Privacy Policy

Last updated: September 29, 2026

What changed on September 28 and 29, 2026

  • Analytics, advertising and support-chat tools now load only after you allow them in the cookie banner.
  • You can download your data and delete your account yourself in Settings → Privacy & data.
  • New accounts receive product update emails only if they opt in.
  • Open-weight AI models developed in China now run only on providers outside China.
  • Two-factor authentication is available for email-and-password sign-in.
  • September 29, 2026: you can switch off chat frustration analysis in Settings; we keep only a hash of the email used for the free starter credit; resolved bug reports are deleted after about 12 months; we email a purchase confirmation after each purchase; withdrawing marketing consent stops advertising attribution through Whop immediately.
  • This policy now lists our service providers, where they process data, and how long we keep each kind of data.

1. Who we are

Roboquant Technologies LTD ("we", "us") operates Roboquant (the "Service") and is the controller of your personal data under the EU General Data Protection Regulation (GDPR) and the law of the Republic of Cyprus.

Roboquant Technologies LTD
Ioanni Pasikrati 3A
6012 Larnaca, Cyprus
VAT: CY6038146J
Email: info@roboquant.dev

We have not appointed a Data Protection Officer. For any privacy question or request, write to info@roboquant.dev.

2. What we process, why, and on what legal basis

PurposeDataLegal basis (GDPR)
Create and run your account, sign-in and two-factor authenticationEmail, name, sign-in provider link, password hash, session data, IP addressContract (Art. 6(1)(b))
Provide the Service: strategies, indicators, backtests, optimizations, charts, AI chat, chart analysis, dictation, live and replay trading toolsContent you create or upload, chat messages, images you attach, voice recordings for dictation, usage recordsContract (Art. 6(1)(b))
Connect a broker or your own AI provider key when you choose toBroker account identifiers, encrypted credentials, API keysContract (Art. 6(1)(b))
Billing, credits, refunds and withdrawalsPlan, payment and credit records, withdrawal requests, and the purchase confirmation email we send after each subscription, charged plan change or credit top-up (card data stays with the payment provider)Contract (Art. 6(1)(b)); legal obligation for accounting records (Art. 6(1)(c))
Record that you accepted the Terms and confirmed you are 18 or older, that you acknowledged the withdrawal notice at checkout, and market-data attestations you signCompliance records with the document version and time (when you join through a claim or invite link, acceptance is recorded when the browser that showed you the statement completes the step), and for attestations the details the exchange requiresLegal obligation (Art. 6(1)(c)); legitimate interest in being able to prove these facts (Art. 6(1)(f))
Offer a one-click bug report when a chat message looks like you are having trouble with the productThe text of the chat message you typed (never AI replies, code output or market data)Legitimate interest in finding and fixing product problems (Art. 6(1)(f)). You can switch this off in Settings → Privacy & data ("Don't analyse my chat messages for frustration signals"); if we cannot check your choice, the message is not sent
Security, abuse prevention and service logsIP address, request logs, error reportsLegitimate interest (Art. 6(1)(f))
Customer supportMessages you send us by email or in the support chatContract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))
Bug reports you submitYour email and user ID, title, description, the page address, browser and operating system, and a screenshot if you attach oneContract (support, Art. 6(1)(b)); legitimate interest in fixing problems (Art. 6(1)(f))
Prevent repeat claims of the free starter credit, and manage early-access and pre-order listsFor the starter credit, a one-way SHA-256 hash of your email (not the email itself); for early-access and pre-order lists, your email addressLegitimate interest (Art. 6(1)(f)); legal obligation for pre-order payment records (Art. 6(1)(c))
Product update emailsEmail address, your email preferenceConsent for accounts created after this policy took effect (Art. 6(1)(a)); legitimate interest for earlier accounts (Art. 6(1)(f)). You can opt out at any time
Analytics, advertising measurement and the support chat widgetCookie identifiers and usage events set by the tools listed in our Cookie PolicyConsent through the cookie banner (Art. 6(1)(a))
Affiliate and referral trackingReferral code in a first-party cookieLegitimate interest in crediting referrals (Art. 6(1)(f)); the third-party affiliate script loads only with marketing consent

You give us most of this data directly. Usage records, logs and cookie identifiers are collected when you use the Service. Payment providers tell us whether a payment succeeded; we never receive your full card number. To create an account you need an email address (with a password or an email sign-in link), or a Google, GitHub or Whop sign-in; to buy a plan or credits you need to give payment details to Whop. Without them we cannot provide the Service.

