JSK TradeProof

Privacy page

Overview

TradeProof analyses your trades inside your own spreadsheet. Your trade data is not
uploaded, not transmitted and not stored by us. Not in summary, not anonymised, not at all.
There is no analytics, no telemetry and no crash reporting in the product.

This is a property of how it is built rather than a promise about how we behave: the analysis
is arithmetic performed by the add-in in your workbook, and there is no server for it to run on.

Information we collect

Your trade data: none. It is read from your sheet, analysed locally, and written back to
new sheets in the same workbook.

Your licence key, when you enter one. To check what you are entitled to, TradeProof sends
your key to https://api.jskapps.com and reads back your tier, your account id and whether
your account is a test account. The request contains your key and nothing else: no
trades, no figures, no file names, no identifiers we generated.

If you enter no key, TradeProof makes no network request whatsoever.

When TradeProof contacts the network

Exactly two requests are possible, and both are consequences of something you did:

| When | Where | What is sent |
| --- | --- | --- |
| You press Activate, or open the panel with a saved key | https://api.jskapps.com/api/access/jsk-tradeproof/ | Your licence key, as an Authorization header |
| (Paid, Google Sheets only) you put a logo link on the settings sheet | The address you typed | An ordinary image request, with no cookies and no key attached |

The logo is fetched once and embedded in the report as image data, so the document you download
contains no link back to anywhere. It renders with the network off, and opening it tells
nobody you opened it.

How we use it

The key is used to answer one question, free or paid, and to return your account id. We do
not build a profile, and we cannot: we never receive anything about your trading.

Permissions and why we need them

Excel requests ReadWriteDocument: read your trades, write the report sheets. It is the
narrowest permission that can write a sheet. AppDomains is limited to www.jskapps.com and
api.jskapps.com.

Google Sheets requests exactly two scopes:

  • spreadsheets.currentonly: the current spreadsheet only. The add-on cannot open, list
    or read any other file in your Drive. This is the narrowest spreadsheet scope Google offers.
  • script.container.ui: show the sidebar and the download window.

It does not request script.external_request, the scope that appears on a consent screen
as "connect to an external service". The licence check runs in the sidebar, in your browser,
so no such permission is needed.

Data storage and retention

| What | Where it lives | Who can see it |
| --- | --- | --- |
| Your trades and reports | Your workbook | Whoever you send the file to |
| Your settings | A TradeProof — Settings sheet in your workbook | Whoever you send the file to |
| Your licence key, in Excel | The task pane's own per-user storage on your machine | You |
| Your licence key, in Google Sheets | Not stored. Re-entered each session | You |
| Your trades, on our servers | Nowhere. We never receive them | None |

Settings travel with the workbook by design, so a report can be reproduced. The key never
does
: sharing a workbook does not share your licence.

Sharing and third parties

We do not sell, rent or share your information. There is no advertising network, no analytics
provider and no third-party script in the product. The only third party involved in a licence
check is our own hosting provider, carrying a request to our own API.

Security

The licence check is HTTPS only. Your key is a credential: the panel masks it by default,
because a spreadsheet sidebar sits open through screen shares and screenshots. Sign out
clears it.

Your choices

  • Use it with no account, and no network request is made at all.
  • Sign out at any time to remove the stored key.
  • Delete the report by deleting the TradeProof — sheets.
  • To have an account and its purchase history removed, write to info@jskapps.com.

Changes to this policy

Material changes will be noted on this page with a date. The add-in's own behaviour is
verifiable: what it sends is in the request above and nowhere else.

Contact

info@jskapps.com · JSK Business Solutions