Privacy Policy
Effective 17 September 2026 · Version tp-260917
1. Controller and contact
Kurtosis, Inc., a Delaware C-corporation that operates TradePolaris.com and the TradePolaris service (“TradePolaris”, “we”, “us”), is the controller of the personal data described here. For a privacy request or question, email support@tradepolaris.com.
2. Data we collect
- Account and identity data: email, display name, password hash, verification state, invite and referral state, account identifiers, preferences, and the versions of legal terms you accepted.
- Product content: portfolios and holdings, strategy specifications and code, backtests, paper deployments, Vega prompts and conversations, research threads, apps, uploaded datasets, reports, watchlists, alerts, and saved settings.
- API and access data: key prefix and hash, label, scope, service-account name, expiry, source restrictions, last-used time, request metadata, budgets, and usage audit events. Raw API secrets are displayed at issuance and are not stored in recoverable form.
- Contact and access-request data: contact-form messages, company, topic, waitlist email, referral activity, and support correspondence.
- Operational data: IP address, device and browser information, authentication and security events, request timing, feature usage, diagnostics, and error traces. We minimise or scrub sensitive request content from analytics and error reporting where supported.
- Billing data: plan, subscription and invoice status, credit balance and ledger, Stripe customer references, and payment lifecycle events. Stripe processes complete card details; they do not pass through our servers.
3. Why we process it
- Contract: create and authenticate accounts; run requested research, risk, backtest, paper, API, sharing, and billing features; provide support.
- Legitimate interests: secure the Service, prevent abuse and fraud, enforce quotas, diagnose failures, understand feature reliability, and improve usability without overriding your rights.
- Legal obligations: keep required billing, tax, security, and rights-request records.
- Consent: send optional marketing or product updates where consent is required. Account, verification, billing, and security messages are service notices.
4. Portfolio, prompt, and AI processing
We use private portfolios, holdings, prompts, and uploaded content to provide the feature you request, maintain your workspace, secure the Service, and support you. We do not sell that data, use it for cross-context behavioural advertising, or use private portfolios or prompts to train our own general-purpose models.
When you use an AI or research feature, the information necessary for that request may be sent to contracted AI, search, market-data, or compute providers. We limit the data sent to what the feature needs and apply the provider and transfer safeguards available to us. Review a share link before publishing it: anyone with a valid bearer-style link may be able to read its contents until revoked.
5. Subprocessors, recipients, and transfers
These are the providers that process personal data on our behalf, what each one receives, and where it is processed. We do not send portfolio contents, holdings, or uploaded datasets to the analytics or error-reporting providers, and complete card details reach only Stripe.
| Provider | Purpose | What it receives | Processed in |
|---|---|---|---|
| Amazon Web Services | Hosting, databases, object storage, logs | All account and product data at rest and in transit | United States (us-east-1) |
| Vercel | Web application hosting and delivery | Requests to the website, IP address, request metadata | United States |
| Modal | Isolated compute for backtests and strategy code | Strategy code and the market data a run needs | United States |
| Stripe | Payments, subscriptions, invoices | Billing email, payment and card details, invoice history | United States |
| Resend | Transactional email (verification, password reset, notices) | Email address and the message content | United States |
| Cloudflare | Turnstile abuse prevention on signup | IP address and a challenge token | United States |
| WorkOS | Authorisation for assistant (MCP) connections | Account identifier and the connection's grant state | United States |
| PostHog | Product analytics on the public pages and in the app | Feature-usage events and, once you sign in, an internal account identifier. No portfolio contents, no prompts, no tokens | European Union (EU cloud) |
| Sentry | Error and performance diagnostics | Scrubbed stack traces and request metadata. No portfolio contents, no prompts | United States |
| Anthropic | AI model provider for research features | The prompt and the context a request needs | United States |
| OpenRouter | Routes requests to additional AI model providers | The prompt and the context a request needs | United States |
| Google Sign-In, when you choose it | The sign-in token exchange for your Google account | United States | |
| Polygon.io | Market, reference, and fundamental data | Data requests only. No account identity, no portfolio contents, no prompts | United States |
| Massive | Delayed intraday market-data stream | Data requests only. No account identity, no portfolio contents, no prompts | United States |
The list is current as of the effective date above. We update it here when a provider is added or replaced, and a material change is published as a new version of this policy.
We may also disclose data to professional advisers, authorities where legally required, or a successor in a merger, financing, or asset transfer subject to appropriate confidentiality. Some recipients operate outside your country. Where required, we rely on adequacy decisions, standard contractual clauses, the UK Addendum, or another lawful transfer mechanism.
