Privacy Policy
LAST UPDATED · 2026-08-26
1. Who we are
EdgeDepth (“we”, “us”) is built and operated from New Zealand. We operate the websites edgedepth.com and app.edgedepth.com and the EdgeDepth product (the live terminal, market replay, event archive and lessons). For privacy matters, contact us at [email protected] with the subject line “Privacy”.
2. What we collect
Account data. Email address, a hashed password (never the password itself), your role and plan, the country and first-touch acquisition source recorded when your account is created, the first EdgeDepth page your browser opened and the EdgeDepth page you were reading immediately before you created the account, and subscription and entitlement records (which plan, when it started, when it lapses). The two page values are stored as a path such as /pricing, never as a full address with a query string. We do not store your IP address on the account record.
Payment data. Pro is paid in Bitcoin through BTCPay Server. We store the invoice reference, amount, currency and payment status. We never see or store card numbers, and we do not link wallet identities beyond what the payment itself reveals.
Product usage. Feature usage and performance telemetry from the app (for example which views are used and how fast they render), lesson and quiz progress, replay sessions, terminal sessions and how long each was open and visible, and paper-trading records you create. Paper trading is simulated; we never connect to an exchange account and we never ask for exchange credentials or API keys.
Your page journey. While you are signed in we record which EdgeDepth pages you open and how long each one was actually visible on your screen, so we can see where the product is useful and where people get stuck. We record the path only, such as /research or /events, with the query string and anything after a # removed before it is stored. We do not record your IP address, the address of pages outside EdgeDepth, form contents, keystrokes, or the text of anything you type. This history is part of your account: you can download all of it at any time from your Account page, under Privacy and data, using Download your data, and it is deleted when your account is deleted.
API and connected agents. If you create an API key or connect an AI agent (for example through our MCP server), we store the key’s hash and last four characters, never the key itself; the client registration your agent creates; the scopes you granted; and a usage record per request: which tool or endpoint was called, the query document submitted, what it cost against your monthly allowance, and the timestamp. Query documents are retained because a result has to stay reproducible from its key. They describe markets, not you.
Web analytics. Our marketing pages use a self-hosted, first-party analytics deployment (Umami): pages visited, referrer, country, and browser and device class. It does not use advertising cookies and no third-party analytics vendor receives this data. Visits to the marketing pages are counted anonymously. The marketing site also loads a first-party session recorder that captures anonymised interaction data (clicks, scrolling, movement heatmaps) on those pages to improve them; it runs on our own infrastructure.
Inside the signed-in app the same analytics deployment additionally receives your EdgeDepth account ID, so that what would otherwise be an anonymous visit can be recognised as yours. This is what lets us answer questions about a single account’s experience rather than only about totals. It stays on our own infrastructure and is not shared with any analytics vendor.
Support and contact. Anything you send us by email or through the contact form.
Server logs. Standard connection logs (IP address, user agent, requested URL, timestamp), kept for security, abuse prevention and debugging.
3. What we do not do
We do not sell personal data. We do not run advertising or share data with ad networks. We do not connect to your exchange accounts. We do not use your data to train machine-learning models on your behalf or anyone else’s.
4. Service providers
We use a small number of providers who process limited data for us: Cloudflare (content delivery and security in front of our servers, which sees connection metadata such as IP address), Resend (delivery of transactional email such as sign-up, receipts and renewal reminders, which processes your email address and message content), and BTCPay Server for Bitcoin invoicing. Our application data lives on servers we control.
One further provider is used by one optional feature only. If you ask a question in plain language instead of building it from the field list, DeepSeek receives the sentence you typed and the current timestamp so it can propose a structured query. It does not receive your email address, account ID, API key or query history. Its proposal is never executed on its own: EdgeDepth recompiles the query from the facts you actually stated and you confirm it before anything runs. Building the query yourself, which is what our own interfaces do by default, involves no third-party model at all.
5. Connected AI agents and the API
You can connect an AI agent (Claude, Cursor, Codex or any MCP-compatible client) to EdgeDepth, either through our hosted MCP server at mcp.edgedepth.com or with an API key. Three things are worth stating plainly.
We receive the request, and nothing around it. Your agent sends us the query it wants to run. We do not receive the conversation it came from, your chat history, conversation summaries, or files you uploaded to that client, and our tools never ask a client for them.
Authorization is yours, and revocable. Connecting uses OAuth: you sign in here, review the scopes the agent requested, and approve. Access tokens are short-lived and the agent renews them quietly while the connection stays in use. Active connections are listed under Connected Apps, and revoking one takes effect immediately.
The assistant’s operator is a separate controller. When you reach EdgeDepth through a third-party assistant, that provider handles your prompts and its own logs under its own privacy policy. We are responsible for what reaches us, not for what happens inside the client.
6. Cookies and local storage
Before signup, we use three thirty-day first-party cookies scoped to .edgedepth.com, read once when an account is created and not used for anything else. The first carries a normalized first-touch source, such as Google organic, Direct, a campaign source, or a referring domain. The second carries the first EdgeDepth page your browser opened, and the third the most recent EdgeDepth page you were on, so the new account records which page brought you and which page you signed up from. All three hold a short value only: no email address, no user ID, no full referring address, no query string and no IP address. app.edgedepth.com sets a separate authentication cookie (also scoped to .edgedepth.com) when you sign in; it is strictly necessary to keep you signed in. The terminal stores preferences (layouts, symbols, replay position) in your browser’s local storage, and we store two analytics identifiers there as well: a random browser ID, so activity from before you signed in can be joined to your account once you do, and a per-tab session ID that resets after thirty minutes of inactivity. Neither is derived from anything about you, and clearing site data clears both. The marketing site’s analytics are cookieless. We set no advertising or cross-site tracking cookies.
7. Retention
Account data is kept while your account is active and deleted or anonymised after you close it, except records we must keep longer: payment and invoice records are retained for seven years to meet New Zealand tax record-keeping requirements, and security logs are kept on a short rolling window. Aggregated analytics that identify no one may be kept indefinitely.
8. Your rights
Signed-in users can download a complete copy of their data at any time from their Account page, under Privacy and data, using Download your data, without asking us. It contains the same records our own staff view can see, including the full page journey described in section 2. You can also ask us to access, correct, export or delete the personal information we hold about you by emailing [email protected] with the subject “Privacy”. We will verify the request against your account email and respond within the timeframes of the New Zealand Privacy Act 2020 (generally 20 working days).
If you are in the EEA or UK, you additionally have the GDPR rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority. Our lawful bases are contract (providing the service you signed up for), legitimate interests (security, product improvement) and legal obligation (tax records).
If you are a California resident, the CCPA rights to know, delete and correct apply through the same contact. We do not sell or share personal information as the CCPA defines those terms.
New Zealand residents can complain to the Office of the Privacy Commissioner (privacy.org.nz).
9. International transfers
We operate from New Zealand and our providers may process data in other jurisdictions (for example Cloudflare’s global network). Where personal data leaves its origin jurisdiction we rely on our providers’ standard data-protection terms.
10. Age
EdgeDepth deals with leveraged-market content and is not directed at children. You must be at least 18 to create an account.
11. Changes
We will update this page when our practices change and revise the date above. Material changes to how we handle account data will be announced to account holders by email.