Privacy Policy
Last updated: August 5, 2026
QuantCrystal ("we," "us," or "our") is operated by Quantum Armadillo, LLC, a Texas limited liability company, which is the data controller for the processing described here. This policy describes how we handle personal information in connection with quantcrystal.com and the QuantCrystal API.
The short version
You can use this site without an account. If you create one, you give us an email address and nothing else is required. Your trading records are private by default. If you choose to publish an account, the only things that become public are your handle, your avatar, and a normalized percent performance curve with summary statistics. Your email, display name, company name, dollar amounts, positions, symbols, and orders are never published — not on opt-in, not on request.
We do not sell or rent your personal information, and we do not share it with third parties except the infrastructure providers named in section 4 that are required to operate the service.
1. Information we collect
Information you provide
- Email address — required to create an account. Sign-in is passwordless: we email you a single-use link rather than asking you to choose a password, so we never hold a password for you at all. Your address is also used for the correspondence described in section 2.
- Display name and company name — both optional, both private always. We use them to address you properly in email and support. They are returned only to you, by the endpoint that serves your own profile, and appear on no public surface.
- Handle — optional, and required only if you decide to publish an account. A handle is a public identifier by design.
- Avatar image — optional. If you upload one it is stored in Cloudflare R2 and served publicly by handle. We validate the file's actual bytes and accept only PNG, JPEG and WebP; SVG is rejected because an SVG can carry script. Uploading nothing leaves a blank placeholder, which is the default.
- Trading activity you generate — the paper orders you submit and the fills, positions and equity history derived from them. This is simulated trading; no real money, brokerage credentials or account numbers are involved.
- Data you submit for analysis — equity curves or return series you send to the simulation and verification endpoints, and the results computed from them.
- Waitlist entry — if you submitted the pre-launch waitlist form, your email address and optional note are stored in Cloudflare KV.
Information stored in your browser
- Session cookie — when you sign in we set an
httpOnly,Securesession cookie scoped to quantcrystal.com. It is strictly necessary to keep you signed in, is not used for tracking, and is cleared when you sign out. - Theme preference — your light/dark choice is saved in local
storage under the key
theme. It never leaves your device. - Onboarding and activation flags — local storage keys recording that you have seen the first-run guide and that you have executed your first paper trade. They stay on your device and contain no trading detail: not a symbol, not a quantity, not an amount.
Information we do not collect
- We do not collect passwords, financial information, brokerage credentials, or payment card numbers. When billing goes live at launch, card data is handled entirely by a third-party processor and we never see or store a card number.
- We do not use Google Analytics, Google Fonts, Google Tag Manager, or any Google service. Webfonts are self-hosted from this domain, so loading a page here does not generate a request to any font CDN.
- We do not use Facebook Pixel or any advertising, retargeting, or cross-site tracking technology.
2. How we use your information, and what you are consenting to
We use your email address to:
- Send you sign-in links. These are transactional and are not marketing; you receive one only when you ask to sign in.
- Send you QuantCrystal correspondence. Creating an account by requesting a sign-in link also subscribes you to occasional product email about QuantCrystal. This is disclosed on the sign-in page itself, above the button, and again in the sign-in email — not in fine print.
- Respond to you if you contact us.
- Send you service notices about your account when they matter.
Unsubscribing
Every correspondence email carries a working one-click unsubscribe link, which does not require you to sign in — requiring a login to stop receiving mail is a dark pattern, so we do not do it. You can also switch correspondence off at any time from your profile page. Turning it off never affects sign-in links, because those are not marketing and you would be locked out without them.
How we use your trading data
Your paper trading activity is used to operate the service: to fill your orders, maintain your positions and journal, and compute your account's statistics. If and only if you publish an account, we additionally use it to render that account's public record page and to rank it on the leaderboard.
We do not and will not sell or rent your personal information, and we do not share it with third parties for their marketing purposes. We share it only with the infrastructure providers in section 4, and only to the extent required to run the service.
We do not trade on your strategies. Your submitted curves, returns, orders and positions are not used to inform our own trading, and are not sold, published or provided to anyone as a data product.
2a. What becomes public if you opt in
Accounts are private by default. Publishing is a deliberate, per-account choice that you can reverse. This table is the complete model — there is no other tier of sharing.
| Private always | Public if you opt in | |
|---|---|---|
| Email, display name, company name | Yes | Never |
| Handle and avatar | — | Yes |
| Performance trend (normalized curve, statistics, days live, trade count) | — | Yes |
| Positions, symbols, orders, dollar amounts, your algorithm | Yes | Never |
A published curve is normalized to percent return from a zero anchor at the start of the record, so your account size cannot be worked backwards from it. The queries that build public pages name their columns explicitly and have no access to your name, your email or any dollar figure.
Resets relabel the record. If you reset a published account to an earlier checkpoint, its public record start date moves forward and the page is relabeled "record since" that new date. Nothing is deleted; the prior journal is marked superseded and retained.
