DRAFT — not reviewed by a lawyer. These are our privacy policy and terms of service as they stand today, published during the closed beta so you can read them before you rely on the service. Neither has been reviewed by external legal counsel; when that review happens we will post the reviewed version here with a new date. Each document states its own status in its opening paragraphs. Questions: write to info@asbab.me or use our contact form — both reach the founders.

Privacy Policy

About this policy. This is the privacy policy for the Institutional Alpha System. It is a working document published during our closed beta so that anyone can read what we collect and why before they ask for access; it is pending review by external legal counsel, and we will post a new version here when it changes. It is written to Canadian PIPEDA standards.

Who we are. This service is operated by Sohaib Mohiuddin and Asrar Mohiuddin, carrying on business in partnership ("we", "us"), under the names Asbab and Institutional Alpha System — Asbab is the business, the Institutional Alpha System is the terminal it operates. Under PIPEDA an organization includes a partnership, and that partnership is the organization accountable for the personal information described here. We are based in Canada.

How to reach us about privacy. Our Privacy Officer is accountable for this policy and for answering questions, access requests and complaints about it. Write to info@asbab.me, or use the contact form on our *Contact us* page — both reach the founders. We have not published a telephone number or a business mailing address because we have not confirmed either, and we would rather leave a field blank than print one that does not reach a person.

Scope. This policy covers the web application and its sign-in, alerting and support surfaces. Our beta is offered in Canada and the United States; when we expand beyond that, the GDPR/CCPA-readiness note in *GDPR / CCPA readiness* applies.

1. What we collect, and why

DataPurposeLawful basisRetention
Email addressSign-in (passwordless magic links or Google sign-in), account administration, service noticesContract (providing the account)Life of account
Google account basic profile (email, name) — only if you choose "Continue with Google"Creating/matching your account. Limited Use: Google user data is used solely for sign-in, never for advertising, and never transferred except as needed to provide sign-in (per the Google API Services User Data Policy)ContractLife of account
Two-factor authentication secret (if you enable 2FA)Verifying your authenticator codes. Held by our identity service; we never collect biometricsContract (security feature you enable)Until you disable 2FA
Public contact-form submissions (your message, and your email address — required if you are requesting access, optional otherwise)Reading and answering you. And, if your message is a beta-access request and a founder approves it, adding your address to our sign-in allowlist so you can reach the app — see the invitation row below — and emailing you to say so, and emailing you a sign-in link whenever you ask to sign in, because a link we email you is how signing in works here — there is no password (see the email-address row above). Your message is stored in our admin panel and a notification is pushed to the founders' private operations channel on Telegram. A contact submission is never filed as a GitHub issue, and is never used to send you marketing; that approval message and those sign-in links are the only emails we ever send youConsent (you send the message)Message and the copy of your address stored with it: deleted 60 days after we last handled it — see *How the 60 days is measured* in Data retention. An approved address on the sign-in allowlist is retained until you or we remove it — it is what grants access, so it deliberately outlives the message. The approval email leaves a delivery record with the providers that carry our mail, on their own schedules
