Privacy Policy
Effective: July 17, 2026
Ravenhold LLC (2108 N St, Ste N, Sacramento, CA 95816) is the data controller for the nocterm desktop terminal, website and account portal. Contact: support@ravenhold.org.
The short version
- Your exchange API keys never reach us. They stay on your device.
- We don’t see your trades. Strategy execution and paper trading run locally.
- We never see your card details. Stripe handles payment.
- We don’t store your AI conversations — but we do send your prompts to a third-party model provider to answer them.
- You can delete your account, and everything above, from the portal.
1. What we collect
Account
Provisioned when you first sign in through our authentication provider (Auth0).
- Your user id (an opaque identifier from Auth0) and email address
- Your subscription tier and feature entitlements
- Account creation date
Settings and preferences
A single per-user settings record: display name, chart and appearance preferences, filters, your last-used symbol and timeframe, and your tracked symbols (watchlist).
AI usage
- Counters only: how many requests you made in a month/day, and an approximate token total, for quota enforcement and cost visibility.
- Whether, and at which version, you accepted the AI disclaimer.
- Your purchased AI credit balance.
We do not store the content of your AI prompts or the model’s replies. We do transmit them — see section 3.
Billing
- An identifier linking you to your Stripe customer record, your subscription id, its status, and which plan price you are on.
- A log of the billing events we have processed (event id, type, timestamp), so a repeated notification is not applied twice.
We never receive or store your card number, or any payment instrument. Stripe does.
Technical
Server logs and metrics: IP address, timestamps, endpoints called, and error diagnostics. IP addresses are used for rate limiting and abuse prevention.
Market data
Candles, trades and order-book data we ingest from venues are not personal data — they concern instruments, not you. Which symbols you track is stored against your account (see Settings).
2. What we deliberately do not collect
This is the part most worth reading, because it is the opposite of what many trading tools do.
| where it lives | |
|---|---|
| Exchange / broker / prop API keys | Your device only, in your operating system’s keyring. Never transmitted to our servers. |
| Your live orders, fills and positions | Between you and your venue. The desktop connects to your venue directly with your own keys. |
| Your paper trading | Local to your device. The paper engine runs on your machine. |
| Your card details | Stripe. Entered on Stripe-hosted checkout pages; they never touch our infrastructure. |
| Your AI prompt content | Not stored by us. Transmitted to fulfil the request — see section 3. |
We do not sell your personal data. We do not share it for advertising. We do not do behavioural ad tracking.
3. Who we share it with
We use these processors/providers. Each receives only what its job requires.
| provider | what it gets | why |
|---|---|---|
| Auth0 (Okta) | Email, authentication data | Sign-in. They are the identity provider; your password (if any) is theirs, never ours. |
| Stripe, Inc. | Your email, payment details you give them, billing address/tax location | Our payment processor — they process your payment on our behalf. They are an independent controller for payments fraud and compliance purposes. |
| OpenRouter and, through it, the model provider serving your request | The content of your AI prompts, including any chart context, script code or market data you include | To generate the response. This is the one place your content leaves our systems. |
| Oracle Cloud (OCI) | Everything we host | Our servers. |
| Cloudflare | Requests to the marketing site | Hosting/CDN for the public site. |
| Giphy | Your search term, if you use GIF search on a chart | To return results. Optional feature. |
We may also disclose data where legally required, to enforce our Terms, or to protect our rights, users or the public — and to an acquirer in a merger or sale, subject to this policy.
About AI prompts specifically
When you use an AI feature, what you send — which may include your script code, chart context and notes — is transmitted to OpenRouter, which routes it to the model provider serving that request. Those providers have their own terms and retention practices, which we do not control.
Do not put anything into an AI prompt that you would not send to a third party. This includes credentials and personal information about others.
4. Why we’re allowed to (legal bases)
For users in the UK/EEA, under UK GDPR / GDPR:
- Performance of a contract — running your account, delivering your plan, storing your settings, processing your purchase.
- Legitimate interests — securing the Service, preventing abuse, rate limiting, enforcing quotas, fixing faults, and understanding aggregate usage. We have weighed these against your rights.
- Legal obligation — tax and accounting records, which as seller of record are ours to keep.
- Consent — anything optional you actively switch on. You can withdraw it by switching the feature back off.
5. International transfers
We are hosted in the United States (Oracle Cloud, San Jose), and our providers operate internationally, so your data may be processed outside your country — including in the United States. Where we transfer personal data out of the UK/EEA we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
6. Retention and deletion
We keep your account data for as long as your account exists.
You can delete your account at any time from Account → Delete account. This permanently removes your identity record and your settings. It cannot be undone; signing up again creates a fresh, empty account.
One honest caveat: billing records survive. Stripe retains transaction records, and we retain invoices and tax records as legally required — independently of your account’s existence.
We keep server logs for a limited period for security and diagnostics, and retain what we must to comply with law or resolve disputes.
7. Your rights
Subject to your local law, you may: access your data; correct it; delete it; restrict or object to processing; request portability; and withdraw consent where consent is the basis.
Much of this is self-service in the portal — your settings are editable and deletion is one button. For anything else, email support@ravenhold.org. We will respond within the time your law requires (one month under UK/EU GDPR).
You may complain to your data protection authority. In the UK that is the ICO (ico.org.uk).
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives for personal information. Your rights to know, delete and correct are covered above, and we will not discriminate against you for exercising them.
8. Cookies and local storage
The web portal uses only what it needs to function: a session/authentication cookie set by our auth provider so you stay signed in, and local storage for your preferences. We do not use advertising or third-party tracking cookies.
The desktop terminal stores your settings and credentials locally on your machine, not in cookies.
9. Security
We use TLS in transit, restrict our internal services to a private network (only the API gateway is publicly reachable), keep secrets out of source control, and scope our payment provider’s API access to the minimum required. Your venue credentials are held by your operating system’s keyring rather than by us, which is the strongest guarantee here: we cannot lose what we never have.
No system is perfectly secure, and we cannot guarantee absolute security.
10. Children
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
11. Changes
We may update this policy. For material changes we will give reasonable notice via the Service or by email. The “Effective” date above always reflects the current version.
Contact
Ravenhold LLC, 2108 N St, Ste N, Sacramento, CA 95816 — support@ravenhold.org