Privacy policy

What personal data we collect and why, who receives it, how long we keep it, what deleting your account removes and keeps, and your rights.

Draft — not yet reviewed by a lawyer. Details in [brackets] are placeholders.

Effective [Effective date]

1. Who is responsible for your data

[Company legal name] (registration number [Company registration number]), [Registered address], is the controller of your personal data. That means we decide how and why it’s used, and we’re responsible for protecting it.

For anything about your data, contact [Privacy contact email].

2. The short version

  • We collect what we need to run your account and your tests: your email address, a hash of your password, sign-in records including your IP address and browser, what you submit, and your subscription status.
  • We use only the cookies needed to sign you in. No advertising, analytics or tracking cookies.
  • We don’t sell your personal data or use it for advertising.
  • AI features send what you type, and the strategy or results they need, to Google’s Gemini API — without your name, email address or IP address.
  • Deleting your account removes your sign-in details, but your run records — and, unless you delete them first, much of what you submitted — stay, stored under a random ID. That is pseudonymous data, not anonymous data — see Deleting your account.
  • You can ask for a copy of your data, or for it to be corrected or deleted, at [Privacy contact email].

3. What we collect

Here is everything we collect, grouped by where it comes from.

Account details

  • Your email address.
  • A hash of your password, made with scrypt and a random salt. We never store the password itself. Accounts created with Google have no password.
  • When you created the account, and when you verified your email address.
  • A display name, if you choose to set one.
  • A random account ID. It isn’t derived from your email address, and it links your account to everything you submit.

Sign-in with Google

If you sign in with Google, Google sends us your Google account ID, your email address and whether Google has verified it, together with the basic profile details its sign-in shares, such as your name. We store only the Google account ID and the email address, and update the email address each time you sign in with Google. We don’t store your name or other profile details.

Sessions and security records

  • For each sign-in: your browser’s user-agent string (which identifies the browser and operating system), the IP address the sign-in came from, when it started, when it was last used, and when it expires — 30 days after you signed in. The Security tab of your account lists your active sessions, with the device, IP address, and when each started and was last used.
  • The codes in the one-time links we email you to verify your address (valid for 24 hours) and to reset your password (valid for 1 hour). We store only a hash of each code.
  • A log of sign-in and account attempts, used to stop repeated attempts: the email address, IP address or account ID involved, the action, whether it succeeded, and when.

What you submit

  • Strategies: their names, specifications, and any plain-English descriptions you write.
  • Runs: the specification, plan, cost settings and description you ran with, any AI summary, and the full result — the scorecard and every simulated trade.
  • Saved settings: validation configurations (a name and your minimum sample sizes and profit factor) and cost profiles (a name, broker, account type, commission and spread settings).
  • Forward-test registrations: the strategy specification, symbols, timeframe, plan and status, and the trades recorded after you registered.
  • Custom indicators: the Python source code you submit, and details about it.
  • Charts: chart files built from your runs — price bars, indicator values and your trades.

Some things stay on your device. A trade CSV file you load to compare with a run is read in your browser and never uploaded; we keep only a summary of counts. Prop-challenge simulations are calculated when you ask and kept only temporarily in server memory; they aren’t saved to our databases.

Free-text fields hold whatever you type into them, so please don’t put personal information in them.

AI conversations

When you use an AI feature, we pass your messages, and the context the feature needs, to our AI provider to get an answer (see Who receives your data). We don’t save the conversations on our servers. If you apply an AI draft and run it, its description and summary become part of that run’s record.

Billing

  • If you buy a plan: which plan, its status, renewal, end and trial dates, whether it’s set to cancel, and the IDs [Payment provider] uses for you and your subscription.
  • The notifications [Payment provider] sends us about your purchases and subscription. We keep each one exactly as received. They can include your email address and account ID, and other purchase details that [Payment provider] chooses to send.
  • We never receive your full card number.

What we don’t collect

We don’t ask for your date of birth, identity documents or postal address. We don’t connect to your broker or trading accounts. We don’t use analytics, advertising or tracking tools, and we don’t collect your location beyond the IP address described above.

4. Why we use it, and our legal basis

Data-protection law requires a legal basis for each way we use your data. These are ours.

Providing the service
Creating and running your account, signing you in, running your tests, storing your strategies and results, and the AI features. Basis: performing our contract with you.
Emails about your account
Verifying your email address and resetting your password — the only emails we send. We don’t send marketing email. Basis: our contract with you.
Security and abuse prevention
Session records, IP addresses and browser details, and the attempt log — to protect accounts, stop repeated sign-in attempts, prevent fraud and abuse, and investigate problems. Basis: our legitimate interest in keeping the service and your account secure.
Payments and subscriptions
Starting checkout, keeping your plan in step with your subscription, and cancelling it if you delete your account. Basis: our contract with you and, where we are the seller, our legal obligation to keep tax and accounting records.
Keeping the research ledger intact
Keeping every trial record, including after an account is deleted, so the multiple-testing accounting at the heart of the method can’t be undone by deleting results. Basis: our legitimate interest in the integrity of the method — see Deleting your account.
Answering you
Replying when you contact us, and handling requests about your data. Basis: our legitimate interest in helping you, and our legal obligations.

