QUANTGPT

Privacy Policy

VERSION 1.3 · EFFECTIVE SEPTEMBER 10, 2026 · DRAFT PENDING COUNSEL REVIEW · QUANTGPT LLC, A FLORIDA LIMITED LIABILITY COMPANY

The short version. We collect what we need to run your account, keep the Service secure, and enforce our terms, and nothing for advertising. We do not sell your data, and we do not run ad trackers. If you join the waitlist we keep your email. If you subscribe we keep your email, a hashed password, and your Stripe customer reference; Stripe keeps your card. We log IP addresses and device details for security and to enforce our terms, and we keep those logs for 12 months. If you link a brokerage account we read balances and positions to show your performance and never see your broker login. Usage telemetry is aggregate and anonymized. You can ask us to show, correct, or delete your data at any time.

// 1. WHO WE ARE AND SCOPE

This policy is issued by QuantGPT LLC, a Florida limited liability company with its principal office at 15350 N Florida Ave, Tampa, FL 33613 ("QuantGPT", "we", "us"), which is the controller of the personal data described here. It covers quantgpt.co and its subdomains, the QuantGPT terminal, the plug-in and API, our mobile applications, and our emails (together, the "Service"). It does not cover third-party services you connect to the Service, such as your AI provider or your broker, which have their own policies.

// 2. WHAT WE COLLECT

We collect the minimum we need, and we list it by where it comes from.

SourceDataNotes
WaitlistEmail address, the time you signed up, and a short tag for the page or program you signed up from.That is the complete list. We do not store your browser or referrer with it.
AccountEmail address, a salted and hashed password (we cannot read it), your plan and its status, the date you joined, your acceptance of the Terms (version, time, and IP address), your subscriber-status certification, any Organization you identify, and your saved workspaces and study definitions.Passwords are hashed with scrypt.
BillingYour Stripe customer and subscription identifiers, plan, and status. Stripe collects your card details, billing address, and payment history directly.We never receive your full card number.
Plug-in keysA cryptographic hash of each key you issue, its label, when it was created, and daily call counts against your quota.We store the hash, not the key. If you lose a key we cannot recover it; you issue a new one.
Brokerage (only if you link one)Account balances, positions, orders, activity, and history that your broker returns, plus daily snapshots of equity, cash, and positions so we can show your performance over time.Never your broker username or password. See Section 6.
CommunityForum posts, replies, avatar choice, badges, and profile details you choose to add.Visible to other members where you post it.
Security and enforcement logsIP address; device and browser characteristics such as user agent, operating system, screen and platform signals, and language; request timing, volume, and patterns; login attempts; plug-in key usage; export, share, and download events; and signals that link accounts to one another, for example two accounts using the same device, key, or payment method.Used to secure the Service, prevent fraud, and enforce our Terms and data licenses. Kept 12 months. See Section 7.
TelemetryCounts of active sessions, studies run, screens run, plug-in calls, and dataset health, computed from short anonymous hashes.Aggregate only. Nothing individual is stored or shown. See Section 8.
SupportWhatever you send us by email, and our replies.
CookiesA session cookie for the terminal, a gate cookie for password-protected areas, and cookies set by Stripe during checkout and by Cloudflare for bot protection.No advertising or cross-site tracking cookies. See the Cookie Policy.

We do not collect precise location, contacts, photos, health data, or government identifiers. We do not buy data about you from data brokers.

// 3. WHY WE USE IT, AND OUR LEGAL BASES

If you are in the European Economic Area, the United Kingdom, or another place that requires a legal basis for processing, the basis for each purpose is shown.

