Your data

Privacy Policy

Version 0.9.0 · draft /Not executed /Effective date: set on execution Drafted July 21, 2026 · revised August 2, 2026
Draft · not executed · do not rely on this

No lawyer has reviewed this document. It was written by the people building EDGEDESK and must be reviewed, revised, and executed by an attorney licensed in the State of Florida before a single paid subscription is accepted. Nothing in it is legal advice to anyone.

Nothing is being sold against this version — the checkout gate refuses a paid subscription while these documents are unexecuted. The early-access list is open, though, and it does collect: an email address, the plan you looked at, your IP address, your browser, and a record of the acknowledgements you ticked against these draft versions. Section 2 describes that record exactly, including the one part of it that does not exist yet.

It is published now in the spirit of the product: nothing hidden, nothing surprising at checkout.

Version 0.9.0-draft · status: draft · pending Florida counsel · matches the legal-version meta tag on this page
In plain English
  • We sell nothing about you. No data brokers, no advertising trackers, not now and not later.
  • Your card never touches our servers. Stripe handles payment; we see only whether a subscription is active.
  • Your journal, your positions, and your private diligence are yours. They are never published, and nothing from them ever goes into the shared signal feed.
  • When you ask the Analyst something, we send our model provider what the question needs: the market’s data, its rules, and the state of your desk — never a picture of your screen, never your payment details.
  • Exchange keys are encrypted and trade-scoped — they can place and cancel your orders, never move your money — and deleting one turns execution off instantly.
  • We keep one category of record longer than everything else, on purpose: proof of what you agreed to and when. Section 2 says exactly what that is and why deleting it would hurt you as much as us.
  • One email gets your data out or gone. Write to support and we export or delete it.

The sections below are the binding version. This summary exists so that none of it arrives as a surprise.

Part 1What we hold

1. What we collect

We do not ask for, and do not want, your name, address, date of birth, government identifiers, or bank details. Your exchange holds those; we do not need them.

2. Agreement records — the one thing we keep longer

Why this category is different

When you accept an agreement, or switch on something that can place an order, we record what you accepted — not merely that you clicked.

The record holds: the version identifier and a cryptographic hash (a fingerprint of the exact text) of each document you accepted, the exact wording of each box you ticked together with a hash of that wording, the time, your IP address, your browser, and which gate it was (subscribing, connecting an exchange key, enabling a standing authorization, or re-accepting a changed document). The hash of a box’s wording and the hash of a whole document are separate things, and the record carries both rather than letting either stand in for the other.

A frozen copy of each published version belongs in that record too, so the page you actually saw can be reproduced rather than approximated. That archive is not built. The note below names it as something checkout cannot open without, and it is described here as something intended rather than something already running behind this page.

These records are deliberately excluded from the deletion schedule in section 11 and are kept for the period in section 11 even after you cancel. A deleted consent record is an unenforceable agreement — which cuts both ways: without it, neither of us could later prove what was or was not agreed, including the protections the agreement gives you. If you ask us to delete your data, these records are what remains, and we will tell you so.

These are separate facts and this page keeps them apart on purpose. Nothing is being sold under this draft — the checkout gate refuses a paid subscription while these documents are unexecuted. A record is kept even so. Joining the early-access list runs through the same consent gate, and from the first submission onward the server writes down what was accepted: the version in force, the documents it named, a hash of each of those documents taken from the published files themselves, the exact wording of every box ticked with a hash of that wording, the time, your IP address, and the browser that sent it. If you have joined that list, one of these records describes you, and this policy governs it. One promised element is not built yet: the frozen copy of each published version. Checkout cannot open until it is built — it is a promise, not a description of today — and it is the only part of this section that describes something still to come.

They are used for one purpose only: establishing what was agreed. They are never used for marketing, never sold, and never shared except as section 7 describes.

3. What we do with it

Run the service, bill you, secure accounts, keep proof of what was agreed, improve the product in aggregate, and meet legal obligations. That’s it. We do not use your data to train models on your identity, we do not profile you for advertising, and we make no automated decision about you that produces a legal or similarly significant effect.

4. What we never do

Part 2Where it goes

5. What the Analyst sends out, exactly

When you press Ask or Run Diligence, we send our AI model provider a structured description of what the question is about: the market and its exchange-published settlement rules, current quotes and book depth, the screen you are on, your position in that market if you hold one, the risk settings that shape the answer, and your question itself. Structured text — never a screenshot of your screen. It never includes your payment details, and your email address is not part of the request.

