Effective: July 9, 2026 · v1.0

Privacy Policy

AlphaSync (源析) — alqedge.com

1. Introduction

This Privacy Policy explains how AlphaSync (“we,” “us,” “our”) collects, uses, discloses, and protects personal information when you use the AlphaSync website and AI stock-analysis service at alqedge.com (the “Service”).

We take a minimal-data approach: we collect only what we need to operate the Service, we do not sell personal information, and we do not use your queries to train AI models. By using the Service you agree to this Policy. If you do not agree, please do not use the Service.

2. Scope and Service Area

  • Audience: The Service is offered only to individuals located in the United States (50 states + DC). We do not knowingly collect personal information from individuals located outside the U.S.
  • Children: The Service is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18.
  • Not a U.S. “financial institution”: We do not provide investment advice and are not subject to the Gramm-Leach-Bliley Act (“GLBA”) as a financial institution.

3. Information We Collect

3.1 Information you provide directly

CategoryExamplesWhen collected
Account informationEmail address, display name (optional), password hashAccount registration
Authentication profile (Google OAuth)Email, name, OAuth tokenIf you choose “Sign in with Google”
Watchlist / preferencesTickers you save, alert preferencesUsing watchlist feature
Support communicationsEmail content, attachmentsWhen you contact support

3.2 Information collected automatically

CategoryExamplesSource
Usage dataPages viewed, features used, query counts, timestampsPostHog analytics
Device & log dataIP address, browser type, OS, referrer, error logsSentry, Cloudflare, server logs
Cookies and similarSession cookies (auth), PostHog analytics cookiesYour browser

3.3 Information collected via third-party payment processor

AlphaSync does NOT directly collect, transmit, or store your payment-card information. When you subscribe, you are redirected to Waffo Pancake (operated by Waffo.com Limited), our Merchant of Record payment processor. Waffo.com Limited collects and processes:

  • Card number, expiration date, CVV, billing address (handled entirely on Waffo's PCI-DSS-compliant checkout);
  • Transaction history (visible to you in your Waffo Pancake customer portal);
  • Email address (shared with AlphaSync so we can associate the subscription with your account).

See Waffo Pancake's privacy policy on the checkout page for details.

3.4 Information we DO NOT collect

  • Social Security number, government ID, or similar identifiers;
  • Bank account or routing numbers;
  • Precise geolocation;
  • Biometric data;
  • Health, immigration, or other “sensitive” categories under CCPA;
  • Your personal brokerage portfolio or holdings;
  • Content of your personal communications outside the Service.

4. How We Use Your Information

PurposeInformation used
Provide and operate the ServiceAccount info, queries, watchlist
Authenticate users and prevent fraudAccount info, IP, device data
Process subscriptions and billingEmail (from Waffo), subscription status
Communicate with you (service notices, security alerts)Email
Send transactional and product emailsEmail
Debug, monitor, and improve the ServiceUsage data, error logs
Comply with legal obligations and enforce our TermsAll relevant categories
Respond to lawful U.S. legal processAll relevant categories

We do NOT:

  • Sell personal information for money or other “valuable consideration” (CCPA §1798.140(ad));
  • “Share” personal information for cross-context behavioral advertising (CCPA §1798.140(ah));
  • Use your stock-analysis queries or saved watchlist to train AI / machine-learning models;
  • Send marketing email without your affirmative consent.

5. How We Disclose Information

5.1 Service providers (processors)

ProviderRoleCategories disclosed
Waffo Pancake (Waffo.com Limited)Payment processor / MoREmail, billing address, transaction data
Supabase Inc.Database, auth, file storage (US-East)Account info, queries, watchlist, reports
DeepSeekLLM providerTicker symbols + market context (no PII)
ResendTransactional emailEmail address
SentryError monitoringError logs (may contain IP, browser)
PostHogProduct analyticsUsage events (pseudonymous user ID)
CloudflareCDN, edge security, GeoIP blockIP address, request metadata
FinnhubMarket dataTicker symbol only (no PII)
SEC EDGARPublic-filing sourcePublic data only (no PII)
Google LLC (OAuth)AuthenticationEmail, name, OAuth token

5.2 For legal reasons

We may disclose information when we believe in good faith that it is necessary to comply with applicable U.S. law, regulation, or legal process; enforce our Terms of Service; or protect the rights, property, or safety of AlphaSync, our users, or others.

