This policy explains what personal data AlphaAssay processes, why, and the rights you have. It applies to the Swiss Federal Act on Data Protection (revDSG) and, where we offer the Service to individuals in the EU/EEA, to the GDPR (Art. 3(2) — extraterritorial scope).
Who is responsible
The controller is AlphaAssay, 6403 Küssnacht am Rigi, Switzerland — see the legal notice. Data-protection contact: hello@alphaassay.com.
The short version: your raw inputs and rules are not retained
We process your submission in memory for the trial and do not retain the raw inputs, rules or
code. What we keep from an assay is the trial's paper trail: a one-way cryptographic
fingerprint, the machine-readable cause of death (died_at, failure codes), summary
statistics, a 32-value compressed sketch of the return profile for family trial accounting, and the
family's structural label with its parameter coordinates. None of this can be reversed into your trades,
rules or code. Two disclosed exceptions exist because their features require them: a pre-registered
spec is stored in full (sealing a claim means storing it), and x402-paid responses are cached
against their payment nonce (one payment buys one result, forever). The exact inventory is in the
table below and, path by path, on what we keep. Data minimisation reduces
what remains available after processing; the pre-registered spec and other listed records remain retained,
and the service has no broker, exchange or order path. This is a scoped control, not a universal guarantee
against operator misuse.
What we process, and why
| data | why | legal basis |
|---|---|---|
| Account details (email, and any name you provide) | create and secure your account, send service messages | contract performance (GDPR 6(1)(b); revDSG contractual) |
| Payment metadata (via Coinbase / x402 or a card processor) | take payment and prevent abuse — we do not store card numbers; the processor handles them | contract performance; legitimate interest in fraud prevention (6(1)(f)) |
| API and request logs (request id, timestamp, endpoint, status, coarse IP/rate-limit signal) | run the API, debug, enforce rate limits, keep an audit trail | legitimate interest (6(1)(f)); legal record-keeping where applicable |
| x402 gauntlet receipts | per settled POST /x402/v1/gauntlet payment: the payment nonce, paying wallet address, transaction id, input digest and cached response. The named receipt binds the payment, input and verdict digests; its own fields report whether Ed25519 signing succeeded or the deployment had no signing key. Responses never contain raw inputs. No expiry (the payment claim does not lapse) | contract performance |
| Purchased certificates | stored in full (signed, including trial disclosure), account-bound, for re-delivery | contract performance |
| Your submitted signals / backtests | run the assay in memory; retained per trial: a one-way fingerprint, the verdict with failure codes, summary statistics (Sharpe, sample length, test period), a 32-value compressed sketch of the return profile (family trial accounting) and the family's structural label — never the raw inputs, rules or code. Exception by design: a pre-registered spec is stored in full (sealing means storing) | contract performance |
Where it is hosted
The Service runs on servers located in the European Union (Germany). Payment processing runs through our payment providers (e.g. Coinbase for x402/USDC), who process the payment data described above under their own terms.
How long we keep it
Operational API and request logs are retained for about 90 days, then deleted or aggregated. Account data is kept while your account exists and for as long as needed to meet legal obligations. Verdict fingerprints and public calibration/graveyard statistics are, by design, anonymised and may be kept as part of the permanent public record — they contain no personal data and no recoverable strategy.
Who we share with
We do not sell your data and do not share it for advertising. We share only what is necessary with payment processors (to take payment) and infrastructure providers (hosting), acting as our processors, and where required by law. There is no other disclosure.
No tracking, no advertising cookies
This site runs no analytics and no advertising trackers. We set only cookies that are strictly necessary for the site or your session to function. There is no cross-site tracking to opt out of because there is none to begin with.
Your rights
Under the revDSG and, where it applies, the GDPR, you can request access to your data, and its rectification, erasure, restriction or portability, and you can object to processing based on legitimate interests. To exercise any of these, email hello@alphaassay.com. You also have the right to lodge a complaint with a supervisory authority — in Switzerland the FDPIC (Federal Data Protection and Information Commissioner), or in the EU/EEA your local data-protection authority.
Changes
We may update this policy; the current version is dated at the top. Material changes take effect when posted here.