Legal
Privacy Policy
Current implementation boundary: This unreviewed draft does not establish that a brokerage, execution, automation, notice, safeguard, or regulated feature is currently available. Availability depends on approved configuration, account, provider, jurisdiction, and applicable law.
APEX Trading Terminal — Privacy Policy
_Last updated: May 17, 2026 (audit pass v2)_ _⚠️ Draft — Pending licensed-attorney review before publication. Not legal advice; no attorney-client relationship is created by this document._
Conditional draft statement; verify implementation and legal applicability before publication: _Changes v2 (2026-05-17): added Florida Digital Bill of Rights disclosure (§6.4); split Anthropic and OpenAI in the service-provider table with retention/training notes (§4.1); added Global Privacy Control honoring (§7); GLBA / financial-data treatment clarified (§8); GDPR EU Representative entry resolved or geofence option flagged (§6.3)._
1. Introduction
Conditional draft statement; verify implementation and legal applicability before publication: Silver Owl Studios LLC ("APEX", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the APEX Trading Terminal platform ("Platform").
Please read this policy carefully. By using the Platform, you consent to the practices described here.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: Name, email address, password
- Profile information: Trading preferences, watchlists, alert configurations
- Payment information: Billing address, payment method details (processed by Stripe — we do not store full card numbers)
- Communications: Messages you send to our support team
- Broker connection: Broker account identifiers when you connect a broker (we do not store broker passwords or full API keys in plain text)
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, time spent, clicks, searches
- Device information: IP address, browser type, operating system, device identifiers
- Log data: Access logs, error logs, performance data
- Cookies and tracking: See our Cookie Policy for details
2.3 Information from Third Parties
- Conditional draft statement; verify implementation and legal applicability before publication: Broker data: Trade history, positions, and account balances from your connected broker (Alpaca or others) — used only to display your portfolio within the Platform
- Conditional draft statement; verify implementation and legal applicability before publication: Market data providers: Real-time and historical market data from Polygon.io and other providers
- Prediction market data: Public market data from Polymarket and Kalshi APIs
2.4 AI Interaction Data
When you interact with NOVA-TRADER, we may collect:
- Your queries and prompts
- Generated responses
- Feedback you provide on AI responses
This data is used to improve the AI system and provide the Service. It is not sold to third parties.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Display market data, execute trade instructions, generate AI analysis
- Process payments: Charge subscription fees via Stripe
- Communicate with you: Send service updates, alerts you've configured, support responses
- Improve the Platform: Analyze usage patterns, fix bugs, develop new features
- Security: Detect and prevent fraud, unauthorized access, and abuse
- Legal compliance: Comply with applicable laws and regulations
- Marketing: Send promotional communications (you can opt out at any time)
We do not:
- Sell your personal information to third parties
- Use your trading data to trade against you
- Share your data with advertisers for targeted advertising
4. How We Share Your Information
4.1 Service Providers
We share data with trusted service providers who help us operate the Platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Billing information |
| Alpaca Securities | Trade execution | Order instructions |
| Polygon.io | Market data | None (we query their API) |
| AWS/Vercel/Railway | Hosting & infrastructure | All data (encrypted) |
| Anthropic (Claude) | AI analysis (NOVA-TRADER) | Query text + relevant market/feature context; configured under Anthropic API "zero-retention" / no-training tier where available |
| OpenAI | AI analysis (NOVA-TRADER, fallback) | Query text + relevant market/feature context; configured under OpenAI API enterprise data-handling terms (no training on API data) |
| Intercom / Email provider | Customer support | Name, email |
All service providers are bound by data processing agreements (DPAs) and may only use your data to provide services to us. We do not authorize any AI service provider to use your prompts, queries, or conversation content to train, fine-tune, or evaluate models, and we configure their APIs accordingly. If any provider's terms materially change, we will update this section before the change takes effect.
4.2 Legal Requirements
We may disclose your information when required by law, court order, or government request, or to protect the rights, property, or safety of APEX, our users, or others.
4.3 Business Transfers
If APEX is acquired, merged, or sells assets, your information may be transferred as part of that transaction. We will notify you via email before your information becomes subject to a different privacy policy.
4.4 With Your Consent
We may share your information for other purposes with your explicit consent.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 3 years after closure |
| Trade/order history | 7 years (financial record requirements) |
| AI interaction logs | 2 years |
| Payment records | 7 years (tax/legal requirements) |
| Usage/analytics data | 2 years |
| Support communications | 3 years |
You may request deletion of your account and personal data at any time (subject to legal retention requirements).
