Legal
Privacy Policy
What Ciphora collects, why it is used, and how you can exercise your privacy rights.
Effective August 4, 2026
Who we are
Ciphora is an early-stage trading-technology project operated from Arizona, United States. For privacy purposes, Ciphora is the controller of personal information submitted through ciphora.ai and the Ciphora Confluence Engine private research beta. Ciphora is not represented here as a corporation, broker, adviser, or other regulated financial institution. The initial application is limited to adults who reside in the United States. Questions and privacy requests can be sent to legal@ciphora.ai.
Information we collect
We collect information you provide directly. If you submit an Early Access application, we collect the fields in the application:
- Name and email address
- Country
- Trading experience and average trades per day
- Whether you use TradingView
- The markets you trade and the instruments or pairs you expect to use
- Whether you are funded with a prop firm and, if so, your funded profitability and the firm(s) you use
- Whether you use paper or simulated trading, how many such accounts you actively use, and, optionally, the platform or provider
- The trading sessions you selected
- The date you applied and your beta status
Beta access provisioning
If you receive beta access, Ciphora may collect your TradingView username and access status to provision or revoke invite-only access to the Ciphora Confluence Engine publication on TradingView. A Ciphora administrator grants access manually. Accepting a beta invitation on this website records your acknowledgments and choices but does not itself grant TradingView access.
If you participate in the beta, Ciphora also processes information you choose to submit through beta feedback forms, including build and research-model versions, instrument, timeframe, session, regime, browser and device environment, dashboard mode and orientation, reproduction steps, product feedback, periodic reviews, and the text fields on those forms. The forms do not accept file uploads. A bug report may include an optional screenshot link or reference; do not use it to share account balances, account identifiers, credentials, or other sensitive financial details.
When you accept a beta invitation, we issue a secure, HttpOnly session cookie to your browser. It lets the onboarding page and feedback forms recognize you as an accepted tester. The session expires automatically and can be revoked when you sign out or when Ciphora revokes access. It grants no other permissions.
How beta evidence is separated
Ciphora keeps three evidence categories distinguishable: automatic platform telemetry, information a participant reports, and research records that Ciphora has reviewed and marked as validated. A participant's description, weekly response, or submitted outcome is not represented as independently validated model performance.
Automatic telemetry records only events the configured website or an explicitly enabled TradingView alert can actually transmit. It does not prove that a chart was viewed, a signal was acted on, or a trade was taken. Completed research-trade records include their source, build, research-model version, export-schema version, and validation state. Aggregated performance figures shown in private dashboards must identify their sample and provenance and exclude pending, rejected, or synthetic records.
Risk and dashboard research prefers percentages, states, R multiples, and remaining-buffer measures over exact account histories. Do not submit passwords, broker credentials, account numbers, payment information, private API keys, authentication tokens, or exact balances through beta research or feedback fields.
Beta telemetry (required for participation)
Marketing consent and telemetry participation are separate. Declining marketing does not affect your application or beta eligibility. Operational telemetry is required for this research beta. If you do not accept this participation condition, you cannot accept an invitation or participate. Telemetry begins only after your acknowledgment is recorded and while your beta participation remains active. Each participant receives a unique, revocable telemetry token that is sent in the request body and never in the URL.
For each alert event, Ciphora collects an event ID, event type, research build ID, instrument, five-minute timeframe, and server receipt time. It may also collect a session label, direction category, Confidence alignment category, alert condition label, and a limited set of non-sensitive diagnostics, such as alert latency and chart resolution. Instrument values are limited to beta candidates. Clearly labeled synthetic test events are marked as tests and excluded from research counts.
Telemetry never includes broker or exchange credentials, brokerage account identifiers, account balances, positions, profit or loss, personal notes, or free-form sensitive trading data. The server enforces a strict schema and rejects payloads containing those fields. That sentence describes the telemetry channel and nothing else. It is not a claim that Ciphora never holds figures of that kind, because the separate account-rule features described under Account condition information you enter, below, do collect account-condition figures that you type in yourself. Those figures reach us through a different endpoint, under a different and separately versioned consent, and are kept under a different retention rule. Telemetry and account-condition figures are never merged into a single record. Ciphora does not use telemetry to compute, infer, store, or market trader profitability, success rates, or funded-account performance. Operational telemetry is not evidence of a trading edge.