We don’t rely on your consent for anything today. If we ever ask for it, you’ll be able to withdraw it at any time.

To open an account you need to give us an email address and a password, or use Google; without them we can’t provide the service. Everything else you submit is up to you.

We don’t make decisions about you based only on automated processing that have legal or similarly significant effects on you. A verdict is an automated assessment of a strategy, not of you.

5. Who receives your data

We share personal data only with the service providers below, and only what each one needs.

Google — sign-in
Only if you choose Sign in with Google. Your browser goes to Google to sign in, and Google sends us the details listed above.
Google — Gemini API (AI features)
When you use an AI feature, we send Google your messages and the context that feature needs, listed below. A strategy specification includes the name you gave the strategy. We don’t send your name, email address, account ID or IP address; Google sees our server’s address, not yours.
  • Strategy drafting: your messages, the indicators you picked, the current strategy specification, and a list of your past trials of that strategy (trial number, symbol, and verdict or failing checks).
  • Scorecard questions: your messages and a summary of the run — its verdict, checks and the reasons behind them, your account’s total trial count, trade statistics, past trials, and the specification.
  • Indicator adaptation: the code or descriptions you paste, and the current draft.
  • Methodology check: the strategy specification.
Email delivery provider
Currently Resend. It receives your email address and the content of the verification or password-reset email.
Payment provider
[Payment provider]. When you check out, we send it your account email address and account ID, so the payment can be matched to your account. You give your payment details to it directly. We also ask it for your subscription details to open its billing portal, and to cancel your subscription if you delete your account.
Hosting provider
[Hosting provider and region]. It runs our servers, databases and file storage, so it holds all the data described on this page.
Authorities and advisers
Courts, regulators or law enforcement when the law requires it, and our professional advisers, such as lawyers and accountants, under a duty of confidentiality.

Market-data providers get nothing about you. When a run needs price data we don’t already hold, our servers request it with our own credentials and no identifier of yours.

We don’t use advertising, analytics or error-monitoring services.

6. International transfers

Some of these providers are based outside the European Economic Area (EEA), or may process data there — for example Google and our email delivery provider, and possibly [Payment provider] and [Hosting provider and region]. When your data leaves the EEA, we protect it with [Transfer safeguards].

You can ask for a copy of these safeguards at [Privacy contact email].

7. How long we keep it

These are the periods the service applies today. Where a record has no automatic clean-up yet, we say so.

Sign-in sessions
Until you sign out or end the session on the Security tab, until a password change or reset ends it, or until you delete your account. A session that has simply expired isn’t removed automatically yet: its record, including the IP address and browser details, stays until you change or reset your password or delete your account.
Attempt log
At least 24 hours. Entries older than that are removed from time to time, not on a fixed schedule. When you delete your account, entries under your email address go at once; entries under an IP address or your account ID wait for the next clean-up.
Strategies, configurations and cost profiles
Until you delete them. Deleting a strategy also deletes the stored inputs and results of its runs, but not its trial records or scorecards. If you delete your account without deleting them first, they’re kept (see Deleting your account).
Trial records and scorecards
Indefinitely, including after you delete your account. This is the research ledger.
Custom-indicator code
Indefinitely. There’s no way to delete it yet. Submitting the same indicator again replaces its current version, but the record of each earlier submission, with its code, is kept too.
Forward-test registrations
Indefinitely. You can withdraw a registration but not delete it. An active registration keeps recording trades until you withdraw it — even after you delete your account.
Chart files
Indefinitely. They aren’t removed automatically.
Subscription record
Until you delete your account.
Payment notifications
Indefinitely, including after you delete your account. They contain your email address.
Server logs
Our servers write operational logs. They can include your account ID (inside run identifiers) and, when something fails, part of a response from Google or [Payment provider]. How long logs are kept depends on [Hosting provider and region].

8. Deleting your account

You can delete your account on the Security tab: choose Delete account, then type your email address to confirm. If a paid plan is still live, we cancel its renewal with [Payment provider] first. If we can’t, the deletion stops and you’re asked to cancel from the billing portal.

What’s deleted straight away

  • Your account details: email address, password hash, display name and verification dates.
  • Your Google link, all your sessions (with their IP addresses and browser details), and your email-link codes.
  • Your subscription record, and the attempt-log entries under your email address.
  • On the device you delete from, the settings the app saved in your browser.