Invitation and access-grant records (invitee email — entered by a founder or taken from an approved public access request — plus the redemption/grant record)Operating invite-only registration and beta accessLegitimate interest (controlled access)Invite *tokens* purge ≤35 days after use/expiry; the per-email access grant is retained for the life of the access — nothing expires it automatically, and it survives deletion of the request that produced it
Bug reports (your description, optional contact email, page/browser/screen context)Fixing the problems you report. Reports are stored in our admin panel; they may also be filed as an issue in our private GitHub repository, and a notification is pushed to the founders' private operations channel on Telegram so a report is seen quickly. That notification contains the first 200 characters of your description, the page you were on, and the contact email you supplied (or "anonymous" if you supplied none). This happens whether or not you have connected Telegram to your account — it is a message to *us*, not to youConsent (you submit the report)Admin store: deleted 60 days after we last handled it — see *How the 60 days is measured* in Data retention. A GitHub issue persists until the founders close or delete it; the Telegram notification persists in the founders' private chat history until deleted
Product feedback you choose to send (a 1–5 rating; an optional note of up to 1000 characters; your account email address only if you tick the follow-up box, which is unticked by default)Understanding how the product is working for you and improving it. Stored in our admin panel, and a notification containing an extract of your note and — if you ticked the box — your email address is pushed to the founders' private operations channel on Telegram. Feedback is never filed as a GitHub issue, and is never used to send you marketing. We also record which screen you sent it from, your theme and window size, how many sessions you had had, and whether we prompted you or you started it yourself. We do not record which tickers you were looking atConsent (you choose to send it; the email address is separately consented and is taken from your signed-in session, never typed in)No fixed period yet. The automated deletion for this store is not built, so a submission is retained until we delete it by hand; ask us and we will
Sign-in security records: a masked form of your email address (its first letter and its domain), and the list of countries your account has signed in fromDetecting account compromise. When you sign in from a country your account has not signed in from before, a notification is pushed to the founders on Telegram, carrying that masked address, the country, and the city our hosting platform reports for the connection. It is sent because you signed in — not because you sent us anything, and whether or not you have ever connected Telegram to your accountLegitimate interest (account security)The country list: life of account. The Telegram notification: until the founders delete it from their private Telegram history
Sampled access log: IP address, approximate city-level location (from hosting-platform headers), browser type, page areaSecurity, audit, abuse preventionLegitimate interest (security)60 days, then deleted automatically
Anonymous session identifier (random, not linked to your account)"Online now" counter, capacity planningLegitimate interest (operations)Hours
Watchlist, notes, and alert preferencesProviding the service you configuredContractLife of account
Chart drawings and indicator selections — the levels, dates and shapes you draw on a chart (including the entry, target and stop levels of a risk-and-reward drawing), and the indicators and parameters you chooseDrawing on a chart and choosing indicators. These are kept by your browser on the device you used; we do not hold a copy, so a different browser or machine starts blank.Not applicable: this stays on your device.Until you clear your browser's storage for this site.
Operational metrics (pipeline runs, alert delivery outcomes, aggregate usage — and an active-day record: which days your account used the service, nothing about what you looked at)Keeping the service healthyLegitimate interest (operations)Active-day record: 60 days, then only the anonymous daily total survives. Other metrics: aggregated; bounded windows (pruned automatically)

