Version: 1 | Locale: en | Effective date: July 2, 2026
Qompyl, Inc. (“Qompyl”, “we”, “us”, “our”) respects your privacy. This Privacy Policy describes the personal information we collect about you, how we use and share that information, and the choices and rights you have. It applies to your use of the Qompyl mobile applications, web interfaces, APIs, and related services (the “Service”).
The detailed sections below are the binding text. Where this summary and the detailed sections appear inconsistent, the detailed sections control.
When you create an Account we collect identifiers we receive from our authentication provider (Supabase), which include your email address, a user identifier, and authentication metadata. If you provide additional profile details (name, display name, locale preference, timezone) we collect those as well.
When you build trading strategies, configure condition blocks, or run backtests we collect the configurations, parameters, and inputs you provide and the outputs we generate (including AI-generated suggestions and interpretations). Both the proprietary data submitted and the subsequent materials produced are governed by intellectual property protections.
If you link a third-party broker to your Account, the connection is mediated by a third-party broker-aggregation provider (SnapTrade or a similar service provider). We collect the connection metadata that provider returns to us — a connection identifier, status, and references that allow us to read account state (such as balances, holdings, and positions) and, where supported, to submit orders you initiate. We do not receive or store your broker login password. The information we collect through a broker connection is “nonpublic personal information” (NPI) under the federal Gramm-Leach-Bliley Act (GLBA) and analogous state financial-privacy laws; we treat it as NPI for purposes of our collection, use, sharing, and security practices set out in this Privacy Policy, regardless of whether Qompyl itself is a “financial institution” under those laws.
We automatically collect technical information about how you interact with the Service: IP address, device type and operating system, mobile-application version, time-zone setting, language preference, crash reports, performance metrics, and timestamps for the actions you take in the Service. This information is necessary to operate, secure, and improve the Service.
If you contact us we collect the contents of your communication and any attachments, along with the contact details you provide.
The mobile application uses local persistent storage (such as AsyncStorage) to remember your session, language preference, and similar app state. The web interfaces, when available, may use cookies and similar technologies as described in a separate notice presented at that time.
We use the information described above for the following purposes:
To create and manage your Account, render the application, run your backtests, route orders to your linked broker (when you place them), serve AI-generated suggestions, and otherwise deliver the features you request.
To detect and prevent fraud, abuse, unauthorized access, market manipulation, and violations of our Terms; to authenticate users; to monitor for security incidents; and to investigate and respond to incidents.
To comply with applicable laws, including securities, anti-money-laundering, sanctions, tax, and books-and-records requirements; to respond to lawful requests from regulators, law enforcement, or courts.
To diagnose technical issues, monitor performance, and improve the stability of the Service.
To send you transactional communications about your Account, security alerts, consent re-prompts when our legal documents change, and (with your consent) product updates and marketing.
We do not use your strategy text, backtest configurations, AI prompts, or other Content as training data for any machine-learning model without your separate, explicit consent. We may use de-identified, aggregated patterns derived from your usage to evaluate model quality.
Where applicable law (such as US state consumer-privacy laws or international equivalents) requires a legal basis, we rely on:
We share information with vendors that process information on our behalf and under contractual confidentiality obligations, including our authentication provider (Supabase or similar service provider), our cloud and hosting providers, our broker-integration provider, our market-data vendors, our analytics and observability providers, and our customer-support tooling.
When you initiate an action that requires interaction with a linked broker — refreshing balances, requesting positions, or (where supported) placing an order — we transmit, through our broker-aggregation provider, the information necessary to perform that action (your connection reference and, where applicable, the order parameters you specified). The broker-aggregation provider and the broker each handle your information under their own privacy notices and information-security programs and have their own GLBA compliance obligations. We share NPI with the broker-aggregation provider and the broker only as necessary to provide the broker-connection service you have requested; this sharing falls within the GLBA exceptions for service-provider and joint-marketing arrangements (15 USC §6802(b)(2)) and for processing necessary to effect, administer, or enforce a transaction the consumer has requested or authorized (15 USC §6802(e)). Accordingly, no GLBA opt-out applies to this sharing, but you may sever the connection at any time through the in-app broker-connection controls or by closing your Account (see Section 7).
We share information with third parties when you ask us to.
We share information when we have a good-faith belief that disclosure is required by law, regulation, court order, subpoena, or governmental request, or is necessary to protect the rights, property, or safety of Qompyl, our users, or the public.
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction; we will notify you of any change in ownership or use of your personal information.
We do not sell your personal information for monetary or other valuable consideration.
We retain personal information for as long as your Account is active, plus the period required to satisfy our legal, regulatory, accounting, and dispute-resolution obligations. Trading-related records (orders, executions, strategy configurations relied on for orders) are retained for at least seven (7) years from the date of the activity. We may also retain de-identified or aggregated information indefinitely.
Depending on your jurisdiction, you may have the right to:
You can exercise most of these rights through in-app account settings; for any right that is not exposed in-app you can contact privacy@qompyl.com. We will respond within the timeframes required by applicable law (generally 30–45 days for US state-law requests). We may need to verify your identity before fulfilling a request.
The Service is not directed to children under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@qompyl.com and we will take appropriate steps to delete it.
We operate in the United States and may process and store your information there or in other jurisdictions in which we or our service providers maintain facilities. When we transfer personal information out of a jurisdiction with stricter data-protection rules than those in the destination jurisdiction, we use appropriate safeguards (such as standard contractual clauses) where required.
We maintain a written information-security program designed to protect personal information — including the nonpublic personal information (“NPI”) covered by the Gramm-Leach-Bliley Act (“GLBA”) and analogous state-law equivalents — from unauthorized access, disclosure, alteration, and destruction. The program implements administrative, technical, and physical safeguards proportionate to the size, complexity, and sensitivity of the information we handle, including: (a) periodic risk assessments; (b) access controls and least-privilege principles (role-based access controls, JWT-based authentication); (c) encryption in transit (TLS) and encryption at rest; (d) audit logging and continuous security monitoring; (e) oversight of service providers, including the broker-aggregation provider and other vendors that process NPI on our behalf, and contractually imposed safeguards obligations on those providers; (f) employee training on information-security and privacy responsibilities; and (g) incident-response procedures designed to investigate, contain, and remediate security incidents. No method of transmission or storage is completely secure; we will notify you of a security breach affecting your personal information when required by applicable law.
We may update this Privacy Policy from time to time. When we make a change that we consider material, we will publish a new version of this document and our in-app consent gate will prompt you to review and accept the updated Privacy Policy before you can continue using the Service. If you do not wish to accept the updated Privacy Policy, you may close your Account at any time through the in-app account-deletion flow or by contacting privacy@qompyl.com; we will not treat continued use of the Service as acceptance of an updated Privacy Policy in the absence of your explicit consent through the consent gate.
Privacy questions and requests: privacy@qompyl.com. General support: support@qompyl.com.