The short version. Quanify is software that connects to brokerage accounts you own and routes orders on your instructions. To do that we process your account details, the broker connection you authorize, and the trading data that connection returns.
- We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not show ads.
- Broker access tokens are encrypted at rest and used only to operate the Services. You can revoke them at your broker at any time and disconnect them in Quanify.
- Passwords are stored only as salted scrypt hashes. Card details are held by Stripe, never by us.
- Google Analytics loads only if you click Allow on our cookie notice. Browsers that send a Global Privacy Control signal are treated as having declined.
- Data is stored and processed in the United States. The Services are intended for adults in the United States.
- To access, correct or delete your data, email [email protected].
This summary is for convenience only and is not a substitute for the full Policy below.
1. Who we are and what this Policy covers
Quanify LLC, an Arizona limited liability company ("Quanify," "we," "us" or "our"), operates the websites at quanify.pro, trade.quanify.pro and chart.quanify.pro, the Quanify trading workspace, the Quanify Chart, the Quanify mobile and desktop applications, our Discord community, and related services (together, the "Services"). This Privacy Policy ("Policy") explains what personal information we collect through the Services, how we use and disclose it, how long we keep it, and the choices and rights you have.
Quanify is software. We are not a broker, futures commission merchant, introducing broker, commodity trading advisor, commodity pool operator or investment adviser. We never hold your funds or have custody of your accounts. Orders are sent to your broker through the broker's interface using access you authorize, and your broker's own privacy policy governs the information it holds about you.
This Policy is part of, and should be read together with, our Terms of Service and Risk Disclosure. Capitalized terms not defined here have the meanings given in the Terms. This Policy does not cover third-party websites or services, including your broker, TradingView, Stripe, Discord, Google or Apple, each of which has its own privacy practices.
2. Information we collect
2.1 Information you give us
- Account information: email address, username and password. Passwords are stored only as salted scrypt hashes and never in plaintext. If you sign in with Google or Apple, we receive the account identifier and email address that provider shares with us.
- Subscription information: your plan, subscription status and renewal date, and the customer and subscription identifiers Stripe assigns to you. Payment card details are entered directly with Stripe; we do not receive or store full card numbers.
- Agreement records: when you accept our Terms of Service, Privacy Policy and Risk Disclosure, we record the date and time, the version accepted, your IP address and your browser's user agent.
- Strategy and routing configuration: strategies you create, webhook tokens and passwords, the accounts you link to each strategy, multipliers, copy groups, leader and follower selections, mute and arm settings, paper accounts and workspace preferences.
- Discord linking (optional): if you link Discord, your Discord user ID and username, used to assign community roles.
- Partner applications: the information you choose to include if you apply to our partner program.
- Support correspondence: the content of emails you send to [email protected] and any information you include in them.
2.2 Information from your broker
When you connect a brokerage account (currently Tradovate, with other brokers to be added), we receive and store an OAuth or access token that lets the Services act on the account within the permissions you grant. Through that connection we read and process broker account IDs and names, account and sub-account balances, positions, working orders, orders, fills, and realized and unrealized profit and loss. See Section 5.
2.3 Information generated by your use of the Services
- Trading activity records: signals and webhooks received for your strategies, orders the Services placed or attempted on your behalf and their results, copy-trade activity, trade logs, forward-test trades and paper account records.
- Technical and security information: IP address, browser user agent, session records (including when a session was last active), security and audit events (such as sign-ins, password changes and settings changes), rate-limiting counters, and hashed one-time email verification and password reset codes.
- Checkout records: short-lived records used to complete a Stripe checkout and create or match your account.
- Cookies and local storage: described in Section 6. If you allow analytics, Google Analytics collects information about pages viewed and how you interact with our websites.
2.4 Information from the Quanify Chart
- Chart settings: your chart colour and grid preferences, stored with your account so they follow you between devices.
- Drawings: the drawings you save on each instrument, such as lines, rays, boxes, Fibonacci levels and text labels, including their times, prices, colours, timeframe and any text you type. Text labels are free text, so do not put personal or sensitive information in them.
- Chart notice acceptances: each time you accept the risk and market data notice shown when the chart opens, we record your user ID, the notice version, the date and time, and a one-way hash of your IP address. We store the hash, not the address.
- Market data requests: when you open an instrument, your browser asks our servers for its prices and our servers fetch them from our market data provider. Your browser does not connect to the provider, and we do not send the provider your personal information.