We do not collect: payment card data (none in beta; at paid launch, payments are processed entirely by Stripe and card data never touches our systems), precise geolocation, advertising identifiers, or biometric data.

2. What we do not do

No advertising. No sale of personal information. No sharing with data brokers. No third-party analytics trackers or cross-site tracking. No profiling of you for marketing. Market analysis runs server-side on public market data — it is not built from your personal information (see *Automated decision-making*).

3. Service providers (data processors)

We use a small set of processors, each bound to process personal data only to provide the service. The table lists purpose, general processing location, and safeguard. Where we do not have a particular protection in place, the safeguard column says so rather than leaving you to assume it.

ProcessorWhat it does for us / what it may receiveProcessing locationSafeguard
SupabaseDatabase + authentication (identities, sessions, 2FA secrets, watchlist, preferences), and the store holding contact messages, bug reports and product feedback. Also composes and dispatches our outbound email: sign-in links, and the beta-access approval message, are built from templates held in Supabase Auth and handed by it to the mail-transport provider in the next row, so Supabase receives the recipient address and the message body and keeps its own send recordUnited States (`us-east-1`)the provider's standard data-processing terms, incorporated by reference into its terms of service — accepted on sign-up, not separately negotiated by us, and not independently verified (2026-09-03); the cross-border transfer is disclosed to you here under PIPEDA, which is our own act and does not depend on the provider
VercelApplication hosting + delivery; source of coarse geolocation headersGlobal edge network, with locations outside Canadathe provider's standard data-processing terms, incorporated by reference into its terms of service — accepted on sign-up, not separately negotiated by us, and not independently verified (2026-09-03)
GoogleTwo separate uses. (a) "Continue with Google" sign-in, only if you choose it. (b) Mail transport for every message we send — sign-in links, and the beta-access approval message, leave Supabase (row above) through a Google SMTP service, which therefore receives your email address, the subject and the full message body, and keeps its own transport log on its own schedule. Use (b) applies to everyone we email, including people who never chose Google sign-inUnited States / globalUse (a): Google API Services User Data Policy (Limited Use); DPA. Use (b): encrypted in transit, and the cross-border transfer is disclosed to you here — but no separate data-processing agreement covers the mail-transport use today. We would rather tell you that than imply an agreement we do not have
AnthropicThe AI analyst. Our servers send it market data and our own engine's output — the ticker, sector, price, our scores and pattern state, the Shariah screen result, fundamentals, the earnings date, and the day's sector rotation — and it returns the written note you read. Verified at the single call site on 2026-09-02: the request carries no account identifier, no email address, no watchlist, no saved note, no chart drawing or indicator selection, and no text you wrote. It is listed here for completeness because it is a processor outside Canada that our servers call while serving you — not because it receives personal information about youUnited States / globalAnthropic's commercial API terms. Because the request carries none of your personal information — verified at the call site on 2026-09-02, and re-verified whenever what we send changes — no transfer of your personal information arises on this row. It is listed anyway, so that you can see what the AI analyst is and what it is given
SentryError monitoring — technical error data from application crashes and server errors only. Bug reports you submit are not sent to Sentry. No session recording, no personal profiles. Events pass through a server-side redaction filter that removes credential- and identifier-shaped values before transmissionUnited States (Sentry's US data region)the provider's standard data-processing terms, incorporated by reference into its terms of service — accepted on sign-up, not separately negotiated by us, and not independently verified (2026-09-03). The two safeguards that are ours rather than the provider's, and are therefore checkable: a data-minimal configuration, and a server-side redaction filter that strips credential- and identifier-shaped values before anything is transmitted
GitHubStores bug reports you submit as private-repository issues for founder triage (sanitized description + context, and the contact email you supplied). Contact-form messages and product feedback are never filed as issues — that is a fixed policy setting in the code, not a judgement call made per submissionUnited States / globalThe repository is private — that one is ours and is checkable. The data-processing terms are the provider's standard terms, incorporated by reference into its terms of service — accepted on sign-up, not separately negotiated by us, and not independently verified (2026-09-03). Best-effort: report intake does not depend on it
TelegramThree separate uses. (a) Alert delivery — only for accounts that choose to connect Telegram. (b) Founder operations notificationsfor all three things you can send us: a bug report, a contact-form message, or product feedback. In each case a notification containing an extract of what you wrote and the email address attached to it is pushed to the founders' private operations channel. (c) The sign-in security signal — when you sign in from a country your account has not signed in from before, a notification carrying a masked form of your email address (its first letter and its domain), the country, and the city our hosting platform reports for the connection is pushed to the founders. Uses (b) and (c) apply whether or not you have ever connected Telegram — they are messages to *us*, not to youGlobalUse (a) requires your explicit connection. Use (b) is disclosed here and occurs only when you choose to send us something. Use (c) is not something you choose — your own sign-in triggers it; it is disclosed here and in *What we collect, and why*. No controller-to-processor agreement covers uses (b) and (c)
Stripe — from paid launch; not in use during the betaSubscription payment processing; card data goes directly to Stripe and never touches our systemsUnited States / globalPCI-DSS compliance is Stripe's published certification; the data-processing terms are incorporated by reference into its terms of service — accepted on sign-up, not separately negotiated by us, and not independently verified (2026-09-03). Not in use during the beta, so nothing has been transferred under it yet.

*Market-data sources — Polygon, Alpaca, Financial Modeling Prep, Finnhub and the U.S. Securities and Exchange Commission's public EDGAR service (verified against the shipped adapters, 2026-08-05) — receive ticker requests from our servers, not your personal information: the request reaches them from us, not from your browser, and carries no identifier belonging to you. They are therefore not listed above as processors of your personal data. Whether we are licensed to redistribute what they return is a licensing question rather than a privacy one, and it is handled separately.*

4. International data transfers

We are Canada-based, but some processors listed above store or process data outside Canada (for example, in the United States). Under PIPEDA, personal information transferred to a third party for processing remains our responsibility — whatever agreement is or is not in place with that processor. Where we have contractual protections (a data-processing agreement, and standard contractual clauses where applicable), we rely on them to require a comparable level of protection. Where we do not, the safeguard column in the table above says so — today that is the mail-transport use and the founder notifications on Telegram. By using the service you understand that your information may be processed outside your province or country.

