Skip to main content

Privacy Policy

This policy explains what information NineQuantAI (ninequantai.com, "the platform") collects, how we use and store it, and what rights you can exercise. Please read it in full before using the platform.

Last updated: 09/09/2026

1. Information we collect

We collect only what is necessary to provide the service, in five categories:

  • Account information — the email address, name and phone number (country/region code plus number) you enter when you register. Sign-in uses an emailed one-time code; the platform sets no password, and codes are stored as hashes that expire once used or timed out.
    • Your name is whatever you type. We do not check it against any identity document, and we never ask you to upload one.
    • Your phone number is not verified, and we send nothing to it — no text messages, no calls. It never reaches an SMS provider or any other third party; it sits in our database as a fallback way to reach you.
  • Registration and sign-in records — at registration and on every sign-in thereafter, we record the time, your IP address, the country or region derived from that IP, your browser's user agent and the interface language you were using, and we keep a running count of how many times you have signed in.
    • Location is recorded only as a two-letter country/region code (US, CN, and so on). We do not store a city, coordinates or anything more precise, and we never call the browser's geolocation API.
    • The country or region is derived by an offline IP database running on our own servers. The lookup happens entirely inside our infrastructure: your IP address is never sent to a third-party lookup service.
  • Usage data — API key call records (endpoint path, time, response status), call-volume statistics, and the symbol, date range and strategy parameters you submit to the backtest tool.
  • Technical information — the IP address in our access logs, browser type, device information and request records (path, time, duration, status code).
  • Analyticsself-hosted traffic statistics that record, for each visit, the page path, referrer, interface language, IP address, browser User-Agent and a visitor identifier stored in your browser (see section 5). That identifier lets us tell whether the same person came back a week later; once you register, it also links the pages you browsed before registering to your account. All of this runs on our own servers: we use no third-party advertising cookies, join no ad networks, perform no cross-site tracking, and send none of this data to any third party.

We do not collect government ID numbers, bank card numbers or precise location, and we never touch your brokerage account — the platform connects to no broker and has no order-placing capability.

2. How we use information

The information we collect is used only to:

  • Provide, maintain and improve the service — run backtests, return market data and keep your backtest history.
  • Verify identity, manage accounts and send notices — deliver sign-in codes, identify account ownership and send notices directly related to the service (such as security alerts or changes to these terms). Every notice goes out by email; we send nothing to the phone number you provide.
  • Keep accounts secure — registration and sign-in records (time, IP, country/region code, sign-in count) let us spot unusual sign-ins, such as one account appearing in two countries minutes apart, and give us something concrete to check when you write to us about a problem with your account. Your name and phone number let us confirm account ownership when you contact us.
  • Rate-limit and prevent abuse — enforce per-plan quotas and frequency limits, and detect abnormal access and scraping.
  • Produce anonymous aggregate statistics — understand how features are used and which countries and regions our users come from, and decide where to invest further.

We do not use your information to market third-party products to you, and we never recommend any security or investment product based on your backtest parameters. Your name and phone number are not used for marketing of any kind.

3. Storage and security

  • Encryption in transit — HTTPS is enforced site-wide, and every API call travels over TLS.
  • Sign-in codes are stored as hashes only — they cannot be reversed to the original value.
  • API keys are viewable in full in your dashboard — to make that possible we also keep a copy encrypted with a server-side key, so an API key is not in the category of "we cannot see it either". Treat it like a password; if you suspect it has leaked, reset it in the dashboard and the old key stops working immediately.
  • Access control — the production database is not exposed to the public internet. The admin console requires administrator rights, and every time an administrator opens a user detail page or sign-in history — the places that show a name, phone number, IP addresses and full sign-in records — an audit entry records who looked at whom, and when.
  • Retention:
    • Account information (including your name and phone number) and your registration and sign-in records are kept for as long as the account exists and are removed with it when you close the account: the sign-in records are attached to the account by a database-level cascade, so they cannot be left behind once the account is gone.
    • Sign-in code records (email address, the IP the request came from, timestamp) are deleted automatically after 7 days, whether or not that address ever completed registration. Those few days exist so we can check what happened if you write to say a code never arrived.
    • Traffic statistics and server access logs are kept as long as operations require, for troubleshooting, abuse prevention and aggregate statistics. They keep the full IP address and User-Agent; we do not anonymise them — anonymising would destroy the "same person" signal that abuse prevention depends on. When you close your account, the traffic statistics relating to you are deleted with it, including the records from before you registered that carry only a visitor identifier.
    • Administrative audit logs are kept long term and contain the email address of the administrator who performed the action; the user ID of the person acted upon is cleared when that person closes their account. The point of an audit log is that the person being audited cannot erase it.

