Legal

Privacy Policy

Last updated:

On this page

This policy explains what TradingView Strategy Optimizer ("we", "the service") collects, why, and what happens to it. The service has two parts: this website, where you create an account and manage your plan, and the browser extension, which does its work inside your own browser.

Summary

  • Your strategies, the parameter combinations tested and every backtest result stay in your browser. We never receive them, with one opt-in exception: the results you choose to contribute to a testing community campaign, described below.
  • We store what accounts and plans require: your identity from Google, the TradingView account your plan is bound to, and counts of what you used.
  • We do not sell your data, and we do not use it for advertising or cross-site tracking.
  • We never receive your TradingView credentials, and we are not affiliated with TradingView.

What we collect

Everything on our servers, and why it is there:

DataWhy we hold it
Account identityThe email address and name Google shares when you sign in, plus the account id our identity provider assigns. This is how you sign in and how your plan is recognized.
Plan and payment statusWhich plan you are on and whether it is active, held by our billing provider. Card details are handled by the payment processor and never reach our servers.
TradingView account identifierThe identifier of the single TradingView account your plan is bound to. It is what stops one subscription being shared across many accounts.
Usage countsHow many runs you launched, how many combinations were tested, how many alerts you created, each with a timestamp. This drives your usage view and plan enforcement.
Action authorizationsWhen you launch a gated action, a single-use permission recording the action, its size in combinations and swept parameters, and when it was issued and used. This is how a plan cap is enforced on our side rather than trusted from the browser.
Community recordsIf you create or join a testing community: the community's name and description, the stable identity and display name of the strategy it is built around, its invite codes, the membership rows with their role, state and dates, the display name you chose for yourself there, and an append-only trail of the administrative decisions taken.
Measured history depthHow far back your own TradingView account can load price history, as a bar count with the symbol and timeframe it was measured on and the time of the reading. It is what lets a campaign require a minimum history. No plan name and no credentials are involved.
Contributed campaign resultsOnly when you press Contribute on a campaign, and only for that campaign: the parameters and backtest metrics of each combination you compute, the range that was tested, which combinations you were assigned, your progress and last contact, which combinations failed and why, and how fast your machine computed. The extension lists these categories and waits for your acknowledgement every time you start.
Security recordsAn append-only log of binding, reset and refusal events tied to your account, kept to detect subscription sharing and abuse. It is never sent back to the extension.

We do not collect analytics on your browsing, we run no advertising or cross-site trackers, and we do not sell or share any of the above with third parties for marketing.

What stays in your browser

The extension is local-first. The following is written to a database inside the extension, on your machine, and is never uploaded to us or to anyone else, unless you opt in to contribute it to a community campaign as described in the next section, or you turn on the AI assistant and choose a hosted provider for it as described in the section after that:

  • The strategies it detects, their names, and every input it reads from them.
  • The values in your sweeps, your saved configurations, and the symbols and timeframes you test.
  • Every combination tested and every metric TradingView reported for it.

The only thing derived from a run of your own that reaches us is a count, as listed above: how many combinations were tested, never which ones or what they produced.

The AI assistant

The assistant turns something you type in your own words into a proposal you then edit and confirm: a definition of what counts as a best result, a search space over a strategy’s inputs, or a campaign for a testing community. It is off until you turn it on, and by default it runs on your own machine: either the browser’s own on-device model, or a model server you run yourself on a loopback address. In both of those cases nothing leaves your machine at all.

You may instead choose a hosted provider from a fixed list we ship, using your own API key. If you do, that is the one part of this product that sends anything to a company other than us, and it works like this:

  • It is a separate, explicit choice. Turning the assistant on and choosing a hosted provider are two different acts. Before a provider is selected the extension lists every category of data a request contains; before a key field even exists, it names the company that would receive it and asks you to accept that specifically. Accepting one provider says nothing about another.
  • A request contains what you typed, our own vocabulary, and the strategy’s control panel. The figure names this system records with their labels and directions, the names of the shipped weighting profiles, your current definition of best, and the shape the answer has to take. When you ask about a search space or a campaign it also carries the strategy’s display name and, for each input you can configure, its id, label, group, type, current value, default, and either its numeric bounds and step or the options it offers, plus the help text TradingView shows for it. That text was written by whoever published the script, not by us. It also carries your own search space as it stands, and a count of anything left out to stay inside the request limits.
  • What a request never contains. No result value from any backtest, no chart data, no equity curve, no trade list, no per-trade value, no strategy logic or Pine source, no exchange, and no identifier of you, your account, your subscription or this project. The symbol and the timeframe travel in one case only: when you are defining a campaign for a community, where they are what the campaign is about, and they are chosen from a list the request itself carries rather than typed by the model. The parameter limit your plan allows is never sent either: that is a statement about what you pay us, so it is checked on your own machine.
  • It goes straight from your browser to that provider. It does not pass through our servers, we never see the request, and we never see your key.
  • The key is yours. It is stored on your machine, unencrypted, which the interface says where you paste it: there is no passphrase in this product, so anything we encrypted it with would sit beside it. One action removes it, and that action also stops any request already running. We do not pay for, meter, count or bill your use of any model.

How the AI assistant works lists every field a request contains, names the five providers you can choose from, and explains how to run a model on your own machine instead. The extension states the same list on its own settings page, generated from the same table, and every surface that asks you for a sentence links to it.

Testing communities

Testing communities let a group split one parameter space across several machines. They are the only part of the service that transmits optimization data to us, they are entirely opt-in, and they change nothing about the results you produce for yourself.

  • Creating or joining a community stores the community records and the measured history depth listed above. It transmits no parameter, no range and no result.
  • Contributing to a campaign is a separate, explicit act. The extension lists every category of data it will send and waits for your acknowledgement before the first combination runs, every time you start, and it stops sending the moment you stop contributing.
  • Your own copy is never affected. Everything you compute is written to your browser first and stays readable there after you leave the community, after the campaign closes and after the community is deleted.
  • Who can read what you contributed is decided by the community's owner and admins, per campaign. Other members see your community display name, never your email address or your account identifier.
  • Your Pine source and strategy logic are never transmitted, in a community or out of it. A strategy is referenced only by its stable identity and its display name.

Deleting a community, or a campaign, removes its records from our side. What you computed remains in your own browser for you to keep or clear.

What the extension accesses

The extension operates on TradingView pages you open. It reads your strategy inputs and the Strategy Tester metrics TradingView itself produces, applies each combination to the chart, and stores the results locally. It uses your existing TradingView session in your browser, so we never receive your TradingView credentials.

Its browser permissions exist for exactly that:

  • Access to TradingView pages, to read the chart and drive the Strategy Tester.
  • Access to our own API and sign-in origins, to verify your plan and your account binding.
  • Tabs, storage, context menus and cookies, to open its own pages, keep your settings and results locally, and read the session that identifies you to our API.

It does not read pages outside TradingView and our own origins. The only data it ever sends onward is what this policy lists: the account and plan records above, and, if you opt in, the campaign results a contribution transmits.

Cookies and sessions

This website uses the session cookies set by our identity provider to keep you signed in. The extension reads that same session on our origin so the panel knows who you are. There are no advertising or cross-site tracking cookies.

Who else processes it

ProviderRole
ClerkAccounts, sign-in and subscription management.
CloudflareHosting for this website and our API, and the database holding the records above.
GoogleThe sign-in provider, when you choose to sign in with your Google account.
Payment processorCard handling and invoicing through our billing provider. We never see or store card details.

Retention and deletion

We keep your account identity for as long as your account exists. You can delete your account at any time from your account page, which removes your profile from our identity provider.

Usage counts, action authorizations and security records are tied to your account identifier and are retained for plan enforcement and abuse prevention. If you want them erased after deleting your account, email us and we will remove them. Locally stored data is yours to clear at any time: delete it from within the extension, or uninstall the extension.

Community records and contributed campaign results are kept while the community and campaign exist, and are removed when they are deleted. Deleting your account hands a community you own to another admin or deletes it, and ends your other memberships.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email support@stratopti.com and we will answer within 30 days. Deleting your account is self-service and immediate, so you never have to wait on us for that.

Changes

We may update this policy as the service evolves. The "last updated" date above always reflects the current version, and a change that materially widens what we collect will be announced on this site before it takes effect.

Contact

Questions about this policy? Reach us at support@stratopti.com.