TRADEPOLARIS
PricingLog in
Sign Up Now
Sign Up Now
TradePolaris

Privacy Policy

Effective 17 September 2026 · Version tp-260917

1. Controller and contact

Kurtosis, Inc., a Delaware C-corporation that operates TradePolaris.com and the TradePolaris service (“TradePolaris”, “we”, “us”), is the controller of the personal data described here. For a privacy request or question, email support@tradepolaris.com.

2. Data we collect

  • Account and identity data: email, display name, password hash, verification state, invite and referral state, account identifiers, preferences, and the versions of legal terms you accepted.
  • Product content: portfolios and holdings, strategy specifications and code, backtests, paper deployments, Vega prompts and conversations, research threads, apps, uploaded datasets, reports, watchlists, alerts, and saved settings.
  • API and access data: key prefix and hash, label, scope, service-account name, expiry, source restrictions, last-used time, request metadata, budgets, and usage audit events. Raw API secrets are displayed at issuance and are not stored in recoverable form.
  • Contact and access-request data: contact-form messages, company, topic, waitlist email, referral activity, and support correspondence.
  • Operational data: IP address, device and browser information, authentication and security events, request timing, feature usage, diagnostics, and error traces. We minimise or scrub sensitive request content from analytics and error reporting where supported.
  • Billing data: plan, subscription and invoice status, credit balance and ledger, Stripe customer references, and payment lifecycle events. Stripe processes complete card details; they do not pass through our servers.

3. Why we process it

  • Contract: create and authenticate accounts; run requested research, risk, backtest, paper, API, sharing, and billing features; provide support.
  • Legitimate interests: secure the Service, prevent abuse and fraud, enforce quotas, diagnose failures, understand feature reliability, and improve usability without overriding your rights.
  • Legal obligations: keep required billing, tax, security, and rights-request records.
  • Consent: send optional marketing or product updates where consent is required. Account, verification, billing, and security messages are service notices.

4. Portfolio, prompt, and AI processing

We use private portfolios, holdings, prompts, and uploaded content to provide the feature you request, maintain your workspace, secure the Service, and support you. We do not sell that data, use it for cross-context behavioural advertising, or use private portfolios or prompts to train our own general-purpose models.

When you use an AI or research feature, the information necessary for that request may be sent to contracted AI, search, market-data, or compute providers. We limit the data sent to what the feature needs and apply the provider and transfer safeguards available to us. Review a share link before publishing it: anyone with a valid bearer-style link may be able to read its contents until revoked.

5. Subprocessors, recipients, and transfers

These are the providers that process personal data on our behalf, what each one receives, and where it is processed. We do not send portfolio contents, holdings, or uploaded datasets to the analytics or error-reporting providers, and complete card details reach only Stripe.

ProviderPurposeWhat it receivesProcessed in
Amazon Web ServicesHosting, databases, object storage, logsAll account and product data at rest and in transitUnited States (us-east-1)
VercelWeb application hosting and deliveryRequests to the website, IP address, request metadataUnited States
ModalIsolated compute for backtests and strategy codeStrategy code and the market data a run needsUnited States
StripePayments, subscriptions, invoicesBilling email, payment and card details, invoice historyUnited States
ResendTransactional email (verification, password reset, notices)Email address and the message contentUnited States
CloudflareTurnstile abuse prevention on signupIP address and a challenge tokenUnited States
WorkOSAuthorisation for assistant (MCP) connectionsAccount identifier and the connection's grant stateUnited States
PostHogProduct analytics on the public pages and in the appFeature-usage events and, once you sign in, an internal account identifier. No portfolio contents, no prompts, no tokensEuropean Union (EU cloud)
SentryError and performance diagnosticsScrubbed stack traces and request metadata. No portfolio contents, no promptsUnited States
AnthropicAI model provider for research featuresThe prompt and the context a request needsUnited States
OpenRouterRoutes requests to additional AI model providersThe prompt and the context a request needsUnited States
GoogleGoogle Sign-In, when you choose itThe sign-in token exchange for your Google accountUnited States
Polygon.ioMarket, reference, and fundamental dataData requests only. No account identity, no portfolio contents, no promptsUnited States
MassiveDelayed intraday market-data streamData requests only. No account identity, no portfolio contents, no promptsUnited States

The list is current as of the effective date above. We update it here when a provider is added or replaced, and a material change is published as a new version of this policy.

We may also disclose data to professional advisers, authorities where legally required, or a successor in a merger, financing, or asset transfer subject to appropriate confidentiality. Some recipients operate outside your country. Where required, we rely on adequacy decisions, standard contractual clauses, the UK Addendum, or another lawful transfer mechanism.

6. Cookies and browser storage

We use necessary HttpOnly session cookies, opaque generation and revocation markers, and a browser-visible one-way account-context cookie to keep sessions signed in and prevent a stale tab from using another account’s rotated credentials. Session and local storage hold interface state such as theme, tab account context, and in-progress product state.