5. Your rights

Subject to applicable law, you may:

  • Access the personal information we hold about you and learn how it is used and to whom it has been disclosed;
  • Correct information that is inaccurate or incomplete;
  • Get a copy of that information in a commonly used file format. There is no self-serve export button in the app — we assemble the copy by hand and send it within the window below, and we would rather tell you that than point you at a control that does not exist;
  • Delete your account and associated personal information (see *Data retention* for what deletion removes and what security logs age out on their own schedule);
  • Withdraw consent where processing is based on consent (this may limit or end your ability to use the service);
  • Ask questions or complain about our handling of your information — and, if unsatisfied, escalate to the Office of the Privacy Commissioner of Canada (or your provincial regulator).

To exercise any right, write to info@asbab.me or use the contact form on our *Contact us* page. We will verify your identity (to protect your account) and respond within 30 days, which is the maximum PIPEDA allows; if we need more time or must decline a request, we will tell you why. There is no charge for a reasonable request.

6. Data retention (summary)

We keep personal information only as long as needed for the purpose collected or as law requires, then delete or de-identify it.

DataRetention
Account data (email, Google profile, watchlist, notes, preferences)Life of account; deleted on account deletion
Chart drawings and indicator selectionsNot kept by us. They stay in the browser you made them in, on that device, until you clear that browser's storage for this site. Deleting your account does not remove them, because we never held them
Two-factor secretUntil you disable 2FA
Contact-form submissions (admin store: your message + the address stored with it)Deleted 60 days after we last handled it — see *How the 60 days is measured* below this table
Contact-form submissions (Telegram operations notification to the founders)Until deleted from the founders' private chat history — the same posture as the bug-report notification row below
Sign-in allowlist grant (an address approved for beta access)Until you or we remove it. No automatic expiry: the grant is what lets an approved person sign in, so it deliberately outlives the request that produced it. Ask us and we will remove it
Email we send you — the records held by whoever carries the messageOn those providers' own schedules, outside our sweep. A third retention life, distinct from the 60-day admin copy and from the allowlist grant. There are two such records, not one: Supabase composes and dispatches the message and keeps a send record, and Google transports it and keeps its own log of the recipient address and the message. Both would be replaced, or re-scoped, by whatever carries our mail if we adopt an owned sending domain. We do not print a figure here, because we do not have a contracted one to print
Invitation recordsInvite *tokens* purge ≤35 days after use/expiry; the per-email grant is the allowlist row above
Bug reports (admin store)Deleted 60 days after we last handled it — see *How the 60 days is measured* below this table
Bug reports (GitHub issue copy)Until the founders close/delete the issue
Bug reports (Telegram operations notification to the founders)Until deleted from the founders' private chat history. No automated deletion reaches this copy; ask us and we will delete it
Product feedback (admin store: your rating, your note, and your email if you consented)No automated deletion exists for this store. Retained until we delete it manually. Ask us and we will. We are deliberately not printing a figure here: the neighbouring 60-day rows describe a sweep that does not match this data, and writing "60 days" would state a limit nothing enforces
Product feedback (Telegram operations notification to the founders)Until deleted from the founders' private chat history — the same posture as the two notification rows above. No automated deletion reaches this copy either; ask us and we will delete it
Sign-in country history + masked email (security)Life of account. The new-country notification pushed to the founders on Telegram persists in their private Telegram history until deleted
Sampled access log (IP, coarse location, browser)60 days from the day it was recorded, deleted automatically
Anonymous session identifierHours
Operational metricsAggregated; bounded windows, pruned automatically
Active-day record (which days your account used the service)60 days, then only the anonymous daily total survives
Breach records (PIPEDA s. 10.3)24 months from the date we determine a breach occurred

How the 60 days is measured — and where it does not yet work the way it should. For contact-form submissions and bug reports, the automatic deletion runs 60 days after the row was last handled, not 60 days after you sent it. Handling a row — reading it, or approving, declining or revoking an access request — restarts that 60-day period, so a message we keep coming back to is kept longer than one we do not. We are stating this plainly rather than printing a flat figure the system does not honour. We intend to change it so the period runs from the date you sent the message; until then, you can ask us to delete your message and we will. *(The sampled access log and the active-day record are not affected: those are recorded once and never rewritten, so their 60 days runs from the day of the record.)*

Deleting your account removes your email, watchlist, notes and preferences; bounded security and operational logs age out on the schedules above. Your chart drawings and your indicator selections are not on that list, because we never held them — they are in the browser you made them in, and clearing that browser's storage for this site is what removes them. Of the things we do hold, four copies of what you submitted are not reached by automated deletion — the private GitHub issue (bug reports only), the Telegram operations notification, any product feedback you sent (that store has no automated deletion at all), and, if you were approved for beta access, the sign-in allowlist entry holding your address, which has no automatic expiry by design. Nothing else. Ask us and we will delete all four; we are working toward covering the first three automatically.

