Legal

Privacy Policy

Effective: June 13, 2026 · Last updated: June 13, 2026

This Privacy Policy explains how ZE Capitals ("ZE", "we", "us", or "our") collects, uses, stores, and shares information when you use our platform. By using the Platform, you agree to the practices described here.

1. Information We Collect

We collect the following categories of information:

Account information

  • Name (display name) and email address provided at registration.
  • Authentication tokens issued by our authentication provider.
  • OAuth identity data if you sign in with Google or Apple (such as your name, email, and profile photo URL).

Broker credentials

  • Alpaca API key and secret provided when connecting your broker account.
  • These credentials are stored encrypted at rest in a dedicated secrets store.
  • We never store your brokerage username or password.

Portfolio and trading data

  • Positions, orders, and trade history synced from your connected Alpaca account.
  • Trade approvals, rejections, and execution records generated on the Platform.
  • Portfolio weights, P&L calculations, and performance metrics.
  • Risk metrics and circuit-breaker states.

AI / JARVIS conversation data

Important: When you use JARVIS (our AI chat assistant), your messages and selected portfolio data are transmitted to Anthropic, Inc. for processing by Claude AI models. Anthropic's handling of this data is governed by Anthropic's Privacy Policy. Conversation history is also stored in our database to enable session persistence across devices.

Platform preferences and settings

  • Watchlist symbols.
  • Notification preferences (email address for alerts, Slack webhook URL if configured).
  • Theme preference (light/dark), stored in localStorage in your browser.

Usage and technical data

  • Server-side logs generated by our application and hosting infrastructure.
  • API call timestamps used for rate limiting (held in memory per instance, not persisted).
  • System health and pipeline run records (task names, completion times, error states).
  • IP address and browser user-agent, captured in standard server access logs.

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: authenticate your account, run the quantitative pipeline, display your portfolio, and route approved orders to your broker.
  • Power AI features: send your messages and portfolio context to Anthropic to generate JARVIS responses and AI research dossiers.
  • Send notifications: deliver risk-halt email alerts and, if configured, Slack notifications using the credentials you provide.
  • Maintain security: enforce rate limits, detect abuse, and protect against unauthorized access.
  • Improve the Platform: review anonymized system-health and pipeline performance data to identify and fix issues.
  • Billing: process subscription payments and manage your plan when billing is enabled.
  • Legal compliance: comply with applicable laws, respond to lawful requests, and enforce our Terms of Service.

We do not sell your personal data to third parties. We do not use your data for advertising or marketing profiling.

3. Third-Party Service Providers

We share data with the following service providers only to the extent necessary to operate the Platform:

Anthropic, Inc. (AI processing)

  • Your JARVIS chat messages and any portfolio data included in a conversation are sent to Anthropic for processing.
  • AI research analysis (factor score dossiers) for candidate securities is also processed by Anthropic.
  • Anthropic's data handling is governed by their API usage policy and privacy policy.

Alpaca Markets (broker integration)

  • Your API credentials are used to read positions, submit orders, and sync account state.
  • Alpaca operates as an independent broker-dealer regulated by FINRA and the SEC.

Managed database and authentication provider

  • All Platform data (account records, portfolio data, AI conversations, settings) is stored in a managed cloud database.
  • Authentication (email/password and Google or Apple sign-in) is handled by our authentication provider.
  • Broker credentials are stored in an encrypted secrets store.

Cloud hosting (infrastructure)

  • Our web application and backend processing run on managed cloud infrastructure located in the United States.
  • Application logs and operator credentials are stored within this infrastructure.

Transactional email provider

  • Your email address and alert content are transmitted to a third-party transactional email provider when email notifications are enabled.

Market-data providers

  • Third-party market-data and fundamentals providers are used to fetch prices and company data. These services receive only query parameters such as ticker symbols and do not receive your personal account data.

Payment processor (when billing is active)

  • Payment card information is handled directly by our payment processor and is never stored on our servers.

