Quawd · Legal
Privacy Policy
Quawd Privacy Policy
Version: 0.4 Last updated: 2026-07-15
This Privacy Policy describes how Quawd, Inc. ("Quawd", "we", "us") collects, uses, shares, and protects information about you in connection with the Quawd Platform (the "Service"). It applies to information collected through the Service, our website at quawd.bot, and any related applications. By using the Service you acknowledge that you have read this Policy.
1. Information We Collect
1.1 Information you provide directly
- Account information. Email address, password (stored hashed), display name, and any other profile information you submit.
- Authentication tokens. When you sign in with a third-party identity provider (for example, Google), we receive the basic profile information that provider returns to us, but not your password.
- Brokerage credentials. If you connect a brokerage account, you submit API credentials. These credentials are stored encrypted in Google Cloud Secret Manager and are never logged or displayed in plaintext after submission.
- Strategies and User Content. Any Strategies, configuration data, notes, prompts to Quawd Bot, and similar content you submit to the Service.
- Payment information. If you subscribe to a paid plan, our payment processor (Stripe, Inc.) collects payment-card information directly. Quawd receives a token and limited metadata (last four digits, card brand, expiration); we do not store full card numbers.
- Support communications. Information you provide when you contact us for support.
1.2 Information collected automatically
- Usage data. Pages and features you access, actions you take, request timestamps, and similar telemetry.
- Device and connection information. IP address, browser type and version, operating system, device identifiers, and referring pages.
- Cookies and similar technologies. We use cookies for authentication, session management, preferences, and analytics. You can control cookies through your browser settings; disabling them may impair functionality of the Service.
1.3 Information from third parties
- Brokerage activity. When you connect a brokerage, we receive account information and order/position data from that brokerage's API to the extent of the permissions you grant.
- Market data. We receive market data from third-party providers to support backtesting, paper-trading, and live execution.
- Identity verification. If we are required to verify your identity (for compliance or fraud prevention), we may receive verification information from third-party providers.
1.4 Information via AI assistant connectors (OpenAI ChatGPT, Anthropic Claude, and other MCP clients)
Quawd is also available through AI-assistant platforms that support the Model Context Protocol (MCP) — currently OpenAI's ChatGPT and Anthropic's Claude (Claude Desktop / claude.ai). When you use Quawd this way:
-
What we receive as input. The connected assistant sends our MCP server only the specific tool name and arguments needed to fulfill the request you made to it — for example, the parameters of a Strategy you asked it to build, or the identifier of a backtest you asked it to fetch. We do not receive the rest of your conversation with that assistant, only the tool calls it decides to make on your behalf. Depending on which tool is called, this may include:
- Strategy definitions, condition parameters, symbols, and date ranges (to build and run backtests, walk-forward analyses, and signal scans)
- Research project names, descriptions, and scratchpad notes (to organize your work across sessions)
- Portfolio composition and allocation settings
-
What we return as output. Our MCP server sends the tool's result (for example, backtest metrics, a strategy summary, or a scan result) back to the assistant that called it, so it can respond to you. That output becomes part of your conversation with OpenAI or Anthropic and is retained and processed there under that platform's own privacy policy — Quawd does not control OpenAI's or Anthropic's retention, logging, or model-training practices for that conversation.
-
Connection metadata and logs. As with any request to Quawd, a connector call also carries standard request metadata we use to authenticate and operate the Service: your OAuth identity and the Account it is bound to, your tier and capability claims, and operational logs (timestamps, IP address, and error traces). This is the same account, usage, and device/log information described in Sections 1.2–1.3.
Strategies, backtests, and other artifacts a connector creates are still stored in your Quawd Account exactly as if you had built them through the Quawd web app, and are governed by the same retention (Section 4) and access-and-deletion rights (Section 6) described elsewhere in this Policy — you can view, edit, or delete anything an assistant created for you at quawd.bot regardless of which client created it.
