Legal

Last updated: 2026-08-30

Privacy Policy

This policy explains what personal data AlphaProve collects, why we process it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).

Effective date: 2026-08-30. It applies to alphaprove.com and the AlphaProve platform.

1. Who we are

SC FAOXIM SRL, Str. Rudului 264, Ploiești, Prahova, Romania (“AlphaProve”, “we”, “us”, or “our”), is the data controller responsible for your personal data in connection with the Service. You can reach us about privacy matters at support@alphaprove.com.

2. What data we collect

We collect and process the following categories of personal data:

  • Account data: your email address, a securely hashed password, and, if you sign in with Google, the identifier returned by Google. You may also provide a name.
  • Your strategies and results: the trading strategies you create or upload and the backtest, forward-walk, and simulation results they produce.
  • AI conversation history: the prompts you send and the AI-generated responses when you use the strategy-assist features.
  • Usage and operational telemetry: technical and diagnostic data about how the Service is used (collected via OpenTelemetry), such as request and performance metrics and error logs, used to keep the Service reliable and secure.
  • Subscription and tier metadata: your plan, AI-credit usage, and billing status. We do not store your payment-card numbers; card data is handled entirely by our payment processor, Stripe.

4. How we use your data

We use personal data to:

  • provide, operate, and maintain the Service and your account;
  • run your backtests, forward-walks, and simulations, and generate strategies you request;
  • process subscriptions, manage AI-credit allowances, and handle billing through Stripe;
  • send you essential service and transactional messages (for example account, security, and billing notices);
  • keep the Service secure, diagnose problems, and prevent abuse; and
  • comply with our legal obligations.

5. Third parties and sub-processors

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract and only as needed to provide the Service:

  • AI model providers: when you use the strategy-assist features, the content of your prompts and AI conversations is transmitted to a third-party AI model provider so it can generate or refine strategies for you. Depending on the model in use, that provider is one of Anthropic (Claude), OpenAI (GPT), Google (Gemini), DeepSeek (DeepSeek), Alibaba Cloud (Qwen), Moonshot AI (Kimi) or Zhipu AI (GLM). We do not send your account credentials or payment details to any AI provider.
  • Stripe (payment processing): handles your subscription payments and card data. We never receive or store your full card number.
  • Resend (transactional email): delivers our service and account emails to you.
  • Cloudflare (hosting network, CDN, and DDoS protection): helps deliver and protect the Service.
  • Sentry (error monitoring): receives technical error reports (stack traces, browser and OS details, and your IP address) when something in the Service breaks, so we can find and fix it. Our Sentry project is configured for European Union data residency.
  • PostHog EU (product analytics): records pseudonymous, cookieless usage events (for example page and feature interactions, keyed to a random identifier) so we can understand how the Service is used and improve it. We do not send your name, email, or payment details. Events are processed in the European Union, and we honour your browser’s “Do Not Track” signal.

Our core infrastructure (where your account, strategies, and results are stored) is self-hosted within the European Union. We may also disclose data where required by law or to protect our rights, users, or the Service.

6. International data transfers

Your core data is stored on infrastructure located in the European Union. Some sub-processors, in particular the AI provider used to generate strategies, may process data outside the European Economic Area (EEA). Where that happens, we rely on appropriate safeguards recognised under the GDPR (such as the European Commission’s Standard Contractual Clauses or an adequacy decision) to protect your data.

Per sub-processor:

  • Core infrastructure: self-hosted in the European Union (Romania); no international transfer.
  • AI model provider: prompts and AI conversations may be processed outside the EEA; protected by the European Commission’s Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified).
  • Stripe (US): certified under the EU–US Data Privacy Framework, supplemented by Standard Contractual Clauses.
  • Cloudflare (US): certified under the EU–US Data Privacy Framework, supplemented by Standard Contractual Clauses.
  • Resend (US): Standard Contractual Clauses.
  • Sentry: error data is ingested and stored in the EU region; any residual access by the US vendor is covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.
  • PostHog: analytics events are processed and stored in the European Union; any residual access by the US vendor is covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.

You can contact us at any time and we will tell you which mechanism currently applies to a particular provider.

7. Data retention

We keep your personal data for as long as your account is active and as needed to provide the Service. When you close your account, we delete or anonymise your personal data, except where we must retain certain records to meet legal obligations (for example billing and tax records) or to resolve disputes and enforce our agreements.

Our standard retention windows:

  • Account and profile data: for the life of your account, then deleted within 30 days of account deletion.
  • Strategies, backtests, results, and AI conversations: for the life of your account (you can delete them yourself at any time); removed with your account within 30 days.
  • Waitlist email addresses: until you are invited or 24 months after sign-up, whichever comes first; deleted earlier on request.
  • Support and email correspondence: 24 months.
  • Security and server logs (including error reports): 12 months.
  • Pseudonymous analytics events: 12 months.
  • Billing and tax records: as required by Romanian accounting law (currently up to 10 years).

Where a longer retention period is required by law (for example for accounting, tax, or fraud-prevention purposes), we keep only the specific records needed for that purpose and delete or anonymise the rest without undue delay.

8. Your rights under the GDPR

Subject to the conditions in the GDPR, you have the right to:

  • Access: obtain a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: ask us to delete your data (the “right to be forgotten”).
  • Restriction: ask us to limit how we process your data.
  • Portability: receive your data in a structured, commonly used, machine-readable format.
  • Objection: object to processing based on our legitimate interests.
  • Withdraw consent: where we rely on consent, withdraw it at any time, without affecting processing already carried out.

You also have the right to lodge a complaint with a supervisory authority (in particular the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)) or with the authority in your country of residence.

9. How to exercise your rights

To exercise any of these rights, email us at support@alphaprove.com. We will respond within the time limits set by the GDPR (generally within one month). For now, exporting or deleting your account data is handled through our support team on request; we may ask you to verify your identity before we act.

10. Cookies

We use strictly necessary cookies to keep you signed in and to maintain your session and security. These are essential to operate the Service and do not require consent. We do not currently use non-essential advertising or tracking cookies. If we introduce non-essential analytics or marketing cookies in the future, we will present a consent banner and only set them with your consent.

11. How we protect your data

We take security seriously. Passwords are stored only in salted, hashed form; tenant data is isolated using database row-level security so one account cannot access another’s data; and any strategy code you run executes inside a locked-down server-side sandbox. We use encryption in transit and apply appropriate technical and organisational measures. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.

12. Children

The Service is intended only for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service and update the “last updated” date above. Please review this policy periodically.

14. Contact us

For any privacy question, or to exercise your rights, contact:

We have not appointed a Data Protection Officer, as the scale and nature of our processing does not require one under Article 37 GDPR, and, being established in the European Union (Romania), we are not required to designate an EU representative under Article 27. For all privacy matters, the contact above applies.