PurposeData usedLegal basis
Provide the Service: accounts, login, studies, workspaces, plug-in access, communityAccount, plug-in keys, community, cookiesPerformance of our contract with you
Take payment and manage subscriptionsBillingPerformance of contract; legal obligation (tax and accounting records)
Show your brokerage performance, if you link an accountBrokeragePerformance of contract, at your request; you may disconnect at any time
Tell waitlist members about the launch and product updatesWaitlist emailConsent, which you can withdraw with one click in any email
Send service messages (receipts, security notices, changes to terms)Account emailPerformance of contract; legitimate interest in running the Service
Secure the Service, prevent fraud and abuse, and enforce quotasSecurity and enforcement logs, plug-in call countsLegitimate interest in security and in meeting our obligations to data providers
Enforce our Terms and protect our intellectual property and licensed data: detect extraction, scraping, redistribution, competitive use, and multiple or evasive accounts; identify the person or organization responsible; preserve evidence; pursue claimsSecurity and enforcement logs, account, plug-in keys, export and share eventsLegitimate interest in protecting our business, our data providers, and other users; establishment, exercise, or defense of legal claims
Understand aggregate usage and keep the Service healthyTelemetryLegitimate interest; data is anonymized by design
Comply with law, respond to lawful requests, establish or defend legal claimsAny of the above as requiredLegal obligation; legitimate interest

We do not use your data for advertising, we do not build profiles for marketing, and we do not sell or rent it. We do not make decisions about you by automated means that have legal or similarly significant effects; enforcement decisions are reviewed by a person.

// 4. WHO WE SHARE IT WITH

We share personal data only with providers who process it for us under contract, and only as needed:

We may also disclose data if required by law, subpoena, or court order; to protect the rights, safety, or property of QuantGPT, our users, or the public; to enforce our terms; or as part of a merger, acquisition, financing, or sale of assets, in which case this policy continues to apply to your data until it is changed with notice.

We have not sold personal information in the preceding 12 months and we do not "share" it for cross-context behavioral advertising as those terms are defined in California law.

// 5. YOUR AI PROVIDER AND THE PLUG-IN

The plug-in lets an AI assistant you operate, such as Claude or ChatGPT, call our Service with a key you issue. Your prompts, conversations, and anything you type go to your AI provider, under its terms and privacy policy, not to us. We receive only the structured tool calls the assistant makes to our endpoint (for example "run this backtest with these parameters"), plus your key hash, call counts, and the technical information in Section 7. We return computed results. We do not receive your conversation history from the provider.

Where the Service itself uses an AI model to parse a request you type into the terminal into a structured study, we send only that request text to the model provider [PROVIDER NAME WHEN LIVE] under a contract that prohibits training on it, and we do not send your identity with it.

// 6. BROKERAGE DATA

Linking is optional and off by default. If you link a brokerage account:

// 7. SECURITY AND ENFORCEMENT LOGS

We say this plainly because it matters to how the Service is protected. Every request to the Service is logged with the IP address it came from, characteristics of the device and browser that made it, the time and pattern of requests, and, for accounts, the key or session used. We use these records to:

These records are kept for 12 months, and longer where they relate to an active investigation, a suspected breach, or a legal claim, for as long as that matter remains open. They are not used for advertising or profiling for marketing, and they are not sold. Exports and share cards may carry identifiers tied to your account for the same purpose, as described in Section 15.3 of the Terms.

// 8. COOKIES AND TELEMETRY

We use functional cookies: a session cookie so the terminal knows you are logged in, a gate cookie for password-protected areas, cookies set by Stripe during checkout, and a Cloudflare bot-protection cookie. On quantgpt.co we use Vercel Web Analytics, which is cookieless and counts page views without identifying you. The marketing site also carries a Whop attribution pixel that is dormant until we activate it; when active it tells Whop that a visit from a Whop referral reached our site so that creator commissions can be paid, and it is disclosed in the Cookie Policy with what it collects. When we advertise on Reddit, the marketing site also carries the Reddit Pixel, which tells Reddit that a page visit or a waitlist signup followed one of our ads; it loads only for United States visitors, never when your browser sends the Global Privacy Control or Do Not Track signal, and never inside the terminal. Under California law that measurement can count as sharing personal data for cross-context advertising; we honor Global Privacy Control as your opt-out, and the Cookie Policy lists the cookie and Reddit's own controls. If you create an account or subscribe after arriving from a Reddit ad, we also tell Reddit's Conversions API, from our server, that the ad led to a sign-up or a purchase, using the click id Reddit attached to your visit and a hashed form of your email; accounts that did not arrive from a Reddit ad are never reported. Beyond those two pixels we use no cross-site advertising trackers, and we do not sell personal data.

Our telemetry is built so that nothing individual is stored. Sessions and keys are reduced to short anonymous hashes used only to count how many are active inside a rolling window; the outputs are counts and dataset health. The public cluster page shows only those aggregates.

