Privacy Policy — v0 PLACEHOLDER
⚠️ PLACEHOLDER TEXT — NOT LEGALLY REVIEWED.
Pre-lawyer draft by Prometheus on 2026-04-18. Paired with
terms-v0-placeholder.md— both require lawyer review before going live onapp.sentienttrading.ai.Version:
v0-placeholder· Last updated: 2026-04-18
1. Who we are
Sentient Options Platform is operated by Gaban Ventures LLC ("Gaban Ventures," "we," "us"). This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and your rights over it.
Questions or requests: leon@gaban.com
2. What we collect
We collect two categories of data:
2.1 Account information (from your OAuth provider)
When you sign in with Google or X (Twitter), the provider shares:
- Your name
- Your email address
- Your profile picture URL (if available)
- A unique user ID from the provider
That's everything on the identity side. We do not request or receive your date of birth, address, phone number, Social Security number, financial information, contact list, posts, or browsing history.
2.2 Trading data (from TastyTrade's API, with your authorization)
When you connect your TastyTrade account, we receive from TastyTrade's API:
- Your TastyTrade account number
- Orders placed, filled, rolled, or closed by our bot on your account
- Open positions and their current values
- Your account balance and buying power (only the amount required to size trades correctly)
- Timestamps and execution details for every trade
We derive analytics from this data: profit-and-loss per trade, win rate, drawdown, and similar performance metrics.
3. How we use your data
We use your data for five purposes only:
- Running your bot — executing the iron condor strategy on your TastyTrade account
- Displaying your dashboard — showing you your positions, performance, and trade history
- Improving the trading system — analyzing trade execution data across all user accounts (including yours) to refine the strategy, catch bugs, and tune parameters. Your data contributes to aggregate research that benefits every user.
- Admin oversight — Gaban Ventures personnel can view trade execution data and performance across all accounts to operate the Platform safely
- Security and audit — logging authentication events, credential changes, and bot actions so we can detect and respond to incidents
4. How we protect your data
- Credentials are encrypted at rest. Your TastyTrade OAuth refresh token is never stored in plain text.
- Transit is encrypted. All connections to the Platform use HTTPS/TLS.
- Access is role-limited. Only Gaban Ventures personnel who need access to operate the Platform can view your data.
- Row-level security. Our database enforces per-user isolation at the SQL layer — other users of the Platform cannot see your data.
- Audit logs. Every time your credentials are read or written, we log who, what, and when.
5. Who we share data with
We do not sell, rent, or share your personal data for advertising or commercial gain. We share data only with:
- Google / X — your OAuth provider, to authenticate you (they already have this data)
- TastyTrade — your broker, to place trades on your account (they already have this data)
- Supabase — our database provider, which hosts the data on our behalf under a standard data-processing agreement
- Vercel — our application hosting provider, which runs the Platform's servers
- Courts and regulators — if we receive a valid legal request compelling disclosure
That's it. No advertising networks. No data brokers. No third-party analytics that identify you.
6. Your rights
6.1 Access
You can see most of your data directly in the Platform — your settings page, dashboard, and trade history show the core of what we hold.
6.2 Correction
Most of your data (name, email, avatar) comes from your OAuth provider — correct it with Google or X and it will update on our end at next sign-in.
6.3 Deletion
You can request full deletion of your account and personal data by clicking Settings → Danger Zone → Delete Account (Phase 2 UI) or by emailing leon@gaban.com.
When you request deletion:
- Your bot stops immediately
- Your encrypted TastyTrade credentials are wiped
- Your name, email, avatar, and directly-identifiable trade records are deleted within 30 days
- Anonymized aggregate data derived from your trading may be retained for ongoing strategy research — this data has no identifier linking it back to you
6.4 Portability
On request, we will provide a machine-readable export of the trade data associated with your account. Email leon@gaban.com.
6.5 Withdraw consent
You can revoke autotrading authorization at any time via Settings → Danger Zone → Revoke TastyTrade Access. This stops new trades within minutes and deletes your stored credentials.
6.6 Complain
If you believe we have mishandled your data, email us first at leon@gaban.com and we will try to resolve it. If unresolved, you may have additional rights under applicable law (e.g., to file a complaint with a data protection authority if you are in the EU/UK, or the California Attorney General if you are in California).
7. Data retention
- Account identifiers (name, email, avatar, OAuth IDs): retained while your account is active; deleted within 30 days of account deletion request
- Credentials (encrypted TastyTrade tokens): retained while you are connected; deleted immediately upon revocation or account deletion
- Trade execution data (orders, fills, positions): retained while your account is active; personally-identifiable trade records deleted within 30 days of account deletion
- Anonymized aggregate analytics: may be retained indefinitely for ongoing strategy research
- Security and audit logs: retained up to 12 months for incident response
8. Location of data
Data is stored in the United States on Supabase and Vercel infrastructure. If you are outside the US, using the Platform means you consent to the transfer of your data to the US.
9. Cookies
We use only strictly-necessary cookies — for session authentication and saving your theme preference. We do not use advertising cookies, analytics cookies that identify you personally, or third-party tracking pixels.
10. Children
The Platform is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has used the Platform, email us and we will delete their data immediately.
11. Changes to this policy
When we materially change this policy, we will notify you via the email on file and/or via an in-app prompt requiring you to review the new version. Continued use after a change indicates acceptance.
12. Contact
leon@gaban.com for questions, corrections, deletion requests, or complaints.
Mailing address: [TO BE FILLED IN]
END OF PLACEHOLDER — v0