Ciphora processes telemetry only to evaluate beta reliability, installation success, alert delivery, usability, and research validity. Telemetry is not used for advertising or sold.
Where it lives: telemetry, feedback, and beta application records are stored in a Postgres database operated by Neon (our database hosting provider), which processes the data on our behalf under its own security and privacy commitments. Vercel hosts the application that receives telemetry, and Kit (ConvertKit) processes email data as described elsewhere in this policy.
Retention, revocation, and deletion: telemetry and feedback are deleted or de-identified within 24 months after the earlier of the end of your participation and the end of the beta, subject to the shorter periods and limited exceptions in the Retention schedule below. Because operational telemetry is a condition of participation rather than an optional extra, asking Ciphora to revoke your telemetry token ends your participation in the research beta. It is not a way to remain in the beta with collection switched off. Revocation stops further collection immediately. You can request access to or deletion of your stored telemetry and feedback by emailing the contact address above; applicable requests are handled under the process described below.
Telemetry is sent over HTTPS to https://ciphora.ai/api/beta/telemetry. The revocable token is sent in the request body, never in the URL, and stored only as a cryptographic hash. Payloads are validated, size limited, rate limited, and deduplicated. No security measure is absolute. Beta software and infrastructure can fail, so do not send any data beyond what the alert template defines.
Account condition information you enter
Some beta features can use figures describing the condition of your own paper or simulated trading account. This is a separate, optional collection with its own consent text and its own version identifier. It is not covered by the application acknowledgments or by the operational telemetry condition above, and agreeing to it is never a condition of applying or of participating in the beta. These features sit behind an explicit opt-in feature state that is off unless Ciphora deliberately turns it on. While that state is off, none of the collection described in this section happens at all. While it is on, collection still begins only for a participant who has separately consented, and it stops for that participant as soon as they withdraw.
You type every figure yourself. Ciphora does not connect to a broker, an exchange, or a prop firm, and no account is synchronized on your behalf. The figures you enter are exactly nine, and the form accepts nothing else: your current account equity including unrealized profit and loss; the maximum-loss-limit floor your platform displays; the highest end-of-day balance your platform records, which is optional; your profit or loss for the current day; the total money at risk from your open positions to their protective stops, which is optional but required whenever any contract is open; the position cap your platform displays for the account right now; how many contracts you currently have open; how many losing trades you have taken in a row; and how many trades you have taken today.
There is no field anywhere in this collection for an account name or label, an account number, a per-trade risk percentage, or a maximum-loss, daily-loss or trade limit of your own choosing, and an unrecognized field is rejected rather than stored. Earlier versions of this policy described some of those as collected. They were not collected then and are not collected now; this section was corrected and the policy version was moved so the correction is on the record rather than made silently.
Separately from those figures, you make three choices from lists Ciphora fixes: your evaluation stage, chosen from Ciphora's supported stages rather than written in free text; whether your contract counts are minis or micros; and whether the optional daily loss limit applies to you. The amount of that daily loss limit is set by Ciphora, not by you.
Alongside your figures and choices we store the rule envelope they were evaluated against, because a result cannot be explained or reproduced without it. Every part of that envelope is fixed by Ciphora and cannot be supplied or overridden by you: the account currency; the maximum loss limit; the daily loss limit amount used when the election applies; the internal rule profile actually applied, or a marker recording that no verified profile exists for the stage you asked for; the dated version identifier of that rule profile; and the versions of the account-rule consent and of the policies you accepted. We also record bookkeeping that the server owns rather than you: an identifier for the record, the time the server captured it, the time we received it, and the fixed time at which the record stops being usable. You cannot supply, backdate, postdate, or extend any of those times, and a submission that tries to set one is rejected.
Ciphora never asks for and must never be given a broker or exchange password, an API key or secret, an account number, payment-card details, or any permission to place, modify, or cancel an order. Screenshots are not collected. A record of your account condition is a structured, timestamped set of the figures you typed and nothing more.