7. Cookies & local storage

We use only what the service needs to work — no advertising or cross-site tracking cookies, and no third-party analytics trackers:

  • Essential cookies: your sign-in session cookie (host-scoped, HttpOnly) and short-lived security cookies used during sign-in (e.g., OAuth state/nonce, and the invite cookie). Without these, sign-in cannot work.
  • Local storage, kept only on that device: interface preferences such as theme, layout and colour choices, and your chart type and time interval. A phone can honestly want a different chart than a desktop, so these do not follow you.
  • Local storage, also kept only on that device: the drawings you make on a chart, and the indicators you choose. We hold no copy of either, so a different browser or a different machine starts blank.
  • Local storage, kept as a working copy of what your account holds on our server: your watchlist.
  • What signing out clears: signing out clears your watchlist and your chart drawings from that browser. Your indicator selection is not cleared by signing out — it stays on the device until the next selection made there replaces it.
  • None of it is a tracking identifier.

We do not use cookies to build advertising profiles or to follow you across other sites.

8. Automated decision-making

Our analysis engine computes grades, patterns, and statistics from public market data — it does not profile you and does not make automated decisions *about you* that produce legal or similarly significant effects.

The written analyst notes are produced by an AI model run by Anthropic (see *Service providers*). The same limit holds there, and it is a fact about the request we send, not a policy we intend to follow: what we send that model is market data and our own engine's output for a ticker or for the day's scan. It is the same note for every reader — it is not written about you, it is not adapted to you, and the request carries nothing that identifies you. Your watchlist, your notes and your chart drawings are never part of it. The notes are general information, not personalised advice, and nothing in this service is a recommendation to buy or sell anything.

The only automated processing that concerns your account is security — detecting a sign-in from a new country, rate-limiting, and abuse detection, which may trigger a security notice or temporarily limit access — and service measurement: we record which days your account used the service, keep that record for 60 days, and keep only the daily totals after that. It contains nothing about what you looked at, and no decision about you is made from it. Write to info@asbab.me with any question about these.

9. Children's and minors' data

The service is intended for adults and is not directed to children. We do not knowingly collect personal information from anyone under the age of majority in their province/territory (or, for a future US audience, under 13 per COPPA and under the applicable state age otherwise). If you believe a minor has provided us personal information, write to info@asbab.me and we will delete it.

10. Email

While in beta we send no marketing email at all. The only messages we send are sign-in links — one whenever you ask to sign in, because a link we email you is how signing in works here — and, if you requested beta access and a founder approves it, a message telling you so. We will not add you to a mailing list. Marketing email, if ever introduced, will be opt-in with a working unsubscribe and sender identification, per CASL.

11. GDPR / CCPA readiness (applies when we expand beyond CA/US)

Our beta is offered in Canada and the United States, so the EU/UK GDPR is not yet engaged. The CCPA/CPRA is a separate question and it does not turn on geography — California is inside the area we offer the beta in — so it turns on that statute's own thresholds (revenue, the number of California consumers whose personal information we handle, and the share of revenue from selling or sharing it). We are under all of them today, and we sell and share nothing. When we expand:

  • GDPR/UK GDPR (EU/UK users): we will identify a lawful basis per purpose, provide the full data-subject rights (access, rectification, erasure, restriction, portability, objection), name a transfer mechanism (adequacy/SCCs) for data leaving the EEA/UK, honor a 1-month response window, and assess whether a representative/DPO is required.
  • CCPA/CPRA (California users, if thresholds are met): we will provide notice-at-collection, the rights to know/delete/correct, and the right to opt out of "sale"/"sharing" — which we already satisfy in substance because we do not sell or share personal information (see *What we do not do*).

This section is a readiness note, not a present commitment for regions we do not yet serve.