// 9. HOW LONG WE KEEP IT

DataRetention
Waitlist emailUntil you unsubscribe or ask us to remove it, or 24 months after launch, whichever is first.
Account and workspacesFor the life of your account, then deleted within 30 days of closure or a deletion request, except as noted below.
Terms acceptance recordFor the life of your account plus 5 years, as evidence of the agreement.
Billing records7 years after the transaction, as required for tax and accounting. Stripe applies its own retention.
Plug-in key hashes and call countsKey hashes until revoked or the account closes; daily call counts for 12 months.
Brokerage data and snapshotsWhile linked; deleted within 30 days of disconnection or account closure.
Community postsWhile your account is open. On closure you may ask us to delete them or to keep them attributed to a removed account.
Security and enforcement logs12 months; longer for an active investigation, suspected breach, or legal claim, until it is closed.
TelemetryAggregate counters only; anonymous hashes expire within 24 hours.
Support email3 years.

Backups may hold copies for up to 35 days beyond these periods, after which they are overwritten. Where you request deletion, we may retain the minimum needed to honor the request itself, to complete an open investigation or legal matter, or to meet a legal obligation.

// 10. SECURITY AND BREACH NOTICE

We protect data with measures appropriate to its sensitivity: encryption in transit everywhere; hashed passwords and hashed keys; read-only, scoped brokerage access; secrets kept out of code and logs; rate limiting and lockouts on authentication; and a policy of not storing what we do not need. No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and any regulator as the law requires, including, for Florida residents, within the time required by the Florida Information Protection Act, section 501.171 of the Florida Statutes.

// 11. YOUR RIGHTS

Wherever you live, you can email desk@quantgpt.co to ask us to show you the data we hold about you, correct it, delete it, or stop using it for marketing. We will verify the request by matching it to your account email, and we will respond within 30 days, or within 45 days where California law allows, telling you if we need longer.

European Economic Area and United Kingdom

You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interest, and to withdraw consent at any time without affecting earlier processing. Where you object to processing we carry out for security or enforcement, we will stop unless we have compelling legitimate grounds that override your interests or the processing is needed to establish, exercise, or defend legal claims. You may complain to your local supervisory authority; in the UK that is the Information Commissioner's Office. [COUNSEL: confirm whether an EU or UK representative under GDPR Article 27 is required for the expected user base, and name them here if so.]

California

Under the CCPA and CPRA you have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; to opt out of sale or sharing (we do neither); to limit use of sensitive personal information (we do not use it beyond providing the Service); and not to be discriminated against for exercising these rights. We honor Global Privacy Control signals as an opt-out of sale or sharing. You may designate an authorized agent by giving them written permission that we can verify.

Other U.S. states

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others) have comparable rights to access, correct, delete, and port data and to opt out of targeted advertising and sale, which we do not do. If we decline a request, you may appeal by replying to our response, and we will explain the outcome in writing.

// 12. INTERNATIONAL TRANSFERS

We are based in the United States and our providers are in the United States. If you use the Service from elsewhere, your data is transferred to and processed in the United States, where privacy laws may differ from yours. For transfers from the EEA, UK, or Switzerland we rely on standard contractual clauses with our providers and, where applicable, the EU-U.S. Data Privacy Framework participation of those providers. You may ask us for details of the safeguards in place.

// 13. CHILDREN

The Service is for adults. You must be 18 or older to create an account. We do not knowingly collect personal data from anyone under 18, and never from anyone under 13. If you believe a minor has given us data, contact us and we will delete it.

// 14. MOBILE APPS

Our iOS and Android apps collect the same categories described above and nothing beyond what the app's store listing discloses. The apps do not access your contacts, photos, microphone, camera, or precise location. Any data the app stores on your device is protected by the platform's encryption. Apple's App Privacy labels and Google Play's Data Safety section for our apps are kept consistent with this policy. In-app purchases made through the app stores are subject to the store's payment terms.

// 15. CHANGES

We will update this policy as the Service changes. Material changes will be announced by email or in the Service at least 14 days before they take effect. The date at the top shows the current version.

// 16. CONTACT

QuantGPT LLC
15350 N Florida Ave
Tampa, FL 33613
desk@quantgpt.co