6. Your Rights
6.1 All Users
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your account and personal data
- Opt-out of marketing: Unsubscribe from promotional emails at any time
- Data portability: Request your data in a portable format
6.2 California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act (as amended by the California Privacy Rights Act), California residents have the right to:
- Know what personal information is collected, used, shared, or sold
- Delete personal information held by us
- Correct inaccurate personal information
- Opt-out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising)
- Limit the use and disclosure of sensitive personal information (which may include financial account information used to verify identity)
- Non-discrimination for exercising your privacy rights
To exercise CCPA/CPRA rights, contact us at legal@silverowl.dev or visit our Privacy Request page.
6.3 EU/EEA/UK Residents (GDPR / UK GDPR)
Under the General Data Protection Regulation (EU 2016/679) and the UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Data portability
- Object to processing
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with your local data protection authority
Our legal basis for processing your data:
- Contract: Processing necessary to provide the Service
- Legitimate interests: Security, fraud prevention, service improvement
- Consent: Marketing communications, optional data collection
- Legal obligation: Financial record retention, AML, sanctions screening
EU Representative (Art. 27 GDPR): contact legal@silverowl.dev
To exercise GDPR/UK GDPR rights, contact: legal@silverowl.dev
We will respond to data requests within 30 days (extendable to 60 days where permitted under Art. 12(3) GDPR).
6.4 Florida Residents (Florida Digital Bill of Rights)
Under the Florida Digital Bill of Rights (FL Stat. §§ 501.701–501.722), Florida consumers may have the right to:
- Confirm whether we process their personal data and access that data
- Correct inaccuracies in their personal data
- Delete their personal data
- Obtain a portable copy of their personal data
- Opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of decisions producing legal or similarly significant effects
- Opt out of the collection or processing of sensitive data, including precise geolocation data and biometric data
The FDBR currently applies only to controllers meeting specific revenue and processing thresholds (FL Stat. § 501.702(8)). Whether APEX meets those thresholds will be reassessed at each annual review. Regardless of threshold status, APEX honors these rights on request for Florida residents. To exercise FDBR rights, contact legal@silverowl.dev.
6.5 Other U.S. State Privacy Laws
Residents of other U.S. states with comprehensive privacy laws (including CO, CT, VA, UT, OR, TX, MT, IA, DE, NJ, NH, MN, MD, KY, TN, and others as enacted) may have substantially similar rights. We honor verifiable consumer requests under these laws on a state-of-residency basis. Contact legal@silverowl.dev to exercise these rights.
7. Cookies and Tracking
We use cookies and similar tracking technologies. See our full Cookie Policy for details.
Summary of cookies used:
| Type | Purpose | Can Opt Out? |
|---|---|---|
| Essential | Login sessions, security | No |
| Functional | Preferences, watchlist settings | No |
| Analytics | Usage analysis (anonymized) | Yes |
| Marketing | Promotional (if applicable) | Yes |
You can manage cookie preferences through your browser settings or our Cookie Consent tool.
7.1 Global Privacy Control (GPC) and Universal Opt-Out
Where required by applicable law (including California, Colorado, Connecticut, and other states recognizing universal opt-out signals), we honor the Global Privacy Control (GPC) browser signal as a request to opt out of the sale or sharing of personal information and targeted advertising. We do not currently respond to legacy "Do Not Track" signals.
8. Data Security
8.0 Financial Data — GLBA Treatment
To the extent APEX receives or processes "nonpublic personal information" of consumers within the meaning of the Gramm-Leach-Bliley Act (15 U.S.C. §6801 et seq.) in connection with a financial product or service — including data obtained from your connected broker — we apply administrative, technical, and physical safeguards consistent with the GLBA Safeguards Rule (16 CFR Part 314) and the SEC's Regulation S-P where applicable. We do not sell or share NPI for marketing purposes.
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256)
- Multi-factor authentication option for accounts
- Regular security audits
- Restricted employee access to user data
- Incident response plan for data breaches
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact legal@silverowl.dev immediately.
In the event of a data breach affecting your personal information, we will notify you within 72 hours as required by applicable law.
9. Children's Privacy
The Platform is not intended for users under 18 years of age and is not directed to children under 13. We do not knowingly collect personal information from minors, including "personal information from a child" within the meaning of COPPA (15 U.S.C. §§ 6501–6506). If you believe we have collected information from a minor, contact us at legal@silverowl.dev and we will delete it promptly.
10. International Data Transfers
We are based in the United States. If you access the Platform from outside the US, your information may be transferred to and processed in the US, where data protection laws may differ from your country.
For EU/EEA users, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission for international data transfers.
11. Third-Party Links
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you use.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or in-app notification at least 14 days before the changes take effect. The "Last updated" date at the top of this policy reflects the most recent revision.
13. Contact Us
For privacy-related questions, requests, or complaints:
Silver Owl Studios LLC Privacy Team: legal@silverowl.dev Contact: legal@silverowl.dev
Conditional draft statement; verify implementation and legal applicability before publication: Response time: Within 30 days for data requests (extendable as permitted by law), within 72 hours for security incidents affecting personal data.