Privacy Policy · version v0.2 · 2026-08-29
Draft — pending review by counsel. Written in our own words from a structure checklist; the operating entity, governing law and dispute forum are shown as placeholders until counsel confirms them. Nothing here has been presented to any user for acceptance yet.
Privacy Policy
This explains what Greeks Vault (Green Bucks, Frisco, Texas, USA) collects about you, why, how long we keep it and what you can do about it.
1. What we collect
- Account: name, e-mail, password (stored only as a salted hash), plan, sign-in times, IP address of sign-ins, and — if you enable it — a two-factor secret and hashed backup codes.
- Profile and knowledge check: your answers to the options-experience questions and the result.
- Your work on the Platform: bots, strategies, drafts, watchlist, backtests, simulator sessions, paper positions and their history.
- Broker connection: for Schwab, the OAuth tokens Schwab issues for your account (encrypted at rest) and a masked account hint; we never see or store your Schwab password. For IBKR, the login you give us for the Gateway session we run for you (encrypted at rest) — see the Broker Connection Agreement.
- Technical: server logs (request paths, timestamps, IP), error logs, and the audit trail of admin actions on your account (grants, holds, demo extensions), with the reason the admin wrote.
- Payment: when billing is enabled it is handled by a payment provider; we store what they return (plan, status, last four digits at most), never full card numbers.
2. Why
To run the Platform for you; to submit orders you configured to your broker; to keep your account secure; to meet legal, tax and data-licensing obligations; to support you; and to improve the Platform using aggregated, non-identifying statistics. We do not sell personal data and we do not use it for advertising.
3. Who sees it
- Our staff, on a need-to-know basis. Admin actions on your account are logged with the actor's identity.
- Service providers we rely on: hosting, e-mail delivery, market-data and archive providers, and your broker (only what the connection needs). Each is bound to use data only to provide their service.
- Authorities, where the law requires.
4. Where and how long
Data is stored on our servers (currently hosted in the United Kingdom) and backed up off-site. We keep account and trading records while your account exists and for as long afterwards as law, tax or dispute needs require (typically up to seven years for trading records); server logs are rotated on a shorter cycle. Broker tokens are deleted when you disconnect.
5. Your rights
You can see and update your profile in Settings, disconnect a broker at any time, turn two-factor on or off, and ask us to export or delete your account data (subject to records we must keep). Requests: support@greeksvault.com. Depending on where you live you may have further rights (access, correction, erasure, portability, objection) and the right to complain to a supervisory authority.
6. Security
HTTPS everywhere; passwords hashed; broker secrets encrypted with a server-side key; session cookies HttpOnly and Secure; optional TOTP two-factor; rate limits on sign-in and code entry. No system is perfectly secure — report anything suspicious to us immediately.
7. Changes
We will post the new version here with a new date and, for material changes, tell you by e-mail or in the Platform.