This Privacy Policy explains how Quant24 Inc. ("Quant24", "we", "us") collects, uses, shares and protects personal data when you visit quant24.io (the "Site"), use the web application at beta.quant24.io (the "App"), join our waiting list, apply to a program or write to us (together, the "Service").
The short version: we collect what the Service needs to work and nothing that belongs at your broker. We never ask for brokerage passwords, bank logins, card numbers, government identifiers or identity documents. We do not sell personal data, and we do not use it for advertising.
Scope and who is responsible
Quant24 Inc., a Delaware corporation, is the controller of the personal data described in this Policy. You can reach us at b.caldera@quant24.io.
This Policy covers the Site, the App and our communications. It does not cover your broker, futures commission merchant or proprietary-trading firm, our payment processor's own pages, or any third-party site we link to; each of them has its own privacy notice.
The English version of this Policy governs. Translations, where we provide them, are for convenience only. This Policy forms part of our Terms of Service.
Information we collect
We collect the categories below. Where a category is marked planned, the feature does not exist yet and we will update this Policy before it does.
Waiting list (Site)
When you join the waiting list we store your email address, the role you pick (retail trader, builder or fund), the language of the form, whether you opted in to marketing email, the source of the sign-up, the date, your IP address and your browser's user-agent string. Older versions of the form also asked for a name and a country; if you provided them, we still hold them. The IP address is also used, briefly and in memory only, to limit the number of sign-ups per address.
The waiting-list form on the App (beta.quant24.io) stores less: your email address in lower case, a name and a country if you give them, whether you opted in to the one message we send when Sandbox opens, the source of the sign-up, the date, and whether the confirmation email went out (its status and the identifier our email provider returns). It does not store your IP address or your browser's user-agent string. Each sign-up also sends us the internal notice described under Applications, contact forms and support below, with the source of the sign-up in place of a message. There is one record per email address: signing up twice tells you that you are already on the list and writes nothing new.
Account (App)
When you create an account we store your email address, the time it was verified, and, if you sign in with Google, the name, profile image and account identifier that Google shares with us together with the tokens needed to keep that sign-in working. We do not store passwords: sign-in works with a one-time link sent to your email, or through Google. Sessions are kept in a signed cookie.
Product data (App)
What you write to the Strategist (goals, questions, strategies you bring), the assumptions and Goal Specs derived from it, the candidate strategies, the results of the validation engine, the Strategy Packages, Evidence Ledgers and reports generated for you, your approvals and pauses, and the event log of any strategy you run. During pre-launch all market data involved is synthetic and none of this data refers to a real brokerage account.
Consent and product-analytics records (App)
We record each consent you give or refuse (cookies, marketing, terms) with its version and date, tied to your account or, before you sign in, to an anonymous identifier. If you allow product analytics, we record events about how you use the App (for example, that a validation run finished) with the properties needed to understand the funnel. Nothing is recorded for analytics before you consent.
In this build the only consent recorded in the consent log is the one from the cookie banner; your marketing opt-in on the waiting list is kept with the waiting-list record itself, without a version or a date of its own. The q24_consent cookie holds your choice (analytics on or off), the date, the version of the Cookie Policy in force when you chose and a random identifier; the same choice is written to our database under that identifier, with no name, email or account attached, so that we can show a choice was made without knowing who made it. Site analytics is not configured in this build: accepting it records the choice and loads nothing until a Cloudflare Web Analytics key exists, and this Policy will say so when it does.
Billing (App, planned)
When paid plans launch, payments will be handled by Stripe. Stripe collects your card details directly on its own pages; we receive and store a customer identifier, the plan you chose, the status of your subscription and invoices. We never see your full card number.
Applications, contact forms and support
If you apply to the Founder Program or the Creator Program, contact us as an investor or journalist, or write to support, we keep what you send us (name, email, message, links you include) and our correspondence with you.