These records are stored in the same Neon database described below, alongside a record of which consent version you accepted and when, and are retained under the Retention schedule below. You may withdraw this consent at any time using the withdrawal control in the beta area or by emailing us. Withdrawal takes effect immediately, and from that moment no new account-condition record is accepted from you, every record you had already submitted stops being usable as an input, no further result is produced for you, and the rule profile your figures were evaluated under is retired.
Withdrawal is not an instant erasure, and we would rather say so than imply otherwise. The records you already submitted, the results already produced from them, and the record of what you consented to and when all remain stored after you withdraw. They are simply no longer used. They are removed when the applicable period in the Retention schedule below expires, or sooner if you make a deletion request we can grant. The consent record itself is kept for its full period, because it is the evidence of both the consent and its withdrawal.
Output produced from these figures reports whether a signal met the account rules that applied to your stage and election at one moment in time. Each result is itself kept as a record, so that a past result can be explained and reproduced rather than merely asserted. A stored result holds the outcome, the full ordered list of reasons that produced it, the account-condition band it was produced under, the identifiers of the signal, the account-condition record and the rule profile it used, and the time it was produced. These records are linked to your participant record. They are personal information about you, not anonymous statistics, and they are retained under the Retention schedule below.
A result is decision-support only. It is not financial advice, not an instruction to trade, not a prediction, and not a probability of winning. It can be delayed, out of date, unavailable, or wrong, and your trading decisions remain your own. In the current build these features are also not operational: the sizing and selectivity policies they would need are deliberately absent, so the software cannot return an approval or a position size at all, and every result it can reach is a rejection, a not-evaluated outcome, or an error.
Optional public-site analytics and what we do not collect
This website does not set advertising or marketing trackers. We do not sell personal information, and we do not buy data about you from third parties.
Where Cloudflare Web Analytics is enabled for a deployment, this site is served through Cloudflare and the Web Analytics beacon is loaded on it. Whether the beacon is enabled on any particular deployment is a deployment configuration setting, and this policy does not assert it as verified. When it is enabled, Cloudflare Web Analytics measures aggregate site use and performance, including visits, page views, referring sites, country, device type, browser, operating system, page path, page-load timing, and Core Web Vitals. Cloudflare states that Web Analytics does not use cookies or local storage for analytics and does not fingerprint or track individual visitors over time. Cloudflare Web Analytics does not log query strings. Cloudflare processes the beacon data as our infrastructure and analytics provider.
Where Google Analytics 4 is configured, Ciphora offers a separate analytics choice on informational public pages. The Google tag is not requested unless you select Allow analytics. It remains disabled on application, contact, login, beta, and Director routes even after that choice. The implementation sends a page path without its query string or fragment and a referrer reduced to an origin or same-site path. It does not send form contents, assistant questions, application identifiers, account-condition figures, trading records, or a Ciphora user identifier. Advertising storage, advertising user data, ad personalization, Google signals, and ad personalization signals remain disabled.
If you allow Google Analytics, Google may set first-party analytics cookies such as _ga and _ga_* and process a randomly generated browser identifier, public page views, approximate location, device and browser information, language, timestamps, and basic interaction or performance information. Google Analytics 4 uses an IP address at collection time to derive location and route the request, but Google states that GA4 does not log or store the IP address. Google processes this information as our optional analytics provider. The property must use the two-month user and event data-retention setting before this feature is activated; Google explains that this setting does not govern every aggregated standard report.
Your choice is stored in this browser as a small local-storage preference. You can reopen Analytics preferences in the footer, change your choice, and decline future analytics at any time. Declining disables the tag and attempts to remove accessible _ga cookies from this site. It does not retract information already received by Google; you may use the privacy-request process below for an applicable request.
We do not require or ask you to provide broker credentials, broker API keys, exchange credentials, account passwords, account balances, or private trading records through the Early Access form or the Knowledge Assistant. Please do not submit them there. The single place Ciphora accepts figures about your account is the separate, separately consented account-condition form described above, and even there it never accepts a credential, an account number, or a payment detail of any kind.
Payments
Payment-card data is not collected because no payment flow is enabled and Ciphora Confluence Engine is not currently for sale. No payment processor is currently active for Ciphora. Before any paid access is enabled, this policy will be updated to name the approved payment provider and to describe exactly what data it processes.
