TRUST & DATA
Security & data
Last updated: September 16, 2026
Your platform remains the source of truth. TSPilot is designed to use the active TopstepX page and the chart already open there; it does not ask you to hand over a second set of trading credentials.
What TradeSidecar reads
The extension reads only the page state needed by an enabled feature. Depending on what you use, that includes:
- Active contract, favorite contracts and symbol selection.
- Active chart timeframe and OHLC data exported by the TradingView chart.
- Account, position and order state needed to display or perform a requested action.
- Platform metadata needed to validate the current page, chart and account context.
TSPilot reuses the state and API client already available in the supported page. It does not create a separate market-data connection, subscribe to another instrument or request additional chart history.
What TSPilot does not read or store
- Your TopstepX password or Google password.
- Your payment-card number.
- Your platform authentication token as a separately stored value or harvested credential.
- Unrelated browser history or unrelated website content.
The current extension has no AI provider connection and does not send chart, order or position data to an AI provider. AI Market Context is Coming Soon.
What leaves the browser
The current extension does not send trading-page data to the TradeSidecar website. The extension may call the product API at https://ts.zhishik.com with an opaque device session to read server-verified Free/Pro capabilities. The website sends the information needed for the features you request: email or Google account identity during sign-in, a selected plan when starting checkout, and subscription status needed to show account access. Creem receives payment and subscription information through its hosted checkout and billing services.
Local storage
Chrome extension storage holds preferences such as panel position, module folds, quantities, drawing-hotkey mappings, indicator configuration and automatic-assistance configuration. These settings are not account credentials. Preference backup files are created only when you choose to export them and exclude credentials, orders, positions and automatic-run state.
Chrome permissions
| Permission | Why it is needed |
|---|---|
storage | Save local panel, quantity, indicator, automation and drawing-hotkey preferences. |
scripting | Run the extension's chart and page bridge in the supported TopstepX document so it can reuse the page's existing state and API client. |
alarms | Keep product entitlement refresh and the background page lifecycle reliable without creating a market-data or account connection. |
https://topstepx.com/* | Limit the extension to the supported TopstepX pages. It does not request a general web host permission. |
https://ts.zhishik.com/* | Pair the extension with a signed-in TradeSidecar account and read server-verified capabilities; it never receives payment or OAuth secrets. |
The manifest does not request a separate account WebSocket, market-data permission or payment permission. Permissions may change only with a documented product need and an updated disclosure.
Execution and user control
Manual order and position actions are initiated by you from the panel. Optional automation assistance is off by default and requires an explicit configuration and start action. It can pause when the active page, chart, account or connection changes. Always review the supported platform before an action.
Billing and account security
Google sign-in uses a server-side OAuth flow and an HttpOnly, Secure HTTPS session cookie with SameSite=Lax. Creem hosts payment collection as Merchant of Record; card data does not pass through TradeSidecar. Pro access is granted from server-verified subscription state, not from browser local storage or a URL flag.
Future AI disclosure
Before AI Market Context is enabled, we will state which chart or account fields are sent, which provider receives them, whether they are used for training, how long they are retained and what opt-out controls are available. No AI request is active in the current build.
Questions and reports
Report a security or privacy concern to support@tradesidecar.com. Do not include passwords, authentication tokens, card numbers or unnecessary account details.