On the App, each form writes one record to our database: the kind of form, your email address in lower case, your name, the fields as you sent them with surrounding spaces removed, the time, a status we use to track the reply, and whether the confirmation email was sent (its status and the identifier our email provider returns). The record does not hold the consent checkbox, the token of the human check or your IP address. The human check itself is Cloudflare Turnstile, which runs between your browser and Cloudflare. The widget sends Cloudflare your IP address and browser signals (user-agent, TLS fingerprint) directly, as Cloudflare's Turnstile privacy addendum describes, and Cloudflare also uses those signals to improve Turnstile; it does not read what you type into the form. We then send Cloudflare the token it issued and your IP address once, so that the token can be verified.
We receive an internal email at the founders' address with your name, email, country, the time and the first three hundred characters of your message; a founder reads it and answers you. We keep a submission until the matter it opened is closed or you ask us to delete it, and in no case longer than we keep the correspondence around it (see the retention table below). To have it deleted, write to b.caldera@quant24.io from the address you used. Never put credentials in a form: we do not need passwords, API keys, card numbers or broker logins, and the form refuses a message that looks like it contains one.
Technical data and logs
Our hosting providers keep server logs with IP address, requested URL, timestamps, referrer and user-agent for security and debugging. The App also keeps structured application logs that include your account identifier and the identifier of the strategy session involved, so that a problem can be traced. Error-monitoring, when enabled, will capture stack traces and the request context of failures.
To limit how many times a form can be submitted from one connection, we count submissions for ten minutes after each submission against a key derived from your IP address: the address is first truncated (its last part is dropped, so the key names a block of addresses rather than a device) and then hashed. The counter lives in a short-lived store, expires on its own, and is never written to the database or to the record of your submission; the key does not contain the address, and we do not try to work it back.
Brokerage connections (App, planned)
Broker connections do not exist yet. When they do, we will store the access credentials or tokens that your broker or its technology vendor issues for third-party software, encrypted, together with the account identifiers and order and position data needed to run and audit an approved strategy. We will publish the details in this Policy before enabling the feature.
What we do not collect
- brokerage passwords, bank or card logins, or card numbers in forms we control;
- Social Security numbers, tax identification numbers, dates of birth or identity documents (identity verification, where required, is done by your broker, not by us);
- precise geolocation, biometric data or the contents of your device;
- data from data brokers, and data for advertising profiles.
How we use information
We use personal data to:
- run the Service: create and secure your account, turn your goals into strategies, validate them, store and show your results, and, when available, execute approved strategies and bill your subscription;
- keep an audit trail: the Evidence Ledger, approvals and event logs exist so that every decision the software made can be reconstructed, for you and, where required, for a regulator;
- communicate with you: waiting-list confirmations, security and risk notices, changes to the Service or to these documents, replies to your messages, and, only if you opted in, product news;
- protect the Service: detect abuse, rate-limit sign-ups, investigate incidents and enforce the Terms;
- improve the Service: understand how features are used, in aggregate, and only for product analytics you have consented to;
- comply with law: respond to lawful requests, keep records we are required to keep, and establish or defend legal claims.
We do not use your personal data or your prompts to train machine-learning models, and we select model providers whose documented terms exclude training on customer data. We do not make decisions about you by automated means that have legal or similarly significant effects; the App's outputs are tools you choose whether to act on.
