Privacy Policy
Last updated: July 5, 2026
Open Market Terminal ("we", "the service") is a market research and education tool. This policy explains what we collect, why, and what stays on your device.
1. What we collect
- Account data — email address, display name, and (for email accounts) a salted PBKDF2-SHA256 password hash. We never store plaintext passwords.
- Sign-in identity — if you sign in with Google or GitHub, we receive only your verified email address and display name from that provider. We do not receive or store their passwords or tokens beyond the sign-in exchange.
- Workspace preferences — watchlist symbols, panel layout, theme, language, and accent color, synced to your account so they follow you across devices.
- Support & feedback messages — messages you send through the in-app support widget, kept so we can follow up.
- Technical data — your IP address is used in memory for rate limiting and abuse prevention; server logs record requests for operations. A single HttpOnly session cookie keeps you signed in. We use no advertising or tracking cookies and no third-party analytics.
2. What stays on your device
- Custom AI modules — modules you build are stored only in your browser's localStorage and run sandboxed in your browser. Their code is never uploaded to or stored on our servers.
- Your own API keys — if you add a personal OpenRouter key, it is kept in your browser. It is transmitted with each AI request so we can proxy the call, but it is never written to our database or logs.
- Guest settings (theme, language, watchlist before signing in) also live only in your browser.
3. Third-party processors
- OpenRouter — AI features send the market-data snapshot and your request text to OpenRouter (and through it, the model providers) to generate a response.
- Stripe — paid subscriptions are processed by Stripe Checkout. Card details never touch our servers.
- Google / GitHub — optional sign-in, as described above.
- Market data providers — price and news requests are made server-side; your identity is not attached to them.
4. Retention & deletion
Account data is kept while your account exists. To delete your account and its data, contact us through the in-app support widget and we will remove it within 30 days. Backups roll off automatically on a short cycle.
5. Security
All traffic is served over HTTPS. Passwords are salted and hashed (PBKDF2-SHA256), session cookies are HttpOnly and Secure, and admin access is restricted. No system is perfectly secure; use a unique password.
6. Children
The service is not directed to anyone under 18 and we do not knowingly collect data from minors.
7. Changes
We may update this policy; material changes will be reflected by the date above. Continued use after a change means you accept the updated policy.
8. Contact
Questions or requests: use the in-app support widget (bottom-right of the terminal).