12. Security

Transport encryption everywhere (TLS + HSTS), passwordless authentication (no password database exists), optional two-factor authentication, invite-only registration, bounded sign-in sessions (longer for 2FA-verified sessions), scoped server-side database credentials with per-tenant access checks, continuous dependency auditing and secret scanning, error monitoring without session recording, and bounded data retention. No system is perfectly secure; we will notify affected users and the Office of the Privacy Commissioner of Canada of any breach creating a real risk of significant harm, as PIPEDA requires, and we keep a record of every breach of security safeguards for 24 months — whether or not it is one we must notify you about — as the federal breach-record regulations require.

13. Changes

We will post changes here with a new effective date; material changes will be announced in-app.

14. How to reach us

Questions, requests, or complaints: write to our Privacy Officer at info@asbab.me, or use the contact form on our *Contact us* page. We have not published a postal address; we will add one here when we have confirmed it.

Effective date: 2026-09-02.


Terms of Service

Who we are. The Institutional Alpha System (the "service") is operated by Sohaib Mohiuddin and Asrar Mohiuddin, carrying on business in partnership in Canada ("we", "us", "our"). The business is not incorporated. If that changes, we will say so here.

What this is. These terms are the agreement between you and us about your use of the service. Read them together with the Privacy Policy on this page, which explains what personal information we hold, why we hold it, and what you can ask us to do with it.

Agreeing to these terms. By creating an account or using the service, you agree to these terms. If you do not agree, do not use the service.

They have not yet been reviewed by an external lawyer. These terms are the terms we operate under today and they apply to your use of the service now. We are publishing them during the closed beta because you are entitled to read them before you rely on the service, not because a lawyer has approved them. When that review has happened we will post the reviewed version here with a new date, and we will tell you in the app if anything material changes.

1. What the service is — and what it is not

The service is a research and education terminal for publicly traded securities. It computes statistics, detects chart patterns, replays historical market data, draws charts, and produces written analysis. You can also do your own work in it — choose indicators, draw lines and levels on a chart, and keep a watchlist.

Analysis, not advice. We publish general-audience market research and education. Nothing here is a recommendation to buy, sell or hold any security, nothing is tailored to your circumstances, and no adviser-client relationship is created. We are not registered as an investment adviser, dealer or broker in any jurisdiction. Trading involves substantial risk of loss — you are responsible for your own decisions, and you should consult a licensed professional before acting.

The written notes describe method, not action. Our written analysis, including the notes produced by an AI model, is built from public market data and from our own engine's output. It is the same note for every reader: it is not written about you, it is not adapted to your holdings or your objectives, and it does not tell you what to do. If you ask the service a question, it explains how something is measured; it does not tell you what to buy.

Anything you draw is your own arithmetic, not our recommendation. Where the service computes something from levels you placed yourself — an entry, a target, a stop, a reward-to-risk ratio — every number in it came from you. We do the arithmetic on your inputs. We are not proposing the trade, and a line you drew is never presented as a level the system produced.

Shariah screening is advisory. Automated advisory approximation — not a fatwa or certification; verify independently.

The screen returns one of four states and we show you which: Compliant, Review, Unverified, or Not compliant. A name reads Unverified when we do not yet hold the evidence to complete its screen. That is a statement about our data coverage, not about the company — we would rather tell you we don't know than guess in your favour. The screen is produced by software from public information, it may be wrong or incomplete, and we hold no scholarly endorsement or certification of any kind. This is a screening tool, not a religious ruling. Verify with a qualified scholar or a certification service before you act on it.

No orders, no custody. The service places no orders, connects to no brokerage account, and holds no securities, no cash and no brokerage credentials.

Historical and hypothetical results. Any backtest or track-record figure we show is a historical replay of a signal, shown with the losses included. Hypothetical and past results do not predict future results.

You accept the risk. Trading and investing can lose you money. You use what the service produces at your own risk.

2. Who can use it

You must be the age of majority in your province or territory — or, if you are in the United States, of legal age to enter a binding contract — and you must use the service only where it is lawful for you to do so. The service is intended for adults and is not directed to children. Our beta is offered in Canada and the United States.

3. Your account

Beta access is invite-only. An invitation is personal: an invite link works only for the email address it was issued to, works once, and may not be transferred or shared.