2. How We Use Information
We use the information we collect to:
- provide, operate, and maintain the Service, including running the Strategies you build;
- authenticate you and secure your Account;
- process transactions and bill subscriptions;
- communicate with you about the Service, including sending transactional notices, updates, and support responses;
- comply with legal obligations, respond to lawful requests, and enforce our Terms;
- detect, investigate, and prevent fraud, abuse, or violations of our Terms;
- improve the reliability, security, usability, and system performance of the Service through aggregated and de-identified analytics;
- record and retain consent and audit information as described in our Terms; and
- with your consent where required, send marketing communications. You may opt out of marketing communications at any time using the "unsubscribe" link in any marketing email.
We do not sell your personal information. Quawd does not use brokerage activity, Strategies, or trading history for targeted advertising.
2.1 AI inference and model training
Inputs you submit to Quawd Bot (including prompts, Strategies, and configuration data) may be processed by third-party AI providers (see Section 3.1) for inference purposes — that is, to generate responses back to you within the Service.
Quawd does not use your Strategies, prompts, or other User Content to train generalized AI models. Inputs sent to third-party AI providers are governed by those providers' API terms; under Anthropic's API terms, customer inputs and outputs are not used to train Anthropic's generally available models. We do not separately train any Quawd model on your User Content.
We also use LangSmith (LangChain, Inc.) to trace and monitor Quawd Bot's own conversations in the Quawd web app — this captures the prompts, model responses, and internal tool-call spans for that conversation, for debugging, quality, and cost monitoring. LangSmith tracing applies only to conversations with Quawd Bot inside the Quawd web app; it does not receive tool calls placed directly against our MCP server by ChatGPT, Claude, or another connector (Section 1.4) — those go straight to Quawd's infrastructure and are not sent to LangSmith.
2.2 Purpose and recipients of connector tool data
We use data received through AI assistant connector tool calls (Section 1.4) for the same purposes as data submitted directly through the web app: to authenticate the request, build/compile/run the Strategy you requested, and persist the resulting artifacts (Strategies, backtests, scratchpad notes) to your Account.
The tool arguments a connector sends us, and the results we return to it, are exchanged directly with the AI-assistant platform you're using — OpenAI (ChatGPT) or Anthropic (Claude) — as the mechanics of that exchange (Section 1.4). We do not separately forward connector tool data to any other third party beyond the service providers listed in Section 3.1 needed to run the Service (for example, BigQuery/Firestore to fetch market data and persist results). One exception: if you invoke a tool that itself triggers Quawd's own research agent (a guided research workflow), that agent's inputs are processed by Anthropic for inference under Section 2.1/3.1, regardless of which client (ChatGPT, Claude, or the web app) invoked it — that path is not traced by LangSmith either, since LangSmith is wired only to the web app's own Quawd Bot conversations as described above.
Access to connector tools is authorized via OAuth and scoped to your Account's tier and capabilities; connecting an assistant does not grant its provider any rights to your Account beyond executing the specific tool calls you authorize. You can revoke a connector's access at any time from that assistant's connector/plugin settings, or by contacting us to revoke the associated OAuth grant.
We do not keep the raw tool-call arguments and results as a separate long-term store beyond what is needed to produce and persist the resulting artifact and the operational logs described in Section 4 (logs are retained for no more than 18 months). The artifacts themselves persist in your Account until you delete them. Revoking a connector stops it from making further calls but does not delete artifacts it already created — remove those at quawd.bot under your access-and-deletion rights (Section 6) — nor does it remove copies of tool outputs already contained in your ChatGPT or Claude conversation, which are governed by that platform's own policy and controls.
3. How We Share Information
We share information only as described below.
3.1 Service providers
We share information with third-party service providers that operate the Service on our behalf, under contractual obligations to use the information only for the purposes we direct. Current providers include:
- Google Cloud Platform — hosting, storage (Firestore), and authentication (Firebase).
- Stripe, Inc. — payment processing.
- Anthropic, PBC — language-model inference for Quawd Bot.
