QuantX

Privacy Policy

QuantX AI LLC
Last updated: July 17, 2026
Effective date: [INSERT LAUNCH DATE]

DRAFT — NOT LEGAL ADVICE. Prepared for review by a licensed attorney. Not reviewed by counsel. Do not publish as-is. See review notes at the end.


1. Overview

QuantX AI LLC ("QuantX," "we," "us") operates a behavioral analytics platform for traders. This policy explains what we collect, why, who we share it with, and what control you have.

Contact: enzo@quantx.digital
Address: 1230 NE 81 Terrace, Miami, Florida 33138

Scope. This policy covers quantx.digital, app.quantx.digital, and the QuantX Service.

Who this is for. The Service is offered to users in the United States and is not directed to residents of the European Economic Area or United Kingdom. It is not directed to anyone under 18.

Read this part. QuantX is unusual: the Service works by collecting detailed information about how you think and behave — your reflections, your emotional states, your patterns under pressure. This is more personal than most software collects. We've tried to describe it plainly rather than bury it.


2. What We Collect

2.1 You give us

Account information

  • Email address
  • Password (stored as a cryptographic hash — we never see it)
  • Name, if you provide one

Payment information

  • Handled entirely by Stripe. We never receive, process, or store your card number.
  • We store a Stripe customer identifier, your subscription status and tier, and your billing history as reported by Stripe.

Consent records

  • When you agree to a paid subscription with a free trial, we record the exact text you agreed to, the date and time, the plan and price, your IP address, and your browser's user agent. This is a legal record of your consent and is retained as described in Section 6.

Trading data

  • Trades you import or enter: instruments, entries, exits, sizes, timestamps, outcomes, and related fields.

Journal and reflective content

  • Structured session journals: intentions, emotional states, rule adherence, reflections.
  • Free-form entries and annotations you write.
  • Uploads you provide to TradeSeer AI, such as screenshots or documents.

Communications

  • Emails you send us.

2.2 Generated automatically

Behavioral metrics and derived data

  • Scores, indices, archetype classifications, reports, and other analysis computed from the data you provide.

Usage data

  • Pages visited, features used, session timestamps, actions taken.

Technical data

  • IP address, browser type and version, device type, operating system, referring URL.

Cookies and similar technologies

  • See Section 8.

2.3 We do not collect

  • Your card number, CVV, or full payment credentials. Stripe holds these.
  • Exchange or broker credentials where the Service uses file import.
  • Your funds. We never hold, transmit, or have access to money or assets.
  • Government identifiers, biometrics, or precise geolocation.

⚠️ REVIEW NOTE: §2.3 must be verified against the software as built before publication. If any exchange connection uses API keys or OAuth tokens, this section is inaccurate and must be rewritten to describe what is stored, how it is encrypted, and what permission scope is requested. Confirm before launch.


3. Why We Collect It

PurposeData used
Create and maintain your accountAccount info
Provide the Service — metrics, archetypes, reports, AI featuresTrading data, journal content, derived data
Process payments and manage subscriptionsPayment info via Stripe
Prove consent in a payment disputeConsent records
Send transactional email (trial reminders, receipts, security notices)Account info
Respond to support requestsCommunications
Detect fraud, abuse, and duplicate trialsTechnical data, payment identifiers
Debug, secure, and improve the ServiceUsage and technical data
Comply with lawAs required

We do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not use your trading data or journal content to train third-party AI models — see Section 4.


4. Who We Share It With

We share personal information only with service providers who need it to operate the Service, and only for that purpose.

Our service providers

Stripe, Inc. — payment processing
Receives: your email, payment details you enter directly with them, transaction records.
Governed by Stripe's own privacy policy.

Supabase — database and authentication
Stores: essentially all Service data, including trading data and journal content, encrypted at rest.

Vercel — hosting and delivery
Processes: technical data, request logs.

Anthropic, PBC — AI processing
Receives: the content necessary to generate AI features, which may include your trading data and journal content.

⚠️ REVIEW NOTE — IMPORTANT: The following sentence must be verified against your actual Anthropic contract terms and API configuration before publication. Do not publish this claim unverified.

"Content sent to Anthropic through the API is not used to train Anthropic's models."

Verify the applicable terms, any data retention period, and whether zero-retention is enabled. State what is actually true, not what is generally true of the API.

Email provider — [INSERT PROVIDER]
Receives: your email address and message content for transactional email.

⚠️ REVIEW NOTE: Name the actual provider before publication.

Other disclosures

Legal. We may disclose information if required by law, subpoena, or court order, or where we believe in good faith it is necessary to protect our rights, your safety, or the safety of others.

Business transfer. If QuantX is acquired, merged, or sells substantially all assets, your information may transfer to the acquirer, subject to this policy or a successor policy with materially equivalent protections.

Aggregated or de-identified data. We may share data that cannot reasonably identify you.

We do not share your information with advertisers, data brokers, or marketing partners.


5. Where It's Stored and How It's Protected

Location. Data is stored on infrastructure operated by Supabase and Vercel, primarily in the United States.

Security measures include:

  • Encryption in transit (TLS) and at rest
  • Row-level security restricting every record to its owner
  • Password hashing
  • Access controls and audit logging
  • Regular security review

No card data. We never store card numbers. Stripe is PCI-DSS Level 1 certified.

