Privacy Policy
Effective Date: April 23, 2026 | Last Updated: April 23, 2026
1. Introduction
GAZUM® Corp. ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the GAZUM® Market Intelligence platform ("Service").
By using the Service, you consent to the practices described in this policy. If you do not agree, do not use the Service.
2. Information We Collect
2.1 Information You Provide
Account Information:
- Full name, first name, last name
- Email address
- Password (hashed with bcrypt — never stored in plaintext)
- Phone number (optional)
- Profile picture (optional)
- Timezone preference
- Two-factor authentication secret (encrypted at rest)
- Backup codes for 2FA recovery (hashed)
Payment Information:
- Billing name and address
- Payment method details (processed and stored securely by Stripe — we do not store full card numbers on our servers)
- Stripe customer identifier and subscription identifiers
- Transaction and invoice history
User-Generated Content:
- Custom scanner configurations, watchlists, and saved dashboard layouts
- Alert settings and widget preferences
- Trade journal entries, including broker name, symbol, side, entry/exit price and time, position size, notes, tags, playbook references, and attached screenshots
- Playbooks, checklists, and strategy configurations
- Chat messages, public profile details, shared watchlists, and alert listings you publish
- Support ticket content and Widget Feedback submissions
- NDA signatures, including the signed version string and timestamp
Broker and Third-Party Connections:
- OAuth access and refresh tokens for connected brokers (e.g. TradeStation). Tokens are encrypted at rest and used only for your explicit broker actions.
- Connected-account metadata (account number, account name). We do not have standing authority to trade on your behalf outside of direct user action.
Voice and AI Content:
- Audio you submit to speech-to-text features (e.g. AI Trading Coach voice input) is streamed to ElevenLabs for transcription and not retained beyond the session.
- Text you submit to AI features (AI Coach, AI Copilot, AI Ensemble, Pre-Trade Coach, Screenshot-to-Setup, Auction Playbook) is sent to third-party AI providers as described in Section 4.
- Uploaded screenshots and charts you submit to Screenshot-to-Setup or Chart Vision are sent to the relevant AI provider for the duration of the request.
2.2 Information Collected Automatically
Usage Data:
- Pages and features accessed, time spent on the Service
- Scanner queries, widget interactions, feature usage analytics
- Error logs, performance metrics, client-side crash reports
- AI credit and voice credit ledgers (amounts debited and for which feature)
- Audit log entries for account, subscription, and admin-action changes
Device and Session Information:
- Browser type and version, operating system, device type, screen resolution
- IP address and approximate geolocation (city/country derived from IP)
- Session tokens, last-seen and last-login timestamps
3. How We Use Your Information
3.1 Service Delivery
- Create and manage your account
- Provide access to features based on your subscription tier and active Starter Packs
- Process payments, subscriptions, and promotion codes
- Save your preferences, layouts, custom scanners, and journal entries
- Deliver alerts, notifications, briefings, and voice narration you've configured
- Enable broker integrations and live-trading actions you initiate
- Generate AI-powered insights (scores, predictions, coach replies, trade critiques)
3.2 Service Improvement
Analyze usage patterns, debug errors, develop new features, conduct internal research.
3.3 Security
Detect and prevent fraud; monitor for unauthorized access; enforce the Terms; comply with legal obligations.
3.4 Communications
Account notices, subscription receipts and renewal reminders, morning briefings and weekly recaps (opt-in/out per email preference), product announcements.
4. Data Sharing and Third-Party Service Providers
4.1 Service Providers
We share data with trusted third parties who help operate the Service. Each is under a data-processing agreement where the provider offers one:
| Provider | Purpose | Data Shared |
|---|---|---|
| Fly.io | Application hosting + egress | Request logs, IP addresses |
| Supabase | Managed PostgreSQL database | All account data (encrypted in transit; bcrypt/AES-256 for sensitive fields) |
| Stripe | Payment processing and subscription billing | Name, email, billing address, payment method, invoice history |
| Resend | Transactional email delivery | Recipient email, subject, message body |
| Anthropic | Claude API for AI Coach, AI Copilot, AI Ensemble, Pre-Trade Coach, News Impact, Auction Playbook, Screenshot-to-Setup | Prompts, journal entries, setup notes, screenshots you submit. No training on your data per Anthropic's API terms. |
| OpenAI | Text embeddings (semantic search within your journal) | Plain-text journal content you opt into embedding. No training per OpenAI API terms. |
| ElevenLabs | Text-to-speech narration and speech-to-text transcription (Voice Credits) | Text for synthesis; audio for transcription. Not retained beyond the request. |
| QuoteMedia | Equities and ETF market data | None from you — we only receive data from this provider |
| Rithmic | Futures real-time data | None from you — inbound market data only |
| TradeStation | Brokerage integration (Live Trading feature, if enabled) | OAuth access tokens, order/position data you initiate |
| Binance | Crypto market data | None from you — inbound market data only |
| Tigris (Fly object storage) | Storage for trade screenshots, avatars, recorded education videos | Uploaded images and video files |
| Stream Chat | In-app chat and direct messaging | Username, message content, channel membership |
| LiveKit | Real-time audio/video for Live Room (when used) | Session metadata; audio/video is peer-to-peer and not stored |
| Twilio | SMS notifications (where opted in) | Phone number, SMS content |
| TradingView | Advanced charting library | None (charting runs client-side against our datafeed) |
Not every user interacts with every processor. For example, TradeStation only receives data when you explicitly connect a broker; ElevenLabs only receives data when you use Voice Credits.
