Privacy Policy

Effective date: March 25, 2026
Last updated: August 12, 2026

Your privacy is important to us. This Privacy Policy explains what information we collect, how we use it, and the rights you have over your data when you use the Quantum Wealth Asset Intelligence Platform.

1. What Data We Collect

We collect the following categories of information:

Account Information

Your name, email address, and hashed password provided at registration. This information is required to create and maintain your account.

Portfolio and Financial Data

Asset positions, transaction history, account balances, performance snapshots, and any other financial data you enter into the platform directly or via statement imports. This is Your Data — you own it and we process it solely to provide the Service. If you upload a statement file, the file itself is read to extract this data — see Section 6, which explains exactly where that file is sent.

Usage Data

Information about how you interact with the platform, including pages visited, features used, actions taken, and timestamps. This is used for platform improvements, debugging, and security monitoring.

Technical Data

IP address, browser type, and device information collected automatically when you access the platform. This is used for security and authentication purposes only.

2. How We Use Your Data

We use your information only for the following purposes:

  • To provide, operate, and maintain the Quantum Wealth platform.
  • To authenticate you and secure your account.
  • To display your portfolio analytics, reports, and financial summaries.
  • To read the statements you upload and extract the holdings, balances, and account details from them. This involves sending the statement to the AI providers named in Section 6.
  • To generate AI-assisted research on securities you look up. These requests carry market data only — never your positions (see Section 6).
  • To send important account notifications (account approval, security alerts).
  • To diagnose bugs and improve platform performance.
  • To comply with legal obligations if required by applicable law.

We do not sell or rent your data, and we do not share it with anyone for advertising or marketing. We do send data to the third-party processors listed in Section 6 in order to run the features described above — that is the only reason your data ever leaves our servers.

3. Data Storage and Security

Your data is stored in a secured database. Passwords are stored using a strong one-way hashing algorithm and are never stored in plain text. Traffic between your browser and the platform is encrypted with HTTPS. The database runs on the same machine as the application and is reached over a local loopback connection, so database traffic never travels across a network.

Access to production systems is restricted to authorised administrators only. We implement industry-standard security controls including rate limiting, session expiry, and HTTPS enforcement across all platform endpoints.

While we take reasonable steps to protect your information, no system is completely secure. You are responsible for keeping your login credentials confidential and for reporting any suspected unauthorised access to support@ankoracw.space.

4. Your Rights

You have the following rights regarding your personal data:

  • Access: You may request a copy of the personal data we hold about you at any time.
  • Export: You may request an export of your portfolio data in a machine-readable format.
  • Correction: You may ask us to correct inaccurate account information we hold about you.
  • Deletion: You may request deletion of your account and all associated data. Deletion requests will be processed within 30 days, subject to any legal obligations requiring us to retain certain records.

To exercise any of these rights, please contact us at support@ankoracw.space.

5. Cookies

We use a single, strictly necessary session cookie (__Host-wip_session) to maintain your authenticated session. This cookie is:

  • Set only when you log in and cleared when you log out or it expires.
  • Scoped to the platform domain and never sent to third parties.
  • Not used for tracking or advertising purposes.

We do not use analytics cookies, advertising cookies, or any third-party tracking technologies. This is a statement about tracking only — it does not mean that no third party ever receives your data. Section 6 lists every third party that does.

6. Third-Party Services and AI Processing

Parts of the platform are powered by artificial-intelligence models that we do not run ourselves. Using them means your data is sent to the companies that do run them. The list below is the complete set of third parties that receive data from the platform, and it states plainly what each one receives.

Google — statement scanning (Gemini API)

When you upload a PDF statement, the platform sends the complete, unmodified PDF fileto Google's Gemini API so the model can read the holdings tables. That file contains whatever your bank or broker printed on it, which normally includes your name, the institution's name, your account number, the statement period, every position with its quantity, price, and market value, and your cash balances. This is the primary scanner for PDF statements from every institution except Interactive Brokers, whose statements are read by our own parser first — but that exception depends on the PDF containing selectable text. An Interactive Brokers statement that is a scan or a photograph has no text for our parser to read, so it is sent to Google like any other scanned statement.

