PLACEHOLDER-DO-NOT-PUBLISH. This page is a drafting brief, not a privacy policy, and nothing on it is in force. It cannot be finished until the legal entity exists: a privacy policy has to name the data controller, its registered address and a contact point, and RECAPITAL has none of those yet. The text below lists what the document has to cover so the reviewed version can be dropped straight in.
Data controller
To be completed once the company is formed. Needs the registered legal name, the registered address, the VAT or company number, and a contact route for privacy requests.
What we collect
To be drafted. Has to cover, at minimum: account details given at sign-up (name, email, phone number and country); trading data, whether typed in, imported from a file or synced from a broker; OAuth tokens for connected broker accounts; chart screenshots attached to trades; Desk messages and the trades a member shares in them; and usage data.
Legal basis for processing
To be drafted, per category of data.
How broker tokens are stored
To be drafted. This is the part a reader will care about most and the part the payment provider will read closely: it has to describe how the tokens are encrypted, who can reach them and what they are used for.
Sub-processors
To be drafted. Needs the current list — the database and storage provider, the payment provider, the email provider and analytics — with what each one receives.
Historical insights and analytics: verified implementation facts
As of the September 2026 source review, Insights and Analytics use deterministic calculations in the browser. They do not call an external AI provider or send trade rows, notes, account balances, or broker identifiers to a model. There is no user-supplied LLM key feature. This does not replace the disclosures needed for ordinary journal storage, hosting, or broker synchronization.
If a generative provider is introduced, update this brief before enabling it. The reviewed policy must identify the provider, data sent, processing purpose and legal basis, retention and training terms, processing locations, and any applicable international-transfer arrangements. These facts must come from the actual service agreement and deployment configuration; they are not established by this source review.
International transfers
To be drafted.
How long we keep it
To be drafted. Has to state the retention periods and be explicit that data is retained after a subscription is cancelled and after an account is locked out, and for how long.
Desk messages must be covered explicitly (docs/DESKS-MESSAGING-SECURITY.md): they are encrypted and private between the member and the Desk's leads, and are not end-to-end encrypted. RECAPITAL can read a message only if it is reported, and every such read is logged. Messages are deleted 12 months after they are sent (placeholder period — confirm with the lawyer), and when the member leaves or the Desk is deleted; a message under an open report is kept until the report is closed. Never describe Desk messages as end-to-end encrypted.
Your rights
To be drafted. Access, export, correction, deletion, objection, and how to exercise each.
Cookies
To be drafted, alongside the cookie consent mechanism, which does not exist yet.
Contact
To be completed with the entity.