Legal
Privacy Policy
Effective: June 13, 2026 · Last updated: June 13, 2026
This Privacy Policy explains how ZE Capitals ("ZE", "we", "us", or "our") collects, uses, stores, and shares information when you use our platform. By using the Platform, you agree to the practices described here.
1. Information We Collect
We collect the following categories of information:
Account information
- Name (display name) and email address provided at registration.
- Authentication tokens issued by our authentication provider.
- OAuth identity data if you sign in with Google or Apple (such as your name, email, and profile photo URL).
Broker credentials
- Alpaca API key and secret provided when connecting your broker account.
- These credentials are stored encrypted at rest in a dedicated secrets store.
- We never store your brokerage username or password.
Portfolio and trading data
- Positions, orders, and trade history synced from your connected Alpaca account.
- Trade approvals, rejections, and execution records generated on the Platform.
- Portfolio weights, P&L calculations, and performance metrics.
- Risk metrics and circuit-breaker states.
AI / JARVIS conversation data
Platform preferences and settings
- Watchlist symbols.
- Notification preferences (email address for alerts, Slack webhook URL if configured).
- Theme preference (light/dark), stored in localStorage in your browser.
Usage and technical data
- Server-side logs generated by our application and hosting infrastructure.
- API call timestamps used for rate limiting (held in memory per instance, not persisted).
- System health and pipeline run records (task names, completion times, error states).
- IP address and browser user-agent, captured in standard server access logs.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service: authenticate your account, run the quantitative pipeline, display your portfolio, and route approved orders to your broker.
- Power AI features: send your messages and portfolio context to Anthropic to generate JARVIS responses and AI research dossiers.
- Send notifications: deliver risk-halt email alerts and, if configured, Slack notifications using the credentials you provide.
- Maintain security: enforce rate limits, detect abuse, and protect against unauthorized access.
- Improve the Platform: review anonymized system-health and pipeline performance data to identify and fix issues.
- Billing: process subscription payments and manage your plan when billing is enabled.
- Legal compliance: comply with applicable laws, respond to lawful requests, and enforce our Terms of Service.
We do not sell your personal data to third parties. We do not use your data for advertising or marketing profiling.
3. Third-Party Service Providers
We share data with the following service providers only to the extent necessary to operate the Platform:
Anthropic, Inc. (AI processing)
- Your JARVIS chat messages and any portfolio data included in a conversation are sent to Anthropic for processing.
- AI research analysis (factor score dossiers) for candidate securities is also processed by Anthropic.
- Anthropic's data handling is governed by their API usage policy and privacy policy.
Alpaca Markets (broker integration)
- Your API credentials are used to read positions, submit orders, and sync account state.
- Alpaca operates as an independent broker-dealer regulated by FINRA and the SEC.
Managed database and authentication provider
- All Platform data (account records, portfolio data, AI conversations, settings) is stored in a managed cloud database.
- Authentication (email/password and Google or Apple sign-in) is handled by our authentication provider.
- Broker credentials are stored in an encrypted secrets store.
Cloud hosting (infrastructure)
- Our web application and backend processing run on managed cloud infrastructure located in the United States.
- Application logs and operator credentials are stored within this infrastructure.
Transactional email provider
- Your email address and alert content are transmitted to a third-party transactional email provider when email notifications are enabled.
Market-data providers
- Third-party market-data and fundamentals providers are used to fetch prices and company data. These services receive only query parameters such as ticker symbols and do not receive your personal account data.
Payment processor (when billing is active)
- Payment card information is handled directly by our payment processor and is never stored on our servers.
4. AI Feature Data — Special Notice
- The text of your chat messages.
- Portfolio context (e.g., selected positions, factor scores) that you or the Platform includes in a conversation prompt.
- Security names and tickers for AI research dossiers.
Do not include personally identifying information, account numbers, or sensitive financial details beyond what is necessary in your JARVIS messages. Conversations are stored in our database and subject to our data retention policy.
AI-generated outputs are stored per-message to enable session history. You may request deletion of your conversation history by contacting us.
5. Broker Credentials — Special Notice
Your Alpaca API key and secret are sensitive financial credentials. We protect them as follows:
- Stored encrypted at rest in a dedicated secrets store.
- Never logged in plaintext in application logs or error messages.
- Accessed server-side only — never transmitted to your browser after initial save.
- Deleted promptly when you remove your broker connection.
If you believe your broker credentials have been compromised, revoke them immediately in your Alpaca account dashboard and reconnect with new credentials.
7. Data Retention
We retain data for the following periods:
- Account data: retained for the life of your account plus 90 days after deletion.
- Portfolio and trading data: retained for the life of your account plus 12 months for regulatory and audit purposes.
- AI conversation history: retained until you request deletion or your account is deleted. Configurable retention windows are planned.
- System health and pipeline logs: retained for 90 days.
- Application logs: retained per our log retention settings (typically 30–90 days).
- Broker credentials: deleted immediately when you disconnect your broker or close your account.
8. Security
We implement the following security measures to protect your data:
- All data in transit is encrypted using TLS 1.2+.
- All data at rest is encrypted using strong, industry-standard encryption.
- Broker credentials are stored in an encrypted secrets store, never in plaintext.
- Access controls restrict each account to its own data.
- API routes are protected by rate limiting to prevent abuse.
- Operator-level credentials (such as API keys for data and AI providers) are kept in a dedicated secrets manager.
- Access to production infrastructure is restricted to authorized personnel.
No system is perfectly secure. Use a strong, unique password and notify us immediately if you suspect unauthorized access to your account.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
All users
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate data.
- Deletion: request deletion of your account and associated personal data (subject to retention requirements for regulatory and legal purposes).
- Portability: request an export of your data in a machine-readable format.
California residents (CCPA / CPRA)
- You have the right to know what personal information we collect and how it is used.
- You have the right to opt out of the sale of personal information. We do not sell personal information.
- You have the right to non-discrimination for exercising your privacy rights.
EEA / UK residents (GDPR / UK GDPR)
- Our legal bases for processing are: (i) contractual necessity (to provide the Service), (ii) legitimate interest (security, fraud prevention), and (iii) consent (AI features).
- You have rights of access, rectification, erasure, restriction, portability, and to object to processing.
- You may lodge a complaint with your local data protection authority.
- We rely on Standard Contractual Clauses (SCCs) for transfers of personal data outside the EEA.
To exercise any right, contact us at the address in Section 13.
10. Children's Privacy
The Platform is not directed to persons under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a minor, contact us and we will delete it promptly.
11. International Data Transfers
ZE Capitals operates infrastructure in the United States. If you access the Platform from outside the United States, your data is transferred to and processed in the US. We take steps to ensure appropriate safeguards for international transfers, including Standard Contractual Clauses where required by applicable law.
12. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will notify you by email or in-app notice and update the "Last updated" date at the top. Your continued use of the Platform after changes are posted constitutes acceptance of the revised policy.
13. Contact Us
For privacy-related questions, requests, or complaints:
- Email: privacy@zecapitals.com
We will respond to verifiable requests within 30 days (or sooner as required by applicable law).
Table of contents