Privacy Policy
No lawyer has reviewed this document. It was written by the people building EDGEDESK and must be reviewed, revised, and executed by an attorney licensed in the State of Florida before a single paid subscription is accepted. Nothing in it is legal advice to anyone.
Nothing is being sold against this version — the checkout gate refuses a paid subscription while these documents are unexecuted. The early-access list is open, though, and it does collect: an email address, the plan you looked at, your IP address, your browser, and a record of the acknowledgements you ticked against these draft versions. Section 2 describes that record exactly, including the one part of it that does not exist yet.
It is published now in the spirit of the product: nothing hidden, nothing surprising at checkout.
- We sell nothing about you. No data brokers, no advertising trackers, not now and not later.
- Your card never touches our servers. Stripe handles payment; we see only whether a subscription is active.
- Your journal, your positions, and your private diligence are yours. They are never published, and nothing from them ever goes into the shared signal feed.
- When you ask the Analyst something, we send our model provider what the question needs: the market’s data, its rules, and the state of your desk — never a picture of your screen, never your payment details.
- Exchange keys are encrypted and trade-scoped — they can place and cancel your orders, never move your money — and deleting one turns execution off instantly.
- We keep one category of record longer than everything else, on purpose: proof of what you agreed to and when. Section 2 says exactly what that is and why deleting it would hurt you as much as us.
- One email gets your data out or gone. Write to support and we export or delete it.
The sections below are the binding version. This summary exists so that none of it arrives as a surprise.
1. What we collect
- Account: your email address (used for magic-link login) and plan status.
- Billing: handled by Stripe. Card numbers never touch our servers; we store only the subscription state Stripe reports.
- Exchange API keys (optional): encrypted at rest, Trade-scoped keyAn exchange key limited to the permissions the desk actually needs — placing and canceling your orders and reading your own positions. It cannot withdraw or move money, and you can delete it at any time., used solely to transmit orders you authorize. Never used to read more than the product needs (positions, balances, order status). Deletable by you at any time; deleting them disables execution instantly.
- Usage: product events (pages, features, Analyst credit usage) and your desk settings (bankroll, Kelly fraction, guard toggles) so the product works and so guard states can be shown on your private order log. A credit record stores which action ran, on which market, when, and how many credits it cost — not the text of what you asked. That text lives with your research below, visible only to you.
- Technical and security data: your IP address, browser and device type, and timestamps, captured when you sign in, when you accept an agreement, when you connect or delete an exchange key, and when you switch on anything that can place an order. We collect it to secure accounts, to detect abuse, and to make the records in section 2 mean something.
- Your research: your trade journal, conviction inputs, and private Analyst diligence results are stored for you and shown only to you.
- Support: what you write to us, so we can answer it.
We do not ask for, and do not want, your name, address, date of birth, government identifiers, or bank details. Your exchange holds those; we do not need them.
2. Agreement records — the one thing we keep longer
When you accept an agreement, or switch on something that can place an order, we record what you accepted — not merely that you clicked.
The record holds: the version identifier and a cryptographic hash (a fingerprint of the exact text) of each document you accepted, the exact wording of each box you ticked together with a hash of that wording, the time, your IP address, your browser, and which gate it was (subscribing, connecting an exchange key, enabling a standing authorization, or re-accepting a changed document). The hash of a box’s wording and the hash of a whole document are separate things, and the record carries both rather than letting either stand in for the other.
A frozen copy of each published version belongs in that record too, so the page you actually saw can be reproduced rather than approximated. That archive is not built. The note below names it as something checkout cannot open without, and it is described here as something intended rather than something already running behind this page.
These records are deliberately excluded from the deletion schedule in section 11 and are kept for the period in section 11 even after you cancel. A deleted consent record is an unenforceable agreement — which cuts both ways: without it, neither of us could later prove what was or was not agreed, including the protections the agreement gives you. If you ask us to delete your data, these records are what remains, and we will tell you so.
These are separate facts and this page keeps them apart on purpose. Nothing is being sold under this draft — the checkout gate refuses a paid subscription while these documents are unexecuted. A record is kept even so. Joining the early-access list runs through the same consent gate, and from the first submission onward the server writes down what was accepted: the version in force, the documents it named, a hash of each of those documents taken from the published files themselves, the exact wording of every box ticked with a hash of that wording, the time, your IP address, and the browser that sent it. If you have joined that list, one of these records describes you, and this policy governs it. One promised element is not built yet: the frozen copy of each published version. Checkout cannot open until it is built — it is a promise, not a description of today — and it is the only part of this section that describes something still to come.
They are used for one purpose only: establishing what was agreed. They are never used for marketing, never sold, and never shared except as section 7 describes.
3. What we do with it
Run the service, bill you, secure accounts, keep proof of what was agreed, improve the product in aggregate, and meet legal obligations. That’s it. We do not use your data to train models on your identity, we do not profile you for advertising, and we make no automated decision about you that produces a legal or similarly significant effect.
4. What we never do
- We never sell your personal data, and we never share it for cross-context behavioral advertising.
- We never publish your positions, journal, or private diligence.
- Your private research never feeds the shared signal feed.
- We never trade against you, never share or sell your order flow, and never take payment for it.
- Whether anyone here trades the same markets alongside you is a different question, and it is answered in section 20 of the Risk Disclosure rather than left to this list.
- We never take a screenshot of your screen or read anything outside this product.