- Exported and imported files: a drawings export is created in your browser and saved to your device; we do not keep a copy of the file. Drawings you import are stored like any others.
2.5 Information we do not seek
We do not ask for, and you should not send us, Social Security numbers, government ID numbers, bank account numbers, full payment card numbers, or your broker username and password. If you send us information of this kind anyway, we may delete it.
3. How we use information
We use personal information to:
- Provide and operate the Services: create and authenticate your account, connect your brokers, receive your signals, route and mirror orders as you configure, calculate and display positions and profit and loss, run paper accounts and forward tests, save and sync your chart settings and drawings, and deliver fill alerts, flatten, mute and other workspace features.
- Bill you: start, renew, change and cancel subscriptions through Stripe, apply promotion codes, and handle failed payments and disputes.
- Communicate with you: send transactional and service emails (see Section 7) and respond to support requests.
- Keep the Services secure: prevent fraud, abuse and unauthorized access, enforce rate limits, investigate incidents, and maintain audit trails of what the Services did on your behalf.
- Protect licensed market data: enforce the market data terms in our Terms of Service and the licences under which we supply market data, which may include limiting, logging and monitoring requests for market data and investigating suspected misuse.
- Maintain, troubleshoot and improve the Services: diagnose errors, measure performance and reliability, and, if you allowed analytics, understand which pages are read.
- Comply with law and protect rights: meet legal, tax and accounting obligations, keep records of your acceptance of our agreements and notices, respond to lawful requests, enforce our Terms of Service, and establish, exercise or defend legal claims.
We may create de-identified or aggregated information that no longer identifies you and use it for any lawful purpose. Where we do, we will maintain it in de-identified form and will not attempt to re-identify it, except as permitted by law. We do not use your personal information to make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not use your trading data to trade for our own account.
4. How we disclose information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not disclose your trading activity to other members. We disclose personal information only as described below.
4.1 Service providers and third parties we rely on
| Provider | Role | Information involved | Location |
|---|---|---|---|
| Railway | Application hosting and managed PostgreSQL database | All data stored by the Services | United States |
| Stripe | Payment processing, checkout, customer portal | Email, plan, billing and payment details you give Stripe, customer and subscription IDs | United States |
| Resend | Transactional email delivery | Email address, username and the content of the message | United States |
| Tradovate and other brokers you connect | Brokerage interface that receives your orders and returns account data | Access tokens, account identifiers, orders, positions, fills and balances | As set by the broker |
| Discord | Optional account linking and community roles; private staff channels for internal operational notices | Discord ID and username; for internal notices, limited account details such as your username, email address, user ID and plan, and the event (for example, an agreement acceptance, which also includes the IP address and browser recorded with it, or a partner application) | United States |
| Google and Apple | Optional sign-in | The identifier and email address the provider returns | United States |
| Google Analytics | Website analytics, only after you click Allow | Pages viewed, device and browser information, truncated IP address, analytics cookie identifiers; no account identifiers are sent | United States |
| Market data provider | Futures prices used to value open positions and to draw charts | No personal information. Our servers request the prices; your browser does not connect to the provider | Not applicable |
| TradingView | Sends the alerts you configure to your Quanify webhook | Whatever you place in your alert, plus your webhook token; TradingView's handling of your data is governed by its own policy | As set by TradingView |
Service providers may use the information only to perform services for us and as permitted by their agreements with us and their own terms. Brokers, TradingView, Discord, Google and Apple are independent services you choose to use; they process your information under their own privacy policies.
4.2 Other disclosures
- At your direction: for example, when you download or share a P&L image card, post in our Discord, or connect a third-party service.
- Legal and safety: when we believe in good faith that disclosure is required by law, subpoena, court order or other legal process, or is necessary to protect the rights, property or safety of Quanify, our users or others, to investigate fraud or security issues, or to enforce our agreements, including the licences under which we supply market data.
- Professional advisers: to our lawyers, accountants and auditors under duties of confidentiality.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, sale of assets or similar transaction, or in bankruptcy, personal information may be transferred to the successor or acquirer, subject to this Policy or a policy at least as protective.
5. Broker connections and credentials
We connect to brokers through the broker's own authorization flow (for Tradovate, OAuth). We do not ask for or store your broker username or password. The access and refresh tokens the broker issues are encrypted at rest and are used only to operate the Services for you: placing, modifying and cancelling orders you have configured, flattening positions on your instruction, and reading account, position, order, fill and balance data so the workspace can display it and the copy and automation engines can act on it.
