Legal

Privacy Policy

Effective August 4, 2026 · Last updated September 19, 2026

This Privacy Policy explains how Nefarious Digital, doing business as Nefarious (“Nefarious,” “we,” “us,” “our”), collects, uses, shares, and protects information about you when you use https://www.nefarious.trading, the member tools on it, and related services we operate (the “Service”). It is written to reflect how the Service actually works today; where a feature is optional or limited to certain members, we say so.

The Nefarious Discord server and Whop marketplace are operated by Discord Inc. and Whop, Inc. respectively. Your use of those platforms is also governed by their privacy policies; this Policy covers what we do with data we receive from or about you through them.

Privacy questions or requests: Business@nefarious.trading.

01Who we are (controller)

The data controller for the Service is Nefarious Digital. Contact: Business@nefarious.trading. We have not appointed a Data Protection Officer or EU/UK representative; if that changes we will list them here.

02Scope

This Policy applies when you:

  • visit any page on nefarious.trading, including research articles, education, market tools, analyst pages, and pricing;
  • sign in with Discord to use member tools;
  • use gated tools (congress trading, economic calendar, interest rates, Trump schedule, Position Manager, skew map, SniperYos watchlist, workout tracker, affiliates dashboard);
  • post comments, whiteboard items, workout logs, exercise requests, or other content;
  • connect Google Fit for steps and sleep;
  • subscribe to the research / watchlist newsletter;
  • are a Whop member or an affiliate, or joined the Discord through an affiliate’s invite.

03Information we collect

A. Discord sign-in

When you click “Sign in with Discord” we request the Discord OAuth scopes identify and guilds.members.read. Discord then gives us your Discord user ID, username, avatar identifier, and the role IDs you hold in the Nefarious Discord server. We do not receive your email address, password, friends, DMs, or membership in other servers. We store this identity in a signed, HTTP-only session cookie (see Cookies) rather than in a database account, and we use it to decide which tools you can open.

B. Membership status from Whop

Paid memberships are sold by Whop. A sync process we run pushes the current roster of Whop members who have linked a Discord account into our database every few minutes so the site can check VIP access. For each member this includes: Discord ID and username, Whop user ID, membership ID, product and plan IDs and names, membership status, whether it is currently valid, and the membership start and expiry timestamps. The roster is replaced on each sync, so members who lapse drop out of it. We never see or store your card number, billing address, or Whop login credentials.

C. Content you create

  • Research & watchlist comments — your comment text, the ticker it relates to, and your Discord ID, username, and avatar, shown to other members with access to that post.
  • Whiteboard (staff/moderators) — board items, sticky notes, text, shapes, uploaded images (stored as image data inside our database), comments with your Discord ID and username, and a presence record (username, last seen). Live cursor positions and names are held in server memory only for a few seconds and are never written to disk.
  • Workout tracker — workouts (title, notes, start/end time, duration, sets, reps, weight, distance, RPE), routines, rest days, body measurements you enter, exercise notes, unit preferences, and a profile record holding your Discord username and avatar so leaderboards can display you.
  • Discord shares & requests — if you press “Share to Discord,” the share-card image and a summary with your Discord mention are posted into a Nefarious channel via a webhook. Exercise requests post your Discord mention and the requested exercise name the same way. We do not keep separate copies; the messages live in Discord.
  • Newsletter — the email address you enter, where you signed up (pop-up, article footer, or watchlist), the page path, your browser’s user-agent string, the time, and the email categories you chose (research newsletter and/or promotions) with the time you made that choice.
  • Quizzes — the analyst-matcher and market quizzes run entirely in your browser; answers are not sent to us.

D. Google Fit health data (optional)

If you connect Google Fit from the workout profile page, we request the Google scopes fitness.activity.read and fitness.sleep.read. We store the OAuth access and refresh tokens, their expiry, the granted scope, and (when Google provides it) the email address of the connected Google account, and we import daily step counts and sleep duration, stages, and score. This is health data and is subject to the additional rules in Section 4. We do not request or receive heart rate, location, weight from Google, or any other Google account data.

E. Affiliate programme data

If you joined the Discord through an affiliate’s invite link and later bought a Whop membership, a daily sync links your Discord ID and username, join date, membership status, and the payment amounts and dates of your Whop purchases to that affiliate so their commission can be calculated. Affiliates can see this list for their own referrals only; staff can see all affiliates. Payout records store the affiliate’s Discord ID, amount, date, a transaction reference, and an optional note.

