Privacy Policy
1. Who We Are
QDS Sentinel is a trading policy oversight and guardrails platform operated by Quantum Data Solutions, LLC ("QDS," "we," "us," or "our"). We are not a registered investment advisor or broker-dealer. Nothing in Sentinel constitutes investment advice.
Contact: hello@qdsventures.com
2. What We Collect
We collect only what is necessary to provide the service:
- Account information: email address and a securely hashed password (PBKDF2-SHA256, 600,000 iterations). We never store your plain-text password.
- Broker connection and account data: encrypted SnapTrade connection secrets, selected-account identifiers, and periodic portfolio snapshots (positions, orders, and balances). We do not receive or store your broker password.
- Oversight events: policy evaluation results (allow, flag, block) for each agent action we review. These form your audit trail.
- Policy and API data: policy settings, Policy Assistant prompts, Guardian API key metadata and hashes, submitted trade/account context, and resulting evaluations. Plaintext API keys are shown once and are not stored.
- Beta, support, and usage data: beta application responses, feedback, timestamps, IP addresses used for abuse controls, and operational/error logs. We do not use advertising trackers or sell data for targeted advertising.
- Billing data: payment processing is handled entirely by Stripe. QDS never sees or stores your card number.
3. How We Use Your Data
- To provide, operate, and improve the QDS Sentinel service.
- To detect and prevent abuse, fraud, and security threats.
- To send you transactional emails (account verification, password reset, billing receipts). We do not send marketing emails without your explicit opt-in.
- To comply with applicable law.
We do not sell, rent, or share your personal data with third parties for advertising.
4. Broker Data and SnapTrade
Sentinel connects to supported brokerage accounts through SnapTrade, a third-party brokerage connectivity provider. Sentinel requests data-access connections and receives periodic account snapshots used for oversight. SnapTrade's connection portal handles brokerage authentication. QDS does not receive your broker password, and Sentinel does not place trades on your behalf.
5. Data Retention
- Account data: retained while your account is active. You may delete the account in the app or contact us for help with a verified request.
- Broker snapshots: the latest encrypted snapshot for each watched account is refreshed in place and retained while the connection or account is active.
- Oversight events (audit log): retained for the duration of your subscription. You may export your full audit log at any time from the app.
- API keys: active and revoked key hashes/metadata are retained while the account is active for security and audit purposes.
- Deleted accounts: the deletion workflow removes linked account data, API-key records, policies, oversight events, feedback, telemetry, and beta/waitlist records from active application storage. A non-user-linked deletion event may remain. Residual encrypted copies may persist temporarily in infrastructure-provider backups and age out under provider retention controls, unless longer retention is required by law.
6. Security
We take security seriously:
- Passwords are hashed with PBKDF2-SHA256 (600,000 iterations) — we cannot recover your password.
- Broker tokens and portfolio snapshots are encrypted at rest using AES-256-GCM with HKDF-derived keys.
- All data in transit is protected by TLS 1.2+.
- The API enforces rate limiting and account lockout to defend against brute-force attacks.
- Oversight events are internally hash-chained to help detect local alteration.
No system is perfectly secure. If you discover a vulnerability, please disclose it responsibly to hello@qdsventures.com.
7. Cookies and Local Storage
Sentinel uses browser session storage for the signed-in session token; it is cleared when the browser session ends and can also be revoked by logout. Local storage is used for non-sensitive preferences such as the selected tab and onboarding state. We do not use advertising cookies or tracking pixels. We use Cloudflare Turnstile for bot protection.
8. Third-Party Services
- Cloudflare: infrastructure, DNS, and edge security. Cloudflare Privacy Policy.
- SnapTrade: brokerage connectivity. SnapTrade Privacy Policy.
- Stripe: payment processing. Stripe Privacy Policy.
- Resend: transactional email delivery. Resend Privacy Policy.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data, and to appeal or complain about a privacy decision. You may disconnect brokerage access and delete your account from the app. For other requests, email hello@qdsventures.com. We will verify the request and respond within the period required by applicable law.
10. Children's Privacy
Sentinel is not directed at or intended for use by individuals under 18 years of age. We do not knowingly collect personal data from minors.
11. Changes to This Policy
We may update this policy as the service evolves. Material changes will be communicated by email or an in-app notice at least 14 days before they take effect. Continued use of Sentinel after the effective date constitutes acceptance of the updated policy.
12. Contact
Questions about this policy? Email hello@qdsventures.com. We aim to respond within 5 business days.
© 2026 Quantum Data Solutions, LLC · Privacy Policy · Terms of Service