Privacy Policy

Last updated: 2026-09-10 — the short version: your data stays on our infrastructure.

What we collect. Account data (email, password hash, optional TOTP secrets), product data you create (watchlists, drawings, alerts, workspaces, journal entries), first-party usage analytics (page views and feature events keyed to a random identifier stored in your browser — not a fingerprint), and an audit log on your account — sign-ins, password resets, two-factor changes, plan changes and exports — which is included in your export. If you subscribe, your account also holds your Stripe customer id and subscription status; Stripe holds the payment method.

Where it lives. On our own servers: our Postgres database, with our own Redis in front of it as the sign-in session cache and as the home of rate-limit and monthly-allowance counters, keyed to your account id and expiring on their own. Analytics events go to our own database — there is no Google Analytics, no advertising pixel, and no third-party analytics service. No third-party code runs on our pages, with one exception: the checkout page. Paying happens on our domain, where the checkout page loads Stripe's own script from js.stripe.com and shows Stripe's payment form inside a Stripe frame — your card details are typed into Stripe's frame and go to Stripe, never to our servers. Managing or cancelling a subscription opens Stripe's billing portal on Stripe's domain, from Settings → Billing.

Third parties we do use. Stripe processes payments (we never see card numbers). Transactional email — sign-in verification, password resets and similar account mail — is sent by our own mail service from our domain, quantz.online: through Google's Gmail API from a QuantZ mailbox on that domain when that transport is configured, or otherwise straight to your mail provider, signed with our own DKIM key, or through a Google Workspace SMTP relay. Server-side, we query market-data vendors and, for some AI features, vendor language models — AI requests are stamped so you can see when a vendor model (rather than our self-hosted one) answered.

Cookies. A session cookie when you sign in, and a deployment-group cookie for canary rollouts. No cross-site tracking cookies.

Getting your data out. Export is self-serve and needs no request: the Export button on Journal and Book returns your data as open JSON, with a manifest that accounts for every table in our database — what is in the file, what we hold back (credentials only, because handing them over would hand over the account), and the account-record fields the file leaves out.

Deleting your data. You can clear the anonymous analytics identifier yourself by clearing site data. Account deletion is handled by hand: email sales@quantz.online from your account address and we delete the account and the data tied to it. Export first if you want a copy — the export is yours to run at any time.

Who controls your data. The data controller is QuantZ, a sole proprietorship operating from the Province of Ontario, Canada. Privacy enquiries: sales@quantz.online.

Where your data are handled. We are based in Ontario, Canada, but your data are processed and stored on servers in the United States — New Jersey, on infrastructure we rent from DigitalOcean. Using the Service therefore involves your data being held in the United States, whatever country you are in. Payments are handled separately by Stripe on Stripe’s own systems.

Legal basis and your rights. We accept accounts worldwide, so rather than ask which privacy law covers you, we give everyone the same rights: ask what we hold, take a copy (export is self-serve and needs no request), have it corrected, and have your account and its data deleted. We use your data to run the Service you asked for, to keep your account secure, and to bill you if you subscribe — not for advertising or profiling. We do not sell personal information and we do not share it for cross-context behavioural advertising. If the law where you live gives you more than this, that law wins and we will honour it; write to sales@quantz.online.

Changes. Material changes to this policy will be announced in the changelog before they take effect.