F. Information collected automatically

  • Server logs. Our hosting provider (Vercel) records requests to the site, including IP address, user agent, requested URL, referrer, and timestamp, for security and debugging. These logs are retained by Vercel for a short period.
  • Web analytics. We use Vercel Web Analytics, which counts page views and referrers using a hashed, daily-rotating identifier. It sets no cookies, does not fingerprint devices, and gives us aggregate statistics only (pages, countries, devices, referrers).
  • Rate limiting. Newsletter sign-ups store a one-way hash of your IP address and email for 60 seconds to stop abuse; the raw IP is not stored with your subscription.
  • Browser storage. Some preferences are kept in your browser only — see Cookies & browser storage.

We do not use advertising pixels, third-party tracking cookies, session replay, or cross-site tracking, and we do not build advertising profiles.

G. Public and market data

Market tools display data about companies, filings, congress members, economic events, and prices sourced server-side from public and licensed providers (for example Yahoo Finance, Nasdaq, SEC EDGAR, and, where configured, Finnhub, Financial Modeling Prep, or Polygon). This data is about issuers and public figures, not about you; your browser never contacts those providers directly.

04Health data (Google Fit): extra protections

Steps and sleep imported from Google Fit are treated as sensitive data. We commit that:

  • Consent only. Nothing is imported until you complete Google’s consent screen. You can disconnect at any time from the workout profile page or by revoking access at myaccount.google.com/permissions.
  • Limited use. Health data is used only to show you your own steps and sleep, to compute the health leaderboards you opt into, and for security. It is never used for advertising, never sold, never shared with data brokers, and never used to train AI models. Our use complies with the Google API Services User Data Policy, including its Limited Use requirements.
  • Visibility. Steps and sleep leaderboards are restricted to designated members; other members see your username, avatar, and ranked totals only if you appear on a board you are eligible for.
  • Deletion. Disconnecting deletes your Google tokens immediately and stops all imports. Previously imported daily step and sleep rows remain in your account until you ask us to delete them at Business@nefarious.trading, which we will do within 30 days.
  • Storage. Tokens and metrics are stored in our managed Postgres database (see Security) and are readable only by the Service and by staff with database access who need it to run the feature.

05How and why we use information (legal bases)

Where the EU/UK GDPR or similar laws apply, we rely on the legal bases shown in brackets.

  • Sign you in and keep you signed in using your Discord identity [contract].
  • Decide what you can access by matching your Discord ID and roles against Whop membership status and staff allowlists [contract; legitimate interest in enforcing paid access].
  • Run the features you use — store and display your workouts, comments, whiteboard items; compute streaks, statistics, and leaderboards; post shares you request to Discord [contract].
  • Import and show Google Fit steps and sleep [explicit consent — withdraw by disconnecting].
  • Send the research / watchlist newsletter you subscribed to [consent — withdraw by unsubscribing].
  • Calculate and pay affiliate commissions [contract with the affiliate; legitimate interest in operating the referral programme].
  • Keep the Service secure — rate limiting, abuse detection, signed cookies, log review, investigating violations of the Terms and Community Guidelines [legitimate interest; legal obligation].
  • Understand aggregate usage through cookie-free analytics [legitimate interest].
  • Communicate with you about access problems, security incidents, or material changes to the Service or these documents [contract; legal obligation].
  • Comply with law, respond to lawful requests, handle DMCA notices, and enforce our rights [legal obligation; legitimate interest].

We do not use your personal data for automated decision-making that has legal or similarly significant effects on you. Access checks are simple rule lookups (role held / membership valid).

06Cookies & browser storage

We use only strictly necessary cookies, all set by us (first-party). We do not use advertising or third-party tracking cookies, so we do not show a cookie-consent banner.

  • nefarious_session — your Discord ID, username, avatar hash, and Nefarious role IDs, signed with HMAC-SHA256 so it cannot be forged. HTTP-only, SameSite=Lax, Secure in production. Lifetime 14 days or until you sign out. Because roles are captured at sign-in, a role change on Discord may take until your next sign-in to affect the site.
  • auth_next — remembers which page to return you to after Discord sign-in. HTTP-only, 10 minutes.
  • google_health_oauth — a signed anti-forgery token used only during the Google Fit connection flow. HTTP-only, 10 minutes, deleted when the flow completes.

Local storage. To make the site work smoothly, some settings live only in your browser’s localStorage / sessionStorage and are never sent to us: newsletter pop-up dismissed/subscribed flags; an in-progress workout draft, rest-timer preference, and unit preferences; whiteboard camera position, grid, snap, and theme; the last board you opened; whether you minimised the analyst-matcher quiz; education course progress; and the research theme (light/dark). Clearing site data in your browser removes them.

Third-party resources your browser loads. Some pages load content directly from other companies, which see your IP address and browser details under their own policies: Discord’s CDN (member avatars on leaderboards and comments), Amazon CloudFront (our background and tutorial videos), and YouTube in privacy-enhanced mode (youtube-nocookie.com) for embedded videos, which does not set tracking cookies unless you play the video. Fonts are self-hosted; no requests go to Google Fonts.