You can make a published account private again at any time from its settings, which removes it from the leaderboard and its public page.
3. Data storage and security
Account records, paper trading data and the fills journal are stored in Cloudflare D1. Avatar images are stored in Cloudflare R2. Waitlist entries are stored in Cloudflare KV. All of these are operated by Cloudflare, Inc. and reached through Cloudflare Workers over HTTPS.
Some specifics worth stating because they limit what a breach could expose: we store no passwords, because sign-in is passwordless. Sign-in link tokens are stored hashed and are single-use with a 15-minute lifetime. API keys are stored hashed — we show you a key once, at creation, and cannot recover it afterwards. We hold no payment card data of any kind.
The fills journal is append-only by design. A reset marks entries superseded rather than deleting them, which is what makes a published record auditable. If you ask us to delete your account, that includes the journal — see section 6.
We apply reasonable administrative and technical safeguards, but no method of electronic storage or transmission is completely secure, and we do not claim otherwise.
4. Third-party services (processors)
These are the only third parties that process your data, and each is named because it is actually in use:
- Cloudflare, Inc. — hosting, CDN, Workers, and all storage: D1 (accounts and trading records), R2 (avatar images), KV (waitlist). Cloudflare also processes your IP address for delivery and security when serving pages. In use today.
- Mailgun (Sinch) — delivery of sign-in links and QuantCrystal correspondence. It processes your email address and message content for that purpose. In use today.
- Alpaca Securities LLC — market data only. We request prices and quotes; no user data is sent to them, and no order of yours is ever routed to them or to any other broker. QuantCrystal is the simulator, and nothing here reaches a real market.
- Payment processing — not in use. No paid tier is live and we hold no card data. A specific processor will be named here before any payment is ever taken.
- Anthropic — AI analysis, run on market data. No user personal data and no user trading data is sent for that purpose.
We use no analytics vendor, no advertising network, and no cross-site tracking service. Product usage is measured only by milestone flags stored on your own device, as described in section 1.
5. Cookies
QuantCrystal sets one cookie: a strictly necessary session cookie
issued when you sign in, marked httpOnly and Secure and
scoped to quantcrystal.com so that the apex and www share one session. It exists
to keep you signed in and is cleared when you sign out.
We use no tracking cookies, no advertising cookies, and no cookie-based analytics. Our hosting provider may set strictly necessary technical cookies for security and performance; these do not track you across websites.
6. Your rights
You have the right to request access to the personal data we hold about you, correction of it, or its deletion. Several of these you can exercise yourself, immediately, without asking us:
- Correct your details — edit your handle, display name and company name on your profile page.
- Remove your avatar — delete it from your profile; it is removed from storage.
- Stop correspondence — the toggle on your profile, or the one-click link in any message.
- Un-publish a record — set the account back to private and its public page and leaderboard entry go away.
- Revoke API keys — from your profile, at any time.
For access to, or deletion of, everything we hold — including your account, your paper trading history and the journal behind it — use the contact route in section 11. We act on it and confirm. There is no dark pattern between you and the door: no retention offer, no phone call, no "are you sure" maze.
EU/EEA and UK residents
If you are in the European Union, European Economic Area, or United Kingdom, you have rights under the GDPR and UK GDPR including access, rectification, erasure, portability, restriction of processing, and objection, as well as the right to lodge a complaint with your supervisory authority. Where we process an email address you gave us, the legal basis is your consent, which you may withdraw at any time.
California residents
Under the California Consumer Privacy Act you have the right to know what personal information is collected, to have it deleted, and to opt out of its sale. We do not sell personal information.
7. Children's privacy
QuantCrystal is not directed at anyone under 18 and we do not knowingly collect personal information from minors. If we learn we have, we will delete it promptly.
8. Data retention
We keep your account data for as long as your account exists. Sign-in link tokens expire in 15 minutes and are pruned after use. Session records expire and are pruned automatically.
Your paper trading journal is retained for the life of the account, because it is the evidence behind any statistic the account reports — a record whose history can be quietly trimmed is not a record. On a deletion request, that journal is deleted along with everything else within 30 days.
Waitlist entries are kept until launch notification has been sent and you have had a chance to act on it, or until you ask us to delete the entry. Aggregated, non-identifying counts may be retained indefinitely.
9. Changes to this policy
We may update this policy. Changes are posted here with a new "Last updated" date. This version describes the account era: passwordless sign-in, paper trading accounts, avatars, opt-in public records, and the API. Billing is not live, and this page will be updated with a named payment processor before any charge is ever made.
10. Relationship to MarketCrystal
QuantCrystal and MarketCrystal (marketcrystal.ai) are operated by the same owner but are separate sites on separate domains, with separate browser storage. MarketCrystal has its own privacy policy governing its own data practices; this policy does not cover that site.
11. Contact
For privacy questions or to exercise your rights, use the contact form. It is the contact route we publish: we do not put an email address on the page, because published addresses get harvested.