You control the connection:
- Disconnect in Quanify: disconnecting a broker stops the Services from using that connection.
- Revoke at your broker: you can revoke Quanify's access in your broker's settings at any time, which invalidates the tokens we hold regardless of anything on our side.
Webhook tokens and passwords let anyone who has them send signals to your strategies. Keep them secret and rotate them if you think they have been exposed. You are responsible for the security of your devices, email account, TradingView account and broker account. Trading data we read from your broker is used to provide the Services and is subject to the retention rules in Section 8.
6. Cookies, local storage and analytics
We use a small number of first-party cookies and browser storage entries. Strictly necessary cookies are required for sign-in, security and checkout and cannot be switched off in the Services. Analytics cookies are set only if you allow them. We do not use advertising cookies, pixels or trackers.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| quanify_session | Cookie, strictly necessary, HttpOnly | Keeps you signed in across quanify.pro and trade.quanify.pro | Up to 7 days, or until you sign out |
| quanify_csrf | Cookie, strictly necessary | Protects forms and account actions against cross-site request forgery | Up to 7 days, or until you sign out |
| quanify_oauth_state, quanify_oauth_next | Cookies, strictly necessary, HttpOnly | Secure the Google or Apple sign-in handshake and return you to the right page | 10 minutes |
| quanify_checkout | Cookie, strictly necessary, HttpOnly | Ties a Stripe checkout to the browser that started it | 2 hours |
| quanify_consent | Cookie, strictly necessary | Remembers whether you allowed or declined analytics | 1 year |
| quanify_theme | Cookie, preference | Remembers your light or dark theme across Quanify subdomains | 1 year |
| qa-* keys | Local storage, preference | Remembers workspace and dashboard preferences on your device | Until you clear your browser storage |
| qc-* keys, quanify-theme | Local storage, functional | On the chart: keeps a copy of your chart settings and drawings so the chart loads quickly and keeps unsaved changes until they sync, remembers favourite timeframes and your theme, and records that you accepted the chart notice if you tick "Don't show again today" | Until you clear your browser storage; the notice record only applies until the end of that day |
| quanify_ref | Local storage, functional | Remembers a referral code from a link you followed so it can be attributed at checkout | Until you clear your browser storage |
| _ga, _ga_* | Cookies, analytics (Google Analytics), only after you click Allow | Distinguish visitors and sessions so we can see which pages are read | Up to 2 years, as set by Google |
6.1 Your analytics choice
On your first visit we show a notice asking whether to allow analytics. If you click Decline, or do not answer, the Google Analytics script is not loaded at all. If you click Allow, Google Analytics is loaded with IP truncation enabled and without account identifiers. You can change your choice at any time by deleting the quanify_consent cookie in your browser, after which the notice will appear again; deleting the _ga cookies removes existing analytics identifiers. Google also offers a browser add-on to opt out of Google Analytics.
6.2 Global Privacy Control and Do Not Track
If your browser sends a Global Privacy Control (GPC) signal, we treat it as a decision to decline analytics for that browser, and Google Analytics will not load. Because we do not sell or share personal information and do not use advertising cookies, there is nothing further for GPC to switch off. There is no common industry standard for "Do Not Track" signals, so we do not respond to them separately; our analytics remain off unless you click Allow.
7. Communications
We send transactional and service emails through Resend, including sign-up verification codes, welcome messages, password reset and password changed notices, subscription confirmations, payment failure notices and cancellation notices. We may also send notices about security, changes to our Terms or this Policy, and material changes to the Services. These messages are part of the Services, and you cannot opt out of them while your account is active. We do not currently send marketing email; if we begin to, we will provide a way to unsubscribe from it. We do not send SMS messages.
8. Data retention
We keep personal information only as long as reasonably necessary for the purposes described in this Policy. Specific periods currently applied by the Services:
- Email verification and password reset codes: stored only as hashes, expire after 10 minutes, and are deleted by a routine cleanup after they expire.
- Session records: deleted by a routine cleanup after the session expires (sessions last up to 7 days) or is ended.
- Security and audit events: deleted after approximately 90 days.
- Checkout records: deleted after approximately 30 days.
- Rate-limiting counters: held in memory only and discarded when they expire or the server restarts.
- Chart settings and drawings: kept while your account is open, until you change or delete them in the chart or ask us to delete them, including as part of an account deletion request. Copies in your browser stay until you clear your browser storage.
