Privacy Policy
Last updated July 18, 2026
This policy explains what data Quantreno collects, why, who it is shared with, and the choices you have. The short version: we collect what the service needs to run, we encrypt your trading-venue credentials, we do not sell your data, and we do not run advertising.
1. What we collect
Account data. Your email address and a password (stored only as a salted hash), or your basic Google profile (name, email) if you sign in with Google.
Trading-venue credentials. The API credentials you supply to connect a venue (for example Kalshi or Alpaca). They are encrypted at rest with AES-256-GCM and used only to operate your connection.
Trading data. The budgets and limits you set, the proposals drafted for you, your approvals and rejections, the orders placed, and your resulting positions and performance — plus the account data those venues report back (balances, positions, fills).
Chat and AI activity. Your conversations with the agent, the briefs and research generated for you, and a record of each AI call (for audit and cost accounting).
Technical data. Server logs (such as IP address and request metadata, for security and debugging) and aggregate, cookieless usage analytics via Vercel Analytics.
2. How we use it
We use this data to:
- run the service — research, draft proposals, and place, monitor, or cancel the orders you approve;
- enforce the budgets and risk limits you set at the moment of placement;
- keep the record straight — an auditable history of trades, briefs, and AI activity;
- secure the service and prevent abuse; and
- understand aggregate usage and improve the product.
We do not sell your personal data, and we do not use it for third-party advertising.
3. AI processing
Chat messages and research requests are processed by third-party AI model providers, reached through an AI gateway: the model you select in the product, plus a small set of fixed helper models the service itself uses (naming chats, drafting documents, the research analyst). Only models on the product's own allowed list can be selected — anything else is rejected before it reaches a provider. The providers currently behind all of these are Anthropic, Google, OpenAI, and xAI (a list generated from that same allowed list, so it stays in step with every path your content can take). We send what the request needs — your messages and the relevant trading context — and those providers process it under their own terms.
4. Who we share data with
- Your trading venues — the orders you approve are sent to the venue through the credentials you supplied; that is the point of the service.
- Infrastructure providers — hosting, database, and storage (the service runs on Vercel), which process data on our behalf.
- AI model providers — as described in section 3.
- Market-data and web-search providers — research queries are sent to fetch prices, news, and sources; these queries do not include your identity.
- Legal — if required by law, or to protect the service and its users.
5. Cookies
Quantreno sets a session cookie to keep you signed in. Your theme preference is stored in your browser. There are no advertising or cross-site tracking cookies; the analytics are cookieless and aggregate.
6. Security
Data is encrypted in transit (TLS). Venue credentials are encrypted at rest with AES-256-GCM; passwords are stored only as salted hashes. Access to production systems is restricted. No system is perfectly secure — if a breach affects your data, we will notify you as the law requires.
7. Retention
We keep your data while your account is active. Trading records and the audit history are kept as long as needed for accurate books and legal obligations. When your account is closed (you can request this at any time — section 8), we delete or anonymize your personal data except what those obligations require us to keep.
8. Your choices and rights
You can disconnect a trading venue at any time (and revoke its credentials at the venue itself). You can ask us to access, correct, export, or delete your personal data — email support@quantreno.com and we will respond as your local law requires (including the CCPA for California residents and the GDPR where it applies).
9. Children
Quantreno is for adults. It is not directed at anyone under 18, and we do not knowingly collect data from them.
10. Changes to this policy
We may update this policy as the product evolves. The "Last updated" date at the top reflects the current version, and material changes will be announced with reasonable notice.
11. Contact
Quantreno is operated by AutEng, Inc., a Delaware corporation. Questions about privacy: support@quantreno.com. See also the Terms of Service.