3. AI features

The AI chat, chart analysis and dictation use AI models. AI chats show a notice that you are chatting with an AI and that answers can be wrong. What you type, attach or dictate is sent to the AI model that handles the request (see section 5) so it can answer. AI output is not financial advice: check code and results before trading.

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR). The bug-report classification described above only decides whether the chat offers you a "report a problem" button.

4. Cookies

Only strictly necessary cookies are set before you choose. Analytics, advertising and the support chat load only after you allow them, and you can change your choice at any time with "Cookie settings" in the footer or in Settings → Privacy & data. Details and cookie names are in our Cookie Policy.

5. Who receives your data

We use these service providers for the tasks listed. We do not sell your personal data.

RecipientWhat forWhere
Amazon Web Services (AWS)Backend servers, database, file storage, backups, secretsIreland (eu-west-1); database backups copied to Germany (eu-central-1)
VercelWeb application hosting, cookieless Web Analytics and Speed Insights, and the AI Gateway that routes AI requestsFunctions in Frankfurt; global edge network; United States
Anthropic, OpenAI, Google (Gemini)AI models that answer chat and chart-analysis requests, through the Vercel AI Gateway. OpenAI also transcribes dictation audioUnited States
AI inference providers: Amazon Bedrock, Google Vertex AI, Microsoft Azure, DeepInfra, Fireworks AI, Together AI, Baseten, Parasail, Modal, Groq, CerebrasRun open-weight models, including models developed in China (for example DeepSeek, Qwen, GLM, Kimi, MiniMax). For those models we only allow these providers, which are outside China and, according to Vercel AI Gateway, offer zero data retention and no training on your dataUnited States and other regions outside China
TypeSafeClassifies chat messages you type for signs of trouble with the productOutside the EEA
WhopPayments, memberships and credit top-ups; sign-in with Whop if you choose it; advertising attribution only with marketing consent, stopping immediately when you withdraw itUnited States
StripePayments for older subscriptionsUnited States
ResendSending account, billing and product emailsUnited States
CrispSupport chat, only after you allow functional cookiesFrance (EU)
Google (Analytics, Ads, Tag Manager), Meta (Pixel), Microsoft (Clarity), RewardfulAnalytics, advertising measurement and affiliate tracking, only with your consentUnited States
Google, GitHubSign-in, if you choose to sign in with them. GitHub also receives repository requests if you connect a GitHub repositoryUnited States
DiscordInternal notifications of bug reports to our team: your email, user ID, report title and description, page address, browser details and a link to the screenshotUnited States
CaptAPIFetches the transcript of a public YouTube, TikTok, Instagram, X or Facebook video when you give the AI chat its link; only the link is sentOutside the EEA
Your broker (for example Tradovate)Receives your orders and returns account data, only if you connect itDepends on the broker
OpenRouter or another AI provider whose key you addOnly if you add your own API key: your requests then go to that provider under your own account and its termsDepends on the provider

Market data comes from Databento and CME; we send them no personal data. We may also disclose data when the law requires it, to protect our rights or users' safety, or to a buyer in a merger or acquisition, who would remain bound by this policy.

6. Transfers outside the EEA

Our database and stored files are in the EU. Some providers above process data in the United States or other countries outside the European Economic Area. For these transfers we rely on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. Requests to our platform AI models are not sent to AI hosts in China. You can ask us for a copy of the safeguards at info@roboquant.dev.