- Chart notice acceptances: kept while your account is open and for six years after it closes, as evidence of the terms you accepted and to establish or defend legal claims.
- Analytics cookies: as set by Google (see Section 6).
Routine cleanups run periodically, so deletion happens shortly after, not at the exact moment, a period ends. All other personal information, including account, subscription, broker connection, strategy, routing and trading activity records, is kept for as long as your account is active and afterwards as needed for legal, tax, accounting, dispute resolution, fraud prevention and security purposes, or until you ask us to delete it and we are not required or permitted to keep it. Records of your acceptance of our agreements may be kept for as long as they are needed to establish the terms that applied to you. Stripe retains payment records under its own policies. Residual copies in logs or backups, if any, are overwritten or deleted in the ordinary course.
9. Security
We use reasonable administrative, technical and physical safeguards designed to protect personal information, appropriate to the nature of the information and the Services. These include encryption of traffic in transit using HTTPS, encryption at rest of broker access tokens, hashing of passwords and one-time codes, HttpOnly and SameSite session cookies, cross-site request forgery protection, rate limiting, and limiting internal access to those who need it.
No method of transmission over the internet or of electronic storage is completely secure, and no safeguard can prevent every incident. We cannot and do not guarantee the security of any information, and you provide information and use the Services at your own risk. You are responsible for choosing a strong, unique password, keeping your credentials, webhook tokens and devices secure, and telling us promptly at [email protected] if you believe your account has been compromised. You should also maintain risk controls with your broker, as described in our Risk Disclosure.
If we determine that a security incident has compromised personal information in a way that requires notice, we will notify affected individuals, regulators and others as required by applicable law, including Arizona's data breach notification law (Arizona Revised Statutes Section 18-551 et seq.), using the contact information we have for you. Our responsibility for any security incident is limited as set out in our Terms of Service, to the fullest extent permitted by law.
10. Your choices and rights
10.1 Choices available to everyone
- Profile: update your username and password in Settings.
- Brokers: disconnect a broker in Quanify and revoke access at your broker at any time.
- Discord: remove Quanify from your Discord authorized apps, or ask us to unlink your Discord account.
- Analytics: decline or withdraw analytics as described in Section 6.
- Subscription: cancel through the Stripe customer portal linked from Settings.
- Chart: change your chart settings, and export or delete your drawings, in the chart.
10.2 Access, correction and deletion requests
You may ask us to confirm whether we process your personal information, to give you a copy of it, to correct inaccurate information, or to delete it, by emailing [email protected] from the email address on your account with the subject "Privacy request." Depending on where you live, you may have some or all of these rights by law, along with the rights described in Section 11 and Section 12. We honor requests as required by applicable law and will consider requests from any user.
When we delete your account, we remove or de-identify your account, broker connection and engine records, except information we must or may keep for the legal, tax, accounting, dispute, fraud prevention and security purposes described in Section 8. Deleting your account does not delete information held by your broker, Stripe, Discord, TradingView or other third parties; contact them directly. Before requesting deletion, disarm your strategies, stop copy trading and confirm your broker positions, because deletion ends the Services' ability to act on your accounts.
10.3 Verification
To protect your information, we must verify your identity before acting on a request. We will normally ask you to send the request from, or confirm it through, the email address on your account, and we may ask for additional information that matches our records. We will use information provided for verification only for that purpose. We may decline a request we cannot verify, and we may decline or limit requests as permitted by law, for example where they are manifestly unfounded or excessive or would affect the rights of others.
10.4 Authorized agents
Where the law allows, you may use an authorized agent to submit a request. We may require the agent to provide written permission signed by you, and may require you to verify your identity directly with us or confirm that you gave the agent permission, unless the agent holds a valid power of attorney.
10.5 Response times and appeals
We aim to respond within 45 days of receiving a verifiable request, and may extend that period by up to an additional 45 days where reasonably necessary, in which case we will tell you. If we decline your request, we will explain why. Where your state provides a right to appeal, you may appeal by replying to our decision with the subject "Privacy appeal"; we will respond within the time required by law, and if we deny the appeal you may contact your state attorney general.
10.6 Non-discrimination
We will not discriminate against you for exercising your privacy rights, including by denying the Services, charging different prices or providing a different quality of service, except that some requests (such as deletion) necessarily end our ability to provide the Services to you.
