Privacy Policy
Effective 30 September 2026 · FIBORB LLC
Lockout Sync is operated by FIBORB LLC, an Illinois limited liability company. This policy
explains what we collect, why, how long we keep it, and what you can ask us to do with it.
It covers the Lockout Sync mobile application, the masterlockoutsync.com and
api.masterlockoutsync.com websites, and the NinjaTrader add-ons sold on masterlockoutsync.com
(Lockout Sync for NinjaTrader and Emergency Flatten ALL).
1. Information you give us
- Account details — your email address and a password, or a Google,
Facebook or X sign-in (section 5). Passwords are never stored; only a salted scrypt hash is
kept, which cannot be reversed into your password.
- Your name and country — collected when you create an account. Your name is
used to address you in the app and in email; your country is recorded to meet our legal and
tax obligations and to know which markets we serve.
- Optional details — which prop firm or broker you use, how you heard about
us, and whether you want marketing email. All three are optional, none affects the service,
and marketing consent is recorded separately from your acceptance of the Terms so that
agreeing to the Terms never signs you up for email.
- Brokerage credentials — if you choose to add a connection, the username and
password for that brokerage account, and the details the platform needs to route the sign-in
(for Rithmic, the system and gateway; for CTS T4, the T4 firm named in your T4 login email).
These are encrypted at rest with AES-256-GCM and are
used for one purpose only: signing in to that brokerage on your behalf so the app can read
your accounts and act when you instruct it to.
- Support messages — anything you send us through the support form or by email.
With a message sent through the form we also record your name, email address and IP address,
and, if you are signed in, your account reference, plan and app version. The message is stored
on our server and also emailed to our support mailbox. Email you send to
support@masterlockoutsync.com reaches the same mailbox through Cloudflare's email
forwarding.
- NinjaTrader add-on purchases — if you buy Lockout Sync for NinjaTrader,
Stripe's checkout page collects your email address, your name and billing address, your
payment card details, and the email address of your NinjaTrader account, which you type in
yourself and which can differ from the address you pay with. We use the NinjaTrader account
email for one purpose: to have NinjaTrader create your licence for that account (section 5).
We use your email address to send you your order and licence emails. For the Monthly plan,
Stripe also creates a customer record for you; for a Lifetime purchase, it does so only when
it needs one. Our server keeps no copy of these details. Stripe holds the order, and our
server keeps only one-way hashes of Stripe's order and event references, so that no order
is handled twice. We also receive an email about each order with your name, your checkout
email address and the NinjaTrader account email, which we keep as our record of the order
(section 7).
- Referral programme — if you enter someone's referral code, we record the
code, your account, your email address, the IP address and device identifier you used, the
date, and whether a reward was paid. If you share your own code, we record the code as yours
and the rewards it has earned. We use these only to run the programme: to pay rewards, to
stop a code being used on your own account or twice on one device, and to apply the programme's rules. The
person whose code you used sees only how many people used it and subscribed, never who.
2. Information collected automatically
- Device identifier — a random identifier generated by the app. It is not your
advertising ID, hardware serial, or any identifier that follows you across other apps.
- IP address and timestamps — recorded at sign-up, at sign-in, when you
accept our Terms of Use, when you send a support message and when you enter a referral code.
This is kept as a record of consent, to answer your message, and to detect abuse.
- App version and diagnostic information — to reproduce faults you report.
- Brokerage account data — balances, positions, orders and drawdown figures,
retrieved from your brokerage while the app is running so it can display them and act on them.
One row per account per trading day — that day's P&L, its closing balance and the day's trades
(time, contract, side, quantity and price) — is kept, encrypted, for your journal, and deleted
with your account.
- Your journal notes — whatever you choose to type against a trading day
or week, in your own words. Stored encrypted with the rest of your journal, editable and
erasable from the app at any time, and deleted with your account. It is never analysed, never
used in any decision about your account, and never shared. A journal backup you export is a
file saved on your own device; we do not receive a copy of it.
- Push notification token — if you allow notifications, a token from
Google Firebase Cloud Messaging for that installation of the app, used only to send you
alerts (a connection that signed out, a broker that stopped answering, a daily loss limit
reached, a lockout that fired). Removed when you sign out on that device, and deleted with
your account.
- Add-on update check — when a NinjaTrader add-on starts, it asks our server
whether a newer version exists. The request carries only the product name and version; like
any web request, it also reaches us from your IP address.
- Server access logs — our servers may keep short-term access logs (IP
address, request path and time) for security and troubleshooting, for a limited period
(section 7).
3. What we do not do
We do not sell your personal information. We have never done so and have no
plans to. We do not share it with data brokers, advertisers or analytics networks.
We do not use your trading data for any purpose other than operating the app for you.
Your balances, positions and activity are not aggregated, analysed for our benefit, used to inform
anyone else's trading, or sold in any form, anonymised or otherwise.
We do not place trades. The app can only close positions and cancel orders. It
cannot open a position or enter an order.
We do not run advertising or third-party trackers. There is no analytics SDK
and no tracking pixel in the application. Meta's Facebook sign-in SDK is in the app only
so that you can sign in with Facebook: the app starts it only when you tap that button, its automatic event logging and
advertising-identifier collection are switched off, and the app requests no
advertising-identifier permission.
