Legal
Privacy Policy
Last updated: August 21, 2026
This Privacy Policy describes how Kill $witch (“we”, “us”, “our”) collects, uses, and protects information when you use our Chrome extension and related websites (including killwitch.vercel.app and checkout pages hosted on stripe-verify-api.vercel.app).
Kill $witch is a trading risk-management tool. It helps prop firm traders enforce personal daily loss limits and session lockouts. We designed the product to minimize data collection and keep control on your device whenever possible.
1. Information we collect
- Extension settings & session data (local) — risk limits, lockout state, simulated or synced session stats, onboarding status, language preference, and Pro subscription status. Stored in Chrome local storage on your device.
- Account data (optional) — if you create a local account or sign in with Google, we store your email, display name, and authentication session locally. Passwords are hashed with PBKDF2 and never stored in plain text.
- Prop firm connection data (optional) — if you connect a supported prop firm portal, we read session telemetry needed to enforce limits (e.g. balance, drawdown, consecutive losses). This is used only to power lockouts and dashboard stats.
- Payment data — handled by Stripe. We receive subscription status, customer ID, and email from Stripe after checkout. We do not store full card numbers.
- AI readiness answers (optional) — if you use the Mental Readiness gate, your questionnaire answers may be sent to OpenAI for analysis.
2. How we use information
- Enforce your configured risk limits and platform lockouts
- Display dashboard status, alerts, and subscription access
- Verify Pro subscription status after Stripe checkout
- Power optional AI tilt/readiness features when enabled
- Improve reliability and fix bugs (no advertising profiles)
3. Chrome permissions
Kill $witch requests only the permissions needed for its core function:
- storage — save settings and session state locally
- tabs — detect supported trading platforms and show lockout overlays
- scripting — inject the lockout overlay on trading sites you use
- identity — optional Google sign-in
- offscreen — play alert sounds during tilt warnings
- host permissions — access only supported trading platforms, payment verification, Google auth, and optional AI/prop firm APIs listed in the extension manifest
4. Third-party services
- Stripe — subscription billing (Stripe Privacy)
- Google — optional OAuth sign-in (Google Privacy)
- OpenAI — optional AI analysis when enabled (OpenAI Privacy)
- Prop firm platforms — only when you explicitly connect an account
- Vercel — hosts our website and payment verification API
5. What we do not do
- We do not sell your personal data
- We do not use cross-site tracking for advertising
- We do not read unrelated browsing activity outside supported trading domains
6. Data retention & deletion
Most data stays on your device until you uninstall the extension or clear Chrome storage. You can remove local data by uninstalling Kill $witch or clearing site/extension data in Chrome settings. Subscription records in Stripe can be managed through the billing portal linked from the app.
7. Your rights
Depending on your location, you may have rights to access, correct, or delete personal data we hold. Contact us at the email below and we will respond within a reasonable time.
8. Children
Kill $witch is not intended for users under 18. We do not knowingly collect data from children.
9. Changes to this policy
We may update this page from time to time. The “Last updated” date above will change when we do. Continued use of Kill $witch after changes means you accept the updated policy.
10. Contact
Questions about this Privacy Policy or your data:
killswitchapp@gmail.com