6. Cookies and browser storage
We use necessary HttpOnly session cookies, opaque generation and revocation markers, and a browser-visible one-way account-context cookie to keep sessions signed in and prevent a stale tab from using another account’s rotated credentials. Session and local storage hold interface state such as theme, tab account context, and in-progress product state.
Product analytics runs on the public pages only after you allow it, and in the signed-in app under the Terms you accept at signup. Section 7 sets out that choice and lists every name stored. PostHog receives limited product-usage events and, once you are signed in, an internal account identifier, never raw authentication tokens, portfolio contents, or prompts. Its client is configured to keep that identifier in browser local storage rather than in a cookie, so the only cookies the Service sets are the essential ones above. We use no advertising cookies and no cross-site tracking network.
7. Your analytics choice, and what each name stores
On the public pages a notice asks you to choose before any product analytics runs. There are two answers and neither one is hidden behind a menu. “Only necessary” means no analytics code is loaded at all, and the pages work exactly the same. “Allow analytics” starts it from that moment. Until you answer, nothing analytics-related is loaded, requested, or stored.
Your answer outranks everything else. Once you have chosen “Only necessary”, we do not run product analytics in that browser, signed in or signed out, until you change it.
While you are signed in and have not answered the notice, product analytics runs under the Terms you accepted when you created the account, so the notice does not appear over the app. Signing out ends that in the same moment: the site asks our own server whether the session is still live rather than trusting a marker left in the browser, so once you are signed out the notice comes back on the public pages and nothing analytics-related runs until you answer it. The one request made before you answer goes to this site, to ask that question, and only when a previous sign-in left a marker behind.
These are the names, and nothing else is set:
- pw_access and pw_refresh: the signed-in session itself. Set only after you sign in.
- pw_auth_gen: the generation marker that stops a late response from restoring a session you already left.
- pw_auth_epoch: a one-way account marker, readable by the page, that stops a stale tab from using another account’s rotated credentials. It can outlive a sign-out by up to 30 days, which is why it is never treated as proof that you are signed in.
- pw_auth_revoked_…: short-lived markers recording that a session was revoked.
- tp-analytics-consent: your answer to the notice. It is browser local storage rather than a cookie, it holds one word, and it is never sent to us.
- ph_<project key>_posthog: PostHog’s own anonymous device and visit identifier. It appears only after you allow analytics, or while you are signed in. It is not an advertising identifier and it is not shared with any advertising network.
To change your answer, clear this site’s stored data in your browser. The notice appears again on your next visit and the choice you make then is the one that applies.
8. Retention
Account and product content is generally retained while your account is active or until you delete the relevant item. The operational records below are swept on these schedules:
- Billing webhook records: 180 days.
- Paper-trading scan runs: 90 days.
- Finished backtest runs: 365 days.
- Queued analysis and evaluation requests: 30 days.
- API and MCP per-call usage records: 400 days.
- Assistant interaction events: 7 days.
The record of which legal versions you accepted is kept for as long as the account exists, because it is the evidence of the agreement itself.
After account deletion, we delete or anonymise personal data within 30 days where practicable, subject to backups, fraud prevention, unresolved disputes, and records we must keep for tax, payment, or legal compliance. Public links are disabled as part of account deletion, but copies already downloaded by another person are outside our control.
9. Sale, sharing, and automated decisions
We do not sell personal information and do not share it for cross-context behavioural advertising. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about you. Product risk scores and strategy gates evaluate portfolios or simulations, not a person’s eligibility for employment, credit, insurance, or another legal right.
10. Your privacy rights
Depending on where you live, you may ask to access, correct, delete, or export personal data; restrict or object to processing; withdraw consent; or appeal a refused request. UK and EEA residents may complain to their local supervisory authority. California residents may request to know, correct, or delete personal information and to opt out of sale or sharing (we do neither), without discrimination.
You do not have to write to us for the two most common requests. Signed in, your account page exports your data and deletes your account, and deletion cancels any paid subscription as part of the same request.
Email support@tradepolaris.com from the account address where possible. We may verify identity and authority before acting. We aim to respond within 30 days, or the shorter or longer period required by applicable law.
11. Security
We use TLS in transit, encryption at rest on AWS, hashed passwords and API keys, scoped access controls, logged production access, and isolated strategy compute. No system is perfectly secure. Report a suspected vulnerability to security@tradepolaris.com.
12. Children
The Service is for people aged 18 and over. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data to the Service.
13. Changes
We may update this policy as the Service or law changes. We post the new effective date and version here, and when the version changes we ask you to accept the new documents the next time you sign in. Each acceptance is recorded separately, so the record of which version you agreed to, and when, is not overwritten by a later one.