Privacy

Privacy Policy

Last updated: July 12, 2026 · applies to the Quant Terminal website, app and waitlist · operated by Quant Terminal LLC (Wyoming, USA)
TL;DR — the whole policy in four lines We collect the minimum to run the product: your email (waitlist / Google sign-in), your app data (paper trades, settings, watchlist), and a session cookie. We run no ads, no third-party analytics, and no trackers, and we never sell your personal data. It's disclosed only to the infrastructure providers that run the product (Google sign-in, Cloudflare delivery, Resend email — as service providers on our behalf). Market-data requests go through our own server, so data providers never see who you are. Want your data gone? One email and it's deleted.

01What we collect, and why

DataWhenWhy
Email addressYou join the waitlistTo contact you about early access and launch. Nothing else.
Google profile basics (ID, email, name, profile photo)You sign in with GoogleTo create your account. We request only the basic profile scopes — we can't see your contacts, Drive, or anything else.
Your app data (simulated paper trades, risk settings, watchlist)You use the app while signed inSo your workspace syncs across devices. Signed out, it stays only in your browser's local storage.
Session cookie (qt_session)You sign inKeeps you signed in. Essential, first-party, HttpOnly. We set no other cookies.
IP address (transient)Any requestUsed in memory for rate-limiting and abuse prevention. Not written to our database or tied to your profile.

02What we deliberately don't do

  • No third-party analytics. No Google Analytics, no Meta pixel, no fingerprinting, no tracking scripts of any kind. The only usage measurement is first-party and cookie-free: our own server keeps an aggregate daily counter per page (e.g. "/blog was served 12 times today") with no IP address, no device info, and no identity attached — it can't see who you are, only that a page was served.
  • No advertising and no ad networks.
  • No selling, renting, or "sharing" of personal data — to anyone, for anything, including the definitions of "sale"/"sharing" used by the CCPA/CPRA. (Disclosures to the service providers that operate the product on our instructions — listed in §03 — are not sales or sharing under those definitions.)
  • No exchange API keys, no wallets, no funds. The product has no way to receive them.
  • No payment data yet. If paid plans launch, payments will be processed by a payment provider (e.g. Stripe); card numbers will never touch our servers, and this policy will be updated.

03Market data & third parties

The app displays market data from providers (e.g. CoinGecko, Binance public endpoints, CoinMetrics community, Deribit, alternative.me, news RSS feeds). These requests are made by our server, not your browser — providers see our server asking for public market data; they do not receive your identity, IP, or account information from us.

The exceptions that do interact with your browser directly: Google (when you choose to sign in — governed by Google's own privacy policy) and your Google profile photo, which your browser fetches from Google's servers when shown.

The Service is delivered through Cloudflare, a content-delivery and security network that sits in front of our server. To route traffic, defend against attacks, and apply rate limits, Cloudflare processes basic connection data (including your IP address and request metadata) as a service provider on our behalf. This is used for delivery and security only — not advertising or cross-site tracking. See Cloudflare's privacy policy for details.

Transactional email (welcome and waitlist messages) is delivered through Resend, an email service provider that processes your email address on our behalf solely to send those messages. Resend does not use your address for its own purposes. See Resend's privacy policy for details.

04Where your data lives & how long

  • Account and app data are stored in our database and kept while your account is active. Data may be processed or stored in the United States or other countries where our infrastructure providers operate.
  • Deleted data may remain in routine, access-restricted backups for a period after deletion before those backups are rotated out and it is permanently removed.
  • Waitlist emails are kept until launch outreach is complete. If you unsubscribe we stop all emails immediately and keep only a minimal suppression entry (so we can never email you again); email us for full deletion of your address.
  • Sessions expire automatically after 30 days, or immediately when you sign out.
  • The public contains no user data — only the engine's own timestamped signal history.

05Your rights (GDPR / CCPA and common sense)

  • Access / export: ask and we'll send you everything we hold about you.
  • Deletion: ask and we'll delete your profile, app data and waitlist entry. Signing out deletes the live session immediately.
  • Correction / objection / portability: same — email us, we'll do it. No forms, no dark patterns.
  • We don't discriminate against users who exercise privacy rights, and we don't require an account to use the core terminal.

06Security

Secrets and API keys are stored server-side only and never sent to browsers. Sessions use HttpOnly cookies. Endpoints are rate-limited. The public track record is append-only and its writer is locked. No system is perfectly secure — if we ever learn of a breach affecting your data, we will provide any legally required notifications in accordance with applicable law.

Legal disclosures: we may disclose information if required by law, court order, or other legal process, or where reasonably necessary to protect the rights, property, or safety of Quant Terminal, our users, or others.

07Children

The service is for users 18+ (see Terms). We do not knowingly collect data from minors; if you believe a minor has provided data, contact us and we'll delete it.

08Changes & contact

If this policy changes, the date above changes and material changes will be noted on this page. Questions, data requests, abuse reports, or takedown notices: email [email protected] or reply to any email from us. We aim to answer privacy requests within 30 days.