Privacy Policy
This policy describes what the Service actually collects and does with your information. It is deliberately specific; if you cannot find something, ask us.
1. Who operates the Service
Options Strategy Hub is operated by SpyWave LLC ("we", "us"). Options Strategy Hub is a product of SpyWave LLC. This Privacy Policy explains what information we collect when you use the website at https://optionsstrategyhub.com and the application at https://app.optionsstrategyhub.com (the "Service"), why we collect it, who we share it with, how long we keep it, and the choices you have. It is written to match how the Service actually works; the technical inventory behind it is kept with the Service's documentation.
2. Information you give us
- Account information. When you sign in through our identity provider (Auth0) we receive and store an opaque account identifier, your email address and, if your sign-in method provides it, your name. We never receive your password.
- Billing details. When you subscribe, Stripe collects your payment details directly. We store only the Stripe customer and subscription identifiers, your plan, billing interval, subscription status, renewal date, whether the Founder offer applied, and the identifiers of the Stripe events we processed. We never receive or store your card number.
- Databento credential. If you connect your Databento API key, we store it encrypted on our server for your account only, together with when it was saved and the result of your last connection test (success or failure, the message, and the list of datasets the key can see). The key is never displayed back to you in full and is used only to fetch data for your own runs.
- Strategies and backtests. The strategy definitions you create or import, the settings of each run (period, execution mode, data window, approved spend), the derived results of each run you save (trade records, equity curve, indicator snapshots at entry, analytics, event reactions) and the lineage between strategy versions.
- AI feature inputs. The questions you type, the plain-English ideas you ask the AI to turn into a strategy, and the replies you paste back in copy/paste mode.
- Support communications. Anything you send us at sean@spywaveai.com.
- Consent records. Which versions of our policies you accepted and when.
3. Information collected automatically
- Product activity events. The application records events such as sign-up, sign-in, subscription changes, Databento connection and disconnection, estimates, approvals, backtests started, completed or failed, AI use, exports and comparisons, each with your account identifier, a timestamp and small non-sensitive properties (for example the execution mode or an error code). Credentials and strategy definitions are never written to these events.
- Diagnostics. When something fails, the application records a reference id, an error code, a message, a scrubbed technical detail and, for unexpected errors, a scrubbed stack trace, together with the account identifier of the affected run. Credentials are removed before anything is written.
- Operator audit log. Actions taken by our staff on accounts (for example a suspension or a support-access session) are recorded in an append-only log with the staff member's identifier, the affected account identifier, the reason and the time.
- Server and network logs. Our web server and reverse proxy log requests in the ordinary way: the IP address, time, requested path, response status and browser user-agent. The application itself does not record IP addresses.
- Cost records. For each run we keep the Databento estimate, the maximum you approved, the amount quoted at purchase and the outcome. These contain no credentials.
4. Cookies and similar technologies
The application uses only the cookies it needs to work: a signed session cookie that keeps you signed in after Auth0 authentication, and the connection state the application framework (Streamlit) needs to run your session. Our identity provider sets its own cookies on its sign-in pages under its own policy. We have disabled the application framework's usage reporting.
We do not use advertising cookies, analytics trackers, session-replay tools, social-media pixels or similar third-party tracking on the website or in the application. If that ever changes, this policy will be updated first and, where the law requires it, we will ask for your consent before loading them.
The marketing website loads its typefaces from Google Fonts; your browser therefore requests those font files from Google's servers, which receive your IP address and browser details under Google's privacy policy.
5. Why we use your information
- To provide the Service: sign you in, keep your account, run and store your backtests, and show your results.
- Authentication and security: verify your identity, detect and prevent unauthorized access, abuse, fraud and attempts to bypass limits.
- Billing: start and manage your subscription through Stripe, apply entitlements, meter usage against your plan and handle payment problems.
- Cost authorization: show you Databento's price before a run and enforce the maximum you approved.
- AI features: send your run's computed evidence and your question to the AI provider and show you the reply, only when you use those features.
- Reliability and improvement: diagnose failures, measure how the product is used in aggregate, and improve it.
- Support: answer your messages and investigate problems you report.
- Legal obligations: keep the records we must keep, respond to lawful requests, and enforce our Terms.
6. Who we share information with
We share personal information only with the service providers that are needed to run the Service, each for its own purpose and under its own terms:
- Auth0 (identity): handles sign-up, sign-in and password or two-factor management. It processes your email and sign-in activity.
- Stripe (payments): processes your payment details, invoices and subscription. Stripe is an independent controller of the payment data it collects.