- LangChain, Inc. (LangSmith) — tracing/observability of Quawd Bot's own web-app conversations (prompts, responses, and internal tool-call spans); see Section 2.1.
- Sentry (Functional Software, Inc.) — error reporting and observability (error events, stack traces, and request context).
- OpenAI, L.L.C. and Anthropic, PBC — as the providers of the ChatGPT and Claude AI-assistant platforms, when you choose to use Quawd through one of those connectors; see Section 1.4.
- Brokerages and exchanges — for users who connect a brokerage, Quawd transmits orders and reads account state via the brokerage's API.
3.2 Business transfers
If Quawd is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction.
3.3 Legal and safety
We may disclose information when we believe in good faith that disclosure is required by law or legal process, or is necessary to protect the rights, property, or safety of Quawd, our users, or the public.
3.4 With your consent
We may share information for any other purpose disclosed to you with your consent.
4. Data Retention
We retain personal information for as long as your Account is active and as needed to provide the Service. After Account deletion, we retain certain information as required for legal, regulatory, accounting, or audit purposes, including:
- Consent records (acknowledgments of disclaimers): retained as immutable audit records. Identifiers may be hashed (irreversibly) after Account deletion to reduce identifiability while preserving evidentiary value.
- Transaction and billing records: as required by tax and financial regulations.
- Logs: typically up to 18 months, then deleted or aggregated.
- Support requests: messages submitted through the contact form on
/supportare retained for 24 months to support follow-up on long-lived issues, then deleted.
When information is no longer needed for any of these purposes it is deleted or de-identified.
5. Security
Quawd implements technical and organizational measures designed to protect personal information from unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS), encryption at rest, hardened access controls, secret management for sensitive credentials (Google Cloud Secret Manager), audit logging, and regular review of our security posture. No system is perfectly secure. You are responsible for maintaining the confidentiality of your Account credentials.
Quawd will provide notice of material security incidents affecting your personal information as required by applicable law, using the contact information associated with your Account.
6. Your Rights and Choices
Depending on your jurisdiction, you may have rights to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete information, subject to the retention exceptions in Section 4.
- Port your information to another service in a structured, machine-readable format.
- Restrict or object to certain processing.
- Withdraw consent to processing that relies on your consent.
To exercise these rights, email us at david@quawd.bot. We will respond within the timeframes required by applicable law. We may need to verify your identity before fulfilling certain requests.
6.1 California residents (CCPA/CPRA)
California residents have additional rights, including the right to know what categories of personal information we have collected, the right to non-discrimination for exercising privacy rights, and the right to opt out of any "sale" or "sharing" of personal information as those terms are defined under California law. We do not sell or share personal information as those terms are used in the CCPA/CPRA.
6.2 European Economic Area, United Kingdom, and Switzerland
Where the GDPR or UK GDPR applies, our legal bases for processing are: performance of a contract (providing the Service), legal obligation (retaining records), our legitimate interests (security, fraud prevention, product improvement), and your consent (for marketing or other optional uses). You have the right to lodge a complaint with your local supervisory authority.
7. International Data Transfers
Quawd is based in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. Where required, we use appropriate safeguards (such as standard contractual clauses) for international transfers.
8. Children
The Service is not directed to children under thirteen (13), and we do not knowingly collect personal information from children under thirteen. If you believe we have collected information from a child under thirteen, please contact us and we will delete it.
9. Cookies and Tracking
We use first-party and third-party cookies for the purposes described in Section 1.2. We do not currently use cookies for cross-site behavioral advertising. We honor "Do Not Track" signals where required by applicable law; otherwise, our cookie behavior is controlled through your browser.
10. Third-Party Sites
The Service may contain links to third-party sites (including your brokerage). This Policy does not apply to those sites. We encourage you to review their privacy policies before providing them information.
11. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date above will reflect the most recent revision. For material changes, we will provide reasonable notice (for example, by in-product banner or email).
12. Contact
Privacy questions or requests: Email: david@quawd.bot
End of Privacy Policy.