Plain-language summary: PineBag has no user accounts, ads, analytics or tracking. Strategy source, ticker names and reports stay in your browser. The license server receives only the minimum identifiers needed to run the trial, validate a key and prevent abuse.
1. Data that stays in your browser
The following is stored only in the extension’s local storage in your Chrome profile and is never sent to PineBag:
- Pine Script source you load or type, including versions saved with reports;
- your ticker list, settings, theme and language;
- the latest 50 backtest reports, including trades and metrics;
- the status of a running backtest for each TradingView tab;
- the TradingView username or email shown in the panel footer. It remains in local tab state and is not included in reports or exports.
You can delete reports on the Reports page. Removing the extension deletes all local extension data.
2. Data sent to TradingView
To run a backtest, PineBag works inside your signed-in TradingView tab. Pine Script source is sent to TradingView’s Pine compiler, while ticker, timeframe, period and strategy settings go to TradingView over the same connection used by the chart.
PineBag does not read cookies. The TradingView session token is used only in the memory of the TradingView page to open that page’s connection. It is never stored, passed to another extension context or sent to PineBag.
3. Data sent to the PineBag license server
The extension contacts api.pinebag.com, hosted on Cloudflare, to check the free trial and license. It sends:
- a random installation identifier and a random recovery identifier stored in Chrome Sync where available;
- a SHA-256 hash of coarse, stable device characteristics; raw characteristics never leave the browser;
- the license key and activation instance after activation;
- for each run, a random run ID, ticker count, SHA-256 hash of the ticker list, run mode and SHA-256 hash of the TradingView username or email.
The strategy, report and ticker names are never sent. The server receives an IP address as part of HTTPS and stores only a keyed hash of its network prefix (/24 for IPv4, /48 for IPv6). Identifiers are stored as keyed hashes and used only for the trial, licensing, quotas and abuse prevention.
4. Payments and license keys
Subscriptions are sold by Lemon Squeezy, the merchant of record. Checkout, card details, invoices and delivery of the license key are handled by Lemon Squeezy under its own privacy policy. PineBag never sees card details. The license server asks Lemon Squeezy whether a key and subscription are active; it does not store the customer name or email returned with a key.
5. What PineBag does not do
- no advertising, analytics, telemetry or third-party trackers;
- no selling, renting or sharing of user data;
- no use of data unrelated to backtesting and licensing;
- no remote code: everything the extension runs ships inside the extension package.
6. Permissions
| Permission | Purpose |
|---|---|
| sidePanel | Keeps the main interface next to the chart during a backtest. |
| storage, unlimitedStorage | Stores settings, strategy, ticker list and full reports locally. |
| scripting | Attaches packaged PineBag scripts to an already open TradingView chart after installation or update. |
| clipboardRead | Reads an EXCHANGE:SYMBOL list only when you click Paste tickers. |
| tradingview.com | Runs the backtest in the signed-in chart tab and uses TradingView’s compiler. |
| api.pinebag.com | Checks the free trial, license and per-run authorization. |
7. Your choices
- Delete individual or all reports from the Reports page.
- Remove the extension to delete its local data.
- Deactivate a license on a device to free its seat.
- Request deletion of hashed license records through support; include the license key if you have one.
8. Contact and changes
If this policy changes, a revised version and effective date will be published here. Privacy questions and deletion requests can be sent through pinebag.com/support.