legal · privacy
Privacy Policy
Effective: 2026-09-03
Vantis Terminal (“we”, “us”) operates a research, portfolio-tracking, and learning surface for Nigerian retail investors. This page summarises what data we collect, why we collect it, who we share it with, and the controls available to you. We aim to collect the minimum needed to run the product and keep your data on infrastructure we control or trust.
What we collect
- Account data — email address and (optionally) a display name when you sign up through Clerk.
- Your inputs — positions, watchlist entries, price alerts, journal notes, and any free-text you save inside the terminal. These power the product and are visible only to you.
- Imported documents — CSCS or broker statements, screenshots, CSV files, and pasted text you upload so we can read your holdings out of them. These can carry your name, CHN, account number, and positions. The file itself is held in memory only for as long as it takes to read it; we do not save the file. The rows we read from it appear in a preview you can edit, and only what you confirm is saved to your account. If you try the import before signing up, the preview rows are kept for about an hour so you can claim them after sign-up, then discarded.
- AI chat history — messages you send to Vantis (and the replies) are stored with your account and may be reviewed by us to debug answer quality and to detect abuse of the AI surfaces.
- Usage analytics — anonymous page views, button clicks, and feature usage via PostHog. Used to understand which surfaces are valuable and which are confusing. You can opt out via the cookie banner.
- Error logs — when something crashes, we capture the error message, stack trace, browser version, and the URL of the page that failed via Sentry and an in-app log table. We deliberately do not capture page contents or form fields.
- Operational signals — IP address, request method, and route are temporarily logged by our hosting provider (Railway) for rate-limiting and abuse detection.
Why we collect it
- Operate the service you signed up for.
- Debug crashes and performance issues.
- Understand product usage so we can prioritise what to build.
- Protect the platform from abuse and bots.
- Notify you about features, alerts you set up, and account changes.
Third parties we use
We process your data on infrastructure provided by the vendors below. Each vendor has its own privacy policy that we reviewed before integrating. We picked vendors with a track record of respecting end-user privacy.
- Clerk — authentication, session management, and account email. Stores your password hash and login history.
- Railway — application hosting, database, and cache. Servers run in the US-West (SFO) region. Your account and portfolio data therefore leave Nigeria and are stored in the United States; see Data residency below.
- Resend — transactional email. Sends the emails you asked for (price alerts, the Daily Close, account notices) to the address on your account. Receives your email address and the message body; nothing else.
- PostHog — product analytics. Stores page views and aggregated usage. Opt-out available via the cookie banner.
- Sentry — error and performance monitoring. Stores stack traces and error metadata; we scrub URL query parameters before forwarding.
- Better Stack — uptime monitoring. Pings our public health endpoint every few minutes; does not handle any operator data.
- LogSnag — operational notifications. Receives signup events and service alerts so we can respond to incidents quickly.
- Market data providers — third-party feeds we pull prices, fundamentals, and corporate actions from. We send no operator-identifying data; only ticker symbols and date ranges for the data we fetch.
- AI inference provider — powers AI features like “Ask Vantis”, the Vantis chat, and statement import. Your prompts are forwarded to a third-party inference provider for processing. When you import a statement or a screenshot, the image or text of that document is sent to the same provider so it can read the holdings out of it; that can include your name, CHN, and positions. We keep nothing of the document beyond the call — only the token count and the model used are logged for cost tracking.
- Cloudflare — off-site database backups. A nightly copy of the database is written to a private, access-controlled bucket, encrypted at rest, and kept for disaster recovery only.
Cookies
We use a small number of cookies, all classified as either essential or analytics.
Essential
Cookies set by Clerk to keep you signed in, and short-lived anti-CSRF tokens set by our middleware. These cannot be disabled without breaking the product.
Analytics
Cookies set by PostHog to attribute usage events to the same anonymous visitor across pages. These can be disabled from the cookie banner shown on your first visit, or by clicking “Essential only” at any time. We do not use marketing or third-party advertising cookies.
Data retention
Operator inputs (positions, journals, alerts) are retained for as long as your account is active. Deleting your account removes them from the live database immediately; copies roll out of our database backups within about 60 days. Analytics and error data are retained per the vendor defaults (PostHog: 7 years for events, 30 days for session replay where enabled; Sentry: 90 days). We can shorten retention on request.
Your rights
- Access — request a copy of the data we hold on your account.
- Correction — update or correct inaccurate data directly in the product or by emailing us.
- Deletion — delete your account yourself from Settings → Danger zone. Confirming there removes your portfolios, transactions, alerts, notes, chat history, and the login itself in one step. The same page lets you download everything as CSV first. If you would rather we do it, email [email protected] and we'll process the request within 14 days.
- Analytics opt-out — click “Essential only” on the cookie banner, or clear the
vantis.consent.analyticskey from your browser's localStorage to see the banner again.
Data residency
Our servers and managed dependencies (Railway, Clerk, PostHog, Resend, the AI inference provider) are hosted in the United States; Sentry error data is stored in the EU. Using Vantis from Nigeria means your personal data is transferred out of Nigeria and processed in those countries. Under the Nigeria Data Protection Act 2023 we rely on your consent, given when you sign up and accept this policy, as the basis for that transfer. You can withdraw it at any time by deleting your account. We will document a path for in-region hosting once a credible African option becomes available.
Children
Vantis Terminal is not directed at children under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, email us and we will delete the account.
Changes to this policy
Material changes will be announced to registered operators via email at least 30 days in advance of the effective date. Non-material edits (spelling, clarification) are made silently and reflected in the effective date above.
Contact
Privacy questions, data subject requests, or anything you think we missed — [email protected].