Legal bases (EEA, UK and similar laws)
Where a data-protection law requires a legal basis for each use, ours are:
| Use | Legal basis |
|---|---|
| Providing the Service and billing | Performance of our contract with you |
| Waiting-list confirmation and service notices | Performance of the contract, or our legitimate interest in running the Service |
| Answering your application or message | Steps you ask for before any contract, or our legitimate interest in answering you |
| Marketing email | Your consent, which you can withdraw at any time |
| Product analytics | Your consent |
| Security, abuse prevention and logs | Our legitimate interest in keeping the Service safe |
| Audit trail of strategies and approvals | Our legitimate interest and, where applicable, a legal obligation |
| Record keeping, legal requests, claims | Legal obligation, or our legitimate interest in defending claims |
How AI processing handles your prompts
The Strategist and the Executor use large language models. Your prompts, the Goal Spec derived from them and the context the model needs are sent through Cloudflare AI Gateway to the model that handles the task: models run on Cloudflare Workers AI for conversation and drafting, and Anthropic's Claude models, through the same gateway, for reasoning tasks. The gateway logs requests for reliability and cost control; we configure its retention to the minimum the operation needs.
Model providers process your data under their own terms. Retention is the criterion we select on: we choose providers whose documented terms for API use exclude training on customer data and offer zero-data-retention or an equivalent commitment, and we cite each provider's retention terms only as that provider documents them. What binds a provider is that provider's own terms and whatever we have signed with them, not this sentence. We do not send your email address, account identifiers or billing data to the models.
Numbers are never produced by a model. Backtests, probabilities and metrics are calculated by our own code on our infrastructure.
Cookies and similar technologies
There is one list of cookies, and it is not on this page. The Cookie Policy carries it: what this build sets today, what is planned and the feature each one arrives with, in the same table. It is the page we keep up to date, and it is the page to read — a second table here would drift from it, which is exactly what happened before.
What holds regardless of the list: no cookie is used for advertising or cross-site tracking; non-essential cookies and analytics are off by default and switched on only if you accept them in the consent banner, and you can change that choice at any time. The Site also stores one value in your browser's local storage — your language choice — which never leaves your device and is not a cookie. Stripe sets its own cookies on its checkout and billing pages, on Stripe's domain rather than ours, described in Stripe's privacy notice.
Who receives your data
We share personal data only with the service providers below, who process it on our instructions to run the Service, and with authorities when the law requires it. We do not sell personal data, and we do not share it for cross-context behavioral advertising.
| Provider | What they do for us | Data involved | Where |
|---|---|---|---|
| Cloudflare | Hosts the App (Workers, D1 database, R2 storage, KV, Queues), runs Workers AI and AI Gateway, the human check on forms (Turnstile), DNS and network security | All App data, prompts, logs; for the human check, your IP address and browser signals, which Cloudflare also uses to improve Turnstile | Global network; data stored in the United States |
| Vercel | Hosts the Site and its waiting-list functions | Waiting-list submissions in transit, server logs | United States |
| Supabase | Database for the waiting list | Waiting-list records | United States |
| Resend | Sends transactional and waiting-list email; keeps an audience list for waiting-list contacts | Email address, name if given, message content | United States |
| Sign-in with Google, if you choose it | Google account identifier, name, image, email | Google's regions | |
| Anthropic | Language models for reasoning tasks, via Cloudflare AI Gateway | Prompts and strategy context, no identifiers | United States |
| Stripe (planned) | Payments, subscriptions and invoices | Name, email, card data collected by Stripe, subscription status | United States |
| Error monitoring (planned) | Captures application errors | Stack traces, request context, account identifier | To be confirmed before launch |
We may also disclose personal data:
- to comply with a law, regulation, subpoena or lawful request, including requests from the CFTC, the SEC or a self-regulatory organization if the Service becomes subject to their rules;
- to protect the rights, safety and property of Quant24, our users or the public, including to investigate fraud or security incidents;
- to a successor in a merger, acquisition or sale of assets, under this Policy and with notice to you;
- with your direction, for example when you connect a broker, the broker receives the orders your approved strategy generates.
International transfers
We are based in the United States and our providers store data there. If you use the Service from the European Economic Area, the United Kingdom, Switzerland or another jurisdiction with transfer rules, your data is transferred to the United States. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) with our providers, or on a provider's certification under an approved framework.