Queries are processed to produce your answer and are not used to train models on your identity. The market data and rules text inside a request are public exchange information. The written result comes back to your account as private research under section 1 and is shown only to you.

6. Third parties

Stripe (payments), our hosting provider (infrastructure), our email provider (login links and receipts), and our AI model provider (Analyst queries are processed to generate answers; they are not used to train models on your identity). Each receives only what its function requires, under a written agreement limiting what it may do with it. We do not sell data to any of them and they are not permitted to sell it either.

7. When we disclose data for legal reasons

We may disclose data where we are legally required to — a valid subpoena, court order, or lawful demand — or where it is necessary to establish or defend a legal claim, to enforce the Subscriber Agreement, or to protect the rights or safety of a person. If a business transfer occurs (a merger, acquisition, or sale of assets), data may move with it under this policy.

Where the law allows us to tell you about a demand for your data before we respond to it, we will.

8. Where data is held

The Service is operated from the United States and data is stored and processed there. If you use it from elsewhere, you are sending your data to the United States, whose privacy laws differ from your own. The Service is offered to United States subscribers; see section 6 of the Subscriber Agreement for who may subscribe.

9. Cookies

Essential cookies for login and preferences, and nothing else. No third-party advertising trackers, no cross-site tracking pixels, and no consent banner — because there is nothing to consent to beyond what makes login work.

Part 3Keeping and removing

10. Security

Encryption in transit and at rest, trade-scoped keys, per-account kill switch, access logging, and least-privilege access internally. No system is perfectly secure, and we do not claim otherwise. If a breach affects your data we will notify you as the law requires and as honesty demands, with what we know, when we know it.

11. Retention and deletion

Email support@edgedesk.co to access, export, correct, or delete your data.

12. Children

The Service is not for anyone under 18 and we do not knowingly collect data from anyone under 18. If we learn we have, we delete it. See section 6 of the Subscriber Agreement.

Part 4Your rights

13. Your controls, and where each one lives

14. State privacy rights

Depending on where you live, you may have the right to know what personal data we hold about you, to get a copy of it, to correct it, to delete it, and to not be discriminated against for exercising any of those rights. We extend these rights to every subscriber regardless of state, because operating two standards is worse than operating the better one.

To exercise any of them, email support@edgedesk.co from the address on your account. We respond within [RESPONSE DAYS] days. If we decline a request we tell you why, and you may appeal by replying to that answer; an appeal gets a written decision. Section 11 explains the one category we keep regardless.

We do not sell personal data and we do not share it for targeted advertising, so there is no opt-out to operate for either — there is nothing to opt out of.

15. Changes to this policy

Every version carries a version number and a date, shown at the top of this page. Corrections and clarifications take effect on publication. If a change materially affects what we collect, what we do with it, or who receives it, we email you before it takes effect and ask you to accept the new version in the product — and if you would rather not, you can cancel before it applies and we refund the unused part of any period you paid for. Section 30 of the Subscriber Agreement governs.

16. Contact

Questions, requests, and complaints: support@edgedesk.co, or by mail to Edge Solutions LLC, Attn: Privacy, [NOTICE ADDRESS]. The data controller is Edge Solutions LLC — the same entity named in section 1 of the Subscriber Agreement, and unnamed for the same reason.

Open items for counsel

Draft-only section — removed on execution

Not part of the policy; present only while this document is a draft.

  1. Which privacy statutes apply given a US-only consumer subscription product — the Florida Digital Bill of Rights and its applicability thresholds, and the other state statutes that reach us by subscriber residence rather than by our size.
  2. The retention number in section 11 for agreement records. It must exceed the limitations period in section 24 of the Subscriber Agreement by a sensible margin, and it must be defensible against a deletion request.
  3. Deletion versus proof. Confirm the section 2 carve-out is drafted correctly: a deletion right that erased the consent record would erase the agreement with it.
  4. IP capture at each gate — confirm collecting and retaining it for consent evidence is properly disclosed here and proportionate.
  5. The AI provider relationship — processor terms, the no-training representation in sections 5 and 6, and whether the desk-state fields sent with a question need narrowing.
  6. Response window in section 14, and whether an appeal process is required or merely good practice.
  7. Breach notification mechanics under Florida law and the other states in scope.