What is stored, why, and how to get rid of it.
Last updated 29 August 2026.
The whole tracker works signed out, and while you are signed out nothing you type is sent anywhere. Your figures live in your own browser's local storage, on your own device. We cannot see them, and clearing your browser data removes them.
This is why the site says an account is not needed. Signing in is what changes the answer, which is why it is stated plainly rather than buried here.
| What | Why |
|---|---|
| Email address | To send your sign-in link, and the reminders and alerts you switch on |
| Holdings and position log | So they are the same on every device you sign in on. A logged cycle records which side it was, a short put or a covered call, because the two are scored against different things and only one of them can raise a target alert. Also, per symbol, what you say your shares cost before your brokerage history begins, or that you do not know it |
| Notes you write, and what you say a strategy is | A note on a position; and on a strategy, a note saying why you run it, how often, what shape it takes, the delta you write it at and the tickers you keep it to. These are the only fields here that are free text, so they hold whatever you type and nothing reads them but you: no alert, no scorecard and no email uses them. A strategy also carries one setting that is read, alongside the profit target: whether a contract closing and another opening on the same day is a roll or a new position. It changes how your own contracts are grouped on your own screen and nothing else. They sync so they are on every device, they are deleted with your account like everything else, and if you would rather they never left your browser, sign out and the tool works exactly as it does now with nothing sent anywhere |
| The identifiers of cycles you delete | An id and the date it went, so a device that was offline when you deleted a cycle does not put it back the next time it syncs. It is a record that a row was removed, never a copy of what was in it: no instrument, no strike, no dates from the cycle itself. Kept for six months and then dropped |
| Cycles waiting to be imported | When you press Update from broker, the tool works out which of the cycles your brokerage recorded are not yet in your log, and that short list is stored so your other devices show the same thing without each of them having to read your brokerage again. Each entry is a contract you traded: the underlying, the strike, the expiry, whether it was a put or a call, the dates it was opened and closed, how many contracts, what came in and what went out, and the references for the trade: the aggregator's id, and your brokerage's own where it supplies one, which on Fidelity carries the order number the Log reads to suggest which contract a roll continued. It is the list of what has NOT been imported, so it shrinks as you import and is empty once you have taken everything. Nothing is added to your log from it until you say so, and it is derived from your brokerage history rather than being a second copy of it: the history itself is never stored here. |
| Cycles you told the import to forget | A cycle your brokerage recorded that you have decided not to log, so it stops being offered on every refresh: the underlying, strike, expiry, put or call, the dates it was opened and closed, how many contracts, what came in and went out, and the day you forgot it. Listed under your log, where each one can be brought back. In no figure anywhere. |
| Strategy settings | Instrument, broker, target notional and DTE, so the tool says the same thing everywhere. Also the names you give your own strategies and the profit target you set for each, since those decide which of your closed cycles the scorecard counts as a hit and the level at which the target email is sent. Each logged position carries its strategy’s name in a column of its own so that email can read it |
| Notification settings | Which emails you want, how much notice, and the hour and timezone to send them. Where an alert needs a level, the level itself: the margin cushion you want to be told about, and the days before expiry at which you want to hear that a position has arrived there. Also which entries your calendar feed carries, including whether you have asked it to include your own positions. A new account starts with the three-day expiry email on, and with the timezone Cloudflare places your sign-in in, so the first one does not arrive in the night; saving your settings replaces it with your browser's. On the free plan, whether you want the monthly summary email and the month it was last sent for |
| What the calendar feed serves | The feed carries dates. By default they are computed third Fridays and describe nothing you hold. If you switch on your own positions it also carries, for each open position, its instrument, its strike, whether it is a put or a call, and its expiry date. Never your equity, your size, what anything cost or what it is worth now. It is off unless you turn it on, and anyone holding the feed link can read it, which is why re-issuing the link is the way to revoke it |
| Subscription status | Whether a plan is active, and for a new account's Pro trial the last day of it and which of the trial's four emails has been sent: one when it starts, a week before it ends, three days before, and the day it does. Held as a status, that date, that step, and a Stripe customer reference, never a card |
| How your account is used | A few dated facts and counts on the account itself, which is how we tell whether the trial is worth having: when it started, when a brokerage was first connected, how many trades had been logged after seven days and at the trial's end, whether either of those reached what we call activated (a brokerage, or ten trades, in the first week), when the account first subscribed and whether monthly or yearly, when a trial ended or a subscription stopped, the last day you opened the tracker signed in, and four counts: alert emails sent, alert links followed while signed in, visits to the pricing page while signed in, and brokerage reads that failed. No open-tracking pixel, no record of pages or times, and none of it leaves Restrike |
| Brokerage link | An opaque token from our brokerage data provider, if you connect one. Never a brokerage credential |
| Where you came from | If the link you first arrived on
carried a campaign word, such as ?ref=tiktok, that word.
