Privacy Policy
Effective 27 July 2026 · Version tp-260727
1. Controller and contact
TradePolaris.com (“TradePolaris”, “we”, “us”) is the controller of the personal data described here. For a privacy request or question, email business@tradepolaris.com.
2. Data we collect
- Account and identity data — email, display name, password hash, verification state, invite and referral state, account identifiers, preferences, and the versions of legal terms you accepted.
- Product content — portfolios and holdings, strategy specifications and code, backtests, paper deployments, Vega prompts and conversations, research threads, apps, uploaded datasets, reports, watchlists, alerts, and saved settings.
- API and access data — key prefix and hash, label, scope, service-account name, expiry, source restrictions, last-used time, request metadata, budgets, and usage audit events. Raw API secrets are displayed at issuance and are not stored in recoverable form.
- Contact and beta data — contact-form messages, company, topic, waitlist email, referral activity, and support correspondence.
- Operational data — IP address, device and browser information, authentication and security events, request timing, feature usage, diagnostics, and error traces. We minimise or scrub sensitive request content from analytics and error reporting where supported.
- Billing data — plan, subscription and invoice status, credit balance and ledger, Stripe customer references, and payment lifecycle events. Stripe processes complete card details; they do not pass through our servers.
3. Why we process it
- Contract — create and authenticate accounts; run requested research, risk, backtest, paper, API, sharing, and billing features; provide support.
- Legitimate interests — secure the Service, prevent abuse and fraud, enforce quotas, diagnose failures, understand feature reliability, and improve usability without overriding your rights.
- Legal obligations — keep required billing, tax, security, and rights-request records.
- Consent — send optional marketing or product updates where consent is required. Account, verification, billing, and security messages are service notices.
4. Portfolio, prompt, and AI processing
We use private portfolios, holdings, prompts, and uploaded content to provide the feature you request, maintain your workspace, secure the Service, and support you. We do not sell that data, use it for cross-context behavioural advertising, or use private portfolios or prompts to train our own general-purpose models.
When you use an AI or research feature, the information necessary for that request may be sent to contracted AI, search, market-data, or compute providers. We limit the data sent to what the feature needs and apply the provider and transfer safeguards available to us. Review a share link before publishing it: anyone with a valid bearer-style link may be able to read its contents until revoked.
5. Processors, recipients, and transfers
Providers used to operate the Service include AWS for hosting, storage, and databases; Modal for isolated compute; Vercel for web hosting; Stripe for payments; Resend for transactional email; and Cloudflare Turnstile for abuse prevention. When enabled or used, PostHog processes product-analytics events and Sentry processes scrubbed error and performance information. AI, web-research, and market-data providers process only requests that require their services.
We may also disclose data to professional advisers, authorities where legally required, or a successor in a merger, financing, or asset transfer subject to appropriate confidentiality. Some recipients operate outside your country. Where required, we rely on adequacy decisions, standard contractual clauses, the UK Addendum, or another lawful transfer mechanism.
6. Cookies and browser storage
We use necessary HttpOnly session cookies, opaque generation and revocation markers, and a browser-visible one-way account-context cookie to keep sessions signed in and prevent a stale tab from using another account’s rotated credentials. Session and local storage hold interface state such as theme, tab account context, and in-progress product state.
When PostHog is enabled, it receives limited product-usage events and an internal account identifier after sign-in; it does not receive raw authentication tokens. We do not use third-party advertising cookies.
7. Retention
Account and product content is generally retained while your account is active or until you delete the relevant item. Security, usage, and diagnostic records use rolling retention windows appropriate to their purpose, commonly 90–365 days; billing webhook records may be kept for up to 180 days. API usage and lifecycle records are retained as needed for security, budgets, and auditability.
After account deletion, we delete or anonymise personal data within 30 days where practicable, subject to backups, fraud prevention, unresolved disputes, and records we must keep for tax, payment, or legal compliance. Public links are disabled as part of account deletion, but copies already downloaded by another person are outside our control.
8. Sale, sharing, and automated decisions
We do not sell personal information and do not share it for cross-context behavioural advertising. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about you. Product risk scores and strategy gates evaluate portfolios or simulations, not a person’s eligibility for employment, credit, insurance, or another legal right.
9. Your privacy rights
Depending on where you live, you may ask to access, correct, delete, or export personal data; restrict or object to processing; withdraw consent; or appeal a refused request. UK and EEA residents may complain to their local supervisory authority. California residents may request to know, correct, or delete personal information and to opt out of sale or sharing (we do neither), without discrimination.
Email business@tradepolaris.com from the account address where possible. We may verify identity and authority before acting. We aim to respond within 30 days, or the shorter or longer period required by applicable law.
10. Security
We use TLS in transit, encryption at rest on AWS, hashed passwords and API keys, scoped access controls, logged production access, and isolated strategy compute. No system is perfectly secure. Report a suspected vulnerability to business@tradepolaris.com.
11. Children
The Service is for people aged 18 and over. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data to the Service.
12. Changes
We may update this policy as the Service or law changes. We will post the new effective date and version here and notify registered users of material changes by email or an in-product notice before they take effect where required.