Privacy Policy
This policy says what StatikFinTech, LLC collects when you use SFTi, why, who else sees it, and what you can ask us to do about it. It is written to describe what the system actually does.
The short version
We collect the least we can run an account on: your email, a hashed password, your tier, your API keys and how many calls they made. We never see your card. Stripe handles payment and sends us only a customer reference and the subscription's state. SFTi runs on hardware we own and administer — there is no outside cloud holding your account.
1. What we collect
- Account data — your email address, a bcrypt hash of your password (never the password itself), your tier, whether your email is verified, your role, and the timestamps of account creation and last login.
- API keys and usage — the keys issued to your account, their labels, their daily quota, and a per-day count of calls made with each key. The count is what enforces your allowance.
- Billing references — a Stripe customer id and subscription id, the state of your subscription, and the date of any failed payment. No card number, expiry or CVC ever reaches our servers.
- Email tokens — short-lived tokens for email verification and password reset.
- Session cookie — one httpOnly cookie,
sfti_session, holding a signed token that proves you are logged in. It is not an advertising or tracking cookie and we set no others. - Server logs — ordinary web and application logs, which include IP addresses, timestamps, requested paths and error detail. IP addresses are also held briefly in memory to enforce rate limits on the login and signup endpoints.
- Push subscriptions — if you enable notifications in the app, the browser push endpoint your device gives us, so we can deliver an alert to it.
We do not collect brokerage credentials, bank details, government identifiers, or the contents of your trading accounts. We run no advertising trackers and no third-party analytics on this site.
2. Why we hold it
- To create and operate your account and authenticate you (contract).
- To meter your tier's request allowance and enforce it fairly (contract).
- To take payment, apply your tier and handle refunds and disputes (contract, legal obligation).
- To send you service email — verification, password reset, and notices that affect your subscription (contract). We do not send marketing email.
- To keep the service up, debug it, and defend it against abuse (legitimate interest).
- To keep records we are required to keep, such as payment records (legal obligation).
3. Who else sees it
- Stripe, Inc. — our payment processor. You enter card details on Stripe's own checkout and portal pages; Stripe tells us who paid, for what, and whether it succeeded. Stripe's handling of your payment data is governed by Stripe's privacy policy.
- An email delivery provider — when email delivery is configured on this deployment, your email address and the message body are passed to it so the message can be sent. If it is not configured, no message is sent and the app says so on screen rather than telling you to wait for one.
- Google Fonts — our public pages load two typefaces from
fonts.googleapis.com, which means your browser's IP address is visible to Google when it fetches them. No account data is sent. - Nobody else. We do not sell, rent or trade personal data, and we do not share it for anyone else's marketing. We will disclose data if a valid legal order compels us.
4. Where it lives, and for how long
Account, key, usage and billing-reference data is stored on hardware StatikFinTech, LLC owns and administers in the United States — the same machine that serves this page. We keep account data for as long as your account exists. When you close an account we delete the account record and its API keys, and retain only what we must for legal and accounting purposes (principally payment records). Server logs rotate on a short cycle. Email verification and reset tokens expire within 24 hours and 1 hour respectively.
5. Security
Traffic is served over TLS. Passwords are stored only as bcrypt hashes. Session tokens are signed, httpOnly and same-site. API keys are scoped to one account and can be revoked instantly from your account page. No system is perfectly secure; if we become aware of a breach affecting your data we will tell you.
6. Your choices and rights
- See it — your account page shows your email, tier and every key on the account. Ask us for anything else we hold.
- Correct it — email us to change your address or fix a record.
- Delete it — ask us to close the account and delete it. We will confirm what is deleted and what we must keep.
- Export it — ask and we will send you your account data in a machine-readable form.
- Withdraw consent — turn off push notifications in your browser or the app at any time.
Write to SFTi.Help@sfti-ai.org. We answer within 30 days. Depending on where you live you may also have the right to complain to a data-protection authority.
7. Children
SFTi is not for anyone under 18. We do not knowingly collect data from children; if we learn we have, we delete it.
8. Changes
If this policy changes, the effective date above changes, and material changes are emailed to the address on your account before they take effect.
9. Contact
StatikFinTech, LLC
Privacy and support: SFTi.Help@sfti-ai.org
Direct: Daniel.Morris@sfti-ai.org
Phone: +1 (785) 443-6288