07Who we share information with

We do not sell personal information and do not share it for cross-context behavioural advertising. We share it only:

  • With service providers (processors) who host or process data on our behalf under contract — listed in Section 8.
  • With other members, to the extent the feature is designed to show it: your username, avatar, and comment text on research posts; your username, avatar, and aggregate stats on workout and health leaderboards you appear on; whiteboard content to other whiteboard users; share cards and exercise requests in Discord channels.
  • With affiliates, if you joined through their invite (Section 3E).
  • With Discord and Whop, in the sense that we read data from them and post to Discord at your request; we do not send them additional data about you.
  • For legal reasons — to comply with law, court orders, or lawful requests; to enforce our Terms; or to protect the rights, safety, or property of members or the public, including reporting suspected market manipulation or fraud to regulators.
  • In a business transfer — if Nefarious is acquired or merges, data may transfer to the successor, who must honour this Policy.

08Service providers & third parties

  • Vercel Inc. (USA) — hosts the website and serverless functions; provides request logs and Web Analytics.
  • Neon Inc. (USA) — managed Postgres databases (provisioned through Vercel) storing membership rosters, comments, workout and health data, whiteboard content, newsletter subscribers, affiliate data, and staff tools. Separate projects are used for the main site, the whiteboard, and staff expense/planner tools.
  • Discord Inc. (USA) — OAuth sign-in, role lookup, avatar images, and webhook delivery of shares and requests. We also read the public member count of our server.
  • Whop, Inc. (USA) — membership checkout, billing, refunds, and the membership roster we sync.
  • Google LLC (USA) — Google Fit / Fitness API for optional steps and sleep import; YouTube for embedded videos.
  • Amazon Web Services (CloudFront) — delivers background and tutorial videos.
  • OpenRouter (routing to OpenAI and Google models) — used by staff in the blog editor to draft SEO text, thumbnails, and exercise illustrations. Only editorial content and exercise names are sent; no member personal data.
  • Market data providers — Yahoo Finance, Nasdaq, SEC EDGAR, Financial Modeling Prep (company logos), and optionally Finnhub, Polygon, or Benzinga. Queried from our servers only; they receive no information about you.
  • Our own sync workers — small services we run that push Whop membership, watchlist roles, affiliate stats, congressional trades, calendar, and rate data into the site over authenticated HTTPS.
  • TradingView — our indicators run on TradingView, but the website does not exchange any data with TradingView; your TradingView account is governed solely by TradingView’s policies.

Links to brokers, exchanges, prop firms, and partners take you to sites we do not control; some are affiliate links (see the Disclaimer). Their privacy practices are their own.

09How long we keep data

  • Session cookie — 14 days, or until you sign out.
  • Whop membership roster — replaced every sync; a member who cancels disappears from it once Whop reports the membership invalid.
  • Workouts, measures, routines, notes, profile — until you delete them in the app or ask us to delete your account data.
  • Google Fit tokens — until you disconnect; imported daily metrics — until you request deletion.
  • Comments and whiteboard content — until you or a moderator delete them, or the parent post/board is deleted.
  • Newsletter subscription — until you unsubscribe or ask us to remove you.
  • Affiliate referral and payout records — for the life of the affiliate relationship plus the period required for tax and accounting (typically 7 years for payout records).
  • Rate-limit hashes — effective for 60 seconds; rows are overwritten on the next attempt.
  • Server logs and analytics — kept by Vercel per its retention schedule (raw logs days; aggregate analytics longer).
  • Live cursor positions — about 4 seconds in server memory.

Database backups maintained by our provider may retain deleted data for a short rolling period before it ages out. We may keep limited records longer where needed to resolve disputes, enforce bans, or meet legal obligations.

10Security & encryption

We use technical and organisational measures appropriate to the data we handle:

  • Encryption in transit. All traffic between your browser and the Service, and between the Service and our database and providers, is encrypted with TLS (HTTPS).
  • Encryption at rest. Our database provider, Neon, encrypts stored data at rest with AES-256, and our hosting provider encrypts its storage. We rely on these provider-level controls; we do not additionally encrypt individual fields at the application level, and the Service is not end-to-end encrypted — staff who operate the Service can read stored content when needed to run it.
  • Tamper-proof sessions. Session and OAuth-state cookies are HMAC-signed and HTTP-only, so they cannot be read by page scripts or altered without detection.
  • Access control. Every member API checks your session and role or membership on the server; you can only read or change your own workouts, comments, and health data. Staff tools are limited to a fixed list of staff Discord IDs.
  • Secrets management. API keys, database credentials, and webhook URLs are stored as environment variables, never in the website code.