4. Payment information
Payments are processed by Stripe.
We never see, receive or store your card number, expiry date or card verification code
(CVC): card details are entered on Stripe's own hosted page and go directly to Stripe.
On Stripe's checkout page for an app plan you enter your card details, your email address, any
details your card requires (such as postcode or country) and, if you have one, a promotion code.
What a NinjaTrader add-on checkout collects is set out in section 1. No checkout asks for your
phone number. Stripe may send you receipts and billing emails on our behalf.
What we send to Stripe: your email address, our reference for your account, and the plan you chose.
What we receive from Stripe and keep:
- a customer identifier, stored with your account;
- your subscription's status, plan, trial end and renewal date, whether it is set to end, and
notice of a failed payment with the link to pay it;
- Stripe's fingerprint for the card used at checkout. This is an identifier Stripe creates for
a card, not the card number, and we keep it in the free-trial record (section 7);
- for a NinjaTrader add-on, the NinjaTrader account email, your name and your email address
from the checkout, used as described in section 1.
What we record at Stripe:
- referral credits we add to your Stripe balance;
- if you delete your account while a subscription is still paid up, a note on that
subscription holding the date of deletion, your email address and your former account
reference, so that the subscription can end when its paid time runs out and can be restored
to you if you sign up again with the same address before then (section 8).
Stripe also processes information for its own purposes, such as fraud detection, under its own
privacy policy.
5. Service providers
We share the minimum necessary with a small number of providers who act on our behalf:
- Stripe — payment processing and subscription billing, for the app's plans
and the NinjaTrader add-ons (section 4).
- NinjaTrader — only if you buy a NinjaTrader add-on. To create your licence
we send NinjaTrader, through its vendor licensing service, the NinjaTrader account email you
typed at checkout and the date the licence ends (none, for a lifetime licence). Nothing else
about you is sent. NinjaTrader then holds that licence record, and its own privacy policy
governs what it does with it. NinjaTrader is operated by NinjaTrader, LLC.
- Resend — sending account, security and support email.
- DigitalOcean — hosting the servers on which the service runs.
- Cloudflare — DNS and email forwarding for our domain.
- Google (Firebase Cloud Messaging) — delivering push notifications to
the app, if you allow them. It receives the alert (which names the connection) and your
installation’s token, and nothing else.
- Google — only if you choose to sign in with Google. In that case we
receive your email address, name and a Google account identifier, and we store that
identifier so we can recognise you next time. We do not receive your Google password and
have no other access to your Google account.
- X — only if you choose to sign in with X. In that case we receive your X
account identifier, name and username. We also ask X for the email address confirmed on your
X account, and receive it where X provides it. We store the identifier and name so we can
recognise you next time; we do not keep your username. The email address from X is only
offered back to you, filled in, to confirm with a code, and it is not used for your account
until you do. If you choose to link X to an existing Lockout Sync account, it is used to find
that account, and you then enter that account's password. We do not receive your X password,
we ask X to cancel our access as soon as you are signed in, and we have no other access to
your X account.
- Facebook (Meta) — only if you choose to sign in with Facebook. In that
case we receive your Facebook account identifier and name and, if you allow it, the email
address on your Facebook account, and we store the identifier and name so we can recognise
you next time. That email address is only offered back to you to confirm with a code, and it
is not used for your account until you do. If you choose to link Facebook to an existing
Lockout Sync account, it is used to find that account, and you then enter that account's
password. We do not receive your Facebook password and have no other access
to your Facebook account.
- Healthchecks.io and Pushover — monitoring the service and alerting us when
it, or a connection, is not working. Our server sends Healthchecks.io a regular heartbeat,
and we may also use Pushover to alert us about the service's status. A problem report may
carry a connection's name and any error message from the broker; never credentials,
positions, or your contact details.
We also connect to your brokerage's platform (Tradovate, Rithmic or CTS T4) on your instruction.
What that brokerage or platform does with your data is governed by their own privacy policy, not
this one.
6. Legal disclosure
We may disclose information where we are required to by law, valid legal process, or where it is
necessary to protect our rights, safety, or the safety of others.
7. How long we keep things
- Account and brokerage credentials — until you delete the connection or
your account, or 30 days after a paid subscription ends, then removed.
- Terms acceptance records — retained after account deletion, for as long as
we may need them to defend a legal claim. Each record holds which version and text you
accepted, when, your email address and account reference, and the IP address, device
identifier, app version and app or browser identifier at that moment. These are our record
that you agreed to specific terms at a specific time.
- Free trial record — when you complete a checkout for a plan, we record
a one-way hash of your email address and Stripe's fingerprint for the card you used, with the
date. Older records may also hold one-way hashes of the IP address and device identifier used.
These are retained permanently, including after your account is deleted, so that one free
trial per person can be enforced. A hash cannot be turned back into your email address, IP
address or device identifier, and the fingerprint is not your card number; but the same
address or card used again will match, which is what the record is for.