4. AI Feature Data — Special Notice

When you interact with JARVIS or when the Platform runs AI research analysis, the following data is sent to Anthropic's API:
  • The text of your chat messages.
  • Portfolio context (e.g., selected positions, factor scores) that you or the Platform includes in a conversation prompt.
  • Security names and tickers for AI research dossiers.

Do not include personally identifying information, account numbers, or sensitive financial details beyond what is necessary in your JARVIS messages. Conversations are stored in our database and subject to our data retention policy.

AI-generated outputs are stored per-message to enable session history. You may request deletion of your conversation history by contacting us.

5. Broker Credentials — Special Notice

Your Alpaca API key and secret are sensitive financial credentials. We protect them as follows:

  • Stored encrypted at rest in a dedicated secrets store.
  • Never logged in plaintext in application logs or error messages.
  • Accessed server-side only — never transmitted to your browser after initial save.
  • Deleted promptly when you remove your broker connection.

If you believe your broker credentials have been compromised, revoke them immediately in your Alpaca account dashboard and reconnect with new credentials.

6. Cookies and Local Storage

The Platform uses the following browser storage:

  • Session cookie: required for authentication. Contains your session token. Expires with your session or after its configured time-to-live.
  • Theme preference (localStorage): stores your light/dark mode choice. Contains no personal data. Readable only by our domain.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. The Platform does not use Google Analytics, Facebook Pixel, or similar tracking tools.

7. Data Retention

We retain data for the following periods:

  • Account data: retained for the life of your account plus 90 days after deletion.
  • Portfolio and trading data: retained for the life of your account plus 12 months for regulatory and audit purposes.
  • AI conversation history: retained until you request deletion or your account is deleted. Configurable retention windows are planned.
  • System health and pipeline logs: retained for 90 days.
  • Application logs: retained per our log retention settings (typically 30–90 days).
  • Broker credentials: deleted immediately when you disconnect your broker or close your account.

8. Security

We implement the following security measures to protect your data:

  • All data in transit is encrypted using TLS 1.2+.
  • All data at rest is encrypted using strong, industry-standard encryption.
  • Broker credentials are stored in an encrypted secrets store, never in plaintext.
  • Access controls restrict each account to its own data.
  • API routes are protected by rate limiting to prevent abuse.
  • Operator-level credentials (such as API keys for data and AI providers) are kept in a dedicated secrets manager.
  • Access to production infrastructure is restricted to authorized personnel.

No system is perfectly secure. Use a strong, unique password and notify us immediately if you suspect unauthorized access to your account.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

All users

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate data.
  • Deletion: request deletion of your account and associated personal data (subject to retention requirements for regulatory and legal purposes).
  • Portability: request an export of your data in a machine-readable format.

California residents (CCPA / CPRA)

  • You have the right to know what personal information we collect and how it is used.
  • You have the right to opt out of the sale of personal information. We do not sell personal information.
  • You have the right to non-discrimination for exercising your privacy rights.

EEA / UK residents (GDPR / UK GDPR)

  • Our legal bases for processing are: (i) contractual necessity (to provide the Service), (ii) legitimate interest (security, fraud prevention), and (iii) consent (AI features).
  • You have rights of access, rectification, erasure, restriction, portability, and to object to processing.
  • You may lodge a complaint with your local data protection authority.
  • We rely on Standard Contractual Clauses (SCCs) for transfers of personal data outside the EEA.

To exercise any right, contact us at the address in Section 13.

10. Children's Privacy

The Platform is not directed to persons under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a minor, contact us and we will delete it promptly.

11. International Data Transfers

ZE Capitals operates infrastructure in the United States. If you access the Platform from outside the United States, your data is transferred to and processed in the US. We take steps to ensure appropriate safeguards for international transfers, including Standard Contractual Clauses where required by applicable law.

12. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will notify you by email or in-app notice and update the "Last updated" date at the top. Your continued use of the Platform after changes are posted constitutes acceptance of the revised policy.

13. Contact Us

For privacy-related questions, requests, or complaints:

We will respond to verifiable requests within 30 days (or sooner as required by applicable law).