Privacy

What we collect, why, who sees it, and how to make us stop.

Last updated 2026-09-16

The controller of your information is Prophet Profits Trading LLC, established in New York, United States, at 3180 Express Drive S, Suite E, Islandia, NY 11749, United States. It decides what is collected here and why.

Who is responsible for your information

The operator of Atomic Trading University decides what is collected here and why, which under the UK and EU General Data Protection Regulation makes it the controller of that information. Its registered name and postal address are on the Contact page.

This policy covers the website, the learning platform, the journal, mentoring, and support. It is written to be read rather than to be survived.

What we collect

  • Account: your email address, a display name, whether the address is verified, an age band, and a password digest if you set a password. We never store a password itself.
  • Profiles: the display name and age band of any child profile you add, and the link between it and your account.
  • Learning: which lessons you opened and finished, quiz and drill attempts and scores, chapters mastered, XP, achievements, notes you write on a lesson, and your placement answers.
  • Journal: the trades, setups and reviews you enter yourself, including anything you import from a broker statement. We do not connect to your broker; you supply the file.
  • Billing: which plan and price you hold, subscription status, renewal dates and invoice records. Card details go directly to Stripe and never reach our systems.
  • Support: your messages, any picture or recording you attach, and the email address you asked us to reply to.
  • Mentoring: what you said the session should be about, and the times you offered.
  • AI usage: how many coach, tutor, wire or support replies you have used, so allowances can be counted.
  • Technical: your IP address and request metadata in our hosting provider's short-lived logs, and sign-in attempt records kept to detect brute force.

Why we collect it, and what entitles us to

Under the UK and EU GDPR we have to name a lawful basis for each use. Ours are these.

  • To provide what you signed up for: your account, your progress, gating, the journal, support and mentoring. Basis: performance of our contract with you.
  • To take payment and keep billing records. Basis: performance of the contract, and a legal obligation to keep financial records.
  • To keep the platform secure and to detect abuse. Basis: our legitimate interest in a service that is not being attacked.
  • To improve the curriculum using aggregate figures, such as which chapter people fail most. Basis: legitimate interest, and it is done on aggregates rather than on you.
  • To send product or progress email. Basis: your consent, which is off by default and which you can withdraw in settings without losing anything else.
  • To handle a child profile. Basis: the consent of the parent or guardian who created it, recorded against the version of this policy in force at the time.

Children

A child never holds an account here. A child profile exists only inside an adult's account, is created by that adult, and has no sign-in of its own.

We do not knowingly collect personal information from a child under 13 in the United States, or under the applicable age in the United Kingdom or the European Economic Area, except through a profile created by their parent or guardian with that person's verifiable consent. We record that consent and the policy version it was given against.

What a child profile holds is deliberately minimal: a display name chosen by the adult, an age band, and the learning record. We ask for no address, no phone number, no photograph, no location, no biometric identifier, and no contact details for the child. We do not use a child's information to advertise to them, we do not sell or share it, and we disclose it to no third party for any purpose of their own.

A parent or guardian can at any time review what a child profile holds, export it, or delete it, from family settings. Deleting the profile deletes the learning record with it. You do not have to explain why, and nothing else on your account is affected.

If we learn that we hold information about a child without the required consent, we delete it. If you believe that has happened, contact support and we will act on it quickly.

Who else sees it

We do not sell your information, we do not share it for anybody else's advertising, and we run no advertising trackers. We use a small number of service providers to run the platform, each processing only what its job needs, under contract, and on our instructions.

  • Vercel: hosting and content delivery. Processes requests and short-lived technical logs.
  • Neon: the managed database where your account and learning records are stored.
  • Stripe: payment processing. Stripe is the controller of the card data you give it, under its own policy. We receive a payment status and the last digits, never the card.
  • Resend: sending and receiving email, including sign-in links and support replies.
  • Anthropic: the model behind the coach, tutor, wire and support assistant. It receives the text of your conversation and, in the coach's case, figures drawn from your own record. It is contractually bound not to train on it.
  • Vercel Blob: storage for pictures and recordings attached to a support conversation, in a private store that requires a signed, expiring link to open.
  • We may also disclose information where the law requires it, or to establish or defend a legal claim. If we are ever asked for your data by an authority and are permitted to tell you, we will.

Where it is held

Our providers operate in the United States and elsewhere, so your information may be transferred outside the United Kingdom or the European Economic Area. Where it is, transfers rely on the UK and EU Standard Contractual Clauses or an equivalent approved mechanism, and our providers are engaged on those terms.

How long we keep it

  • Your account and learning record: while your account exists, and deleted when you delete it.
  • Invoices and payment records: seven years, because financial record-keeping law requires it. These survive account deletion, reduced to what the obligation needs.
  • Support conversations: three years from the last message, so a dispute can be traced.
  • Sign-in tokens and attempt records: days, not months.
  • Aggregate statistics with nothing identifying in them: kept indefinitely.

Your rights

Wherever you live, you can ask us for a copy of what we hold, ask us to correct it, or ask us to delete it, and most of it you can do yourself in privacy settings without asking anyone.

If you are in the United Kingdom or the European Economic Area you also have the right to object to processing based on legitimate interests, to ask us to restrict processing, to data portability, and to withdraw consent at any time without affecting what was done before you withdrew it. You can complain to your supervisory authority, and in the UK that is the Information Commissioner's Office.

If you are in a United States state with a comprehensive privacy law, including California, Colorado, Connecticut, Texas, Virginia and others, you have rights to know, to delete, to correct, to a portable copy, and to opt out of sale, of sharing for cross-context advertising, and of profiling with legal effects. We do none of those three things for anybody, so there is nothing there to opt out of, and we honor the Global Privacy Control signal regardless. We will not treat you differently for exercising a right.

To exercise anything not available in settings, contact support. We answer within 30 days, or tell you why we need longer.

Automated decisions

Access to a chapter is decided automatically: within a world, a prerequisite quiz passed at the pass mark opens the next chapter, and a plan decides which worlds are available at all. That is a rule applied to your own results, it is stated openly in the product, and it has no legal effect on you.

We do not profile you to make decisions about your finances, your creditworthiness, or anything outside this platform.

Cookies and what is stored in your browser

We use no advertising cookies, no analytics cookies, and no third-party trackers, which is why this site has no cookie banner asking you to accept them. What we set is what the platform needs to function.

  • tl_session: keeps you signed in. Essential.
  • tl_learner: identifies an anonymous learner so progress survives before you make an account. Essential.
  • tl_profile: remembers which profile on your account is in use. Essential.
  • tl_admin and tl_site: used only for staff access and for a password-gated preview. Essential when in use.
  • One item in local storage remembers that you have already dismissed the support hint. Nothing is sent anywhere.

Security

Sign-in tokens are stored only as hashes, so a copy of our database cannot be replayed as somebody's session. Passwords are stored as a scrypt digest. Traffic is encrypted in transit. Support attachments sit in a private store reachable only through a signed link that expires.

No system is perfectly secure. If a breach ever affects your rights we will tell you and the relevant regulator within the time the law requires: under the New York SHIELD Act that is within thirty days of discovering it for a New York resident, and under the UK and EU GDPR it is seventy-two hours to the supervisory authority.

Changes, and how to reach us

If we change this policy the date at the top changes, and we keep a record of the version you agreed to. A change that materially affects you is notified before it takes effect.

For anything about your information, contact support, which reaches a person whenever you ask for one.