Legal
Privacy Policy
Version: 2026-05-draft
Assistatron Privacy Policy
Deepnet One Ltd · Company No 14414482 · Registered in England and Wales Last updated: May 15, 2026
Who we are
Assistatron is operated by Deepnet One Ltd, a company registered in England and Wales (Company No 14414482). When this policy says "we," "us," or "our," it means Deepnet One Ltd.
Contact: [email protected]
What this policy covers
This policy explains what personal data we collect, why we collect it, how we store and protect it, who we share it with, and what rights you have. It applies to all users of the Assistatron platform, website, and MCP server, whether you are using paper trading or live trading.
What data we collect
Account data
When you sign up, we collect:
- Email address — provided via WorkOS AuthKit during signup or login
- Name (if provided by your identity provider)
- Identity provider metadata — which provider you used (e.g., Google, GitHub, email), your unique identifier from that provider
We do not collect or store your password. Authentication is handled entirely by WorkOS.
Profile and preferences
When you complete onboarding, we collect:
- Trading experience level — your self-reported options and iron condor experience
- Risk tolerance — your chosen risk profile (conservative, moderate, aggressive)
- Account mode — whether you are in paper trading or live trading mode
Brokerage connection data
If you connect a brokerage account, we store:
- Encrypted OAuth tokens (access token and refresh token) — encrypted at the application level using AES-256 before storage. We cannot read your tokens without the encryption key.
- Broker name — which broker you connected (e.g., Alpaca Securities LLC)
- Connection timestamp and disclosure acknowledgment timestamp
- Granted scopes — what permissions you authorized
We do not store your brokerage account password, account number, or personal financial details. We access your brokerage data only through the permissions you granted via OAuth.
Trade data
When you use the platform (paper or live), we process:
- Position data — open positions, strikes, P&L, Greeks, expiry dates
- Order data — proposed and confirmed orders, fill details
- Search data — iron condor search parameters and results
This data is derived from your broker's API (for live trading) or simulated (for paper trading). We store it to provide the platform's services: monitoring, analysis, and trade history.
MCP tool call logs
We log interactions between your assistant and the Assistatron MCP server:
- Tool name called
- Input parameters (with sensitive fields such as tokens redacted)
- Response status (success or error)
- Timestamp and user identifier
These logs are used for debugging, security monitoring, and audit purposes. They are not shared with third parties for marketing.
Feedback
If you submit feedback (via the dashboard or the MCP submit_feedback tool), we store:
- Your feedback text and optional rating
- Timestamp, account mode, and trigger context (e.g., first trade, day 7)
Website analytics
We collect standard website analytics data:
- Page views, referral source, UTM parameters
- Browser type and device type
- IP address (anonymised where possible)
We use this data to understand how visitors find and use the site. We do not use third-party advertising trackers.
Payment data
Subscription payments are processed by Revolut Business. Revolut collects your payment card details directly. We do not see, store, or have access to your card number, CVV, or billing address. We receive only transaction confirmation metadata (amount, date, status).
Why we collect this data
| Data | Legal basis (UK GDPR) | Purpose |
|---|---|---|
| Email, name, identity provider | Contractual necessity (Art. 6(1)(b)) | To create and manage your account |
| Trading experience, risk tolerance | Contractual necessity | To configure your risk profile and preset |
| Encrypted broker OAuth tokens | Contractual necessity | To execute trades on your behalf via your broker |
| Trade and position data | Contractual necessity | To provide monitoring, analysis, and trade history |
| MCP tool call logs | Legitimate interest (Art. 6(1)(f)) | Security, debugging, and audit |
| Feedback | Consent (Art. 6(1)(a)) | To improve the platform |
| Website analytics | Legitimate interest | To understand usage and improve the site |
| Payment metadata | Contractual necessity | To manage your subscription |
Who we share data with
We share your data only with the following parties, and only to the extent necessary to provide the service:
| Recipient | What they receive | Why |
|---|---|---|
| WorkOS | Email, identity provider metadata, session data | Authentication and identity management |
| Your brokerage partner | Trade orders, account queries (via OAuth) | Trade execution at your direction |
| Revolut Business | Payment transaction data | Subscription billing |
| Amazon Web Services (AWS) | All data (encrypted at rest on their infrastructure) | Database hosting and backups |
| Cloudflare | Traffic metadata, cached content | CDN, DDoS protection, DNS |
| Modal | Anonymised option chain parameters (no user data) | GPU compute for the optimiser |
| Benzinga | No user data | Market data provider (option chains) |
We do not sell your data. We do not share your data with advertisers. We do not use your data for purposes unrelated to providing the Assistatron service.
How we protect your data
- Encryption at rest: PostgreSQL database encrypted using AES-256. Brokerage OAuth tokens additionally encrypted at the application level before storage.
- Encryption in transit: All traffic over TLS 1.2+. No unencrypted connections.
- Access control: Production database accessible only from application servers within the VPC. No direct public access. SSH key-based only, root login disabled.
- Authentication: Managed by WorkOS with support for MFA and SSO. Assistatron does not store passwords.
- Audit logging: All MCP tool calls logged with user identity and timestamp.
- Vendor security: All vendors maintain SOC 2 Type II certification or equivalent (see our Cybersecurity Policy for details).
How long we keep your data
| Data | Retention |
|---|---|
| Account data (email, preferences) | Life of the account. Deleted within 30 days of account deletion. |
| Encrypted broker OAuth tokens | While the broker is connected. Deleted and revoked on disconnection. |
| Trade and position data | Life of the account plus 6 months after deletion. |
| MCP tool call logs | 6 months |
| Feedback | Life of the account. Anonymised after account deletion. |
| Website analytics | 6 months |
| Payment metadata | As required by UK tax law (minimum 6 years for financial records). |
| Waitlist emails | Deleted within 48 hours of unsubscribe request. |
Your rights
Under UK GDPR (and EU GDPR for EU residents), you have the right to:
- Access your personal data — request a copy of everything we hold about you
- Correct inaccurate data — tell us if something is wrong and we will fix it
- Delete your data — request that we delete your account and all associated data
- Export your data — receive your data in a portable, machine-readable format
- Restrict processing — ask us to limit how we use your data while a dispute is resolved
- Object to processing based on legitimate interest — we will stop unless we have compelling grounds
- Withdraw consent — where processing is based on consent (e.g., feedback), you can withdraw at any time
To exercise any of these rights, email [email protected]. We will respond within 30 days.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO): https://ico.org.uk/make-a-complaint/
Cookies
The Assistatron website uses only essential cookies required for authentication and session management. We do not use advertising cookies, tracking cookies, or third-party marketing cookies.
If we introduce non-essential cookies in the future, we will update this policy and implement a cookie consent mechanism before doing so.
International transfers
Your data is processed on servers located in eu-west-2 (London). If your data is transferred outside the UK, we ensure it is protected by appropriate safeguards:
- AWS: covered by UK-US Data Bridge and Standard Contractual Clauses
- WorkOS: US-based, covered by Standard Contractual Clauses. See https://workos.com/security
- Cloudflare: global CDN with regional data controls. See https://www.cloudflare.com/trust-hub/
Children
Assistatron is not intended for use by anyone under 18. We do not knowingly collect data from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
Changes to this policy
We may update this policy to reflect changes in our practices, legal requirements, or services. If we make material changes, we will notify you by email at least 14 days before the changes take effect.
The current version of this policy is always available at assistatron.com/privacy.
Contact
For privacy-related questions or requests:
Email: [email protected]
Deepnet One Ltd Registered in England and Wales Company No 14414482