5. What the Analyst sends out, exactly
When you press Ask or Run Diligence, we send our AI model provider a structured description of what the question is about: the market and its exchange-published settlement rules, current quotes and book depth, the screen you are on, your position in that market if you hold one, the risk settings that shape the answer, and your question itself. Structured text — never a screenshot of your screen. It never includes your payment details, and your email address is not part of the request.
Queries are processed to produce your answer and are not used to train models on your identity. The market data and rules text inside a request are public exchange information. The written result comes back to your account as private research under section 1 and is shown only to you.
6. Third parties
Stripe (payments), our hosting provider (infrastructure), our email provider (login links and receipts), and our AI model provider (Analyst queries are processed to generate answers; they are not used to train models on your identity). Each receives only what its function requires, under a written agreement limiting what it may do with it. We do not sell data to any of them and they are not permitted to sell it either.
7. When we disclose data for legal reasons
We may disclose data where we are legally required to — a valid subpoena, court order, or lawful demand — or where it is necessary to establish or defend a legal claim, to enforce the Subscriber Agreement, or to protect the rights or safety of a person. If a business transfer occurs (a merger, acquisition, or sale of assets), data may move with it under this policy.
Where the law allows us to tell you about a demand for your data before we respond to it, we will.
8. Where data is held
The Service is operated from the United States and data is stored and processed there. If you use it from elsewhere, you are sending your data to the United States, whose privacy laws differ from your own. The Service is offered to United States subscribers; see section 6 of the Subscriber Agreement for who may subscribe.
9. Cookies
Essential cookies for login and preferences, and nothing else. No third-party advertising trackers, no cross-site tracking pixels, and no consent banner — because there is nothing to consent to beyond what makes login work.
10. Security
Encryption in transit and at rest, trade-scoped keys, per-account kill switch, access logging, and least-privilege access internally. No system is perfectly secure, and we do not claim otherwise. If a breach affects your data we will notify you as the law requires and as honesty demands, with what we know, when we know it.
11. Retention and deletion
- Account, usage, and research data — kept while your account is active and for 90 days after cancelation, so you can come back or export your journal, then deleted on request or on schedule.
- Exchange API keys — deleted immediately when you delete them, and on account closure.
- Billing records — kept as long as tax and accounting law requires.
- Agreement records under section 2 — kept for [RETENTION PERIOD] after the subscription ends, which must be at least the period in which a claim could still be brought. These survive a deletion request, and we will tell you exactly what was kept.
- Backups — deleted data persists in encrypted backups until they rotate out.
Email support@edgedesk.co to access, export, correct, or delete your data.
12. Children
The Service is not for anyone under 18 and we do not knowingly collect data from anyone under 18. If we learn we have, we delete it. See section 6 of the Subscriber Agreement.
13. Your controls, and where each one lives
- Spend cap — account settings. On by default; it stops Analyst credit spending at the monthly line you set, and it is yours to raise, lower, or switch off.
- Exchange API key — account settings. Deletable in one action; deleting it disables execution instantly.
- Kill switch — per account. Disables execution immediately without deleting anything.
- Anything that re-runs on a schedule, or that can place an order, is a toggle you switched on and can switch off in the same place you found it.
- Export, correction, or deletion — email support@edgedesk.co and we act on the request.
- Marketing email — one-click unsubscribe. Account, billing, security, and agreement-change notices are not marketing and continue for as long as you have an account.
14. State privacy rights
Depending on where you live, you may have the right to know what personal data we hold about you, to get a copy of it, to correct it, to delete it, and to not be discriminated against for exercising any of those rights. We extend these rights to every subscriber regardless of state, because operating two standards is worse than operating the better one.
To exercise any of them, email support@edgedesk.co from the address on your account. We respond within [RESPONSE DAYS] days. If we decline a request we tell you why, and you may appeal by replying to that answer; an appeal gets a written decision. Section 11 explains the one category we keep regardless.
We do not sell personal data and we do not share it for targeted advertising, so there is no opt-out to operate for either — there is nothing to opt out of.
15. Changes to this policy
Every version carries a version number and a date, shown at the top of this page. Corrections and clarifications take effect on publication. If a change materially affects what we collect, what we do with it, or who receives it, we email you before it takes effect and ask you to accept the new version in the product — and if you would rather not, you can cancel before it applies and we refund the unused part of any period you paid for. Section 30 of the Subscriber Agreement governs.
16. Contact
Questions, requests, and complaints: support@edgedesk.co, or by mail to Edge Solutions LLC, Attn: Privacy, [NOTICE ADDRESS]. The data controller is Edge Solutions LLC — the same entity named in section 1 of the Subscriber Agreement, and unnamed for the same reason.
Open items for counsel
Not part of the policy; present only while this document is a draft.
- Which privacy statutes apply given a US-only consumer subscription product — the Florida Digital Bill of Rights and its applicability thresholds, and the other state statutes that reach us by subscriber residence rather than by our size.
- The retention number in section 11 for agreement records. It must exceed the limitations period in section 24 of the Subscriber Agreement by a sensible margin, and it must be defensible against a deletion request.
- Deletion versus proof. Confirm the section 2 carve-out is drafted correctly: a deletion right that erased the consent record would erase the agreement with it.
- IP capture at each gate — confirm collecting and retaining it for consent evidence is properly disclosed here and proportionate.
- The AI provider relationship — processor terms, the no-training representation in sections 5 and 6, and whether the desk-state fields sent with a question need narrowing.
- Response window in section 14, and whether an appeal process is required or merely good practice.
- Breach notification mechanics under Florida law and the other states in scope.