Ollama — statement scanning and securities research

The platform reaches Ollama through a service running on our own server, but the models it is configured to use are cloud-hosted by Ollama, so the content of a request is relayed to Ollama's infrastructure rather than being processed on our machine. Ollama receives:

  • The extracted text of your statement pages — or images of those pages, when the statement is a scan — if the Gemini scan is unavailable or returns nothing.
  • The first page of an Interactive Brokers statement, which carries the account holder name, account number, and net asset value.
  • The holdings pages of an Interactive Brokers statement, when our own parser's totals do not reconcile.
  • The flattened contents of a CSV or Excel file, when our own parser cannot extract anything from it.

Ollama also generates the AI research write-ups for individual securities. Those requests are deliberately built from public market data only and contain no position, holding, or account information: the report is cached and shared between users, so it is generated without knowing whose portfolio prompted it. What Ollama does learn is which ticker symbol was looked up.

Market data providers

The platform fetches publicly available market data — prices, exchange rates, fundamentals, and economic calendar entries — from third-party financial data providers. These requests are made server-side and contain only a security identifier such as a ticker symbol, or a currency pair. They carry no account identifier, no name, and no quantity or value, so these providers do not receive your identity or your holdings.

Your own broker

If you connect an Interactive Brokers account, the platform calls Interactive Brokers' Flex Web Service with the query credentials you supplied in order to retrieve your own statement data. This sends data to your broker, not to a new third party.

Email delivery

Account emails (email verification, password reset) are sent through a mail relay, which receives your email address and the contents of that message. No portfolio data is included in these emails.

What stays on our own server

Everything else. Your stored portfolio, all valuation, performance, allocation, and risk calculations, our own deterministic statement parsers (including the Interactive Brokers parser), the optical character recognition fallback for scanned pages, and anything you type into the platform by hand are processed on our own infrastructure and are not sent to any AI provider. Entering positions manually never involves an AI provider at all.

We do not send your data to these providers so that they can train models on it, and we have not agreed to any such use on your behalf. However, once data reaches a third-party provider it is handled under that provider's own terms and privacy policy, which we do not control and cannot independently verify. We cannot tell you how long Google or Ollama retain what they receive, so we are not going to state a period we would be guessing at.

If you would prefer that your statements are never sent to an AI provider, do not use the PDF statement upload. Entering positions by hand keeps the data on our server, and a CSV or Excel import is read by our own parser first — it reaches an AI provider only if that parser cannot extract anything from the file.

7. International Data Transfers

The platform is hosted on a server in the European Union. The AI providers described in Section 6 are United States companies serving their models from infrastructure outside the European Union. When a statement is scanned, the data it contains is therefore transferred internationally and processed under another jurisdiction's law.

We have not put a specific transfer mechanism, such as EU Standard Contractual Clauses, in place with these providers. We are stating that plainly rather than implying a safeguard that is not there. If this matters to you, the alternatives in Section 6 keep your statement data on our own server.

8. Data Retention

We retain your account and portfolio data for as long as your account is active or as needed to provide the Service. If you request account deletion, we will delete or anonymise your data within 30 days, except where retention is required by law.

An uploaded statement file is read in memory and is not stored as a file on our servers. What we keep from it is the extracted data — holdings, balances, and the details you confirm on import — together with an import audit record that includes the file name. AI-generated securities research is treated as current for 24 hours and regenerated after that, but the older reports are not deleted: they are kept so that your research history remains available to you. Each stored report records which account requested it and when, so we retain a record of which securities you have researched for as long as your account exists. The reports themselves are built from public market data and contain no portfolio or position information.

Deleting your account removes your data from our systems. It does not, and cannot, reach back into the systems of the third-party providers in Section 6 to remove data already transferred to them.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or an in-platform notification. Continued use of the Service after updates take effect constitutes acceptance of the revised policy.

10. Contact

If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us at:

support@ankoracw.space

DashboardTerms of ServiceContact Support