Skip to main content

Privacy Policy

This policy explains what information NineQuantAI (ninequantai.com, "the platform") collects, how we use and store it, and what rights you can exercise. Please read it in full before using the platform.

Last updated: 09/01/2026

1. Information we collect

We collect only what is necessary to provide the service, in four categories:

  • Account information — the email address you register with, and your sign-in credentials stored in encrypted form. Sign-in uses an emailed one-time code; the platform sets no password, and codes are stored as hashes that expire once used or timed out.
  • Usage data — API key call records (endpoint path, time, response status), call-volume statistics, and the symbol, date range and strategy parameters you submit to the backtest tool.
  • Technical information — IP address, browser type, device information and access logs (request path, time, duration, status code).
  • Analytics — self-hosted, anonymous traffic statistics that record only page paths, referrers and aggregate visit counts. We use no third-party advertising cookies, join no ad networks and perform no cross-site tracking.

We do not collect your real name, government ID numbers, bank card numbers, phone number or location, and we never touch your brokerage account — the platform connects to no broker and has no order-placing capability.

2. How we use information

The information we collect is used only to:

  • Provide, maintain and improve the service — run backtests, return market data and keep your backtest history.
  • Verify identity, manage accounts and send notices — deliver sign-in codes, identify account ownership and send notices directly related to the service (such as security alerts or changes to these terms).
  • Rate-limit and prevent abuse — enforce per-plan quotas and frequency limits, and detect abnormal access and scraping.
  • Produce anonymous aggregate statistics — understand how features are used and decide where to invest further.

We do not use your information to market third-party products to you, and we never recommend any security or investment product based on your backtest parameters.

3. Storage and security

  • Encryption in transit — HTTPS is enforced site-wide, and every API call travels over TLS.
  • Hashed storage — API keys and sign-in codes are stored only as hashes, which cannot be reversed to the original value.
  • Access control — the production database is not exposed to the public internet, and operational access requires authorisation and is audited.

Despite these measures, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. Should a security incident affect your rights, we will notify affected users within the time and in the manner required by applicable law.

4. Information sharing

We do not sell or rent your personal information. We share the minimum necessary information only in these three situations:

  1. With your explicit consent — for example, when you ask us to help investigate an issue and authorise us to review the relevant records.
  2. When required by law — in response to a lawful request from a competent authority, or where necessary to comply with laws, regulations or court orders.
  3. To protect rights and safety — where necessary to prevent fraud, abuse or security incidents, or to protect the legitimate interests of the platform, its users or the public.

The third-party infrastructure we rely on to run the service (market data provider, email delivery, cloud hosting and CDN) sees only the minimum data needed for its role. Requests to the market data provider are made by our servers and contain only a symbol and a date range — never any information that identifies you.

5. Cookies and local storage

The platform uses very little browser storage, all of it strictly functional, and sets no advertising or tracking cookies:

  • Local storage (localStorage) — holds your sign-in token to keep you signed in, plus interface preferences such as light/dark theme and up/down colours.
  • Cookie — used only to remember your chosen interface language.

You can clear this data at any time through your browser settings. Doing so signs you out and resets language and theme preferences; nothing else is affected.

6. Your rights

You may exercise the following rights over the information we hold about you:

  • Access — learn what information we hold. Your account details, API key status and call statistics are visible directly in the dashboard.
  • Rectification — correct inaccurate information.
  • Deletion — delete individual backtest records, or reset your API key.
  • Account closure — close your account and delete the associated data. We delete account information and backtest records within 30 days of closure; for security and compliance, some access logs are retained for a limited period after anonymisation.

To exercise these rights, contact us at the email address at the bottom of this page. To protect your account, please write from your registered email address so we can verify it is you.

7. Policy updates

This policy may be updated as features change or the law requires. Every update changes the "last updated" date at the top of this page. Where an update materially affects your rights (for example a new purpose for data, or a new category of recipient), we will give advance notice by email or prominently on the site. Continuing to use the platform after an update constitutes acceptance of the revised policy.

8. Contact us

For any question or comment about this policy, or to exercise any of the rights above, email support@ninequantai.com from your registered address so we can verify your identity. We normally reply within 1–3 business days.