5.3 Business transfers

If AlphaSync is acquired, merged, or sells substantially all of its assets, your personal information may be transferred as part of that transaction. We will notify you by email at least 30 days before the transfer takes effect.

5.4 Otherwise with your consent

We will disclose your information for any other purpose only with your affirmative consent.

6. Cookies and Similar Technologies

Cookie typePurposeDurationRequired?
Auth session cookieKeep you signed inSession / 7 daysYes
PostHog analytics cookieAggregate usage analytics12 monthsNo (honor DNT)
Cloudflare cookiesBot protection, GeoIPSession / 30 daysYes (security)
Waffo Pancake cookiesPayment checkoutPer Waffo policyYes, when paying

We do not use advertising cookies, third-party tracking pixels, or cross-site behavioral tracking.

7. Data Storage and Security

  • Primary database: Supabase Postgres, hosted on US-East region (AWS us-east-1). Row-Level Security (RLS) is enabled on all user-data tables.
  • Application hosting: Backend (FastAPI on Python) and frontend (Next.js) deployed on U.S.-region infrastructure.
  • Backups: Supabase managed backups retained for 7 days; off-site encrypted snapshots retained for 30 days.
  • Encryption: TLS 1.2+ in transit (HTTPS); AES-256 at rest.
  • Access control: Access to production data is limited to the founder/operator; access is logged and audited.
  • Passwords: Stored hashed using Supabase Auth (bcrypt). We never see plaintext passwords.

No system is 100% secure. If we discover a security incident affecting your personal information, we will notify you by email and provide the required breach-notification disclosures.

8. Data Retention

Data categoryRetention
Account info (email, profile)While account is active + 30 days after deletion
Stock analyses / reports24 months after creation; then anonymized or deleted
WatchlistWhile account is active
Usage analytics (PostHog)12 months, then aggregated or deleted
Error logs (Sentry)90 days
Payment transaction records (Waffo)Per Waffo's policy (typically 7 years)
Support emails24 months after last interaction
Backup snapshots30 days

9. Your Rights (CCPA / CPRA and Other U.S. State Laws)

As a U.S. user you have specific rights regarding your personal information. We extend these rights to all U.S. users regardless of state of residence.

9.1 Rights you have

  • Right to Know (CCPA §1798.110): Request what personal information we have collected about you.
  • Right to Access / Portability: Request a copy of your personal information in JSON format.
  • Right to Delete (CCPA §1798.105): Request deletion of your personal information.
  • Right to Correct (CPRA): Request correction of inaccurate personal information.
  • Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information.
  • Right to Non-Discrimination (CCPA §1798.125): We will not discriminate against you for exercising your rights.

9.2 How to exercise these rights

  • Self-service (recommended): Log in → Settings → Privacy → “Download my data” or “Delete my account.”
  • Email request: privacy@alqedge.com. We will respond within 45 days.
  • Authorized agent: California residents may designate an authorized agent.

9.3 Verification

We verify your identity before fulfilling requests. We may ask you to confirm control of the email address on file.

9.4 Appeal

If we deny your request and you are a California resident, you may appeal by replying to our denial email within 30 days.

10. Do Not Track / Global Privacy Controls

We honor “Do Not Track” (DNT) browser signals and Global Privacy Control (GPC) headers as opt-outs of non-essential cookies (analytics). However, the Service is not available outside the U.S., so cross-jurisdictional “Do Not Sell My Personal Information” links are not required.

11. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a child under 18, we will delete it as soon as possible. Parents may contact privacy@alqedge.com to request deletion.

12. International Visitors

The Service is offered only in the United States and is not intended for use outside the U.S. If you are visiting the Service from outside the U.S., please be aware that your information will be transferred to, stored in, and processed in the United States. By using the Service, you consent to such transfer and processing.

We do not target or knowingly serve users in the European Economic Area, the United Kingdom, China, or any OFAC-sanctioned jurisdiction.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated Policy on this page with a new effective date, email you at least 30 days before the changes take effect, and for California residents, describe the changes in a summary of changes notice.

14. Contact

We aim to respond to all privacy requests within 15 business days; CCPA grants us up to 45 days.

© 2026 AlphaSync. All rights reserved. | Terms of Service