- Databento (market data): receives requests made with your own API key, under your own Databento account and agreement. We send Databento the data queries your runs need; Databento sees your key, not your strategy.
- AI provider (Anthropic), only when the AI features are enabled on the server and you use them: receives the computed evidence of the run (headline statistics, breakdowns, winners-versus-losers features, the strategy's settings and per-trade records with identifiers, prices and times), your question and, for refinement, your strategy definition. It does not receive your email, name, Databento key, file paths, other runs or other customers' data. Our requests are made through the provider's commercial API; that provider's data-handling terms govern how long it retains request content, and we do not make promises about its retention or training practices beyond what its published commercial terms state.
- Hosting provider: the servers that run the Service and store its data. Our hosting provider has physical and infrastructure access to its machines under its own terms.
We do not sell personal information and we do not share it for targeted advertising. We do not share one customer's strategies, results, credentials or data with another customer. We may disclose information where the law requires it, to protect our rights, customers or the public, or as part of a merger, acquisition or sale of assets (with notice to you).
7. How long we keep information
- Market data fetched for a run (SPY bars, option chains, 1-second quotes) is held in an isolated workspace for that run only and deleted when the run ends, whether it succeeds, fails or is cancelled. A cleanup sweep removes any workspace left behind by a crash.
- Strategies, saved backtests, cost records and your Databento connection are kept until you delete them or delete your account.
- Account and subscription records are kept while your account exists.
- Consent records are kept while your account exists; after deletion we keep a minimal record of which policy versions were accepted and when, with the account identifier, as evidence of the agreement.
- Operator audit log entries are append-only and are kept for the life of the Service; they reference account identifiers, never credentials or content.
- Product activity events, diagnostics and server logs are kept for 90 days and then deleted.
- Server backups of persistent data are kept for 30 days. Data you delete may remain in a backup until that backup expires; backups are not used to restore deleted data to a live account.
- Payment records are retained by Stripe under its own policies and the legal requirements that apply to payment processing, even after you delete your account.
8. Deleting your account and exporting your data
You can delete your account yourself from Account → Privacy & Data in the application. Deletion removes your account record, your consent record (a minimal acceptance record is retained as described above), your Databento credential, your strategies, saved backtests, cost records, your subscription snapshot and any running job records, and cancels an active subscription with Stripe. It does not remove append-only audit entries that reference your account identifier, entries in activity and diagnostic logs until their retention period ends, records Stripe must keep, or copies in backups until they expire. If an operator suspended your account, deletion still works.
You can download your data at any time from the same page: your account profile, consent record, strategy definitions, saved backtest summaries and trade records, and cost history, in open formats (JSON and CSV). Every run's results can also be exported individually from its Results page.
9. How we protect information
We use safeguards that are appropriate for a small research product in its first beta: sign-in is delegated to an identity provider and verified server-side; your role and account status are checked on every request; Databento keys are encrypted at rest with a key held only on the server and outside the application's code and data directories; every per-customer store is isolated by a validated account identifier; runs execute only inside the customer's own temporary workspace; Stripe webhooks are signature-verified; credentials are scrubbed from error messages, logs and diagnostics; staff actions are recorded in a tamper-evident audit log; and the application is served only over HTTPS.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach affecting your information we will notify you as the law requires.
10. Where information is processed
The Service is hosted on servers we rent from our hosting provider, and our providers (Auth0, Stripe, Databento, Anthropic) operate in the United States and may process data in other countries. If you use the Service from outside the country where our servers are located, your information is transferred to and processed there.
11. Children
The Service is for adults. We do not knowingly collect information from anyone under 18. If you believe a child has created an account, contact us at sean@spywaveai.com and we will delete it.
12. Your rights and choices
Depending on where you live you may have rights to access, correct, delete, export or restrict the use of your personal information, to object to certain processing, and to complain to a supervisory authority. The application lets you view your account details, export your data and delete your account directly. For anything else, email sean@spywaveai.com; we will respond within the time the applicable law allows and may ask you to verify your identity through your signed-in account. We do not discriminate against you for exercising your rights.
13. Changes to this policy
We may update this policy. The version date at the top changes when we do. For material changes we will ask you to accept the new version in the application before you continue using it, and we may also notify the email address on your account.
14. Contact
SpyWave LLC, operator of Options Strategy Hub. Email: sean@spywaveai.com.
Other policies: Terms of Service Risk & Backtesting Disclosure Refund & Cancellation Policy