Privacy Policy

Effective Date: March 8, 2026  |  Last Revised: March 8, 2026

1. Introduction

StrataCore Technologies ("Company", "we", "us", "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the StrataCore platform and services ("Service").

Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service. This policy applies to all information collected through the Service and any related communications.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Data: Name (optional), email address, hashed password, and account preferences when you register;
  • Profile Data: Display name, plan type, and profile settings you configure;
  • Portfolio Scenarios: The financial scenarios, asset symbols, probabilities, and returns you input into the Service;
  • Payment Data: Billing information is processed and stored directly by Stripe, Inc. We do not store full credit card numbers on our servers;
  • Communications: Messages you send to our support team.

2.2 Information Collected Automatically

  • Log Data: IP address, browser type, operating system, referring URLs, and pages visited;
  • Usage Data: Features used, analysis count, session duration, and interaction patterns;
  • Device Information: Device identifiers and connection information;
  • Cookies and Similar Technologies: Authentication tokens and session state. We do not use tracking cookies for advertising purposes.

2.3 Information from Third Parties

  • OAuth Providers: If you choose to sign in via Google or GitHub, we receive your email address and public profile information from that provider;
  • Payment Processors: Stripe provides us with subscription status and customer IDs, but not your full payment details.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service;
  • Create and manage your user account;
  • Process transactions and send billing-related communications;
  • Send transactional emails (email verification, password reset, subscription confirmations);
  • Enforce our Terms of Service and plan limits;
  • Detect, prevent, and address technical issues, fraud, or abuse;
  • Analyze aggregate usage to improve the Service (using anonymized data only);
  • Comply with legal obligations;
  • Respond to your support inquiries.

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We do not use your portfolio data or financial scenarios for any purpose other than providing the Service to you.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), we process personal data under the following legal bases:

  • Contract Performance: To provide the Service you have requested;
  • Legitimate Interests: For security, fraud prevention, and service improvement;
  • Legal Obligation: To comply with applicable laws and regulations;
  • Consent: Where explicitly required (e.g., optional marketing communications).

5. Disclosure of Your Information

We may share your information with:

  • Service Providers: Third-party vendors who assist us in operating the Service (cloud hosting, email delivery via Resend, payment processing via Stripe, error monitoring via Sentry). These parties are bound by contractual data processing agreements;
  • Team Members: If you use the Team plan and share universes or snapshots, the designated team members you invite will have access to the shared content;
  • Legal Authorities: When required by law, court order, or to protect the rights and safety of our users or the public;
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with appropriate confidentiality protections.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data at any time through the account settings ("Delete Account") or by contacting us at privacy@stratacore.app.

We may retain certain information for a limited period as required by law, fraud prevention, or legitimate business interests (e.g., transaction records for accounting purposes).

7. Data Security

We implement industry-standard security measures to protect your information, including:

  • Transport Layer Security (TLS/HTTPS) for all data in transit;
  • bcrypt hashing for all stored passwords;
  • JWT-based authentication with short-lived access tokens and refresh token rotation;
  • Role-based access control and user-scoped data isolation;
  • Regular security reviews and dependency audits.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you;
  • Rectification: Request correction of inaccurate or incomplete data;
  • Erasure: Request deletion of your personal data ("right to be forgotten");
  • Portability: Request export of your data in a machine-readable format;
  • Objection: Object to processing based on legitimate interests;
  • Restriction: Request restriction of processing in certain circumstances;
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time.

9. Contact Us

For privacy-related inquiries, data requests, or concerns:
StrataCore Technologies — Data Privacy Officer
Email: privacy@stratacore.app

This Privacy Policy was last reviewed by legal counsel on March 8, 2026.