How we use your information
- To review Early Access applications and manage beta access
- To send administrative messages about applications or beta access and, only when you separately consent, marketing messages
- To respond when you contact us
- To operate, secure, and improve our services
Lawful bases and required information
Where the GDPR, UK GDPR, or a similar law applies, Ciphora relies on the following bases: steps you ask us to take when you apply or contact us; performance of the Terms of Service after you accept an invitation; legitimate interests in operating, securing, evaluating, and improving a small research beta, including required operational telemetry; consent for optional marketing and optional Google Analytics; and legal obligations when records must be preserved or disclosed by law. Ciphora does not use consent where another basis is more appropriate.
Fields marked required on the application are needed to review the application and administer a possible beta invitation. If you do not provide them, the application cannot be reviewed. Marketing consent and provider names identified as optional are not required. Declining optional marketing does not prevent application review or beta eligibility. Telemetry is not required to apply, but it is a condition of accepting an invitation and participating in the research beta.
Ciphora does not ask for special-category information, government identifiers, account credentials, or payment-card data anywhere in its services. The application, the Knowledge Assistant, the feedback forms, and support messages do not ask for account balances or other financial figures either, and you should not include them there. Figures describing the condition of your own paper or simulated account are collected only through the separate opt-in form described above, under its own separately versioned consent, and are processed on the basis of that consent.
Service providers that process data
If you use the public Knowledge Assistant on the homepage or Help Center, your question and a limited set of reviewed public knowledge-base passages may be sent to Anthropic, our AI provider. Those passages may include text, article titles, links, and stable passage identifiers. Data is sent only when the assistant is enabled, Anthropic is configured, and our server attempts a provider request. Anthropic's model selects which reviewed passages are relevant. If those conditions are not met, the assistant returns a reviewed no-answer message.
Anthropic's output is not shown directly. Our server accepts only passage identifiers from the set it supplied, then builds the displayed answer from the exact reviewed passages or returns a fixed, reviewed no-answer message. Do not include personal, account, or trading information in assistant questions. The assistant does not need that information.
Our website infrastructure providers process requests to serve the site and protect it. Vercel (hosting and request handling) receives standard request data such as IP address, user agent, and requested URL as part of serving the site. When a request is proxied through Cloudflare, Cloudflare processes network and security metadata (such as IP address, user agent, and requested URL) under its own services and policies. We do not make claims here about these providers' internal retention or training practices beyond what their own policies state.
If you affirmatively allow optional public-site analytics and the Google Analytics measurement identifier is configured, Google processes the limited analytics information described above. Ciphora does not enable Google advertising storage, Google signals, ad personalization, or advertising user data through this implementation.
Where your information lives
Application data accepted by the service is stored in a Postgres database operated by Neon on our behalf. Only the contact, application-administration, policy-version, and marketing-choice fields needed for email operations are synchronized to Kit (ConvertKit). Detailed trading-profile answers remain in the Neon database and are not copied to Kit. The Neon database also stores beta telemetry, feedback, invitation and consent records, and related audit history. Kit and Neon process this data as service providers. Vercel hosts our website.
International transfers and geographic limits
The initial private beta application is currently limited to adults who reside in the United States. The server rejects an application that identifies another country before creating an application record or an email-platform delivery job. Website availability in another country does not mean beta access is offered or approved there.
Ciphora and several service providers named above operate in the United States. Public website requests and provider operations may be processed in the United States or another country where a provider operates, and privacy protections and government-access rules may differ from those in your country.
Ciphora will not open applications or invitations in another country until the controller identity, provider contracts, transfer safeguards, local representatives where required, and applicable product, privacy, marketing, consumer, accessibility, and financial-services rules have been reviewed for that jurisdiction. Where European or United Kingdom transfer rules apply, a lawful transfer mechanism and related safeguards must be implemented before accepting an application.
Email choices
Marketing emails include an unsubscribe link. Unsubscribing stops future marketing but does not withdraw an Early Access application or prevent administrative emails needed to review and manage an application you submitted, such as a receipt, status message, or beta invitation. Submitting an application does not guarantee delivery of an administrative email. To withdraw an application, email us.
Your rights
You may ask us to access, correct, export, delete, or restrict personal information we hold about you by emailing legal@ciphora.ai. You may also withdraw consent at any time for processing based on that consent and, where applicable, request data portability. We handle valid requests under applicable law, normally without charge, and may verify your identity before acting. If a legal exception limits your request, we will explain why.