Data retention
We keep personal data only as long as the purpose requires, and then delete or de-identify it. Our current periods:
| Data | How long |
|---|---|
| Waiting-list record | Until you ask us to remove it, or 24 months after general availability, whichever is first |
| Account data | While your account is open, then deleted within 30 days of closure, subject to the rows below |
| Product data (goals, packages, ledgers of strategies that never traded) | While your account is open; you can delete them earlier; deleted with the account |
| Audit trail (approvals, orders, risk events, ledgers of strategies that traded) | At least 5 years after the strategy stops, or longer if a commodities-law record-keeping rule applies to us |
| Consent records | 5 years after the consent is withdrawn or the account closed; kept without your identifier |
| Product-analytics events | 24 months, then aggregated or deleted |
| Billing records and invoices | 7 years, as tax and accounting law requires |
| Server and application logs | 30 to 90 days, depending on the log |
| Support and application correspondence | 3 years after the last message |
| AI Gateway request logs | The minimum the operation needs; to be confirmed before launch |
Your rights
Everyone
You can ask us to access, correct, delete or export your personal data, to restrict or object to certain uses, and to withdraw a consent you gave (withdrawal does not affect processing that already happened). Write to b.caldera@quant24.io from the email address on your account, or use the account settings in the App when they are available. We answer within 30 days, and we may ask you to confirm your identity in a way that does not require documents we do not otherwise hold.
You can unsubscribe from marketing email with the link in every message. Service and security notices are not marketing and continue while you have an account.
California residents
Under the California Consumer Privacy Act you have the right to know what personal information we collect, use and disclose, to delete it, to correct it, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined in the CCPA, and we do not use sensitive personal information to infer characteristics about you. You may designate an authorized agent to make a request on your behalf.
EEA, UK and Swiss residents
You have the rights listed above under the GDPR and the UK GDPR, and the right to lodge a complaint with the supervisory authority of your country of residence or of the place where the issue arose. If we rely on legitimate interests you may object, and we will stop unless we have compelling grounds to continue.
Other jurisdictions
Where your local law gives you rights over your personal data, you can exercise them by writing to us; we apply the rights above to everyone as a baseline.
Security
Data is encrypted in transit (TLS) and at rest by our providers. Secrets and access tokens are stored in the platform's secret store and never in our source code. Access to production data is limited to the founders and to the automated systems that need it, and administrative access requires strong authentication. The App's design keeps sensitive things out of our hands by construction: no passwords, no card numbers, no brokerage logins.
No system is perfectly secure. If you find a vulnerability, please write to b.caldera@quant24.io and give us a reasonable time to fix it before disclosing it.
Children
The Service is for adults. We do not knowingly collect personal data from anyone under 18 (or under the age of majority where they live). If you believe a minor has given us personal data, write to us and we will delete it.
Data breaches
If a security incident affects your personal data, we will investigate, contain it, and notify you and any authority that must be notified without undue delay and within the deadlines that apply to us. We will tell you what happened, what data was involved and what we are doing about it.
Changes to this Policy
We version this Policy (major.minor.patch) and keep every version. A change that adds a category of data, a new provider or a new purpose is at least a minor version and is announced to account holders by email before it takes effect; a change that affects sensitive data or your rights is a major version with at least 14 days' notice. The date at the top of this page is the date of the current version.
While this document is marked DRAFT, it has not yet been reviewed by our counsel and may change before general availability.
Contact
Quant24 Inc., a Delaware corporation. Email: b.caldera@quant24.io. Put "privacy" in the subject line so that your request reaches the right person quickly.
Quant24 is not a registered investment adviser, commodity trading advisor, broker-dealer or futures commission merchant. The product is under development. No real-money trading is being executed. All visualizations, demos and results are simulated and labeled SYNTHETIC. Any past performance referenced is illustrative and does not guarantee future results. Futures trading involves substantial risk of loss, including the possibility of losing more than your initial investment. Nothing in this communication constitutes investment advice or an offer or solicitation of securities.