01 Who we are
QuantovAI (“QuantovAI”, “we”, “us”) operates the QuantovAI platform: a private financial social network offering AI-generated trading signals, community features and performance tracking. This policy covers our website at app.quantovai.com and our Android and iOS applications, which display that same website inside a native app.
The data controller is ZENQUANT LTD, registered at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, company number 16674329.
QuantovAI is not a broker and does not execute trades. Nothing on the platform is financial advice.
02 Summary
The short version of what follows:
| What | Why | Where it goes |
|---|---|---|
| Account details | To create and secure your account | Supabase; Google or Apple if you use them to sign in |
| Content you post | To operate the community features | Supabase; visible to other members |
| Usage events | To understand which features are used | Our own database only — no third-party tracker |
| Payment details | To take subscription payments | Stripe. Not collected in the current version — paid subscriptions are disabled. We never see or store card numbers |
| Push token | To send notifications to your device | Supabase; Google Firebase for delivery |
| Technical data | Security, fraud prevention, reliability | Supabase, Cloudflare |
We do not sell your personal information. We do not use advertising networks, and we do not embed third-party analytics or tracking pixels.
03 Information we collect
Account information
When you request access or sign in, we collect your email address and the profile details you provide, such as your display name and avatar. If you sign in with Google or Apple, we receive your email address, name and profile picture from that provider — we never receive your Google or Apple password.
Content and activity
We store what you create on the platform: posts and comments in the community feed, profile information, referral activity, and your interactions with signals and performance data. Content posted to community areas is visible to other members.
Usage analytics
We record product analytics events in our own database. Each event contains your user ID, a randomly generated session identifier stored in your browser, the event name, the page path and section, your language setting, and event-specific properties. These are recorded only while you are signed in.
This data stays in our infrastructure. It is not shared with an analytics vendor, and there is no Google Analytics, advertising pixel or third-party tracker in the product.
Device and technical information
Our servers and security provider automatically receive your IP address, device and browser type, operating system version and the pages you request. Requests are routed through Cloudflare, which sets a security cookie to distinguish humans from automated traffic.
Push notification token
If you use the mobile app, we collect a device notification token issued by Google Firebase Cloud Messaging, together with the platform name. It is stored against your account so notifications can be addressed to your device. It identifies a device installation, not you personally, and is deleted when you sign out.
Payment information
Paid Elite membership is not available in the current version of QuantovAI, so no new payment information is collected. The description below applies when paid subscriptions are offered again, and to records of subscriptions taken previously.
Subscription payments are processed by Stripe. Card details are entered directly into Stripe's systems — we never receive or store your full card number. We retain the subscription status, plan, billing dates and transaction identifiers Stripe returns to us.
Information from device features
The app can request access to your camera, microphone, photo library and location. These are used only for the feature you are actively using, such as setting a profile picture or uploading a verification document. Nothing is collected in the background.
If you enable biometric unlock, your fingerprint or face data never leaves your device and is never transmitted to us — your device only tells the app whether the check passed.
MetaTrader 5 connection
Connecting a real MetaTrader 5 or broker account is not available in the current version of QuantovAI. No broker credentials, account numbers or live trading data are collected. Training Mode uses virtual funds and no broker connection. The description below applies when the connection feature is offered again, and to details stored while it was previously available.
If you choose to connect a MetaTrader 5 trading account, you give us your account number, your broker's server name, the broker name and the risk settings you select. We store those details, together with the status of the connection and the results our trading service reports back, in our own database against your account.
Your MetaTrader 5 password is used once, at the moment you connect, to register the account with our trading execution service over an encrypted, signed request. It is not stored in our database and is never exposed to other members. QuantovAI is not a broker: your money and your trading account remain with your broker, whose own privacy policy applies to them. You can ask us to remove the connection at any time.
04 How we use information
- To create your account, authenticate you and keep you signed in.
- To operate the platform — signals, community, performance tracking, referrals.
- To process subscription payments and manage Elite membership, when paid membership is offered.
- To send notifications you have asked for.
- To understand which features are used, so we can improve them.
- To detect and prevent fraud, abuse and unauthorised access.
- To respond to support requests.
- To comply with legal obligations.
We do not use your information for automated decision-making that produces legal effects, and we do not sell it.
05 Legal bases
If you are in the UK or European Economic Area, we rely on these legal bases under the GDPR:
| Basis | Applies to |
|---|---|
| Contract | Running your account, delivering the service, taking payment |
| Legitimate interests | Security, fraud prevention, product analytics, service reliability |
| Consent | Push notifications, camera, microphone, photos and location access |
| Legal obligation | Tax and accounting records, responding to lawful requests |
Where we rely on consent, you can withdraw it at any time.
06 Services we use, and why
These providers process data on our behalf. Each is used for a specific purpose, listed below.
