Legal document

Privacy Policy

Last updated: 2026-07-08

1. Who we are

This Policy describes how Alexandria (“we”, “us”), as data controller for the Smart Money Link (“SML”) platform, processes personal information, in accordance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws. This Policy is drawn up in English; translations are provided for convenience and the English version prevails.

2. Local-first architecture

Smart Money Link is designed so that your working data — imported trades, journal notes, playbooks, and settings — is stored locally in your browser (localStorage), on your device. We do not operate a server-side database of your content. This data is not transmitted to or stored on our servers, with the following exceptions:

  • AI features (Pharos) — when you use Pharos, the content you submit (your message and a summary of the relevant data on screen, such as track-record statistics) is sent through our infrastructure to Google's Gemini API for processing. See section 4.
  • Analytics and error reporting — anonymized, aggregated usage data and technical error reports are processed as described in sections 5 and 6.

Because your data lives in your browser: clearing browser storage deletes it, it does not follow you across devices, and anyone with access to your device profile may be able to access it. You can export or erase everything at any time in Settings.

3. Data we process, purposes, and legal bases

For users in the EEA/UK, the legal bases under GDPR art. 6(1) are indicated per purpose:

  • Providing the Service (art. 6(1)(b), contract): rendering the dashboard and its tools. Your content itself stays in your browser (section 2).
  • AI processing (art. 6(1)(b), contract): the content you actively submit to Pharos, processed to generate the response you requested.
  • Security and abuse prevention (art. 6(1)(f), legitimate interest): technical logs, rate limiting, error reports.
  • Aggregate usage measurement (art. 6(1)(f), legitimate interest): cookieless analytics (section 5).
  • Payments and account management (art. 6(1)(b) and (c)): when paid subscriptions and accounts become available, payment data will be processed by a payment provider (e.g., Stripe) — we will not store card numbers. This Policy will be updated before those features launch.

We do not use your data for: third-party advertising, selling contact lists, cross-site behavioral profiling, or any purpose incompatible with the Service.

4. AI features (Pharos) and Google Gemini

When you use Pharos, the specific content you submit — your question plus a compact summary of the data in view (for example, aggregate track-record metrics) — is processed by Google LLC's Gemini API to generate the response. Google processes this content under its Gemini API terms, which include retention for a limited period for abuse monitoring. We do not persist your prompts or the responses in any database of ours; they transit our serverless infrastructure, whose technical logs are retained briefly by our hosting provider.

AI outputs may be inaccurate or incomplete, and are informational only — they are not financial advice. Do not submit sensitive personal information through the chat; it is not needed for any feature.

5. Analytics (cookieless)

We use Vercel Web Analytics, a privacy-friendly service. It does not use cookies and does not track you across sites or apps. Visitors are identified only by a temporary hash generated from the incoming request, automatically discarded within 24 hours. Collected data (page URL, referrer, coarse city-level geolocation, device/OS/browser type) is anonymized and used exclusively in aggregate — we cannot identify individual visitors from it. We also use Vercel Speed Insights to measure real-world page performance.

6. Error reporting

If the application encounters an error in your browser, a technical report (error message, truncated stack trace, page path, browser type) is sent to our infrastructure and written to short-lived operational logs, used solely to detect and fix defects. These reports do not include your journal or trading content.

7. Sub-processors

We use the following sub-processors to provide the Service:

  • Google LLC (Gemini API) — large-language-model processing of the content you submit to AI features. United States (global infrastructure).
  • Vercel Inc. — application hosting, content delivery, cookieless analytics, and operational logs. United States (global edge network).

We will update this list when we add or replace sub-processors. Providers of payment processing and transactional email will be added here before those features launch.

8. International data transfers

Our sub-processors process data in the United States and other countries. Where personal data originating in the EEA, the UK, or Switzerland is transferred to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU-U.S. Data Privacy Framework. You may request details by contacting us.

9. Your rights

Depending on your jurisdiction, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or outdated data.
  • Erase data, subject to legal retention duties.
  • Portability: receive data in a structured, machine-readable format. (Your working data is already exportable as JSON in Settings.)
  • Object to or restrict processing based on legitimate interest.
  • Withdraw consent at any time, where processing is based on consent.

To exercise any right, write to privacy@alexandria.app. We respond within 15 business days. You also have the right to lodge a complaint with your local data protection authority.

10. California privacy rights (CCPA/CPRA)

In the preceding 12 months we have collected the following categories of personal information: identifiers (such as email, if you contact us) and internet activity information (aggregated, anonymized usage data). We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have no actual knowledge of selling or sharing personal information of consumers under 16. California residents may exercise the rights to know, correct, delete, and non-discrimination by writing to privacy@alexandria.app.

11. Security

  • Encrypted connections (HTTPS/TLS) on all communications.
  • Security headers (CSP, HSTS, anti-clickjacking) on every page.
  • API keys and server credentials never exposed to the browser.
  • Minimal server-side surface: no server database of your content to breach.

No system is 100% immune. If an incident compromises personal data, we will notify the competent authority and affected users as required by applicable law.

12. Retention

Your working data stays in your browser under your control — we cannot delete what we do not hold; you can erase it in Settings at any time. Operational logs (errors, access) are retained briefly by our hosting provider and then discarded. Data associated with future accounts/payments will follow statutory retention periods, disclosed when those features launch.

13. Children

The Service is intended for users 18 and older. It is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13; if we learn that we have, we will delete it.

14. Changes to this Policy

We may update this Policy periodically. Material changes will be communicated via a visible notice on the platform (and by email, when accounts exist) at least 15 days in advance.

15. Contact

Privacy questions and data subject requests: privacy@alexandria.app.