Privacy Policy
This policy explains what information AtlasVector ("we", "us") collects, how it is used, who processes it on our behalf, how long we keep it, and the rights and choices you have. We collect only what we need to run the Service, and we say so plainly.
1. What we collect
- Account information — the email address and credentials you provide when you create an account (and, if you enable them, a phone number for one-time verification and an authenticator enrollment for two-factor security), used to authenticate you and secure your sessions. Passwords are stored only in cryptographically hashed form.
- Usage information — technical data such as pages viewed, features used, approximate region, device and browser type, and diagnostic logs, used to operate, secure, and improve the Service.
- Content you enter — tickers you search, questions you ask, watchlists, notes, and preferences, used to return the results you request and remember your setup.
- Waitlist and contact submissions — if you join a waitlist or ask to be notified about a feature, we store the email address supplied with the request, any name, organization, or notes you add, and the submitting connection's IP address and browser signature (used to reach you about what you asked for and to keep the form from being abused). These records are kept until the request is served or you ask us to delete them (section 8); once a request is marked served, a scheduled cleanup deletes the record.
The public portal can be browsed without an account. We do not ask for — and do not want — your brokerage credentials, government identifiers, or other sensitive personal data in order to browse the portal. The Service is not directed at children under 18, and we do not knowingly collect their data.
2. How we use it
- To provide, maintain, and secure the Service and your account.
- To personalize your experience (watchlists, recent searches, preferences).
- To monitor performance, detect and prevent abuse and fraud, and improve features.
- To communicate with you about the Service — security notices, verification codes, and material changes. We do not send marketing email without your consent.
- To comply with legal obligations.
3. What we do not do
- We do not sell your personal information, and we do not share it with third parties for their own advertising.
- We do not use your data to give you personalized investment advice — AtlasVector is a research platform and not an adviser.
- We do not ask for or store real brokerage credentials.
- We do not use your personal information, watchlists, portfolios, or activity to inform AtlasVector's own proprietary trading, to trade against you, or to front-run your interests. AtlasVector's proprietary strategies run on general market data and AtlasVector's own capital only — see the Disclaimer.
4. Who processes it
We share information only with the service providers that help us run AtlasVector — cloud hosting and infrastructure, content delivery, identity/authentication, transactional email delivery, payment processing, and error/performance monitoring — and only as needed to operate the Service. These providers process data on our behalf under their own confidentiality and data-protection obligations. We may also disclose information with your consent, or where required by law, regulation, or valid legal process, or to protect the rights, safety, and integrity of the Service and its users. Questions you submit to AI features are processed by our AI infrastructure providers to generate the response; they are not used to build advertising profiles.
Payments. If you buy a subscription, checkout happens on our payment processor's own hosted page. The processor receives your email address and an internal account reference from us, and the card details you enter there directly from you; it returns to us your subscription status and a customer reference. Card numbers never touch our servers and we do not store them.
The market-data sources behind the prices and fundamentals you see are not sub-processors: they send data to us and receive no personal information about you.
Sub-processor register and DPA. The current register — each sub-processor by name, its role, the categories of personal data it processes, and where it processes them — is available on request from [email protected], as is our data-processing agreement. Email the same address to be added to the change list: we give at least 30 days' notice before a new sub-processor begins processing personal data, so you have time to object.
5. International transfers
Our infrastructure providers may store or process data in countries other than your own. Where personal data leaves the EEA, the UK, or Switzerland, we transfer it only under a lawful transfer mechanism — an adequacy decision where one covers the destination, and otherwise the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. The mechanism that applies to each provider is named for that provider in the sub-processor register described in section 4. By using the Service you acknowledge this processing.
6. Cookies & local storage
We use cookies and browser storage to keep you signed in, remember preferences, and understand aggregate usage. We do not run third-party advertising trackers. You can control cookies through your browser settings; disabling them may limit some features (for example, staying signed in).
7. Security & retention
We use reasonable technical and organizational measures to protect your information — encryption in transit, hashed credentials, scoped access, and audit logging. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
We keep each class of personal information only as long as we need it:
- Account information and the content tied to your account — kept for as long as your account is open. When your account is deleted (on your request), the account record and sign-in identity are removed together with the records linked to it — sessions, verification codes, the subscription record, paper-trading accounts with their orders, positions and fills, watchlists, alerts, saved documents, chat threads, notebooks, strategies and backtests.
- Operational records of your activity — some records your use produced, such as command history and agent working memory, are not removed by account deletion today. They are keyed to an internal account identifier that no longer resolves to your name or email once the account record is gone, and we delete them on request (section 8), except where we must keep a record to meet a legal obligation or resolve a dispute.
- Sign-in sessions — a session expires 30 days after sign-in and is destroyed as soon as you sign out. A scheduled cleanup also deletes expired session records from our systems.
- Email and phone verification codes — 15 minutes, after which the code is no longer usable; the same scheduled cleanup deletes expired code records.
- Usage and diagnostic logs — kept for the shortest period that still lets us investigate a security or reliability incident — we publish that criterion rather than a fixed number we do not yet enforce automatically.
8. Your rights & choices
You can access and update your account information in the app. You may also request a copy of your personal information, ask us to correct or delete it, or object to or restrict certain processing, subject to legal limits. Depending on where you live (for example, the EU/EEA, UK, Australia, or California), you may have additional statutory rights, including the right to lodge a complaint with your local data-protection authority. To exercise any right, contact [email protected] — we will respond within the timeframe required by applicable law.
9. Changes
We may update this policy as the Service evolves. Material changes will be reflected on this page with an updated date, and where required by law we will notify you.
Contact
Privacy questions or requests: [email protected].
See also our Terms of Use and Disclaimer & Important Disclosures.