Skip to content
Legal

Privacy Policy

What personal data SCUTA Quant collects, why, who processes it for us, and how to export or delete it.

Version 2026-10-09-draft

Draft

This document is a draft awaiting review by a lawyer. Text in [BRACKETS] is a placeholder that will be replaced before launch, and the wording may change.

1. Who is responsible

[COMPANY LEGAL NAME], [COMPANY ADDRESS], is responsible for your personal data in SCUTA Quant (the data controller). Contact: [PRIVACY EMAIL]. [EU/UK REPRESENTATIVE AND DATA PROTECTION OFFICER, IF REQUIRED]

2. What we collect

  • Account: email address, display name, a hash of your password (never the password itself), whether your email is verified, and, if you sign in with Google, your Google account id and profile picture URL.
  • Legal acceptances: which version of the Terms of Service and Risk Disclosure you accepted, and when.
  • Sessions: for each signed-in session, the browser’s user agent, IP address and when it was created and last used. You can see and end these in Settings → Sessions.
  • Your content: projects, strategies and their saved versions, notebooks, backtest settings and results, analyses, prop-firm simulations, and what you send to Copilot and its replies.
  • Community: posts, comments and likes you publish (public by design).
  • Billing and usage: your plan, credit balance, usage events (for example a backtest or a Copilot reply and the tokens it used), and the Stripe customer and subscription ids. Card details are handled by Stripe; we never receive full card numbers.
  • Emails: the transactional emails we send you (verification, password reset, security and billing notices).
  • Technical logs: request logs and error reports needed to run and secure the Service. [ERROR MONITORING PROVIDER, IF ENABLED]

We do not use advertising trackers and we do not sell or rent personal data.

3. Why we use it

PurposeDataLegal basis [CONFIRM]
Providing the Service: accounts, running your code, storing results, CopilotAccount, content, usageContract
Security: sessions, rate limits, abuse prevention, the sandboxSessions, logsLegitimate interests
Billing, credits and invoicesBilling and usageContract; legal obligation (tax records)
Transactional emailEmail addressContract
Recording acceptance of the Terms and Risk DisclosureLegal acceptancesLegitimate interests; legal claims
Showing what you publish to the communityCommunity contentContract (at your request)

We do not send marketing emails without your consent.

4. Who processes data for us (subprocessors)

We use these providers to run the Service. Each receives only what it needs for its task and is bound by a data processing agreement [CONFIRM DPAs IN PLACE].

ProviderWhat it doesData it receivesLocation
SupabaseDatabase hostingAll account, content, billing and usage data stored by the Service[REGION]
AnthropicAI models behind CopilotYour Copilot messages and the code, results and context sent with them[REGION]
StripePayments, invoices, billing portalEmail address, plan, payment details you enter with Stripe[REGION]
ResendTransactional emailEmail address, display name, email content[REGION]
[SANDBOX PROVIDER]Isolated execution of strategy and notebook codeThe code being run and the market data it runs on[REGION]
[HOSTING PROVIDER]Hosting the web app and APIAll requests to the Service[REGION]
GoogleSign-in with Google (only if you use it)The Google sign-in exchange[REGION]

Massive supplies market data to us. We request data from Massive on our servers; it does not receive your personal data.

5. International transfers

Some providers process data outside your country. Where the law requires it, transfers rely on [TRANSFER MECHANISM, e.g. adequacy decisions or Standard Contractual Clauses].

6. How long we keep it

  • Account data and content: while your account is open.
  • When you delete your account, we delete your profile, projects, strategies, backtests and analyses, notebooks, simulations, community posts, comments and likes, plan and credit records, sessions and legal acceptances at once. Copies in backups are overwritten within [BACKUP RETENTION PERIOD].
  • Stripe keeps invoices and payment records for as long as the law requires.
  • Technical logs: [LOG RETENTION PERIOD].
  • Copilot requests are processed by Anthropic under its API data policy and retention period [CONFIRM].

7. Your rights and choices

  • Export: Settings → Export data downloads your data as JSON.
  • Correct: change your name, email and password in Settings.
  • Delete: Settings → Delete account deletes your account and data at once.
  • Sessions: see and end sessions in Settings → Sessions.
  • Depending on where you live, you may also have the right to access, restrict or object to processing, and to complain to a data protection authority. Write to [PRIVACY EMAIL]; we answer within [RESPONSE PERIOD].

8. Public content

Posts you publish to the community feed, with your display name, are visible to anyone, and other users can fork published strategies. Deleting a post does not remove copies others already made.

9. Cookies

We use only essential cookies. See the Cookie Policy.

10. Security

Connections are encrypted in transit. Sessions use httpOnly cookies with refresh-token rotation and CSRF protection. Passwords are stored as bcrypt hashes. Strategy and notebook code runs in an isolated sandbox without access to other users’ data. No system is perfectly secure; report vulnerabilities to [SECURITY EMAIL].

11. Children

The Service is not meant for anyone under [MINIMUM AGE], and we do not knowingly collect their data.

12. Changes

We will publish changes here with a new version number and tell you by email or in the app when they matter.