Privacy Policy
Effective: September 30, 2026
This policy explains what Vectaris LLC (“Vectaris,” “we,” “us”) collects when you use vectaris.io and the Vectaris platform (the “Service”), and what we do with it.
The short version: we collect what the product needs to run, plus usage analytics that tell us which parts of it people actually use. No ad trackers, no advertising, no selling your data — and your broker credentials are encrypted and used only to carry out your own instructions.
1. Who we are
Vectaris LLC, a Wyoming limited liability company, operates the Service and is the controller of the personal data described here. Contact: support@vectaris.io.
2. What we collect
Account data
Your email address, your password (stored only as a hash by our authentication provider, Supabase), profile settings, and your subscription tier.
Product data
The things you create in the platform so they can be saved and synced across your devices: workspaces, saved strategies and library items, settings defaults, and session state.
Broker API credentials
To connect a brokerage account you provide that broker’s API credentials (keys, tokens, or secrets). Because these are the most sensitive data we hold, they get their own rules:
- encrypted at the application layer before they are stored, and encrypted in transit (TLS);
- decrypted only transiently, in memory, to transmit your own instructions to your broker;
- never sold, never shared, and never used for any other purpose;
- deleted when you remove the connection or delete your account.
AI API keys and prompts
The AI assistant is bring-your-own-key. Keys you provide are stored encrypted, the same way as broker credentials. Your prompts are proxied to the AI provider you chose; we do not retain them or use them to train models. Your provider processes them under its own terms.
Billing data
Payments are processed by Stripe. We store your subscription status and Stripe customer and subscription identifiers. Your card number never touches our servers.
Logs and security events
Authentication and security events, plus IP addresses and request metadata in short-lived server logs at our hosting providers (Cloudflare, Fly.io).
Usage analytics
We measure how the Service is used so we can tell which parts of it are worth keeping and which are broken. Our analytics provider is PostHog, and every analytics request is sent to our own servers and forwarded from there — your browser never contacts PostHog directly.
- In the platform (platform.vectaris.io): the pages and features you use, actions you take in the interface, approximate location derived from your IP address, device and browser type, and unhandled errors. This is linked to your account — your user id and your email address — so we can tell one person’s session from another’s and reproduce a fault you hit. We record that an action happened and its shape, never its content: that an order was submitted and whether it was a buy or a sell, which broker you connected, that a strategy was saved. No broker credentials, no API keys, no assistant prompts, no strategy code, and no symbols, quantities, prices, balances or positions are ever sent.
- On this site and the documentation site (vectaris.io, docs.vectaris.io): the same measurements, but anonymously. These two sites run in a cookieless mode — no cookie is set and nothing at all is written to your device — and identity is a rotating, privacy-preserving hash computed on the server rather than an identifier that follows you. Both sites also honour your browser’s Do Not Track setting and collect nothing when it is on.
We do not use analytics data for advertising, we do not combine it with data bought from anyone else, and we do not sell or share it. If you would rather we did not measure your use of the platform, email us and we will exclude your account.
3. What we don’t do
- No advertising trackers and no ad networks, on this site or in the platform.
- No advertising.
- No selling or renting personal information.
- No sharing analytics data with data brokers or ad platforms.
- No training AI models on your data.
4. Cookies and local storage
The platform stores a few things in your browser because it cannot work otherwise: your signed-in session (via Supabase), your workspace layout and settings, and a PostHog identifier that lets us count one person’s visits as one person’s rather than many. These are first-party — set by us, readable only by us — and there are no advertising cookies anywhere in the Service.
This marketing site and the documentation site set no cookies at all and write nothing to your device, which is why neither shows you a cookie banner.
5. How we use information
To provide and operate the Service, sync your data across devices, transmit your trading instructions to your broker, process billing, keep the Service secure and prevent abuse, respond to support requests, send transactional email (via Resend), and comply with legal obligations.
6. Legal bases (EEA/UK)
Where GDPR or UK GDPR applies, we process personal data to perform our contract with you (the core service), for our legitimate interests (security, service integrity, and measuring how the Service is used so we can improve it), with your consent where required, and to comply with legal obligations. You can object to the analytics processing at any time — see Your rights below.
7. Who we share it with
We share personal data only with the service providers that run the product:
- Supabase — authentication, database, and storage
- Fly.io — API hosting
- Cloudflare — web hosting, CDN, and DNS
- Stripe — payment processing
- Resend — transactional email
- PostHog — product and usage analytics (PostHog Cloud, United States)
Beyond that: your broker receives the instructions you direct us to send it; your AI provider receives the prompts you send through your own key; and we may disclose information if required by law or to protect the rights, safety, or integrity of the Service. If Vectaris is involved in a merger or acquisition, data may transfer with the business; we will notify you before another privacy policy applies.
8. International transfers
We operate from the United States, and data is processed there. Where transfers from the EEA, UK, or Switzerland require safeguards, we rely on Standard Contractual Clauses or equivalent mechanisms.
9. Retention
We keep your data while your account is active. When you delete your account, we delete or anonymize your personal data within a reasonable period, except records we are legally required to keep (such as billing and tax records). Server logs rotate on short schedules.
10. Security
Data is encrypted in transit and at rest, broker and AI credentials carry an additional layer of application-level encryption, and access is restricted on a least-privilege basis. If a breach affects your personal data, we will notify you without undue delay and as required by applicable law.
11. Your rights
If you are in the EEA or UK, you can ask to access, correct, delete, restrict, or export your personal data, object to certain processing, and lodge a complaint with your supervisory authority.
If you are a California resident, you have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its sale or sharing — though we do not sell or share personal information as those terms are defined by the CCPA. We will never discriminate against you for exercising these rights.
To exercise any right, email support@vectaris.io. We may need to verify your identity before acting on a request.
12. Children
The Service is for adults 18 and older. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
13. Changes
We will post updates to this policy here with a new effective date. When a change is material, we will ask you to read and accept the revised documents the next time you sign in, before you carry on using the platform. We may also email you.
14. Contact
Vectaris LLC, Wyoming, USA — support@vectaris.io