Draft
Privacy
What the system stores today, and the questions a real privacy policy still has to answer.
Status of this document
Draft — not reviewed, not in force
This page has not been drafted or reviewed by a qualified lawyer and is not a privacy policy. The inventory below is accurate about what the software stores; the legal parts of it are unanswered and are marked as such.
What the system stores
Taken from the database schema rather than from memory.
- Your account. Email address, name, and a hash of your password — never the password itself.
- Sessions. A hash of the session token, when it expires, and the IP address and browser the session was created from.
- Organizations. Which organizations you belong to and your role in each.
- Invitations. The address an invitation was sent to, who sent it, when it expires, and whether it was used.
- Broker connections. Which broker an account is with and the state of its connection. The credentials themselves are encrypted and are never displayed — see security.
- Your trading records. Strategies and their versions, signals, order intents, orders, executions, positions and balance snapshots.
- Audit events. Security-relevant and money-relevant actions: what happened, who did it, when, against which record, the before and after values of a settings change, and the IP address it came from. An audit entry never stores a secret value.
What this site does
- There are no third-party analytics, advertising or session-recording scripts on these pages.
- Fonts are served from this site. They are not fetched from a third-party font host as you browse, so reading these pages does not announce your visit to one.
- Signing in sets a cookie that keeps you signed in. Your light or dark theme choice is remembered in your browser and is not sent anywhere.
- If you ask for an invitation, the address you type is sent to this site for the purpose of answering you.
Questions this draft does not answer
- Which law applies, and therefore which rights you have. The operating entity and its jurisdiction are not decided.
- The lawful basis for each kind of processing.
- Retention. How long each category above is kept, and what happens to trading records after an account closes. No period has been set, and saying "no longer than necessary" would be a sentence rather than an answer.
- Processors and sub-processors. Hosting, email delivery and error reporting are all third parties. The list is not final and is not published.
- Where data is stored, and whether it crosses a border.
- How to make a request — access, correction, deletion, export — and who answers it. There is no published contact for this yet.
Last touched 12 September 2026. This document has no effect until it is replaced by a reviewed policy.