Privacy Policy
Effective 2026. This describes what personal data Equisect processes, why, and what control you have over it. The specific legal entity that acts as data controller for your account is named in the Order Form or subscription agreement you sign — see our Terms & Conditions.
What we collect
Account data: your email address (for sign-in and billing contact), your plan/entitlement status, and API keys you create. Usage data: the scenarios you price (fund/cohort, inputs, and the resulting figures), memo drafts and notes you generate or type, and Portfolio-upload files you submit. For paid plans, a record of the bank transfer arranged with our sales team — there is no self-serve checkout, and we never see or store your card or bank account details ourselves; payment is arranged directly with you, off-platform, by our sales team. Basic request logs (timestamp, route, account) for security and abuse prevention.
What we don't collect
We don't run third-party analytics, advertising, or cross-site tracking scripts on Equisect — there is nothing here to opt out of because nothing here tracks you across other sites. We don't sell your data, and we don't share it with any third party except the narrow, operational cases described under "Sub-processors" below.
How we use it
To operate the service (authenticate you, run the pricing/analytics you request, enforce your plan's fair-use limits), to bill and support paid accounts, to keep the service secure (rate-limiting, abuse detection, audit logging of admin actions), and to maintain and improve Equisect's own models and dataset — using our own proprietary fund data, never your uploaded portfolio content (see "Confidentiality of your data" in our Terms).
Legal basis for processing
Where GDPR or a similar framework applies: account and usage data is processed because it's necessary to perform our contract with you (running the service you subscribed to); security and abuse-prevention logging is processed under our legitimate interest in keeping the service reliable and safe for every account; and payment records are kept to meet our legal obligations (tax/accounting). We don't rely on consent for anything described here because we don't run marketing cookies or trackers that would need it.
Sign-in & cookies
We use passwordless email sign-in codes. We never store a password. Each sign-in code is stored only as a one-way hash and expires shortly after it's sent. The only cookie we set is a signed, HTTP-only session cookie that keeps you signed in and protects form submissions against cross-site request forgery — no third-party or advertising cookies are set by Equisect.
AI processing
The optional IC-memo drafting add-on runs on a local AI model hosted on infrastructure we operate — the pricing data and notes you send it are never sent to a third-party AI provider, and each drafting request is a fresh, stateless call that isn't retained to train the model or shared with any other account. See our Disclaimer for what this feature is and isn't.
Sub-processors & third parties
We keep this list short and functional — nothing here is marketing/advertising-related:
- Transactional email. An SMTP relay, used only to deliver sign-in codes and account/billing notifications you'd expect from using the service.
- Error tracking (optional). Where enabled, a third-party error-tracking service receives crash/error reports to help us fix bugs. We configure it to never include request bodies or personal data by default.
- Offsite backups (optional). Where enabled, encrypted database backups are copied to a third-party S3-compatible storage bucket, purely for disaster recovery.
- Public macro data. A small set of macro-economic figures are fetched from FRED®, the Federal Reserve Bank of St. Louis's public data service — this is a read-only public API call, not a place any of your data goes.
Data retention
We keep your account data for as long as your account is active. Payment records are kept for 7 years after they're logged, for standard tax/accounting purposes, then automatically purged. Sign-in codes are single-use and expire within minutes regardless of whether they're used. You can export or permanently delete your account's data yourself at any time from Account (see "Data & privacy"), or email legal@equisect.com to request deletion.
Your rights
You can access and export a machine-readable copy of your account data at any time from Account. You can request correction of inaccurate account data, or deletion of your account and its associated data (subject to the retention exceptions above, e.g. payment records we're legally required to keep) — both available self-service from Account, or by emailing legal@equisect.com. Where GDPR or a similar framework applies, you also have the right to object to certain processing and to lodge a complaint with your local data-protection supervisory authority.
International transfers
Equisect does not transfer your personal data to any location beyond the systems and sub-processors described on this page — see "Sub-processors & third parties" above for the complete list of anywhere your data can go.
Data security
Passwords are never used or stored (see "Sign-in & cookies" above); traffic to Equisect is encrypted in transit; every state-changing request is protected against cross-site request forgery; and administrative access to account data is limited to what support and operations genuinely require, with admin actions (grants, revocations) written to an internal audit log.
Children
Equisect is a professional tool for institutional and business users and is not directed at, or knowingly used by, children.
Changes to this policy
We may update this policy from time to time; the effective date above reflects the latest revision. For a material change, we'll make a reasonable effort to notify active accounts before it takes effect.
Contact
legal@equisect.com