- Referral records — while your account exists, for as long as the referral
programme runs. When you delete your account, your code stops working and your account is
unlinked from every referral record. If you had entered someone's code, your email address
and IP address are deleted from that record and your device identifier is replaced with a
one-way hash, which is kept permanently so that a code cannot be used again on the same
device. What remains (which code was used, when, and whether a reward was paid) is kept as
the record of the credit given.
- Support messages — on our server, until you delete your account, when they
are deleted with it. A message sent without an account is kept for as long as needed to
handle it and for our records. Copies in our support mailbox are kept for as long as needed
to handle your request and for our records, and are deleted with your account if you ask us
to.
- NinjaTrader add-on orders — Stripe holds the order (including the
NinjaTrader account email you typed) as our record of the sale, and keeps payment records
under its own privacy policy and legal obligations. NinjaTrader holds your licence record
(the NinjaTrader account email and its end date) under its own privacy policy; we can end a
licence, but the record itself is held by NinjaTrader. Our emailed copies of the order are
kept for as long as needed for our records.
- Billing records — Stripe keeps records of payments, invoices and refunds
under its own privacy policy and legal obligations, including after your account is
deleted.
- Server access logs — kept for a limited period, for security and
troubleshooting.
8. Deleting your account
You can delete your account and its data at any time, by any of these routes:
- In the app — Manage → Account & Plan → Delete
account. You confirm with your password or, if you sign in with Google, Facebook or
X, by signing in with that provider again. Takes effect immediately.
- On the web, signed in — masterlockoutsync.com/delete-account.
Sign in there and it is deleted immediately.
- On the web, by emailed link — enter the account's email address at
api.masterlockoutsync.com/delete-account.
If an account exists for that address, we email it a link. The link works once and expires
after 60 minutes, and nothing is deleted until you open it and confirm; if you use an
authenticator app, you also enter a code from it. We keep only a one-way hash of the link,
with your account, until it is used or expires. If you did not ask for the link, ignore it:
your account stays as it is.
- By email — write to
support@masterlockoutsync.com from the
address on the account. Actioned within 30 days, and usually the same day.
Deletion removes:
- your account, your name, your email address and country;
- every broker connection and the credentials stored for it;
- your journal and its notes;
- all sessions on every device;
- your two-factor settings and recovery codes;
- your push notification tokens;
- your language choice;
- the support messages held on our server.
Your referral code stops working, any unused referral credit ends, and your email address, IP
address and account are removed from referral records. Section 7 sets out what remains, what we
keep afterwards, and why.
If you pay for a plan, deletion stops your subscription from renewing, and the time you have
already paid for runs to the end of its period. Until then, Stripe holds a note on the
subscription with the deletion date, your email address and your former account reference. If
you sign up again with the same verified address before the period ends, the subscription is
restored to you, but your deleted data is not. When the period ends, or at once if nothing is
paid up, the Stripe customer and the card on file are deleted. A subscription whose payment was
failing is cancelled at once. If Stripe cannot be reached at the moment you delete, nothing is
deleted and you are asked to try again, so that billing is never left running without an
account.
Deleting your Lockout Sync account does not close any open positions and does not affect your
accounts at your prop firm or broker. Those remain entirely yours.
NinjaTrader add-on buyers have no Lockout Sync account to delete. To have your details removed,
email support@masterlockoutsync.com from the
address you paid with. We will end your licence if you ask, delete any Stripe customer record
for you where no subscription is running, and delete our emailed copies of the order. Stripe
keeps payment records under its own privacy policy and legal obligations, and NinjaTrader holds
its licence record under its own privacy policy.
9. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your
personal information, and to withdraw consent to marketing communications. To exercise any of
these, email support@masterlockoutsync.com.
We will respond within 30 days.
You can unsubscribe from marketing email at any time using the link in any such message. Service
and security email — billing notices, password resets, outage warnings — cannot be switched off
while your account is active, because they are necessary to operate it.
10. Security
Credentials and session tokens are encrypted at rest with AES-256-GCM. All traffic between the
app and our servers is encrypted in transit with TLS. Passwords are hashed with scrypt using a
unique salt per account. Two-factor authentication is available and we encourage it.
Who can see your records. The owner of FIBORB LLC can see, through restricted
maintenance tools:
- account records (email, name, country, plan, sign-up date, IP address and device identifier,
how you heard about us, marketing choice, last sign-in);
- support messages;
- free-trial and Terms-acceptance records;
- the health of each connection (its name, whether it is signed in, and any error message
from the broker).
No tool shows a stored credential, your positions or your orders.
No system is perfectly secure. You are responsible for your device, your account password, and
for keeping both out of other people's hands.
11. Children
Lockout Sync is not intended for anyone under 18, and we do not knowingly collect information
from children. If you believe a child has provided us with information, contact us and we will
delete it.
12. International users
Our servers are located in the United States. If you use the service from elsewhere, your
information will be transferred to and processed in the United States.
13. Changes
We may update this policy. Material changes will be notified in the app or by email before they
take effect, and the date at the top of this page will change.
14. Contact
FIBORB LLC · Illinois, United States
support@masterlockoutsync.com