rmclub.org runs an internal trading desk console: a place to record trade decisions, keep a shared journal, and monitor MetaTrader accounts read-only. It is used by a small named group of people.
Signing in uses Sign in with Google. Google sends us an identity token from which we keep only:
We request only the standard openid, email and
profile scopes. We do not receive or ask for your Google password,
your contacts, your Drive, your calendar, or your mail. We cannot act on your
Google account in any way.
After Google, the console asks for a six-digit code from an authenticator app. We store a secret used to check those codes. It never leaves the server and cannot be used to sign in anywhere else.
HttpOnly, Secure and
SameSite=Lax.Data lives on our own hosting at Hostinger. Two third parties are involved, and only for what they do:
We disclose data to nobody else, other than where the law requires it.
The console is read-only by design and cannot place, change or close a trade. Where an account is connected through an Expert Advisor, no credential ever leaves your own terminal. Where an account is connected through MetaApi, only a broker investor (read-only) password is accepted; it is passed straight to MetaApi and is not written to this server.
Sessions: 24 hours. Journal and account data: until deleted by a desk owner. Removing someone's access ends their sessions immediately and stops any further collection about them.
You can sign out at any time, revoke this application's access from your Google account settings, or ask an owner to remove your access and delete the records associated with you. Depending on where you live you may have rights to access, correct, export or erase your personal data; ask and we will do it.
This is a workplace tool and is not directed at anyone under 18.
If this policy changes, the date at the foot of the page changes with it. Questions, or any request about your data: srjhoney39@gmail.com.