Despite these measures, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. Should a security incident affect your rights, we will notify affected users within the time and in the manner required by applicable law.

4. Information sharing

We do not sell or rent your personal information. We share the minimum necessary information only in these three situations:

  1. With your explicit consent — for example, when you ask us to help investigate an issue and authorise us to review the relevant records.
  2. When required by law — in response to a lawful request from a competent authority, or where necessary to comply with laws, regulations or court orders.
  3. To protect rights and safety — where necessary to prevent fraud, abuse or security incidents, or to protect the legitimate interests of the platform, its users or the public.

The third-party infrastructure we rely on to run the service (market data provider, email delivery, cloud hosting and CDN) sees only the minimum data needed for its role. Requests to the market data provider are made by our servers and contain only a symbol and a date range — never any information that identifies you.

5. Cookies and local storage

The platform uses very little browser storage, and everything it sets comes from us — no third-party advertising cookies, no ad networks, no cross-site tracking:

  • Local storage (localStorage) — holds your sign-in token to keep you signed in, plus interface preferences such as light/dark theme and up/down colours.
  • Language cookie — remembers your chosen interface language.
  • **Visitor cookie (nq_vid) — a random string that lasts one year and lets us count repeat visits from the same browser as the same visitor. It answers questions like "how many people came back a week later" and "how many visitors eventually registered". It stays in place after you sign in, which means the pages you browsed before registering can be linked to your account — we say so plainly rather than hiding it in wording. It contains none of your personal information and is never sent to a third party, but by the usual definition it is a tracking cookie**.

You can clear this data at any time through your browser settings. Doing so signs you out, resets language and theme preferences, and makes your next visit count as a new visitor; nothing else is affected.

6. Your rights

You may exercise the following rights over the information we hold about you:

  • Access — learn what information we hold. Your account details, API key status and call statistics are visible directly in the dashboard.
  • Rectification — correct inaccurate information. Your name, phone number, nickname and interface preferences are all editable directly in dashboard settings, and changes take effect immediately.
  • Deletion — delete individual backtest records, or reset your API key. If you would rather we did not keep your name or phone number, ask us to delete them — neither is used to sign in, so the account works exactly as before without them.
  • Account closure — you can close your account yourself in the dashboard settings. Closing it immediately deletes the account record, your registration and sign-in records (including IP addresses and country/region codes), API keys, backtest history, usage statistics, export jobs, and the traffic statistics relating to you — including the pre-registration browsing records that carry only a visitor identifier.

Two exceptions, stated plainly: articles you published publicly stay on the site but are no longer linked to your account; and if you ever acted as an administrator, the administrative audit log keeps the email address you used at the time (a chain of accountability cannot be erased by the person being audited). Raw server access logs (nginx and application logs) are rotated out on the operational schedule rather than deleted per record.

To exercise these rights, contact us at the email address at the bottom of this page. To protect your account, please write from your registered email address so we can verify it is you.

7. Policy updates

This policy may be updated as features change or the law requires. Every update changes the "last updated" date at the top of this page. Where an update materially affects your rights (for example a new purpose for data, or a new category of recipient), we will give advance notice by email or prominently on the site. Continuing to use the platform after an update constitutes acceptance of the revised policy.

8. Contact us

For any question or comment about this policy, or to exercise any of the rights above, email ninequantai@gmail.com from your registered address so we can verify your identity. We normally reply within 1–3 business days.