The limit of any security claim. No system is perfectly secure. We work to protect your information but cannot guarantee absolute security. You are responsible for your password and for notifying us of suspected unauthorized access.

Breach notification. If a breach affecting your personal information occurs, we will notify you as required by applicable law, including Florida Statutes § 501.171.

⚠️ REVIEW NOTE: Every claim in this section must be verified against the system as built. Do not publish a security claim that is aspirational. The marketing site's "bank-grade security" language should also be reviewed for consistency with what is actually implemented.


6. How Long We Keep It

DataRetention
Account and Service dataUntil you delete your account
After account deletionPurged within 30 days
BackupsPurged on the backup rotation cycle, up to 90 days
Payment recordsAs required by tax and financial regulation, typically 7 years (held by Stripe and by us)
Consent records7 years — retained as dispute and regulatory evidence, and retained even after account deletion
Support communications3 years

Why consent records survive deletion. A consent record proves what you agreed to and when. Deleting it would destroy the evidence that protects both of us in a payment dispute. It contains only your consent event — not your trading data or journal content.


7. Your Choices and Rights

Access and export. Export your data from your account settings at any time.

Correction. Edit your account information in settings. Note that some content is intentionally immutable by design — journal entries and annotations cannot be edited after they are closed, because their value depends on being an unrevised record of what you wrote. You can delete them.

Deletion. Delete your account from your settings. This is self-serve — you do not need to email us.

On deletion:

  • Your trading data, journal entries, annotations, archetypes, reports, and derived data are permanently deleted within 30 days
  • Deleting an entry also deletes data derived from it
  • Backups purge on their rotation cycle (up to 90 days)
  • Payment records and consent records are retained as described in Section 6

Marketing email. We currently send only transactional email. If we introduce marketing email, it will include an unsubscribe link.

Cookies. See Section 8.

California residents

Under the CCPA/CPRA you have the right to know what we collect, to delete it, to correct it, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information, and to be free from discrimination for exercising these rights.

Exercise these rights through your account settings or by emailing enzo@quantx.digital. We will verify your identity through your account credentials. We respond within 45 days, extendable by 45 more with notice.

Sensitive personal information. Some of what you write in QuantX — reflections on your emotional state, for instance — may qualify as sensitive personal information under California law. We use it only to provide the Service you asked for, and for no secondary purpose.

⚠️ REVIEW NOTE: Confirm whether QuantX currently meets CCPA applicability thresholds. Even if not, these rights are offered voluntarily and building them now is cheaper than retrofitting. Confirm the "sensitive personal information" characterization with counsel — it affects notice and limitation obligations.

Other states

Several US states have comprehensive privacy laws granting similar rights. We honor equivalent requests from residents of any US state regardless of applicability thresholds.


8. Cookies

We use:

Strictly necessary cookies — authentication and session management. The Service cannot function without them.

Preference cookies — remembering your settings.

⚠️ REVIEW NOTE: If any analytics or third-party tracking is added — Google Analytics, Posthog, Vercel Analytics, Meta Pixel, or similar — this section must be updated and a consent mechanism may be required. Confirm what is actually deployed before publication.

Most browsers let you block cookies. Blocking strictly necessary cookies will prevent you from logging in.

Do Not Track. We do not currently respond to DNT signals, as no common standard exists.


9. Children

The Service is not directed to anyone under 18 and we do not knowingly collect information from minors. If we learn we have, we will delete it. If you believe a minor has provided us information, contact enzo@quantx.digital.


10. International Users

The Service is intended for United States users and our infrastructure is located in the United States. We do not target the EEA or UK.

If you access the Service from outside the United States, you do so on your own initiative and consent to the transfer and processing of your information in the United States, which may have different data protection laws than your country.

⚠️ REVIEW NOTE: The Service does not geo-block. A US-only posture stated in a policy may not defeat GDPR applicability if EU residents in fact sign up and are served. Advise on whether geo-blocking is warranted, or whether GDPR compliance should be built now rather than retrofitted.


11. Changes

We may update this policy. Material changes will be notified by email to your registered address and by notice in the Service at least 30 days before taking effect. The "last updated" date always reflects the current version.


12. Contact

QuantX AI LLC
1230 NE 81 Terrace
Miami, Florida 33138
enzo@quantx.digital


Review Notes for Counsel

  1. §2.3 and §4 — every factual claim about what is collected and who receives it must be verified against the software as built. Particular attention to whether exchange connections store API keys or tokens.
  2. §4, Anthropic — the training-data claim must be verified against actual contract terms and API configuration. Do not publish unverified.
  3. §5 — security claims must match implementation. Cross-check with the marketing site's "bank-grade security" language.
  4. §7, California — confirm CCPA/CPRA applicability and the sensitive-personal-information characterization. The Service collects psychological and behavioral content, which is atypical and may carry heightened obligations.
  5. §8 — confirm actual cookie and analytics deployment.
  6. §10 — advise on geo-blocking vs. GDPR readiness.
  7. §6 — confirm the 7-year consent record retention is appropriate and that retaining it post-deletion is defensible under CCPA deletion rights (we assert a legal-obligation exception).
  8. Email provider — name before publication.
  9. Effective date — insert before publication.