What stays

  • The research ledger: every trial record — including the plain-English descriptions and AI summaries — and every stored scorecard, with its trades.
  • Your saved work, unless you delete it first: strategies (with the inputs of their runs), validation configurations and cost profiles.
  • Custom-indicator code: every version you submitted.
  • Forward-test registrations and their recorded trades. Active registrations keep recording new trades after your account is gone, unless you withdraw them first.
  • Chart files built from your runs.
  • Payment notifications from [Payment provider], which contain your email address and account ID.
  • Attempt-log entries under your IP address or account ID, until the next clean-up, and server logs for as long as they’re kept.

Why we keep the ledger

Kurzharr’s method counts every trial an account runs, and each scorecard shows a deflated-Sharpe figure adjusted for that count. That’s what keeps a lucky result among many tries from looking like a real edge. For the count to mean anything, trials can’t be erased — not by deleting a strategy, and not by deleting an account.

Pseudonymous, not anonymous

What stays is stored under your random account ID, not your email address. That isn’t the same as anonymous: the ID appears inside each run’s identifier, descriptions contain whatever you typed, and if you ever paid for a plan, the payment notifications we keep link the ID to your email address. So the law still treats these records as your personal data, and the rights below still apply to them. If you want them erased too, email [Privacy contact email] and we’ll assess your request under data-protection law.

Before you delete: delete any strategies, configurations and cost profiles you don’t want kept, and withdraw your forward-test registrations.

9. Cookies and browser storage

We use only cookies that are strictly necessary to sign you in and keep sign-in secure. We don’t use advertising, analytics or tracking cookies, and no third-party scripts set cookies on our pages. Our fonts are served from our own servers, so loading a page doesn’t contact Google Fonts.

Cookies we set

kurzhaar_session
Keeps you signed in. Lasts 30 days. Scripts on the page can’t read it, and in the live service it’s sent only over HTTPS.
google_oauth_state and google_oauth_verifier
Protect Sign in with Google against forged requests. Last 10 minutes.
google_oauth_next
Remembers which page to return you to after Sign in with Google. Lasts 10 minutes.

Browser storage

The app also saves a few things in your browser’s local storage, so it remembers your choices between visits. Unlike cookies, they aren’t sent to us with each request.

kurzhaar-user
Your account ID, email address and display name, so the app can show who’s signed in.
kurzhaar-validation-configs and kurzhaar-cost-profiles
Which saved validation configuration and cost profile you last selected.
kurzhaar-universe
The asset class, timeframe and date range you last picked.
kurzhaar-prop-challenge
Your prop-challenge preset, custom rules and risk percentage.
kurzhaar-equity-assumptions
The account size and risk percentage you entered for equity views.
kurzhaar-nav
Whether the sidebar is open.

Signing out clears your account ID, email address and display name from this storage. The other settings stay on that device until you delete your account from it, or clear your browser’s storage.

10. Your rights

Under the GDPR, you have the right to:

  • access your personal data and get a copy;
  • correct it if it’s wrong or incomplete;
  • erase it, in the cases the law provides;
  • restrict how we use it, in some cases;
  • take it with you in a machine-readable format (portability);
  • object to our using it on the basis of legitimate interests;
  • withdraw consent at any time, where we rely on it;
  • complain to a data-protection authority — ours is [Supervisory authority] — or to the authority where you live or work.

To use any of these rights, email [Privacy contact email]. We’ll reply within one month. We may need to confirm it’s you first, usually by asking you to write from your account’s email address.

What you can do yourself

  • See and end your active sessions, change your password, and delete your account, on the Security tab.
  • Change your display name on the Profile tab.
  • Unlink Google from your account, as long as you still have another way to sign in.
  • Delete strategies, validation configurations and cost profiles, and withdraw forward-test registrations.

Some things you can’t do yourself yet: download a copy of your data, change your email address, or delete a custom indicator. Email us and we’ll help.

11. How we protect your data

  • Passwords are stored only as salted scrypt hashes. Session tokens and email-link codes are stored only as hashes.
  • The session cookie can’t be read by scripts on the page, and in the live service it’s sent only over HTTPS.
  • Sign-in, sign-up, password resets and account deletion are rate-limited.
  • Sign in with Google uses state checks and PKCE to block forged sign-ins.
  • Every request for your account’s data is checked against your session, and our internal services authenticate each other with a secret key.

No system is perfectly secure, and we don’t offer two-factor authentication yet. If a breach puts your data at risk, we’ll tell you and the authorities where the law requires.

12. Children

Kurzharr isn’t for anyone under 18, and we don’t knowingly collect data from children. If you think a child has opened an account, contact [Privacy contact email] and we’ll delete the account.

13. Changes to this policy

We’ll publish any update here with a new effective date. If a change matters to you, we’ll also tell you by email or in the app before it takes effect.

14. Contact

Privacy questions and requests: [Privacy contact email]. By post: [Company legal name], [Registered address]. Supervisory authority: [Supervisory authority].