You must give us an email address you control, or use a Google account you control if you sign in with Google. Keep it secure — because there is no password here, the sign-in link we email you is as sensitive as a password. If you turn on two-factor authentication, you are responsible for keeping your authenticator safe; recovering a lost authenticator needs our help and identity verification. Sessions expire after a period of inactivity, and last longer when the session was verified with two-factor authentication.

You are responsible for what happens under your account. One account per person.

4. Acceptable use

You may not:

  • scrape, bulk-export or redistribute the service's data or analysis;
  • probe, reverse-engineer, or try to extract the service's models, thresholds, methodology or detection logic;
  • resell, sublicense or share your access;
  • interfere with the service's operation or security, or with other people's access to it;
  • use automated means to access the service beyond ordinary use; or
  • use the service for anything unlawful or in breach of anyone else's rights.

We may investigate a suspected breach, and we may suspend or end access for one — see Suspension and ending your access below.

5. Market data

The analysis runs on end-of-day data. Intraday prices are last-trade prices from a single exchange, not the consolidated tape, provided by third parties, and may be incomplete or wrong. Full-tape and streaming quotes are not included and are not on the near-term roadmap. We do not warrant that market data is accurate, timely or complete, and you may not redistribute it. Ticker symbols, index names and company marks belong to their owners and are used to identify securities, without any implied endorsement.

6. Your content

What you create in the service stays yours. Your watchlist and your notes, the chart drawings you make, and the indicators and settings you choose belong to you. You give us only the permission we need to store that work and show it back to you. We do not claim ownership of it, we do not sell it, and we do not use it to train AI models. The licence in Feedback and bug reports below does not apply to it.

Where it is kept. Your watchlist and your notes are saved to your account on our server. Your chart drawings and your indicator selections are kept by your web browser, on the device you made them on. What we keep, and for how long, is set out in the Privacy Policy on this page.

Don't keep sensitive information in it. The service is a research tool, not a place to store personal records. Please don't put anything into it — a note, a label, a message — that you would not want held on our servers.

7. Feedback and bug reports

If you send us a bug report, a suggestion, a rating or other feedback, you give us a perpetual, irrevocable, worldwide, royalty-free licence to use it to operate and improve the service, without any obligation to you and without attribution. A bug report may be stored in our internal tools, filed as an issue in our private code repository, and pushed to our private operations channel so that we see it quickly — the Privacy Policy on this page describes each of those copies. Please don't include confidential or sensitive personal information in a report.

8. Beta

The service is in closed beta and under active development. Access is invite-only while we test with real money on real market days. Features may change or break without notice, availability is not guaranteed, and data may be reset. We may contact you about your use of the beta. The terms that apply at a full launch may differ from these, and we will publish them before they apply to you.

9. What the service costs

Nothing, today. The service is free while it is in beta. There is no subscription, no fee and no payment method on file. We do not ask you for card or banking details, we do not charge you, and nothing in these terms obliges you to pay us anything.

If that changes. We may introduce paid plans later. If we do:

  • we will publish the prices, what each plan includes, the billing and renewal terms, and the cancellation and refund policy before anyone is asked to pay;
  • those terms will be added to this page as a new section, and this section will say so;
  • we will not start charging an existing account without asking you first and getting your agreement — carrying on using a free account will never by itself be treated as agreeing to pay; and
  • if you do not want to pay, you can keep using whatever remains free, or stop using the service, and you will owe us nothing.

Until then, there is no price, no billing arrangement, no tax to add, no renewal and no refund policy, because there is nothing to pay. If you read something anywhere that says otherwise, this section is what governs.

10. Our intellectual property

The service and everything we put into it — the software, the analysis, the models, the methodology, the design, and the text and figures we produce — are ours or our licensors', and are protected by intellectual-property and trade-secret law. You get a personal, non-exclusive, non-transferable, revocable licence to use the service for your own use. No other rights are granted and nothing here transfers ownership of anything to you. Our name, our logo and our brand are ours, and you may not use them without our permission. None of this affects your ownership of your own content under Your content above.

11. Disclaimers

The service, including all data, analysis and output, is provided "as is" and "as available", without warranties of any kind, express or implied — including, to the maximum extent the law allows, implied warranties of merchantability, fitness for a particular purpose, accuracy and non-infringement. We do not warrant that the service will be uninterrupted, error-free or secure, or that any output is accurate or suitable for your purposes. You take on the risk of your use of the service and of any investment or religious-compliance decision you make.