It says which post or advert introduced you and nothing else: not the
page you came from, not the address you came from, and nothing that
tells one visitor from another. Usually empty, and never updated after
your account is made |
There are no passwords. Sign-in is by emailed link, and both the link token and your session identifier are stored only as SHA-256 hashes. A copy of the database contains nothing anybody could sign in with.
That is the whole list. Nothing is sold, nothing is shared with advertisers, and there is no advertising network on this site.
There is no consent banner because there is no third-party tracking to consent to. No advertising pixel, no session replay, no analytics company of its own: nothing on this site can identify you, follow you to another site, or be sold. The rest of this section is what is counted, field by field, and the end of it says how to switch the counting off with one click.
Signed in, your account carries a few facts about how it is used, listed in full under "How your account is used" above: dates like the day your trial started and the day you first connected a brokerage, and four counts. They are kept on the account because they are about the account, and they are not joined to anything below. An alert email's link says only that it came from an alert; the count is made because you are signed in when you follow it, and there is no pixel in any email.
The site uses Cloudflare Web Analytics, which is privacy-preserving: it sets no cookie, uses no fingerprinting, and does not track you across sites. It counts page views.
The first-run walkthrough is counted too, and this is the whole of it: when it opens, which of the three ways in you pick, and whether you finish it or skip it. Six numbers, added up by day.
Each of those is a single word from a fixed list, and nothing travels with it. No identifier, no session, no address, nothing you typed, and no record of the time beyond the date. Your IP address is used to rate-limit the endpoint and is never written down. The table these go into has three columns, a name, a day and a count, so there is nowhere to put anything about you even by mistake.
It exists to answer one question, whether people who start the walkthrough finish it, which nothing could answer before. It cannot distinguish one visitor from another and it is not used to.
Pages also record how long they were read, and roughly where from. This one goes further than the counts above, so here is the whole of what a page sends, field by field:
? or a
# is cut off before it is sent, so a link somebody shared
with search terms or a token in it does not carry them here.tiktok.com, never the address of the page on it.Your IP address is used to rate-limit that endpoint and to derive the location above. It is never written down. Nothing you type into the calculator is ever sent: every field listed above is a page address, a host name, a number, or a word from a fixed list, and there is no field that could carry one of your figures even by mistake.
It goes to Cloudflare Analytics Engine, on the same account that already serves this site. No third party is involved, which is why there is no Google Analytics here: that would hand a company whose business is advertising the address and referring page of every visitor, and it would need a cookie banner. This needs neither.
You can turn all of it off, and it takes one click. Visit any page
on this site with ?cf-off=1 on the end of the address, for
example userestrike.com/?cf-off=1, and this browser stops
being counted by either of the things above: the page events and the
Cloudflare page views. It is remembered in your own browser's storage,
nothing about it is sent anywhere, and it lasts until you clear your
browsing data. ?cf-off=0 turns counting back on. A short bar
at the bottom of the page confirms which way it went, because a switch
that changes nothing on screen is indistinguishable from one that did not
work.
One cookie is set, and only when you sign in: your session. It is HttpOnly, Secure and SameSite=Lax, it exists to keep you signed in, and it is not used for tracking. There is no cookie banner because there is nothing to consent to beyond a cookie that is strictly necessary.
Positions, balances, trade history and the orders your broker has already recorded, read-only. Reading an order is reading what filled and at what price; it cannot place, change or cancel one. The history and the orders are used to work out your cycles and are not stored. The list of calls Restrike is permitted to make contains no trading endpoint, and that list is checked by an automated test on every build rather than by memory.
On a Pro account, including a trial, the tracker reads that connection on its own when you open it and your broker's daily sync has run since the last read, so the table stays current without a press. On the free plan it is not read at all, and a connection left from a trial or a subscription is removed fourteen days after it ends. On Pro, pressing Update also asks SnapTrade to re-read your brokerage before it reads: that request names no instrument, no quantity and no price, it changes nothing in your account, and all it does is ask for a record your broker already holds to be fetched sooner. Most brokers post your trade history about a day later, which is their own schedule; where yours also reports today's orders, as Robinhood does, those trades are offered to your log the same day. Restrike is read-only and it never places a trade or moves money.
Disconnecting tells SnapTrade to forget the connection as well as removing it here, and it works whether or not you have an active subscription.
Your data is kept while your account exists. Sign-in links expire after 15 minutes and are deleted the moment they are used. Sessions expire after 30 days.
You can delete everything yourself. Sign in and tap your email address in the header, which opens Your account. It offers two things: remove your synced log and holdings while keeping the account, or delete the account outright.
Deleting the account cancels any subscription immediately, tells SnapTrade to forget you and drop every brokerage connection, and erases your log, holdings, settings and the account record. It cannot be undone. You can also disconnect a brokerage on its own at any time, whether or not you have an active subscription.
If anything goes wrong on the way out, or you would rather we did it, or you want a copy of what is held, email support@userestrike.com from the address on the account.
Restrike is not intended for anyone under 18 and we do not knowingly store data about children.
If this policy changes materially, the date at the top changes and, where it affects you, you will be told by email.
Questions: support@userestrike.com.