Privacy Policy
LAST UPDATED · 2026-07-29
1. Who we are
EdgeDepth (“we”, “us”) is built and operated from New Zealand. We operate the websites edgedepth.com and app.edgedepth.com and the EdgeDepth product (the live terminal, market replay, event archive and lessons). For privacy matters, contact us at [email protected] with the subject line “Privacy”.
2. What we collect
Account data. Email address, a hashed password (never the password itself), your role and plan, the country and first-touch acquisition source recorded when your account is created, and subscription and entitlement records (which plan, when it started, when it lapses). We do not store your IP address on the account record.
Payment data. Pro is paid in Bitcoin through BTCPay Server. We store the invoice reference, amount, currency and payment status. We never see or store card numbers, and we do not link wallet identities beyond what the payment itself reveals.
Product usage. Feature usage and performance telemetry from the app (for example which views are used and how fast they render), lesson and quiz progress, replay sessions, and paper-trading records you create. Paper trading is simulated; we never connect to an exchange account and we never ask for exchange credentials or API keys.
API and connected agents. If you create an API key or connect an AI agent (for example through our MCP server), we store the key’s hash and last four characters, never the key itself; the client registration your agent creates; the scopes you granted; and a usage record per request: which tool or endpoint was called, the query document submitted, what it cost against your monthly allowance, and the timestamp. Query documents are retained because a result has to stay reproducible from its key. They describe markets, not you.
Web analytics. Our marketing pages use a self-hosted, first-party analytics deployment (Umami): pages visited, referrer, country, and browser and device class. It does not use advertising cookies and no third-party analytics vendor receives this data. The marketing site also loads a first-party session recorder that captures anonymised interaction data (clicks, scrolling, movement heatmaps) on those pages to improve them; it runs on our own infrastructure.
Support and contact. Anything you send us by email or through the contact form.
Server logs. Standard connection logs (IP address, user agent, requested URL, timestamp), kept for security, abuse prevention and debugging.
3. What we do not do
We do not sell personal data. We do not run advertising or share data with ad networks. We do not connect to your exchange accounts. We do not use your data to train machine-learning models on your behalf or anyone else’s.
4. Service providers
We use a small number of providers who process limited data for us: Cloudflare (content delivery and security in front of our servers, which sees connection metadata such as IP address), Resend (delivery of transactional email such as sign-up, receipts and renewal reminders, which processes your email address and message content), and BTCPay Server for Bitcoin invoicing. Our application data lives on servers we control.
One further provider is used by one optional feature only. If you ask a question in plain language instead of building it from the field list, DeepSeek receives the sentence you typed and the current timestamp so it can propose a structured query. It does not receive your email address, account ID, API key or query history. Its proposal is never executed on its own: EdgeDepth recompiles the query from the facts you actually stated and you confirm it before anything runs. Building the query yourself, which is what our own interfaces do by default, involves no third-party model at all.
5. Connected AI agents and the API
You can connect an AI agent (Claude, Cursor, Codex or any MCP-compatible client) to EdgeDepth, either through our hosted MCP server at mcp.edgedepth.com or with an API key. Three things are worth stating plainly.
We receive the request, and nothing around it. Your agent sends us the query it wants to run. We do not receive the conversation it came from, your chat history, conversation summaries, or files you uploaded to that client, and our tools never ask a client for them.
Authorization is yours, and revocable. Connecting uses OAuth: you sign in here, review the scopes the agent requested, and approve. Access tokens are short-lived and the agent renews them quietly while the connection stays in use. Active connections are listed under Connected Apps, and revoking one takes effect immediately.
The assistant’s operator is a separate controller. When you reach EdgeDepth through a third-party assistant, that provider handles your prompts and its own logs under its own privacy policy. We are responsible for what reaches us, not for what happens inside the client.
6. Cookies and local storage
Before signup, we use a thirty-day first-party cookie scoped to .edgedepth.com to carry a normalized first-touch source, such as Google organic, Direct, a campaign source, or a referring domain, into the new account. It does not contain your email address, user ID, full referring URL or IP address. app.edgedepth.com sets a separate authentication cookie (also scoped to .edgedepth.com) when you sign in; it is strictly necessary to keep you signed in. The terminal stores preferences (layouts, symbols, replay position) in your browser’s local storage. The marketing site’s analytics are cookieless. We set no advertising or cross-site tracking cookies.
7. Retention
Account data is kept while your account is active and deleted or anonymised after you close it, except records we must keep longer: payment and invoice records are retained for seven years to meet New Zealand tax record-keeping requirements, and security logs are kept on a short rolling window. Aggregated analytics that identify no one may be kept indefinitely.
8. Your rights
You can ask us to access, correct, export or delete the personal information we hold about you by emailing [email protected] with the subject “Privacy”. We will verify the request against your account email and respond within the timeframes of the New Zealand Privacy Act 2020 (generally 20 working days).
If you are in the EEA or UK, you additionally have the GDPR rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority. Our lawful bases are contract (providing the service you signed up for), legitimate interests (security, product improvement) and legal obligation (tax records).
If you are a California resident, the CCPA rights to know, delete and correct apply through the same contact. We do not sell or share personal information as the CCPA defines those terms.
New Zealand residents can complain to the Office of the Privacy Commissioner (privacy.org.nz).
9. International transfers
We operate from New Zealand and our providers may process data in other jurisdictions (for example Cloudflare’s global network). Where personal data leaves its origin jurisdiction we rely on our providers’ standard data-protection terms.
10. Age
EdgeDepth deals with leveraged-market content and is not directed at children. You must be at least 18 to create an account.
11. Changes
We will update this page when our practices change and revise the date above. Material changes to how we handle account data will be announced to account holders by email.