Product analytics runs on the public pages only after you allow it, and in the signed-in app under the Terms you accept at signup. Section 7 sets out that choice and lists every name stored. PostHog receives limited product-usage events and, once you are signed in, an internal account identifier, never raw authentication tokens, portfolio contents, or prompts. Its client is configured to keep that identifier in browser local storage rather than in a cookie, so the only cookies the Service sets are the essential ones above. We use no advertising cookies and no cross-site tracking network.

7. Your analytics choice, and what each name stores

On the public pages a notice asks you to choose before any product analytics runs. There are two answers and neither one is hidden behind a menu. “Only necessary” means no analytics code is loaded at all, and the pages work exactly the same. “Allow analytics” starts it from that moment. Until you answer, nothing analytics-related is loaded, requested, or stored.

Your answer outranks everything else. Once you have chosen “Only necessary”, we do not run product analytics in that browser, signed in or signed out, until you change it.

While you are signed in and have not answered the notice, product analytics runs under the Terms you accepted when you created the account, so the notice does not appear over the app. Signing out ends that in the same moment: the site asks our own server whether the session is still live rather than trusting a marker left in the browser, so once you are signed out the notice comes back on the public pages and nothing analytics-related runs until you answer it. The one request made before you answer goes to this site, to ask that question, and only when a previous sign-in left a marker behind.

These are the names, and nothing else is set:

  • pw_access and pw_refresh: the signed-in session itself. Set only after you sign in.
  • pw_auth_gen: the generation marker that stops a late response from restoring a session you already left.
  • pw_auth_epoch: a one-way account marker, readable by the page, that stops a stale tab from using another account’s rotated credentials. It can outlive a sign-out by up to 30 days, which is why it is never treated as proof that you are signed in.
  • pw_auth_revoked_…: short-lived markers recording that a session was revoked.
  • tp-analytics-consent: your answer to the notice. It is browser local storage rather than a cookie, it holds one word, and it is never sent to us.
  • ph_<project key>_posthog: PostHog’s own anonymous device and visit identifier. It appears only after you allow analytics, or while you are signed in. It is not an advertising identifier and it is not shared with any advertising network.

To change your answer, clear this site’s stored data in your browser. The notice appears again on your next visit and the choice you make then is the one that applies.

8. Retention

Account and product content is generally retained while your account is active or until you delete the relevant item. The operational records below are swept on these schedules:

  • Billing webhook records: 180 days.
  • Paper-trading scan runs: 90 days.
  • Finished backtest runs: 365 days.
  • Queued analysis and evaluation requests: 30 days.
  • API and MCP per-call usage records: 400 days.
  • Assistant interaction events: 7 days.

The record of which legal versions you accepted is kept for as long as the account exists, because it is the evidence of the agreement itself.

After account deletion, we delete or anonymise personal data within 30 days where practicable, subject to backups, fraud prevention, unresolved disputes, and records we must keep for tax, payment, or legal compliance. Public links are disabled as part of account deletion, but copies already downloaded by another person are outside our control.

9. Sale, sharing, and automated decisions

We do not sell personal information and do not share it for cross-context behavioural advertising. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about you. Product risk scores and strategy gates evaluate portfolios or simulations, not a person’s eligibility for employment, credit, insurance, or another legal right.

10. Your privacy rights

Depending on where you live, you may ask to access, correct, delete, or export personal data; restrict or object to processing; withdraw consent; or appeal a refused request. UK and EEA residents may complain to their local supervisory authority. California residents may request to know, correct, or delete personal information and to opt out of sale or sharing (we do neither), without discrimination.

You do not have to write to us for the two most common requests. Signed in, your account page exports your data and deletes your account, and deletion cancels any paid subscription as part of the same request.

Email support@tradepolaris.com from the account address where possible. We may verify identity and authority before acting. We aim to respond within 30 days, or the shorter or longer period required by applicable law.

11. Security

We use TLS in transit, encryption at rest on AWS, hashed passwords and API keys, scoped access controls, logged production access, and isolated strategy compute. No system is perfectly secure. Report a suspected vulnerability to security@tradepolaris.com.

12. Children

The Service is for people aged 18 and over. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data to the Service.

13. Changes

We may update this policy as the Service or law changes. We post the new effective date and version here, and when the version changes we ask you to accept the new documents the next time you sign in. Each acceptance is recorded separately, so the record of which version you agreed to, and when, is not overwritten by a later one.

See the Terms of Use and Disclaimer.
TRADEPOLARIS

Risk that updates as your book moves, and research you can check.

Platform

Aegis
Vega
Strategy Builder
Walk-forward backtesting
Apps
Markets & monitoring
Pricing

Who it's for

Systematic funds
RIAs & wealth managers
Individual investors
Research & data teams

Data & API

TradePolaris MCP
Kappa Data API
Data API documentation
Data API changelog
Excel add-in
OpenAPI specification
Manage API keys
The data lake

Resources

All products
Methodology & gates
Risk limits methodology
FAQ
Changelog
Daily market brief
Desktop app
Support

Company

About
Contact
Sign up
Join the waitlist
Log in
Terms
Privacy
Disclaimer
Accessibility
© 2026 Kurtosis, Inc.Systematic research software. Not investment advice.Charts powered by TradingView