Privacy Policy

Last updated: September 12, 2026

This English version is provided for reference only. The Japanese version is the authoritative text.

1. Introduction

<3 (Less Than Three, "we") sets out in this policy how we handle user information in Folyze Trade (including the website and the mobile applications, the "Service").

The Service connects to a user's MetaTrader 5 ("MT5") trading account and aggregates and visualises its trade history. The information the Service handles is therefore centred on the user's own trading records.

2. Information we collect

The Service collects the following information.

CategoryWhat it covers
Account informationYour email address. If you sign in with an Apple or Google account, the user identifier and email address those providers supply. Passwords are stored hashed by the authentication platform; we never receive them in plain text.
Trading account informationAccount attributes such as the MT5 account number, server name, broker name, account holder name, account currency, leverage, margin calculation mode and account type (live / demo).
Trade dataFill history (symbol, side, volume, price, profit and loss, commission, swap, close reason, comments and so on), position information, balance and equity time series, and per-position price logs.
Information you enterAccount display names and descriptions, and the body text and tags of your trade journal entries.
Notification settingsWhether each notification type is on or off, the drawdown alert threshold, the send time for the daily summary, the disconnect detection threshold, and your time zone.
Device informationThe device token used to deliver push notifications, and the platform type (iOS / Android).
API key informationThe hash of the API key used for the MT5 connection, the label you gave it, and when it was last used. The key itself is shown only when it is issued, and we store it only in a form we cannot reverse.
Purchase informationYour paid plan's subscription state, plan type, purchase date and expiry. Payment details such as card numbers are handled by the App Store, Google Play or the payment provider; we do not receive them.
Usage informationUsage events such as screens viewed and actions taken, device type, OS and app version, and IP address. Once you sign in, these are recorded together with your account identifier.
Diagnostic informationThe content of errors and crashes, the device, OS and app version at the time, the IP address and the account identifier. For errors on the website, this includes a recording of the interactions around the error, with displayed text and entered values masked.

3. Information we do not collect

The Service does not collect any of the following.

  • Advertising identifiers (IDFA / AAID) or any identifier used for tracking
  • Location data
  • On-device data such as contacts, photos or calendars

Neither our apps nor our website embeds an advertising network SDK. We also never use the information we collect to track users across other companies' apps or websites.

The Service also only reads your MT5 account. It never places, modifies or closes an order, and it never collects the information required to do so, such as your trading password.

4. How we use it

  • Aggregating your trade history, calculating statistics and displaying them
  • Delivering notifications on the conditions you set (new fills, drawdown, daily summary, detection of a dropped account connection)
  • Generating and serving performance share links when you explicitly enable them
  • Identity verification and authentication
  • Managing the state of paid subscriptions
  • Improving the Service by analysing how it is used
  • Detecting failures and investigating their cause
  • Preventing abuse, responding to incidents and answering your enquiries

We never use the information we collect to serve advertising, and we never sell it to third parties.

5. Disclosure to third parties and subprocessors

Except where required by law, we do not disclose the information we collect to third parties. We do, however, entrust its handling to the following providers, to the extent needed to run the Service.

Entrusted workInformation handled
Authentication and database (Supabase, Inc.)Stores the information described in this policy. Data is held in the Tokyo region.
Application server hosting (Google Cloud Platform / Google LLC)The information required to run the Service. Runs in the Tokyo region.
Website delivery (Cloudflare, Inc.)Connection information arising from visits to the website.
Push notification delivery (Expo / 650 Industries, Inc., Apple Inc., Google LLC)Device tokens and notification bodies. A notification body may contain an account display name or a profit and loss figure.
Sign-in with an external account (Apple Inc., Google LLC)Only where you sign in with an Apple or Google account.
In-app purchase and subscription management (RevenueCat, Inc., Apple Inc., Google LLC)Your account identifier and purchase information.
Payments on the website (Stripe, Inc.)Payment details. These are handled directly by the payment provider; we do not receive them.
Usage analytics (PostHog, Inc.)Usage information.
Failure detection (Functional Software, Inc. dba Sentry)Diagnostic information.

We also query an external exchange-rate service (Frankfurter) to convert currencies. No information that could identify you is sent with those queries.

Of the above, the providers entrusted with website delivery, push notification delivery, subscription management, payments, usage analytics and failure detection may handle information on servers outside Japan. The destination country is mainly the United States (Cloudflare, Expo, RevenueCat, Stripe, PostHog and Sentry). The United States has no comprehensive personal data protection law equivalent to Japan's Act on the Protection of Personal Information; protection there rests on sector-specific federal laws and state laws. We require these providers, by standard contractual clauses or equivalent agreements, to maintain protections equivalent to those required by Japanese law on an ongoing basis. Details of the destination country's regime and of the measures we require are available on request at the contact below. By registering to use the Service, you consent to these transfers.

6. Information sent to external providers

The Service's website and apps send information from your device to the following providers. What is sent, where it goes and why:

DestinationInformation sentPurpose
PostHog, Inc. (United States)Usage events such as screens viewed and actions taken, device type, OS and app version, IP address, and your account identifier once signed inAnalysing usage to improve the Service
Functional Software, Inc. dba Sentry (United States)Error and crash details, the device, OS and app version at the time, IP address, your account identifier, and on the website a record of the surrounding interactions (with text and input values masked)Detecting failures and investigating their cause
Supabase, Inc. (data stored in the Tokyo region)Email address, authentication tokens, IP addressIdentity verification and authentication
Google LLC (Google Cloud Platform, Tokyo region)Information needed to process your requestsProviding the Service

We send nothing for advertising purposes and nothing that tracks you across other companies' apps or websites. If you do not want this, stop using the Service — usage analytics and failure detection are limited to what running the Service requires.

7. Sharing your results

The Service can let third parties view an account's performance. This feature is off by default and only operates once you explicitly enable it.

Enabling it issues a URL containing a share token, and anyone who knows that URL can view that account's performance without signing in. How widely the URL is distributed is under your control. If you stop sharing, the URL no longer shows anything.

8. Retention and deletion

We retain the information we collect for as long as you hold an account. You can delete your account at any time from the settings screen in the app.

Deleting your account deletes your authentication credentials and all data associated with you described in this policy. This cannot be undone. Data contained in backups is erased once the backup retention period elapses.

9. Security measures

  • All communication is encrypted with TLS.
  • Database access is limited to your own data by row level security and by authorisation in the application layer.
  • API keys are stored hashed, never in plain text.
  • Credentials and connection information are held in a secret management service with restricted access.

10. Your rights

You may ask us to disclose, correct, add to, delete or stop using your information. You can also delete it yourself with the account deletion feature. To make a request, use the contact details at the end of this policy.

11. Use by minors

Because the Service handles records of financial trading, it is not intended for minors. If you are under 16, do not use the Service without the consent of a parent or guardian. We do not knowingly collect information from anyone under 16, and if we find that we hold such information we delete it after verification.

12. Changes to this policy

We may change this policy as needed. Where a change is material, we will announce it in the Service. The updated policy takes effect once it is published on this page.

13. Contact

For enquiries about this policy, please contact us at:

<3 (Less Than Three)
support@folyze.io

Our name and address as the business handling personal information will be provided without delay on request to the contact above.