1. Who is responsible
[COMPANY LEGAL NAME], [COMPANY ADDRESS], is responsible for your personal data in SCUTA Quant (the data controller). Contact: [PRIVACY EMAIL]. [EU/UK REPRESENTATIVE AND DATA PROTECTION OFFICER, IF REQUIRED]
2. What we collect
- Account: email address, display name, a hash of your password (never the password itself), whether your email is verified, and, if you sign in with Google, your Google account id and profile picture URL.
- Legal acceptances: which version of the Terms of Service and Risk Disclosure you accepted, and when.
- Sessions: for each signed-in session, the browser’s user agent, IP address and when it was created and last used. You can see and end these in Settings → Sessions.
- Your content: projects, strategies and their saved versions, notebooks, backtest settings and results, analyses, prop-firm simulations, and what you send to Copilot and its replies.
- Community: posts, comments and likes you publish (public by design).
- Billing and usage: your plan, credit balance, usage events (for example a backtest or a Copilot reply and the tokens it used), and the Stripe customer and subscription ids. Card details are handled by Stripe; we never receive full card numbers.
- Emails: the transactional emails we send you (verification, password reset, security and billing notices).
- Technical logs: request logs and error reports needed to run and secure the Service. [ERROR MONITORING PROVIDER, IF ENABLED]
We do not use advertising trackers and we do not sell or rent personal data.
3. Why we use it
| Purpose | Data | Legal basis [CONFIRM] |
|---|---|---|
| Providing the Service: accounts, running your code, storing results, Copilot | Account, content, usage | Contract |
| Security: sessions, rate limits, abuse prevention, the sandbox | Sessions, logs | Legitimate interests |
| Billing, credits and invoices | Billing and usage | Contract; legal obligation (tax records) |
| Transactional email | Email address | Contract |
| Recording acceptance of the Terms and Risk Disclosure | Legal acceptances | Legitimate interests; legal claims |
| Showing what you publish to the community | Community content | Contract (at your request) |
We do not send marketing emails without your consent.
4. Who processes data for us (subprocessors)
We use these providers to run the Service. Each receives only what it needs for its task and is bound by a data processing agreement [CONFIRM DPAs IN PLACE].
| Provider | What it does | Data it receives | Location |
|---|---|---|---|
| Supabase | Database hosting | All account, content, billing and usage data stored by the Service | [REGION] |
| Anthropic | AI models behind Copilot | Your Copilot messages and the code, results and context sent with them | [REGION] |
| Stripe | Payments, invoices, billing portal | Email address, plan, payment details you enter with Stripe | [REGION] |
| Resend | Transactional email | Email address, display name, email content | [REGION] |
| [SANDBOX PROVIDER] | Isolated execution of strategy and notebook code | The code being run and the market data it runs on | [REGION] |
| [HOSTING PROVIDER] | Hosting the web app and API | All requests to the Service | [REGION] |
| Sign-in with Google (only if you use it) | The Google sign-in exchange | [REGION] |
Massive supplies market data to us. We request data from Massive on our servers; it does not receive your personal data.
5. International transfers
Some providers process data outside your country. Where the law requires it, transfers rely on [TRANSFER MECHANISM, e.g. adequacy decisions or Standard Contractual Clauses].
6. How long we keep it
- Account data and content: while your account is open.
- When you delete your account, we delete your profile, projects, strategies, backtests and analyses, notebooks, simulations, community posts, comments and likes, plan and credit records, sessions and legal acceptances at once. Copies in backups are overwritten within [BACKUP RETENTION PERIOD].
- Stripe keeps invoices and payment records for as long as the law requires.
- Technical logs: [LOG RETENTION PERIOD].
- Copilot requests are processed by Anthropic under its API data policy and retention period [CONFIRM].
7. Your rights and choices
- Export: Settings → Export data downloads your data as JSON.
- Correct: change your name, email and password in Settings.
- Delete: Settings → Delete account deletes your account and data at once.
- Sessions: see and end sessions in Settings → Sessions.
- Depending on where you live, you may also have the right to access, restrict or object to processing, and to complain to a data protection authority. Write to [PRIVACY EMAIL]; we answer within [RESPONSE PERIOD].
8. Public content
Posts you publish to the community feed, with your display name, are visible to anyone, and other users can fork published strategies. Deleting a post does not remove copies others already made.
10. Security
Connections are encrypted in transit. Sessions use httpOnly cookies with refresh-token rotation and CSRF protection. Passwords are stored as bcrypt hashes. Strategy and notebook code runs in an isolated sandbox without access to other users’ data. No system is perfectly secure; report vulnerabilities to [SECURITY EMAIL].
11. Children
The Service is not meant for anyone under [MINIMUM AGE], and we do not knowingly collect their data.
12. Changes
We will publish changes here with a new version number and tell you by email or in the app when they matter.