7. How long we keep data

DataRetention
Account, profile, strategies, indicators, files, chats, backtests, optimizations, settingsUntil you delete them or your account
Compliance records: terms and age confirmation, checkout withdrawal acknowledgements, withdrawal requests, market-data attestations, account-deletion receiptKept after account deletion to establish, exercise or defend legal claims (Art. 17(3)(e)). The deletion receipt holds a one-way SHA-256 hash of your email, not the email itself. No automatic expiry is set today
Credit wallet and usage ledgerDeleted with your account, except usage-request records kept for accounting under your former account ID, with no name or email
Invoices, receipts and payment dataKept by Whop or Stripe under their own policies and legal obligations; we do not keep separate invoices
Bug reports and their screenshotsResolved and closed reports and their screenshots are deleted automatically about 12 months after the report was last updated (a daily job). Screenshots are stored at a public but unguessable web address
Cancellation survey answersDeleted with your account
Email used to claim the free starter creditWe keep only a one-way SHA-256 hash of the email, after account deletion and for as long as the free-credit offer runs, to prevent repeat claims. Older credit ledger entries created before this change contain the email in plain text and are deleted with your account
Early-access list entry and pre-order records (email)Access list entries are kept as a record of who was granted access; pre-order payment records are kept for accounting
Affiliate records, if you were an affiliatePayout details and payout method are erased on deletion; the referral code and commission history stay as financial records
Database backupsDaily database backups and transaction logs are kept for about 400 days, then deleted automatically (in Ireland, with a copy in Frankfurt, Germany)
Server logs15 days
Support chat history (Crisp)Until you ask us to delete it
Your cookie choice12 months (other cookies: see the Cookie Policy)

8. Your rights and how to use them

You have the right to access, correct, erase, restrict and port your data, to object to processing based on legitimate interest, and to withdraw consent at any time without affecting earlier processing. Most of this works directly in the app under Settings → Privacy & data (open Settings from your profile menu or the sidebar):

  • Download my data: a ZIP file with your account data, content, chats, backtests, your compliance records and your strategy and indicator files. Passwords, tokens and API keys are replaced with "[redacted]". Your sign-in provider links and session history are not in the file; ask us and we will send them.
  • Delete account: we email you a confirmation link and delete the account when you open it. This removes your account, strategies, indicators and their files (including all stored versions), chats, backtests, optimizations, chart layouts, broker connections and saved API keys. Stop running bots and cancel a renewing subscription first; the app tells you if something blocks deletion. What we keep after deletion is listed in section 7.
  • Product update emails: switch them on or off here, or use the unsubscribe link in any email.
  • Cookie settings: change or withdraw your cookie consent.

For anything else, including correcting data you cannot edit yourself, or if you cannot use the app, write to info@roboquant.dev. We answer within one month (extendable by two months for complex requests, in which case we tell you why) and may ask you to confirm your identity. Deleting your account here does not delete an account you may hold on Roboquant Connect or the earlier Roboquant 1.0 platform; write to us and we will handle those too.

9. Security

  • Traffic is encrypted with TLS. Stored files and database backups are encrypted at rest.
  • Broker credentials are encrypted with a managed key. Your own AI provider keys are kept in an encrypted secrets store, not in the database.
  • Two-factor authentication (authenticator app, set up by scanning a QR code, plus backup codes) protects email-and-password sign-in. If you sign in with Google, GitHub or Whop, that provider's own security applies; if you sign in with an email link, access to your mailbox protects the account.

No system is perfectly secure. If a personal data breach is likely to put your rights at high risk, we will tell you without undue delay.

10. Age

The Service is only for people aged 18 or older. You confirm this when you create an account. If you believe someone under 18 has an account, write to info@roboquant.dev and we will delete it.

11. Complaints

Please contact us first so we can help. You also have the right to complain to a data protection authority, in particular in the EU country where you live or work. Our lead authority is the Commissioner for Personal Data Protection, Cyprus (dataprotection.gov.cy).

12. Changes to this policy

When we change this policy we update the date above and summarise the change at the top of this page. We tell registered users about material changes by email.