Privacy Policy

Effective Date: March 24, 2026

Section 1Information We Collect

We collect information that you provide directly and information generated through your use of the Platform:

  • Account Information — name, email address, and password when you register
  • Profile Data — subscription tier, preferences, and settings you configure
  • Broker Credentials — API keys and tokens for connected broker accounts (stored encrypted)
  • Trading Data — strategies, backtests, trade history, portfolio positions, and risk configurations
  • Usage Data — pages visited, features used, session duration, device type, browser, and IP address
  • Payment Information — billing details processed securely through Razorpay (we do not store full card numbers)

Section 2How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve the Platform and its features
  • To execute trades and manage broker connections on your behalf
  • To process payments and manage your subscription
  • To send transactional emails (order confirmations, account alerts, security notifications)
  • To analyze usage patterns and optimize Platform performance
  • To detect, prevent, and address fraud, abuse, or technical issues
  • To comply with legal obligations and enforce our Terms of Service

We will never sell your personal data to third parties.

Section 3Data Security

We take the security of your data seriously and implement industry-standard measures to protect it:

  • All data transmitted between your browser and our servers is encrypted via TLS/SSL (HTTPS)
  • Passwords are hashed using bcrypt with unique salts — we never store plaintext passwords
  • Broker API credentials are encrypted at rest using AES-256 encryption
  • Database backups are encrypted and stored in secure, access-controlled environments
  • Access to production systems is restricted to authorized personnel with multi-factor authentication

While we strive to protect your data, no method of transmission or storage is 100% secure. You acknowledge and accept this inherent risk.

Section 4Broker Data

When you connect a broker account (Upstox, Dhan, Fyers, AngelOne, ICICI Direct, Kotak Neo, or Alpaca), we access and store certain data:

  • API Keys & Tokens — stored encrypted and used exclusively for executing your authorized trading operations
  • Account Information — account ID, available margin, and holdings retrieved for portfolio display
  • Order & Trade Data — order history and execution details for trade tracking and performance analytics

We access your broker account only to perform operations you have explicitly initiated or configured (e.g., automated strategy execution). We do not share your broker credentials with any third party.

Section 5Third-Party Services

We integrate with the following third-party services, each governed by their own privacy policies:

  • Razorpay — payment processing for subscriptions (Razorpay Privacy Policy)
  • Anthropic (Claude AI) — AI-powered stock screening, analysis, and Deep Research
  • Broker APIs — Upstox, Dhan, Fyers, AngelOne, ICICI Direct, Kotak Neo, Alpaca for trade execution
  • NSE/BSE Data Feeds — real-time and historical market data

We only share the minimum data necessary for each service to function. We do not share your personal information with third parties for their marketing purposes.

Section 6Data Retention

We retain your data for as long as your account is active or as needed to provide services:

  • Account Data — retained for the lifetime of your account plus 30 days after deletion
  • Trading Data — trade history and backtest results retained for 3 years for analytics and regulatory compliance
  • Usage Logs — server logs and analytics data retained for 12 months
  • Payment Records — transaction records retained for 7 years as required by Indian tax law

When you delete your account, we will remove your personal data within 30 days. Some data may be retained in anonymized form for aggregate analytics.

Section 7Your Rights

You have the following rights regarding your personal data:

  • Access — request a copy of all personal data we hold about you
  • Correction — update or correct inaccurate personal information from your profile
  • Deletion — request complete deletion of your account and associated data
  • Export — download your trading data, strategies, and portfolio information in standard formats
  • Restriction — request that we limit how we process your data
  • Objection — opt out of non-essential data processing at any time

To exercise any of these rights, contact us at support@quantzenai.com. We will respond to your request within 30 days.

Section 8Cookies & Tracking

We use cookies and similar technologies to enhance your experience:

  • Essential Cookies — required for authentication (JWT tokens), session management, and core Platform functionality
  • Preference Cookies — store your UI settings, theme preferences, and dashboard layout
  • Analytics Cookies — help us understand how users interact with the Platform to improve features and performance

We do not use third-party advertising or retargeting cookies. You can manage cookie preferences through your browser settings. Note that disabling essential cookies may prevent the Platform from functioning correctly.

Section 9Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.

  • We will notify registered users of material changes via email at least 7 days before they take effect
  • The "Effective Date" at the top of this page will be updated with each revision
  • Continued use of the Platform after changes constitutes acceptance of the revised policy

We encourage you to review this page periodically to stay informed about how we protect your data.

Section 10Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

support@quantzenai.com

We are committed to resolving any privacy concerns promptly and transparently. For complaints that remain unresolved, you may contact the relevant data protection authority in your jurisdiction.