Privacy at a glance
- TrueFix Studio is local-first. The current app does not require or create a TrueFix cloud account.
- Provider credentials, workspaces, Agent sessions, market data, trading records, and logs are stored on the device running the app.
- Data is sent to a broker, exchange, market-data source, or AI service only when you configure and use that service.
- We do not sell personal data, serve behavioral advertising, or include first-party product analytics in the current website or app.
01 / SCOPE
Scope and responsible party
This policy applies to the TrueFix Studio public website, downloadable applications, and the optional Web Gateway. It also covers information you voluntarily send to TrueFix Labs for support. “TrueFix,” “we,” and “us” refer to TrueFix Labs.
Third-party brokers, exchanges, market-data sources, AI model services, GitHub, and Google process information under their own terms and privacy policies. TrueFix Studio helps you connect to them but does not control their independent practices.
02 / INFORMATION
Information the product handles
Your language preference is stored in browser localStorage under truefix.language. The site does not set advertising or analytics cookies. GitHub Pages and Google Fonts necessarily receive standard request information such as IP address, browser headers, requested URL, and time. The download panel also requests public release metadata from GitHub.
The app stores settings, Provider and AI credentials, instrument mappings, market and research data, workspaces, watchlists, Agent conversations and tool records, strategies, orders, positions, risk and audit evidence, and diagnostic logs locally as needed for the features you use.
When you activate an integration, the app sends the identifiers, queries, prompts, account instructions, authentication data, or orders needed to perform your request. The recipient and exact fields depend on the configured Provider, capability, and your action.
If the local operator enables Web Gateway, it processes login and session information and writes access/security logs that may contain IP address, user agent, referrer, host, request path, response status, and timing. Refresh-token, IP, and user-agent fingerprints are stored as hashes in the local authentication database; the browser may hold an HttpOnly session cookie.
If you contact us, we receive the address or account you use, your message, and any diagnostics or attachments you choose to provide. Do not send API keys, passwords, cookies, private keys, full account numbers, or unredacted financial records.
Market, portfolio, account, and order information may be sensitive. It is handled because it is necessary for the workstation functions you request. TrueFix Studio is not designed to collect health, contacts, precise location, advertising ID, or cross-app activity.
03 / SERVICES
How information is used and disclosed
Information is used to provide the requested workstation function, maintain security and sessions, preserve auditability, diagnose faults, and respond to support. We do not sell or rent it.
User-directed services
Information is transmitted to the broker, exchange, data vendor, news/intelligence source, AI model provider, DNS/ACME service, or other endpoint that you explicitly configure or select. Those services may process data in other countries and may retain it under their agreements with you.
Website infrastructure
The public site is hosted by GitHub Pages and loads fonts from Google Fonts. Links to GitHub Discussions and Releases take you to GitHub. Their privacy policies govern information they receive.
Legal and safety
We may preserve or disclose information sent to us if reasonably necessary to comply with law, protect users, investigate abuse, or defend the security and rights of TrueFix Labs. We will limit disclosure to what is necessary.
04 / STORAGE
Local storage, credentials, and retention
Configuration is stored by default in ~/.truefix-studio/config.toml. Application databases and daily logs are stored in the operating system’s application-data locations under truefix-studio. Provider credentials are kept in the owner-readable local configuration and are redacted from normal UI projections and diagnostics. The current pre-release does not use the operating system Keychain for those credentials, so device and filesystem security remain important.
Local records remain until you remove them, uninstall and delete application data, or a documented product retention/compaction rule applies. Daily log filenames rotate, but rotation alone does not promise automatic deletion. Data sent to a third party follows that party’s retention policy. Support messages remain on the service used to contact us until deleted under its controls or no longer reasonably needed.
05 / YOUR CONTROLS
Your privacy choices
- Do not configure a Provider or AI service you do not want to receive your requests.
- Use read-only, Paper, Demo, Testnet, or Simulator scopes where appropriate, and revoke credentials at the originating service.
- Disable Web Gateway, sign out browsers, revoke individual Web devices, rotate the access password, or clear its local session store.
- Delete local settings, databases, logs, and the website language preference using the instructions on the Technical Support page.
- Contact us to request access to or deletion of personal information that you sent directly to TrueFix Labs. We may need to verify the request.
The current release does not create a hosted TrueFix user account. Google Play’s web account-deletion flow is therefore not applicable to this version. If account creation is introduced, this policy and the deletion controls will be updated before distribution.
06 / SAFETY
Security and children
We use measures such as local user-only permissions, credential redaction, scoped authorization, hashed Web refresh tokens and client fingerprints, short-lived access tokens, session revocation, host/origin checks, and HTTPS requirements for non-loopback Web Gateway access. No system is perfectly secure; protect your device, configuration, backups, and Provider credentials.
TrueFix Studio is a professional financial workstation and is not directed to children. We do not knowingly request personal information from children. Users must satisfy the age and eligibility requirements of every broker, exchange, store, and jurisdiction they use.
07 / CONTACT
Changes and contact
We may update this policy when product features, connected services, or legal requirements change. The date and version at the top identify the current policy. Material changes will be presented through an appropriate product or website notice.
This page describes the current pre-release and is intended to support accurate marketplace disclosures; it is not a substitute for legal advice or for completing each store’s App Privacy/Data safety questionnaire according to the submitted binary.