Security and trust

Built for private trading review, not trade execution.

JournalFlow is designed to help traders import, journal, analyze, and review their process without giving the product permission to place trades or move funds.

Account protection

JournalFlow accounts use authenticated sessions so the workspace, settings, imports, and journal records stay tied to the correct user.

Workspace data separation

Trades, screenshots, accounts, daily logs, reviews, reports, and settings are stored as user-owned workspace records rather than one shared public ledger.

Broker access safety

Supported sync routes are designed around review access: investor passwords, read-only API keys, broker exports, or prop-firm statements.

Payment handling

Paid checkout and subscription management are designed to run through Stripe, so card details are handled by the payment provider.

Broker and platform safety

Connect only what the journal needs.

Trading data is enough for review. JournalFlow should never need withdrawal access, trade execution permission, or a master trading password when a read-only route exists.

No-order product boundary

Marketing, onboarding, integrations, and in-app sync copy should all say the same thing: JournalFlow reviews trades, it does not place them.

Permission check before sync

Users are told to disable trading and withdrawal permissions on exchange API keys and to use investor access for MetaTrader.

Checkout transparency

Pricing and plan pages point users through Stripe-powered checkout and explain which features unlock on Essential, Pro, and Team.

Risk wording on every page

The footer repeats that trading carries substantial risk and that JournalFlow is journaling, analytics, replay, and review software.

Journal data

The data is there to make the review useful.

The product works best when trade history, screenshots, rules, and mistakes stay connected in one private workspace.

Journal records

Trade logs, RR, setup tags, session labels, mistakes, daily notes, reports, and review status are used to power the journal and analytics.

Screenshots and uploads

Chart evidence, broker exports, and statements are attached to the relevant workspace so reviews can stay evidence-led.

Coach context

Coach answers from the journal context available in the workspace, such as trades, rules, mistakes, screenshots, and account state.

Safe setup checklist

Simple rules before connecting a real account.

Keep account login details private and unique. Only connect read-only broker access where supported. Remove trading or withdrawal permissions from API keys before adding them. Do not upload private documents that are not needed for trade review. Contact support if an account, import, or payment looks wrong.

Does JournalFlow place trades?

No. JournalFlow is a trading journal, analytics, replay, import, and review workspace. It does not place orders or manage funds.

Do I need to provide my master trading password?

No. Where broker access is supported, use read-only or investor access. If that is not available, use CSV File Upload or statement imports.

Who handles card details?

Stripe handles checkout and card payment details when paid billing is enabled. JournalFlow should only store the subscription and account state needed to run the product.

Can Coach see my trades?

Coach is designed to answer from journal context in the workspace. That context is what makes the feedback more useful than a generic chat.

Still unsure?

Ask before you connect anything sensitive.

JournalFlow should feel clear before a trader adds broker data, screenshots, or payment details. Send the platform, account type, or concern and check the safest route first.