Software version; and a random installation ID. The account token is a one-way cryptographic hash computed on your machine from your license key and the account number — your full IBKR account number itself never leaves your computer. The token (with the last-4 suffix for support purposes) is what binds the license to your account. The Software may automatically repeat this activation transmission without user action if the server reports the session expired or the hardware changed. The fingerprint and account binding exist to enforce the license (one license, your machines, your account) — they are not used for anything else.

Once per day (license heartbeat), the Software sends: the activation and installation identifiers (including a rotating session credential), the fingerprint hashes, the pseudonymous account token (with last-4 suffix) for the account the Software is configured to trade — which also tells us whether the account is in live or paper mode — the Software version, and the alert email address you saved in the Software's settings. The email address is transmitted so that our mail relay will only ever send email to the address you registered.

Operational email content (in transit). The Software composes its own status emails on your machine — event alerts, a daily summary, and a monthly statement. These emails are MINIMAL: the subject and body carry only a generic category (for example “Nexus Trader - Daily summary”), the name of the locally saved file, and directions to your own PC — no account number, no balances, no positions. The detailed message is written to a local file on your PC instead and does not pass through our infrastructure; the packaged Software has no setting that changes this. Our relay does not store message bodies or subjects — it logs delivery status against an opaque message key. Our email delivery provider (Postmark) processes the messages to deliver them and retains delivered content for its standard delivery-history period as our processor.

Server logs. Like any online service, our servers record the IP address and time of connections for security and abuse prevention.

Billing (planned — not yet active; nothing is collected today). When paid subscriptions begin: (a) payments will be processed by Stripe — your card details will be held by Stripe, never by us; and (b) the Software will report one number per month for billing: the trailing average equity (net liquidation value) of the connected account over the billing month, which determines the monthly fee. No equity history is transmitted for billing — only that monthly figure.

Health telemetry (planned — opt-in, off by default). If you opt in: Software version, last-run status, and an error signature — never positions, balances, or P/L. You can turn it off at any time.

Support. If you email us for help and choose to attach log files, be aware the Software's local logs and trade ledger contain your positions and P/L — send them only if you choose to.

2. What we never collect

Your IBKR username, password, or any broker credential — the Software connects to your own already-logged-in IBKR trading workstation on your PC and has no field, screen, or code path that accepts a broker credential.

Your positions, orders, fills, or account balances as data records — with one planned exception: the single monthly billing equity figure described in §1, once paid subscriptions begin. (The minimal status emails carry none of it.)

Your name — the Software has no name field and never asks for it. (Note that Your Windows computer name and your email address, which we do receive, may themselves contain your name.)

Usage analytics, behavioural tracking, crash reports, advertising identifiers — none exist in the Software.

Anything on your PC outside the Software's own folders.

Software updates, the weekly data bundle, the license revocation list, and a public currency exchange rate are downloaded without any account or license identifiers attached (our standard server logs of IP address and time, §1, still apply to requests made to our servers).

3. What stays on your PC only

The Software keeps its working data under your Windows user profile (%LOCALAPPDATA%): settings, weekly materials, trading state, logs, the trade ledger, and caches. License secrets on your PC are encrypted with Windows' built-in per-user encryption (DPAPI). This data is yours, on your disk, under your control. The Software's connection to IBKR is local (your TWS on the same PC); what IBKR itself sees is governed by IBKR's own privacy terms.

4. Why we use the information, and your consent

Purposes: licensing and license enforcement; delivering the alert/summary/statement emails you configured; providing support you request; security and abuse prevention; and, when subscriptions begin, billing. We do not sell personal information, we do not use it for advertising, and we do not share it with anyone except the service providers below or where the law requires disclosure.

Consent: you consent to the collection described in this policy by installing and activating the Software under the EULA. The license heartbeat and the status-email relay are conditions of the service — the Software cannot operate as a licensed product without them. Health telemetry (when built) is optional, off by default, and can be withdrawn at any time in settings. You may withdraw consent generally by deactivating and uninstalling the Software and contacting us about your stored records (§6–7); withdrawing the required elements ends the service.

5. Service providers (processors)

ProviderRoleLocation
DigitalOceanserver hostingCanada
Postmarktransactional email deliveryUS
CloudflareDNS and inbound email routing for our domainglobal network
Stripe (when billing begins)payment processing; holds card detailsUS/global

Each processes personal information only to provide its service to us, under its own terms. (Stripe will also act as an independent party for the payment relationship itself — card details are between you and Stripe.) We never send your personal information to IBKR, to our market-data sources (FMP, SEC), or to the Bank of Canada, whose public exchange-rate service the Software may query without any identifiers.

6. Retention and deletion

License and activation records (which include your email address and the pseudonymous account token with its last-4 suffix, §1) are kept while your license is active and for afterwards (subject to legal and accounting retention requirements). Mail-relay delivery logs contain no message content. Server access logs are kept for 1 year. You can deactivate an installation at any time using the Software's deactivation command — this requests release of the machine slot (if the Software cannot reach our servers at that moment, contact us and we will release it). To request deletion of your license records, contact us at the address above. Note that we cannot provide a licensed service without the license data itself — deletion of it ends the service.

7. Your rights

You may request access to, correction of, or deletion of your personal information, and you may withdraw telemetry consent at any time, by contacting inquiries@nexustrader.app. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.

8. Security

All connections between the Software and our servers use TLS with certificate verification (there is no setting that disables it). Hardware identifiers are one-way hashed before transmission — the raw identifiers are never sent. Local license secrets are DPAPI-encrypted. Weekly data bundles and software updates are cryptographically signed and verified before use.

9. Website; children; changes

Our website (nexustrader.app) currently uses no analytics or advertising cookies. The Software and service are not directed at minors; you must be the age of majority in your jurisdiction (see the EULA). When this policy changes we will announce it, with a new version number and effective date; the version history will remain available.