These rights vary by location and by the lawful basis used. Ciphora extends the request process above to all applicants and beta participants even when a particular local law does not require every listed right.
Your right to object
Where processing relies on legitimate interests, you may object by emailing legal@ciphora.ai and explaining the processing you want stopped. You may object to direct marketing at any time without giving a reason by using the unsubscribe link or contacting us. Ciphora will stop direct marketing after an effective objection, while retaining only the minimum suppression record needed to honor it.
Complaints and supervisory authorities
You may contact legal@ciphora.ai so we can investigate. You do not have to contact Ciphora before using a complaint right available to you. If European data-protection law applies, you may complain directly to the supervisory authority where you live or work, or where you believe an infringement occurred. United Kingdom residents may complain to the Information Commissioner's Office. California residents may contact the California Privacy Protection Agency where the CCPA applies. These options do not limit any other remedy available under law.
No solely automated significant decisions
Ciphora does not use solely automated processing to make a decision that produces a legal or similarly significant effect. Application screening may organize submitted information, but a Ciphora administrator reviews every beta invitation decision. The Knowledge Assistant selects reviewed public passages and does not decide beta eligibility, trading access, employment, credit, insurance, or any other significant matter.
The account-rule features described above do apply automated rules to figures you enter and do produce an automated result. That result is decision-support returned to you and nothing else. It does not place a trade, does not decide your access to Ciphora or to any third party, and does not affect your beta eligibility, your credit, your employment, your insurance, or any other significant matter. Beta eligibility and account-rule output are separate throughout: an account-rule result is never an input to an invitation decision, and an invitation decision is never an input to an account-rule result. Whatever words a result uses to describe its own outcome refer only to the comparison between the figures you entered and the rules you configured, and carry no meaning outside it. You may disregard any result entirely, and you may withdraw the consent that enables these features at any time.
Retention schedule
Applications that are declined or withdrawn are deleted or de-identified within 12 months after the final decision or withdrawal. Applications that remain pending and are never invited are deleted or de-identified within 12 months after the most recent submission or applicant-initiated update. Records for accepted participants, including consent receipts, access history, feedback, operational telemetry, and any account-condition figures and the results produced from them, are deleted or de-identified within 24 months after the earlier of the end of participation and the end of the beta. Separately from that outer limit, an individual account-condition record stops being usable as an input a fixed ten minutes after the moment you captured it. That expiry ends the record's use immediately, but it is not by itself a deletion: the expired record, and any result produced from it, stay stored until the 24-month rule above or a granted deletion request removes them. Support and privacy-request records are retained for up to 24 months after resolution. Optional marketing contact data is kept until you unsubscribe or withdraw consent. Afterward, Ciphora may retain a minimal suppression record to prevent future marketing.
A shorter period applies when information is no longer needed or a valid deletion request is granted. A longer period applies only when reasonably necessary for security, fraud prevention, legal obligations, or establishing, exercising, or defending legal claims. Infrastructure and security logs controlled by service providers follow each provider's documented schedule. De-identified research records may be retained only when they can no longer reasonably be linked to a person.
Children and age eligibility
The beta application and beta are intended only for adults who are at least 18 and legally able to accept the Terms. Ciphora does not knowingly accept beta applications from anyone under 18. If you believe a minor submitted personal information, contact legal@ciphora.ai so the record can be investigated and deleted where required.
Cookies and consent controls
The public website does not use advertising cookies. Where Cloudflare Web Analytics is enabled for a deployment, it is described above as a cookie-free aggregate analytics service. Google Analytics is optional and remains unloaded until you select Allow analytics; that choice is stored in local storage and can be changed through Analytics preferences in the footer. If allowed, Google Analytics may set the first-party analytics cookies described above. Accepted beta participants also receive a strictly necessary, secure session cookie for onboarding and feedback.
Changes to this policy
If this policy changes in a way that materially affects an applicant or participant, we will update the effective date above and provide any administrative notice required by law through the contact channel associated with the application or beta account. This notice does not depend on marketing consent. If applicable law requires consent to a change, we will request it before the change takes effect.