Privacy Policy
Last updated: 15 August 2026
This policy explains what VANTIQX collects, why, who we share it with, how long we keep it, and how to get it deleted. It covers the VANTIQX mobile app and the VANTIQX web app.
1. Information we collect
- Account data — name, email address, and an authentication credential (passwords are stored only as a salted hash by our authentication provider; if you sign in with Google we receive your Google account email and profile name, never your Google password).
- Content you submit — chart screenshots and other images you upload for analysis, journal entries, notes, goals, saved strategies, community posts and profile avatars.
- Trading account data — if you connect a broker account: the credentials needed to establish that connection, plus account balance, equity, open positions, order history and instrument prices retrieved from it.
- Usage and device data — which features you use, analyses run, subscription tier, app version, device type and operating system, and error/crash diagnostics.
- Subscription data — purchase and entitlement status received from the Apple App Store or Google Play. We never receive or store your card number.
2. How we use it
- To run the analyses, signals and tools you ask for.
- To display your connected trading account, and to submit the orders you instruct the app to place.
- To operate subscriptions, entitlements and any referral rewards.
- To send service messages and the notifications you have enabled.
- To keep the service secure, enforce per-account usage limits, prevent abuse, and fix faults.
We do not sell your personal data, and we do not use your content to train our own models.
3. Uploaded images and AI processing
When you submit a chart screenshot or ask for AI analysis, the image and the accompanying prompt are transmitted to a third-party AI provider through our own server-side proxy so that our provider keys are never exposed in the app. Uploaded images are also stored in our cloud storage so your history and journal remain available to you, and are deleted when you delete the item or your account.
Do not upload documents, identity papers, screenshots of private messages, or anything else you would not want processed by a third-party AI provider.
4. Broker connections and order placement
Broker connectivity is provided by MetaApi (MetaApi Cloud). To connect a MetaTrader 4/5 account we transmit the login, server name and password you supply to MetaApi, which maintains the connection to your broker on your behalf. Those credentials are used to read your account and to submit orders — the ones you confirm individually in Manual mode and, where you have enabled Autopilot with explicit consent, the orders the VANTIQX server places automatically under that standing instruction. Where your broker offers a read-only "investor" password and you only want tracking, use that instead; note that a read-only password cannot place orders, so execution features will not work with it.
You can disconnect a broker account at any time in the app. Disconnecting stops further access; it does not undo orders that have already been placed at your broker.
5. Third parties who process data for us
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | Account data, your content, usage records |
| Vercel | Web app hosting and delivery | Request metadata (including IP address) |
| Google (Gemini API) | AI chart analysis, AI text and image generation | Prompts and uploaded images you submit |
| Anthropic (Claude API) | AI analysis and assistant responses | Prompts and uploaded images you submit |
| Groq, Hugging Face | Additional AI inference for specific features | Prompts you submit |
| MetaApi | Broker account connection, quotes, order placement | Broker credentials, account and trade data |
| Alpha Vantage, Finnhub, Twelve Data, TraderMade, Polygon, PredictHQ | Market prices, news and economic calendar | Instrument symbols only — no personal data |
| PostHog | Product analytics and crash reporting | Pseudonymous user id, feature-usage events, app version, device type, error reports |
| Expo | Push notification delivery | Device push token |
| RevenueCat, Apple, Google | Subscription purchase and entitlement | Purchase receipts and entitlement status |
| Resend | Transactional email | Your email address and the message content |
Each provider processes data only to deliver the function above. We also disclose data where the law requires it, or where necessary to protect our rights or the safety of our users.
6. Analytics
We use PostHog to understand which features are used and to receive crash reports. Events are keyed to a pseudonymous account identifier. Session replay is disabled. Analytics never receives your uploaded images, journal content or broker credentials.
7. How long we keep data
| Data | Retention |
|---|---|
| Account profile | Until you delete your account |
| Analyses, journal entries, goals, community posts, uploaded images | Until you delete the item, or until account deletion |
| Broker connection details | Until you disconnect the account, or until account deletion |
| Usage metering records | Rolling records used to enforce daily limits; removed on account deletion |
| Analytics events | Retained by PostHog under its own retention schedule; not linked to your name or email |
| Billing and purchase records | Kept as long as required for tax and accounting obligations |
Deletion of your account removes your data from our systems within 30 days, including backups taken before the request.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to complain to a supervisory authority. Exercise any of these by emailing contact@tadjfze.com, or delete your account directly — see Delete your account. We do not discriminate against you for exercising these rights.
9. Security
Data is transmitted over TLS. Access to production data is restricted. Third-party API keys are held server-side and never shipped in the app. Row-level security rules restrict every database record to its owner. No system is perfectly secure, and we cannot guarantee absolute security.
10. Children
VANTIQX is not directed at anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
11. International transfers
Our providers operate in multiple countries, including the United States, so your data may be processed outside the country where you live. Where required, we rely on appropriate transfer safeguards.
12. Changes
We may update this policy. Material changes will be announced in the app or by email, and the "last updated" date above will change.
13. Contact
Privacy questions and requests: contact@tadjfze.com.