No system is perfectly secure. If you believe your account or data has been compromised, contact Business@nefarious.trading immediately.

Security incident notice

If we become aware of a personal-data breach that is likely to create a risk to you, we will notify you without undue delay through the Discord announcements channel, the website, and/or the email you gave us, and will notify the relevant supervisory authority where the law requires (for example within 72 hours under the GDPR). Our notice will describe what happened, what data was involved, and what we are doing about it.

11Your rights & choices

Depending on where you live you may have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data (most profile data comes from Discord; change it there and sign in again).
  • Erasure — have your data deleted. You can delete individual workouts, measures, routines, and your own comments in the app and disconnect Google Fit yourself; for deletion of everything linked to your Discord ID, email us.
  • Portability — receive the data you provided in a machine-readable format (JSON).
  • Restriction and objection — ask us to limit processing or object to processing based on legitimate interests.
  • Withdraw consent — disconnect Google Fit, unsubscribe from the newsletter, or revoke the Nefarious app in your Discord Authorized Apps settings at any time. Withdrawal does not affect processing that already happened.
  • Complain — lodge a complaint with your local data-protection authority (in the EU, your national DPA; in the UK, the ICO).

To exercise a right, email Business@nefarious.trading from an address you can be reached at and include your Discord username and ID (Discord → Settings → Advanced → Developer Mode → right-click your name → Copy User ID). Because we hold no email address for most members, we may ask you to confirm the request from your Discord account (for example by DMing a moderator) before acting. We respond within 30 days (45 days for U.S. state-law requests, extendable once), free of charge unless requests are manifestly unfounded or excessive. Where we cannot honour a request, we will explain why.

Marketing emails. Every newsletter or promotional email we send identifies Nefarious as the sender, is sent only to addresses that signed up on our site, and includes a way to unsubscribe. You can also unsubscribe from one or both categories (research newsletter, promotions) by emailing Business@nefarious.trading with the subject “Unsubscribe”; we honour requests within 10 business days as required by CAN-SPAM.

12U.S. state privacy rights (California and others)

If you are a resident of California or another U.S. state with a comprehensive privacy law, you have the rights to know/access, delete, correct, and port your personal information, and to opt out of the “sale” or “sharing” of personal information and of targeted advertising, without discrimination.

  • Categories we collect (last 12 months): identifiers (Discord ID, username, avatar, email for newsletter, IP in logs); commercial information (Whop membership and plan status, purchase amounts for affiliate attribution); internet activity (pages viewed, aggregate analytics); user-generated content (comments, workouts, whiteboard items); and, with consent, health information (steps and sleep). Sources: you, Discord, Whop, Google, and our own sync workers. Purposes: as described in Section 5.
  • We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no opt-out to make; we also do not use or disclose sensitive personal information for purposes other than providing the features you asked for.
  • Disclosures for a business purpose are made to the service providers listed in Section 8 and, for referral attribution, to the affiliate whose invite you used.
  • Authorised agents may submit requests on your behalf with proof of authority; we will still verify your identity through your Discord account.
  • Global Privacy Control. Because we do not sell or share data, a GPC signal does not change how we process your data, but we honour it as an opt-out request.

Submit requests to Business@nefarious.trading. Nevada residents: we do not sell covered information as defined in NRS 603A.

13International transfers

Nefarious operates from the United States and our providers (Vercel, Neon, Discord, Whop, Google, AWS) store and process data primarily in the United States. If you use the Service from the EU, UK, Switzerland, or elsewhere, your data will be transferred to the U.S., whose laws may differ from yours. Where required, we rely on our providers’ Standard Contractual Clauses / UK Addendum and, where applicable, their participation in the EU-U.S. Data Privacy Framework, together with the technical safeguards described above.

14Children

The Service is a trading community and is intended only for adults aged 18 or over. It is not directed to children, and we do not knowingly collect personal data from anyone under 13 (or under 16 where that is the applicable age of digital consent). Discord itself requires users to be at least 13. If you believe a child has provided us with personal data, email Business@nefarious.trading and we will delete it and remove the account from our tools.

15Changes to this Policy

We will update this Policy when our practices change — for example when we add a new integration or data type. The “Last updated” date at the top changes with each revision. For material changes we will post a notice in the Discord announcements channel and on the website before the change takes effect, and where a new use of your data requires consent we will ask for it. Prior versions are available on request.

16Contact

Privacy questions, rights requests, Google Fit / health-data inquiries, and security reports: Business@nefarious.trading.

Also see our Terms of Service, Community Guidelines, and Financial Disclaimer.