Privacy Policy
Effective and last updated: June 30, 2026
This Policy explains the difference between local open-source use and personal-data processing in QuantJourney websites, accounts, APIs, hosted workspaces, cloud data and related services.
1. Scope and controller
QuantJourney operates from Dubai, United Arab Emirates (“QuantJourney,” “we,” “us,” or “our”), and is the controller of personal data collected through our public websites, direct account relationships, access requests, contact forms, feedback and support, unless a service-specific notice, order form or data-processing agreement identifies another QuantJourney entity or role.
This Policy applies to backtester.quantjourney.cloud, api.quantjourney.cloud,
quantjourney.cloud, quantjourney.pro, their subdomains, the hosted Backtester workspace,
QuantJourney APIs and SDKs, QJ Cloud Data, and other QuantJourney services that link to this Policy (the
“Services”). Third-party platforms such as GitHub, PyPI, Discord, Substack and YouTube apply their own privacy
notices to their platforms.
Installing or running the open-source quantjourney-bt package locally does not, by itself, send your
strategy code, parameters or local datasets to QuantJourney. Visiting an online Service necessarily transmits
basic request metadata. Your research content is transmitted only when you deliberately submit it to an online
feature—for example an API, hosted workspace, cloud dataset, support channel or feedback form.
2. Information We Collect
2.1 Account and relationship data
- Name, work email, organization, role or profile and contact details you provide.
- Account identifiers, authentication events, tenant membership, entitlements, API-key metadata and account status.
- Beta requests, support messages, contact inquiries, product feedback, survey responses and communication preferences.
- Plan, order, invoice, transaction and payment-processor reference data; we do not receive full payment-card details from the payment processor.
2.2 Technical and service-use data
- IP address, approximate network location, browser, device, operating system, language, timestamps, referring page and pages or features used.
- Request and response metadata, endpoint, status code, latency, usage count, quota, error, security and audit events.
- Workspace configuration, run metadata, saved reports, artifact identifiers and collaboration events when you use hosted features.
- Dataset, symbol, snapshot and query metadata when you use QJ Cloud Data or an API, subject to the relevant service configuration.
2.3 Content you choose to submit
A hosted workspace or API may process strategy code, parameters, prompts, research configurations, input data, generated results and files that you deliberately submit. Support and feedback channels process the message and attachments you send. Browser-saved theme settings and local strategy drafts remain on your device unless you choose to upload or synchronize them.
2.4 Data from other sources
We may receive account or identity data from an authentication provider, billing status from a payment provider, repository or package activity from GitHub or PyPI where their terms allow it, and professional or public-source information relevant to a business relationship. QJ Cloud Data may include licensed or public records; any personal data within a specific dataset is governed by the applicable data contract and service-specific notice.
3. How We Use Your Information
We process personal data to:
- create and administer accounts, authenticate users, issue and manage access, and provide requested Services;
- execute API and workspace requests, generate research artifacts, deliver data and maintain run or audit history;
- respond to contact, beta, support and feedback submissions and send operational confirmations;
- measure reliability, troubleshoot errors, allocate capacity, enforce quotas and improve product usability;
- protect users and Services, detect abuse, investigate incidents and maintain security and audit records;
- manage contracts, billing, tax, compliance and legal claims; and
- send newsletters or optional product marketing when you have requested it or where law otherwise permits, with an unsubscribe option.
Depending on the context and applicable law, our legal bases are performance of a contract or steps you request before a contract, our legitimate interests in operating and securing the Services and communicating with business users, your consent, and compliance with legal obligations. Where processing is based on consent, you may withdraw it without affecting earlier lawful processing.
4. Browser storage, cookies and analytics
Backtester pages use first-party browser storage for functions such as theme preference, authentication, workspace settings, local drafts, dismissed hints and preview access. Authentication tokens may be stored in your browser when you sign in. Clearing site data may sign you out or remove locally saved settings and drafts.
The public Backtester site does not currently use third-party advertising trackers. We may use privacy-respecting operational measurement or add analytics in the future; if consent is legally required, we will request it before activating non-essential cookies or similar technologies. Other QuantJourney Services may provide an additional cookie notice where their implementation differs.
5. Sharing and processors
We do not sell personal information or use it for third-party cross-context behavioral advertising. We may share personal data only as reasonably necessary with:
- hosting, infrastructure, authentication, email, support, monitoring, payment and professional-service providers acting under appropriate obligations;
- data providers when needed to fulfill a query and permitted by the relevant data contract;
- your organization, tenant administrators or collaborators where the Service is configured for team use;
- a competent authority, court or other party where required by law or reasonably necessary to protect rights, security and users; and
- a successor in a merger, financing, reorganization or sale, subject to appropriate confidentiality and notice requirements.
6. Enterprise and customer-controlled data
When an organization provides the hosted workspace to its personnel or submits personal data for processing under an enterprise agreement, that organization may be the controller and QuantJourney may act as its processor or service provider. In that case, the agreement and any data-processing addendum govern our processing. Users should direct requests concerning organization-controlled data to that organization; we will assist it as required.
7. International transfers
QuantJourney and its providers may process data in countries other than your own. Where applicable law requires a transfer mechanism, we use an adequacy decision, contractual safeguards or another lawful mechanism. A service-specific agreement may define hosting region, data residency or additional transfer controls.
8. Retention
We retain personal data only for as long as reasonably needed for the purposes described above, including the life of an account or contract, support and security follow-up, billing and tax requirements, dispute limitation periods and backup cycles. Retention may vary by Service, record type and customer agreement. We delete or anonymize data when it is no longer needed, unless law or a valid legal hold requires continued retention.
9. Security
We use technical and organizational measures designed to protect personal data, including access controls, authentication, tenant boundaries, logging, encryption in transit and restricted operational access where appropriate to the Service. No Internet transmission or storage system is completely secure. You are responsible for protecting your devices, credentials and API keys and for promptly reporting suspected compromise.
10. Your rights and choices
Subject to applicable law, you may have the right to:
- access, correct or delete your personal data;
- object to or restrict processing;
- receive portable data you supplied where the legal requirements are met;
- withdraw consent and unsubscribe from optional marketing; and
- complain to your competent data-protection authority.
We may need to verify your identity and authority before completing a request. Rights are not absolute; for example, we may retain records required for security, contracts, legal obligations or claims. You may opt out of marketing without losing operational messages necessary for an account or requested Service.
11. Children
The account, API, hosted workspace and cloud data Services are designed for professional, research and educational users and are not directed to children. We do not knowingly collect a child’s personal data in violation of applicable law. Contact us if you believe a child has provided personal data without the required authorization.
12. Changes to this Policy
We may update this Policy to reflect changes to our Services, providers, legal obligations or processing. We will post the revised Policy and update its effective date. If a change materially affects an account or paid hosted Service, we may also notify the account contact or provide an in-product notice where appropriate.
13. Contact
To ask a privacy question or exercise a right, contact us below and include enough information to identify the relevant Service and account. If an order form, invoice, enterprise agreement or service-specific notice identifies a different controller or privacy contact, use the details in that document for the covered processing.
QuantJourney · Dubai, United Arab Emirates
Email: [email protected]
Contact form: backtester.quantjourney.cloud/contact