4.2 AI Data Handling
When you use AI features, the text or images you submit (including journal entries, setup notes, and screenshots) are transmitted to the relevant AI provider to generate a response. We do not authorize these providers to train on your data, per their standard API terms. Outputs are returned to you within the Service and, in some cases, stored in your account so you can review them later (e.g. Trade Journal AI critiques).
4.3 Legal Disclosure
We may disclose data if required by subpoena, court order, or other legal process, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of GAZUM® Corp., our users, or the public.
4.4 No Sale of Personal Data
We do not sell your personal information to third parties.
5. International Data Transfers
GAZUM® Corp. is based in the United States. Most of our service providers (Stripe, Anthropic, OpenAI, Supabase, Fly.io, Resend, ElevenLabs, Stream Chat, LiveKit, Twilio) are also US-based or operate multi-region infrastructure with data processed in the US.
If you access the Service from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data-localisation laws, your data will be transferred to and processed in the United States and potentially other countries where our providers operate. Such transfers rely on Standard Contractual Clauses or equivalent safeguards where required.
6. Data Retention
We retain your data for as long as necessary to maintain your active account, provide the Service, comply with legal obligations, and resolve disputes.
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion + 30 days |
| Trade journal entries and screenshots | Until you delete them, or account deletion + 30 days |
| Subscription and payment records | 7 years (tax / legal requirements) |
| AI prompts and responses | Up to 90 days on our side; see third-party processor terms for their retention |
| Usage / analytics logs | 90 days |
| Support tickets | 3 years |
| Audit logs (security, admin actions) | 2 years |
| Broker OAuth tokens | Until you disconnect the broker or delete your account |
7. Data Security
7.1 Technical Safeguards
- SSL/TLS encryption for all data in transit
- AES-256 encryption for sensitive data at rest (broker tokens, 2FA secrets)
- Password hashing with bcrypt
- Two-factor authentication (2FA) with TOTP + backup codes
- Row-level security (RLS) on database tables that hold user data
- IP-scoped API keys for payment processing (where supported)
- Regular security reviews and automated dependency patching
7.2 Your Responsibilities
- Keeping your password confidential and using a strong, unique password
- Enabling two-factor authentication
- Logging out of shared devices
- Reporting suspicious activity to security@gazum.com
8. Your Privacy Rights
8.1 All Users
All users may request:
- Access: a copy of your personal data
- Correction: update inaccurate or incomplete data
- Deletion: deletion of your account and data
- Portability: your data in a portable format (e.g. JSON/CSV export of your trade journal)
- Opt-out: unsubscribe from marketing communications
Contact privacy@gazum.com to exercise these rights.
8.2 EEA / UK Residents (GDPR / UK GDPR)
EEA and UK residents also have rights to restriction, objection, withdrawing consent, and lodging complaints with their supervisory authority.
8.3 California Residents (CCPA / CPRA)
California residents have the right to know what we collect, delete, correct, opt-out of sales (we do not sell data), and non-discrimination.
9. Cookies and Tracking
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, session security | Session |
| Functional | Preferences, dashboard layouts | 1 year |
| Analytics | Aggregate feature usage | 1 year |
You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.
10. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately at privacy@gazum.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notice and/or email at least 30 days before they take effect. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
12. Contact Us
GAZUM® Corp.
- Privacy Inquiries: privacy@gazum.com
- Data Protection Officer: dpo@gazum.com
- General Support: support@gazum.com
- Security Reports: security@gazum.com
- Website: https://www.gazum.org
© 2026 GAZUM® Corp. All rights reserved.