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database, authentication and file storage — the core backend | Account details, content, analytics events, push tokens |
| Lovable | Hosting for the web application, and brokering the sign-in flow | Requests to the site; sign-in redirects |
| Google Sign-In | Optional way to sign in without a password | Confirms your identity; returns email, name, picture |
| Firebase Cloud Messaging | Delivering push notifications to Android devices | Device token and notification content |
| Google Play Services | Required on Android for notification delivery | Device and app identifiers |
| Sign in with Apple | Optional way to sign in on iOS | Confirms your identity; email may be a relay address |
| Stripe | Taking subscription payments (currently inactive — no new payments are taken) | Card details, billing details, transaction data |
| Cloudflare | Content delivery, DDoS protection and bot filtering | IP address, request headers, security cookie |
| Google Fonts | Serving the typefaces the interface is set in | IP address when fonts are requested |
Each is bound to use the data only to provide their service to us. Links to their privacy policies are available on request, and we will keep this list current as the platform changes.
07 Push notifications
With your permission, we send notifications about signals, community activity and your account.
In a browser these use standard web push. In the mobile app they are delivered through Firebase Cloud Messaging, which requires storing a device token against your account. Notification content passes through Google's servers in order to reach your device.
You can turn notifications off at any time in your device settings. Signing out deletes the stored token for that device, and tokens that stop working — for example after you uninstall the app — are deleted automatically.
08 Device permissions
The mobile app asks for the following. Each is optional, requested only when a feature needs it, and refusing one only disables that feature.
| Permission | Used for |
|---|---|
| Notifications | Delivering the alerts you subscribe to |
| Camera | Taking a profile photo or capturing a document |
| Microphone | Recording audio where a feature offers it |
| Photos & media | Uploading an existing image from your device |
| Location | Only when a page you are using requests it |
| Biometrics | Unlocking the app with fingerprint or face |
| Network state | Detecting when you are offline |
We do not track your location in the background, and we do not access your camera or microphone outside the moment you use a feature that needs them.
09 Cookies and local storage
We use browser and device storage for:
- Authentication — keeping you signed in between visits.
- Session identifier — a random ID that groups your analytics events into one visit. It contains nothing about you and resets when you close the tab.
- Preferences — language and interface settings.
- Security — Cloudflare's bot-detection cookie.
We use no advertising or cross-site tracking cookies. Clearing site data signs you out and resets your preferences.
11 International transfers
Our providers operate globally, so your information may be processed outside your country, including in the United States. Where information leaves the UK or EEA we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
Our primary database is hosted in
the European Union (Frankfurt, Germany — AWS eu-central-1).
12 How long we keep it
| Data | Retained |
|---|---|
| Account & profile | While your account is active. Deleted or anonymised when you close your account, except where the law requires us to keep records |
| Posts & comments | Until you delete them or close your account, subject to legal and security requirements |
| Analytics events | Only as long as reasonably necessary to understand and improve how the product is used |
| Push tokens | Until you sign out, uninstall the app, the token expires or you delete your account |
| Payment records | For the period required by applicable tax and accounting law |
| Server & security logs | Only as long as reasonably necessary for security, fraud prevention, troubleshooting and legal obligations |
Deleting your account. You can delete your QuantovAI account and personal profile yourself at any time: open your Profile in the app, choose Delete my account and confirm. Deletion is immediate and permanent, and removes your profile, posts, comments, stories, likes, follows, notifications, uploaded media, notification tokens, training portfolio and any MetaTrader 5 connection.
If you cannot sign in, you can request deletion from our public page at app.quantovai.com/delete-account or by writing to contact@quantovai.com from the email address on your account. We verify the request and complete it within 30 days.
After deletion we retain only what the law requires: billing and payment records kept in an anonymised form for tax and accounting purposes, and limited security logs. These are no longer linked to your name, email or profile.
13 Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your information, subject to our legal obligations.
- Receive a copy in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
- Complain to your data protection authority.
To exercise any of these, contact us at contact@quantovai.com. We respond within one month. We will not treat you differently for exercising a right.
California residents. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives for personal information.
14 Security
All traffic is encrypted in transit with HTTPS. Access to the database is restricted by row-level security so members can reach only their own records. Payment card data never touches our systems. Sign-in happens in your device's own browser rather than inside the app, so your Google or Apple password is never visible to us.
No system is completely secure, and we cannot guarantee absolute security. Please use a strong, unique password and tell us promptly at contact@quantovai.com if you suspect unauthorised access.
15 Children
QuantovAI is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us personal information, contact us and we will delete it.
16 Third-party links
The platform may link to sites we do not control. Links opened from the app are handed to your device's browser rather than opened inside the app, so you can always see the address bar. This policy does not cover those sites, and we encourage you to read their own.
17 Changes to this policy
We may update this policy as the platform develops. The “last updated” date at the top always reflects the current version. For material changes we will give notice in the app or by email before they take effect.
18 Contact us
For any question about this policy or your information:
- Email contact@quantovai.com
- Post 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