Some consumer-protection laws do not allow these exclusions. Where that is so, they do not apply to you.

12. Limitation of liability

To the maximum extent the law allows:

  • we are not liable for your trading or investment losses — every decision to buy, sell or hold is yours;
  • we are not liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, lost data or lost goodwill, arising from or relating to the service;
  • our total liability for all claims relating to the service is limited to what you have paid us for the service in the twelve months before the event that gave rise to the claim. The service is free, so that amount is currently nothing — we would rather say that plainly than leave you to work it out; and
  • these limits apply even if a limited remedy fails of its essential purpose.

Some laws do not allow some of these limits. Where that is so, the limit does not apply to you, and nothing in these terms takes away a right your local consumer-protection law gives you.

13. Third-party services

The service depends on companies we do not control — the platform that hosts it, the provider that runs our database and sign-in, our market-data sources, and Google if you choose to sign in with a Google account. The ones that receive information about you are listed in the Privacy Policy on this page. Your use of a third-party service is governed by that company's own terms, and we are not responsible for services we do not control.

14. If someone brings a claim against us because of what you did

To the extent the law allows, you will cover our reasonable losses and legal costs if someone brings a claim against us because you misused the service, broke these terms, broke the law, or infringed someone else's rights. We will tell you about any such claim promptly, you will cooperate with the defence, and we may take part with our own lawyers. This does not apply to anything caused by us.

15. Suspension and ending your access

  • By you. You can stop using the service and ask us to delete your account at any time.
  • By us. We may suspend or end your access, with or without notice, if you breach these terms, if the law or one of our providers requires it, if it is necessary to protect the service or the people using it, or if we discontinue the service. Where the problem is not serious and it is practical to do so, we will tell you first and give you a chance to put it right.
  • What survives. When your access ends, your licence to use the service ends and you must stop using it. The parts of these terms that by their nature should continue, continue — what the service is and is not, market data, your content, feedback and bug reports, our intellectual property, disclaimers, limitation of liability, claims against us, problems and disputes, and the general section. What happens to your account data is set out in the Privacy Policy on this page.

16. If you have a problem with us

Talk to us first. Before starting a formal proceeding, use the Contact us form on our site and give us a fair chance to put things right. Most problems can be sorted out that way, and we would rather sort them out.

We do not take your right to go to court away from you. These terms contain no mandatory-arbitration clause and no class-action waiver, and we do not ask you to give up any right that consumer-protection law gives you. If we ever propose an arbitration term, it will be a change to these terms and we will tell you about it before it applies.

Urgent relief. Either of us can still ask a court for urgent relief to protect intellectual property, security, or the operation of the service.

17. Where we are, and the law that applies

We operate from Canada. These terms do not choose a governing law or a court, and they do not ask you to give up the protection of your own. The consumer-protection law of the place where you live applies to you, and the ordinary rules decide which court may hear a dispute. When we have settled where the business is formally established, we will say so here.

18. Events outside our control

We are not liable for a delay or a failure to perform caused by something beyond our reasonable control — including acts of God, outages at our hosting, data or network providers, cyberattacks, labour disputes, war, civil unrest, pandemics, or action by a government.

19. Transfers

You may not assign or transfer these terms or your account without our consent. We may transfer these terms to a successor — for example in a financing, a reorganisation, or a sale of the business — and we will give notice of a change of operator where the law requires it.

20. Changes to these terms

We may update these terms. Material changes will be announced in the app with the date they take effect, and where the law requires your consent to a change we will ask for it. Carrying on using the service after that date means you accept the updated terms. This does not apply to a change that would make you owe us money — see What the service costs above.

21. General

  • Entire agreement. These terms and the Privacy Policy on this page are the whole agreement between you and us about the service, and replace any earlier discussion.
  • Severability. If a provision is held unenforceable, the rest stay in effect and that provision is narrowed only as far as necessary.
  • No waiver. If we do not enforce a provision, we have not waived it.
  • Notices. We may give you notice in the app or by email to the address on your account. You can give us notice through the Contact us form on our site.
  • No third-party beneficiaries. Headings are for convenience only.

22. How to reach us

Use the Contact us form on our site. It is monitored, and it is also the route for any privacy question or request described in the Privacy Policy on this page.

Last updated: 2026-09-02. These terms apply from the day they are published on this page.