Privacy Policy

Effective Date: April 23, 2026 | Last Updated: April 23, 2026


1. Introduction

GAZUM® Corp. ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the GAZUM® Market Intelligence platform ("Service").

By using the Service, you consent to the practices described in this policy. If you do not agree, do not use the Service.


2. Information We Collect

2.1 Information You Provide

Account Information:

  • Full name, first name, last name
  • Email address
  • Password (hashed with bcrypt — never stored in plaintext)
  • Phone number (optional)
  • Profile picture (optional)
  • Timezone preference
  • Two-factor authentication secret (encrypted at rest)
  • Backup codes for 2FA recovery (hashed)

Payment Information:

  • Billing name and address
  • Payment method details (processed and stored securely by Stripe — we do not store full card numbers on our servers)
  • Stripe customer identifier and subscription identifiers
  • Transaction and invoice history

User-Generated Content:

  • Custom scanner configurations, watchlists, and saved dashboard layouts
  • Alert settings and widget preferences
  • Trade journal entries, including broker name, symbol, side, entry/exit price and time, position size, notes, tags, playbook references, and attached screenshots
  • Playbooks, checklists, and strategy configurations
  • Chat messages, public profile details, shared watchlists, and alert listings you publish
  • Support ticket content and Widget Feedback submissions
  • NDA signatures, including the signed version string and timestamp

Broker and Third-Party Connections:

  • OAuth access and refresh tokens for connected brokers (e.g. TradeStation). Tokens are encrypted at rest and used only for your explicit broker actions.
  • Connected-account metadata (account number, account name). We do not have standing authority to trade on your behalf outside of direct user action.

Voice and AI Content:

  • Audio you submit to speech-to-text features (e.g. AI Trading Coach voice input) is streamed to ElevenLabs for transcription and not retained beyond the session.
  • Text you submit to AI features (AI Coach, AI Copilot, AI Ensemble, Pre-Trade Coach, Screenshot-to-Setup, Auction Playbook) is sent to third-party AI providers as described in Section 4.
  • Uploaded screenshots and charts you submit to Screenshot-to-Setup or Chart Vision are sent to the relevant AI provider for the duration of the request.

2.2 Information Collected Automatically

Usage Data:

  • Pages and features accessed, time spent on the Service
  • Scanner queries, widget interactions, feature usage analytics
  • Error logs, performance metrics, client-side crash reports
  • AI credit and voice credit ledgers (amounts debited and for which feature)
  • Audit log entries for account, subscription, and admin-action changes

Device and Session Information:

  • Browser type and version, operating system, device type, screen resolution
  • IP address and approximate geolocation (city/country derived from IP)
  • Session tokens, last-seen and last-login timestamps

3. How We Use Your Information

3.1 Service Delivery

  • Create and manage your account
  • Provide access to features based on your subscription tier and active Starter Packs
  • Process payments, subscriptions, and promotion codes
  • Save your preferences, layouts, custom scanners, and journal entries
  • Deliver alerts, notifications, briefings, and voice narration you've configured
  • Enable broker integrations and live-trading actions you initiate
  • Generate AI-powered insights (scores, predictions, coach replies, trade critiques)

3.2 Service Improvement

Analyze usage patterns, debug errors, develop new features, conduct internal research.

3.3 Security

Detect and prevent fraud; monitor for unauthorized access; enforce the Terms; comply with legal obligations.

3.4 Communications

Account notices, subscription receipts and renewal reminders, morning briefings and weekly recaps (opt-in/out per email preference), product announcements.


4. Data Sharing and Third-Party Service Providers

4.1 Service Providers

We share data with trusted third parties who help operate the Service. Each is under a data-processing agreement where the provider offers one:

ProviderPurposeData Shared
Fly.ioApplication hosting + egressRequest logs, IP addresses
SupabaseManaged PostgreSQL databaseAll account data (encrypted in transit; bcrypt/AES-256 for sensitive fields)
StripePayment processing and subscription billingName, email, billing address, payment method, invoice history
ResendTransactional email deliveryRecipient email, subject, message body
AnthropicClaude API for AI Coach, AI Copilot, AI Ensemble, Pre-Trade Coach, News Impact, Auction Playbook, Screenshot-to-SetupPrompts, journal entries, setup notes, screenshots you submit. No training on your data per Anthropic's API terms.
OpenAIText embeddings (semantic search within your journal)Plain-text journal content you opt into embedding. No training per OpenAI API terms.
ElevenLabsText-to-speech narration and speech-to-text transcription (Voice Credits)Text for synthesis; audio for transcription. Not retained beyond the request.
QuoteMediaEquities and ETF market dataNone from you — we only receive data from this provider
RithmicFutures real-time dataNone from you — inbound market data only
TradeStationBrokerage integration (Live Trading feature, if enabled)OAuth access tokens, order/position data you initiate
BinanceCrypto market dataNone from you — inbound market data only
Tigris (Fly object storage)Storage for trade screenshots, avatars, recorded education videosUploaded images and video files
Stream ChatIn-app chat and direct messagingUsername, message content, channel membership
LiveKitReal-time audio/video for Live Room (when used)Session metadata; audio/video is peer-to-peer and not stored
TwilioSMS notifications (where opted in)Phone number, SMS content
TradingViewAdvanced charting libraryNone (charting runs client-side against our datafeed)

Not every user interacts with every processor. For example, TradeStation only receives data when you explicitly connect a broker; ElevenLabs only receives data when you use Voice Credits.

4.2 AI Data Handling

When you use AI features, the text or images you submit (including journal entries, setup notes, and screenshots) are transmitted to the relevant AI provider to generate a response. We do not authorize these providers to train on your data, per their standard API terms. Outputs are returned to you within the Service and, in some cases, stored in your account so you can review them later (e.g. Trade Journal AI critiques).

4.3 Legal Disclosure

We may disclose data if required by subpoena, court order, or other legal process, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of GAZUM® Corp., our users, or the public.

4.4 No Sale of Personal Data

We do not sell your personal information to third parties.


5. International Data Transfers

GAZUM® Corp. is based in the United States. Most of our service providers (Stripe, Anthropic, OpenAI, Supabase, Fly.io, Resend, ElevenLabs, Stream Chat, LiveKit, Twilio) are also US-based or operate multi-region infrastructure with data processed in the US.

If you access the Service from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data-localisation laws, your data will be transferred to and processed in the United States and potentially other countries where our providers operate. Such transfers rely on Standard Contractual Clauses or equivalent safeguards where required.


6. Data Retention

We retain your data for as long as necessary to maintain your active account, provide the Service, comply with legal obligations, and resolve disputes.

Data TypeRetention Period
Account informationUntil account deletion + 30 days
Trade journal entries and screenshotsUntil you delete them, or account deletion + 30 days
Subscription and payment records7 years (tax / legal requirements)
AI prompts and responsesUp to 90 days on our side; see third-party processor terms for their retention
Usage / analytics logs90 days
Support tickets3 years
Audit logs (security, admin actions)2 years
Broker OAuth tokensUntil you disconnect the broker or delete your account

7. Data Security

7.1 Technical Safeguards

  • SSL/TLS encryption for all data in transit
  • AES-256 encryption for sensitive data at rest (broker tokens, 2FA secrets)
  • Password hashing with bcrypt
  • Two-factor authentication (2FA) with TOTP + backup codes
  • Row-level security (RLS) on database tables that hold user data
  • IP-scoped API keys for payment processing (where supported)
  • Regular security reviews and automated dependency patching

7.2 Your Responsibilities

  • Keeping your password confidential and using a strong, unique password
  • Enabling two-factor authentication
  • Logging out of shared devices
  • Reporting suspicious activity to security@gazum.com

8. Your Privacy Rights

8.1 All Users

All users may request:

  • Access: a copy of your personal data
  • Correction: update inaccurate or incomplete data
  • Deletion: deletion of your account and data
  • Portability: your data in a portable format (e.g. JSON/CSV export of your trade journal)
  • Opt-out: unsubscribe from marketing communications

Contact privacy@gazum.com to exercise these rights.

8.2 EEA / UK Residents (GDPR / UK GDPR)

EEA and UK residents also have rights to restriction, objection, withdrawing consent, and lodging complaints with their supervisory authority.

8.3 California Residents (CCPA / CPRA)

California residents have the right to know what we collect, delete, correct, opt-out of sales (we do not sell data), and non-discrimination.


9. Cookies and Tracking

Cookie TypePurposeDuration
EssentialAuthentication, session securitySession
FunctionalPreferences, dashboard layouts1 year
AnalyticsAggregate feature usage1 year

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.


10. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately at privacy@gazum.com.


11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notice and/or email at least 30 days before they take effect. Your continued use of the Service after an update constitutes acceptance of the revised Policy.


12. Contact Us

GAZUM® Corp.


© 2026 GAZUM® Corp. All rights reserved.