TRUST & DATA

Security & data

What TradeSidecar reads

The extension reads only the page state needed by an enabled feature. Depending on what you use, that includes:

TSPilot reuses the state and API client already available in the supported page. It does not create a separate market-data connection, subscribe to another instrument or request additional chart history.

What TSPilot does not read or store

The current extension has no AI provider connection and does not send chart, order or position data to an AI provider. AI Market Context is Coming Soon.

What leaves the browser

The current extension does not send trading-page data to the TradeSidecar website. The extension may call the product API at https://ts.zhishik.com with an opaque device session to read server-verified Free/Pro capabilities. The website sends the information needed for the features you request: email or Google account identity during sign-in, a selected plan when starting checkout, and subscription status needed to show account access. Creem receives payment and subscription information through its hosted checkout and billing services.

Local storage

Chrome extension storage holds preferences such as panel position, module folds, quantities, drawing-hotkey mappings, indicator configuration and automatic-assistance configuration. These settings are not account credentials. Preference backup files are created only when you choose to export them and exclude credentials, orders, positions and automatic-run state.

Chrome permissions

The manifest does not request a separate account WebSocket, market-data permission or payment permission. Permissions may change only with a documented product need and an updated disclosure.

Execution and user control

Manual order and position actions are initiated by you from the panel. Optional automation assistance is off by default and requires an explicit configuration and start action. It can pause when the active page, chart, account or connection changes. Always review the supported platform before an action.

Billing and account security

Google sign-in uses a server-side OAuth flow and an HttpOnly, Secure HTTPS session cookie with SameSite=Lax. Creem hosts payment collection as Merchant of Record; card data does not pass through TradeSidecar. Pro access is granted from server-verified subscription state, not from browser local storage or a URL flag.

Future AI disclosure

Before AI Market Context is enabled, we will state which chart or account fields are sent, which provider receives them, whether they are used for training, how long they are retained and what opt-out controls are available. No AI request is active in the current build.

Questions and reports

Report a security or privacy concern to support@tradesidecar.com. Do not include passwords, authentication tokens, card numbers or unnecessary account details.