11. Notice to residents of California and other U.S. states
This Section supplements the rest of this Policy and serves as our notice at collection for California residents and our privacy notice under other U.S. state privacy laws, to the extent those laws apply to Quanify. During the 12 months before the effective date of this Policy, we have collected the following categories of personal information, from the sources, for the business purposes, and disclosed to the categories of recipients, described below.
- Identifiers (username, email address, IP address, account and customer IDs, Discord ID, sign-in provider ID). Sources: you, your devices, Stripe, Google, Apple, Discord. Disclosed to: hosting, payment, email, sign-in and analytics providers and Discord, as described in Section 4.
- Customer records and commercial information (plan, subscription status, renewal date, promotion codes, billing history). Sources: you and Stripe. Disclosed to: hosting provider, Stripe, Resend.
- Financial information (broker account IDs and names, balances, positions, orders, fills and profit and loss). Sources: your broker and your use of the Services. Disclosed to: hosting provider and your broker.
- Internet or other electronic network activity (session records, security and audit events, user agent, chart notice acceptances with a hashed IP address, market data requests, and, with your permission, website analytics). Sources: your devices. Disclosed to: hosting provider and, if you allowed analytics, Google.
- Preferences and chart content (workspace and chart preferences, theme, and the drawings and text labels you save on charts). Sources: you and your devices. Disclosed to: hosting provider.
- Sensitive personal information (account log-in credentials, meaning your email with a hashed password, and broker access tokens that allow access to your brokerage account). Sources: you and your broker. Disclosed to: hosting provider and your broker.
We do not collect precise geolocation, biometric, health or government identification information. We use and disclose these categories for the purposes listed in Section 3 and keep them for the periods in Section 8.
No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising or targeted advertising, and we have not done so in the preceding 12 months. We have no actual knowledge of selling or sharing personal information of consumers under 16. We use sensitive personal information only to provide the Services you request, to secure them, and for other purposes permitted without a right to limit, so we do not offer a "Limit the Use of My Sensitive Personal Information" option.
Your rights. Depending on your state, you may have the right to know or access the personal information we have collected about you (including the categories, sources, purposes and recipients), to receive a portable copy, to correct inaccuracies, to delete it, and to opt out of sale, sharing, targeted advertising and certain profiling (we do none of these). To exercise these rights, follow Section 10.
California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing purposes.
Nevada. We do not sell covered information as defined under Nevada law.
12. Visitors outside the United States
The Services are intended for users located in the United States. Quanify is based in the United States, and information is stored and processed in the United States, where data protection laws may differ from those in your country. If you access the Services from outside the United States, you do so on your own initiative and your information will be transferred to, stored and processed in the United States.
If the EU or UK General Data Protection Regulation applies to our processing of your information, Quanify LLC is the controller, and we rely on the following legal bases: performance of our contract with you (operating your account, broker connections, routing and billing); our legitimate interests in securing, maintaining and improving the Services and preventing fraud and abuse, balanced against your rights; compliance with legal obligations (tax, accounting and lawful requests); and your consent (analytics cookies, which you can withdraw at any time without affecting earlier processing). Subject to applicable law, you may have the right to access, correct, delete, restrict or object to processing of your information, to data portability, and to withdraw consent, and you may lodge a complaint with your local supervisory authority. Contact us first at [email protected] so we can try to resolve your concern.
13. Children
The Services are not directed to, and may not be used by, anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will delete it and close the account. If you believe a minor has provided us information, contact [email protected].
14. Third-party services and links
The Services connect to and link to services we do not control, including brokers, TradingView, Stripe, Discord, Google, Apple, prop firms and economic calendar sources. Quanify is not affiliated with any broker, prop firm, exchange or TradingView. We are not responsible for the privacy, security or content of third-party services, and your use of them is governed by their own terms and privacy policies.
15. Changes to this Policy
We may update this Policy from time to time. We will post the updated Policy on this page with a new effective date and, for material changes, will provide additional notice, such as by email or in the Services, and may ask you to accept the updated Policy before continuing to use the Services. Changes take effect on the effective date stated. Your continued use of the Services after that date means you accept the updated Policy, to the extent permitted by law. If you do not agree, stop using the Services and you may ask us to delete your account.
16. Contact us
Questions, requests and complaints about this Policy or our privacy practices can be sent to:
Quanify LLC, Arizona, United States. Email: [email protected]
Please use the subject "Privacy request" for rights requests so we can route them promptly.