Wheel Folio
Back to sign in

Privacy Policy

Last updated July 25, 2026

Overview

Wheel Folio ("Wheel Folio," "we," "us") is a personal options-trading tracker for the wheel strategy (cash-secured puts, covered calls, and LEAPS). This policy explains what information the app collects, how it's used, who it's shared with, and how long it's kept. It's written to describe exactly what this specific app does — not generic boilerplate — and applies both to people with an account on Wheel Folio and to visitors browsing its public pages.

Wheel Folio is a tracking and analysis tool. It does not place trades, hold funds, or connect to your brokerage account. Everything in it — positions, LEAPS, screener results — is information you enter yourself.

Information we collect

Account information. Your email address and a password. Passwords are hashed with bcrypt before storage — we cannot see or recover your actual password, only verify a login attempt against the hash.

Billing information (Starter/Pro only). If you subscribe to a paid plan, your subscription status and plan tier are stored on our servers. Your actual payment details (card number, billing address) are never sent to or stored by Wheel Folio — they go directly to Stripe, our payment processor, which handles them under its own privacy policy.

Trading data you enter. Everything you log yourself: cash-secured put and covered call positions, LEAPS, strikes, premiums, contract counts, dates, fees, notes, and any screener candidates or CSV imports you save. This data is private to your account — no other user can see it.

Wheel Score / CSV Screener settings. Your scoring thresholds and criteria for the CSV Screener are stored only in your browser (localStorage), not on our servers.

Alert preferences and history. If you enable alerts, we store your thresholds (e.g. days-to-expiration, near-strike percentage) and a record of alerts that have fired for your positions.

Security and usage data. We record your IP address in two different ways depending on purpose: (1) to throttle repeated login, registration, and password-reset attempts, your IP is stored only as a one-way cryptographic hash that can't be reversed back into an address, and is automatically deleted after roughly a day; (2) for a security audit log of events like logins, failed logins, registrations, and password resets, your IP address is stored in plain (readable) form for roughly 180 days so that account activity can actually be reviewed if needed, then it's automatically deleted.

Basic traffic analytics. So we can tell how people find Wheel Folio, we count visits to our public pages (the home page, calculators, pricing, guide, and support pages) on our own server. This uses no cookies and no third-party trackers, and we do not store your IP address, your name, or any account identifier alongside these counts. For each visit we record: which page, the website you arrived from (just the site name, like “reddit.com” — never the full link, which could reveal what you searched for), and a one-way code derived from your browser and network that lets us avoid counting the same person twice in one day. That code changes every day and cannot be turned back into anything identifying, so it can't be used to follow you over time or link your visits to your account. We also record the timezone your browser reports (for example “America/New_York”), which tells us roughly what part of the world visitors are in. We use this instead of looking up your IP address, because it avoids handling your IP or sending it to any outside service — and a timezone covers millions of people, so it can't identify you. These counts are deleted after about a year.

How we use this information

  • To provide the service — storing and displaying your positions, calculating returns and breakevens, and running the Wheel Score.
  • To show live stock prices and ITM/OTM/ATM status on your open positions.
  • To send you account-related email: password reset links, and alert digest emails if you've enabled them. We don't send marketing email.
  • To secure the service — detecting and slowing down brute-force login attempts, and keeping an audit trail of security-relevant events.
  • To understand which pages people find useful and which sites send visitors here, using the cookie-free counts described above. We use this to decide what to build and where to spend effort — not to profile individuals, and never shared with anyone.

Who we share information with

We don't sell your data, and we never share your trading data (positions, LEAPS, screener imports) with anyone. The only outside parties involved are the ones required to make the app — and its advertising — function:

  • Finnhub — when you have open positions or LEAPS, we send the bare stock ticker symbols (e.g. "AAPL") to Finnhub to fetch a live price and the company's name and logo. We never send your name, email, position details, or any other personal information to Finnhub — only the ticker itself. Company logos are the one exception to that being entirely server-to-server: the logo image is loaded by your browser directly from Finnhub's image server, so that request carries your IP address and browser information to them, the same way loading any image from another site does. It does not tell them who you are or which position it belongs to.
  • MarketData.app — on the Pro plan, live options Greeks and chain browsing send the ticker, expiration, and strike (public market information — never your name, email, or account details) to MarketData.app to fetch delta, theta, and implied volatility.
  • Stripe — if you subscribe to Starter or Pro, your email and payment details are sent to Stripe to process the subscription. We never see or store your card details ourselves; Stripe handles that under its own privacy policy.
  • Google AdSense — ads served by Google AdSense appear in two places: to free-plan accounts inside the app, and to visitors on our public pages (the home page, guide, calculators, and support pages) whether or not they're signed in. AdSense may use cookies or similar identifiers on your device to select and measure ads, under Google's own privacy policy and ad settings, independent of Wheel Folio. Starter and Pro accounts are ad-free everywhere, including those public pages. Our pricing, terms, privacy, and sign-in pages carry no ads at all.
  • Google Fonts and Fontshare — the fonts used in the app are loaded from these providers' servers, which may log the request (your IP address and browser information) under their own privacy policies.
  • Our hosting provider — the app and database run on IONOS hosting, which stores and processes data on our behalf as infrastructure.

Data retention and deletion

  • Your account data (positions, legs, LEAPS, screener imports, alert settings) is kept until you delete it yourself or an administrator deletes your account.
  • Deleting an account removes all of that account's positions, legs, LEAPS, screener data, alert settings, and pending password-reset tokens, and cancels any active Starter/Pro subscription so billing doesn't continue.
  • Security audit log entries (logins, registrations, password resets, admin actions) are kept for roughly 180 days regardless of whether the related account still exists, then automatically deleted — this is intentional, so a deleted account can't be used to erase evidence of what happened on it beforehand.
  • Rate-limiting records (hashed IPs/emails used to throttle repeated attempts) are automatically deleted after roughly a day.

How we protect your data

  • Passwords are hashed with bcrypt, never stored or logged in plain text.
  • Sessions are stored server-side and identified by a cookie that's HttpOnly (invisible to page scripts), Secure (HTTPS-only), and SameSite=Lax.
  • Every account-changing request requires a matching CSRF token in addition to the session cookie.
  • Login, registration, and password-reset requests are rate-limited to slow down automated attacks.
  • Every account's data is isolated — positions, LEAPS, and screener data are scoped to your user ID and are not visible to other users.
  • The site is served over HTTPS, with security headers (including a Content-Security-Policy) applied to every response.

No system is perfectly secure, and we can't guarantee absolute security, but these are the concrete measures in place today.

Your choices and rights

  • You can edit or delete any position, LEAP, screener entry, or note directly in the app at any time.
  • You can turn off email alerts (while keeping in-app alerts) from the alert settings, accessible via the gear icon in the notifications dropdown.
  • You can request that your account and its data be deleted by contacting us at the address below.

Not financial or tax advice

Wheel Folio's calculators, Wheel Score, and screener are informational tools based on the data you provide and, where noted, live stock prices — they are not personalized investment, financial, or tax advice, and nothing in the app should be relied on as such. LEAPS estimates in particular use intrinsic value only (no live options-chain data), which understates what a contract could actually be sold for before expiration.

Children's privacy

Wheel Folio is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect information from children.

Changes to this policy

If this policy changes in a meaningful way, we'll update the date at the top of this page. Continued use of Wheel Folio after a change means you accept the updated policy.

Contact

Questions about this policy, or requests about your data (including account deletion), can be sent to hello@wheelfolio.com.