← Back to legal

Privacy Policy

Privacy Policy for Illuminum AB

Controller: Illuminum AB · org.nr 559359-4343 · VAT SE559359434301 · Västra Ågatan 22, 753 09 Uppsala, Sweden

Effective date: 23 August 2026 Version: 2026-08-23.1

This is the company-level policy for Illuminum AB, the controller behind both Quant and Gaia (each, a "Service"; together, the "Services"). It distils what the two products' own privacy policies had in common — who we are, your rights, how long we keep things, who else sees your data — into one place, and then states plainly, product by product, what each Service actually stores. Each product's own Terms of Service still governs your use of that product and is the more specific document where the two ever appear to differ; write to us and we will correct whichever text is wrong.

1. Who we are and how to reach us

Illuminum AB is the controller of the personal data processed through Quant and Gaia — the applications, websites and APIs that make up each Service. Contact: david.jirout@illuminum.se, or the postal address above. Where a Service offers a control for a right below (account deletion, profile edits), you may use it directly instead of writing to us.

2. What Quant collects, record by record

Quant stores what you do in it and what you say to it. The list below is complete.

  • Account and profile. Your user id from our identity provider (Auth0), name, email address and whether it is verified, profile picture URL, Stripe customer id, subscription status and end date, licence type, remaining and total analyses, time of creation, last update and last login; and everything you set in the Service — your My Strategy text, your news/URL sources, your recorded portfolio, your time zone, number format, decimal count, portfolio currency and trade-strategy risk ratio; and, if you have reached the plan-selection screen, the version and time of your acknowledgement that immediate supply forfeits the 14-day right of withdrawal.
  • Logins. For every sign-in: the session id, creation, last-seen, expiry and revocation times, your IP address, the country, region and city derived from it and the method that derived it, and your browser, browser version, operating system, OS version and device type (mobile/desktop).
  • Analyses requested. For every analysis you start by accepting the in-app notice: the instrument, candle period, trading zone and city, how it was started, the time you started it, and the version of the notice you accepted and when you accepted it. Sessions opened only because you asked the AI Chat a question carry no notice version.
  • Analysis results. Every verdict you produce or save, with every field of the result: action, bias, score, the legacy confidence number, entry, take-profit, stop-loss, ratio, every indicator value, pattern, sentiment, bar count, unit, horizon, instrument type, cycle read, the signal mix you had enabled, how and when it was saved and any label you gave it.
  • Allowance. The time and licence under which each metered analysis was charged.
  • AI Chat. Every question you type and every answer the model returns, verbatim, with its sequence, time and the analysis it belongs to.
  • Your notes. Every note and decision you record, with the instrument, period, analysis and the times of creation and update.
  • Recorded trades. Every trade you record: instrument, side, units, price, unit/currency, trade date, period and source — and the holdings projected from them.
  • Favourites. Every time you star or unstar an instrument, with the instrument's name, type and currency.

Most of these records also carry your name and email address beside your user id, so that they remain attributable if the identity record is later removed.

Payment card data never reaches us. It is entered on, and held by, Stripe. Market data is not personal data and is not stored against you: price bars are cached per server instance and never joined to your account.

3. What Gaia collects, record by record

Gaia stores your account and session details together with what you search for. The list below is complete.

  • Account and session record. For each session: the time of that session; your user id from our identity provider (Auth0), Stripe customer id, name and email; your account type, organisation type and name, industry and role, where you told us them; your country and city; your language of preference; your subscription plan; your total free-searches count and your sessions count; and, for that session, your device type (mobile/desktop), operating system and browser. Unlike Quant, Gaia does not store your IP address itself — only the country and city resolved from it.
  • Nature-data searches. For each search: the phrase you searched for; a taxonomic scope, where one was given; the language, account/organisation context and country recorded with it as in your account record; the geographic area you searched, as a drawn polygon and as a named area of interest; the date range you searched over (start and end date); a relationship value recorded with the search; and the number of observation results you received.
  • Image searches. For each search: the phrase and taxonomic scope searched for, the same account/organisation/country context, a relationship value, and the number of images you received.
  • Map-layer searches. For each search: the phrase searched for, the same account/organisation/country context, and the number of services you received.
  • Relationship searches. For each search: the phrase and taxonomic scope searched for, the same account/organisation/country context, a relationship value, and the number of relationships you received — this is what we describe elsewhere as Gaia storing "relationships."
  • A search left in progress. Keyed to your account: which module you were using, the query text, its parameters and the map viewport, so a search can resume where you left it.
  • Cached search results. Keyed to your account: which module, and the results themselves, stored as an encoded payload, so a repeat view does not re-run the search.

4. Session, login and device data — the common pattern across both Services

Both Services record, in the records above, when a session or search session starts; that a sign-in occurred, including where it was made through a social login connection via our identity provider, Auth0; the type of device used (mobile or desktop); the operating system; and the city and country resolved from the visitor's IP address at the time. This is the same underlying pattern in both products even though the two databases hold it in differently-shaped tables — a single login records row per login for Quant, a session/profile row per event for Gaia.

5. What the AI Chat receives (Quant only)

When you ask Quant's AI Chat a question, the following is sent to Anthropic (our model provider) to generate the answer: your question and the earlier turns of the same conversation; the analysis on screen as computed under your Trade Settings — verdict, score, levels and every signal's current reading — and the instrument's recent price history; and, where you have saved it, your My Strategy text. Your Trade Settings themselves (the ATR preset, which signals are enabled) are not sent, only the analysis computed under them; your news sources are not sent; and your recorded holdings and transactions are not sent — the Chat is told only, where an EXIT stop message is shown, that a recorded holding exists, and it is instructed not to compute or discuss what any level would realise for you. Your name and email are not sent with the question. Anthropic processes this on our instruction as a processor; we do not use Anthropic's consumer products for it. Gaia has no equivalent chat feature.

6. Why we process it, and on what legal basis

Purpose Records Service Basis (GDPR art. 6(1))
Operating the Service you asked for — sign-in, your settings, your analyses/searches, reopening your own history Quant: account and profile, analysis requests, analysis results, notes, recorded trades, favourites, AI Chat transcripts. Gaia: login records, nature-data searches, image searches, map-layer searches, relationship searches, searches in progress, cached results Both (b) contract
Metering and billing the plan Quant: account and profile (allowance counters, Stripe id), allowance records. Gaia: login records (free-searches and sessions counts, Stripe id, subscription) Both (b) contract
Keeping a record of the risk/no-advice notice you accepted, and of what Quant showed you analysis requests (notice version, time), analysis results Quant (f) legitimate interest — evidencing what was shown and accepted, which also protects you against a notice being changed after the fact
Securing accounts and the Service, including any sanctions or jurisdiction check at sign-in Quant: login records (IP, geo, device). Gaia: login records (country, city, device) Both (f) legitimate interest; (c) legal obligation where a sanctions/eligibility check applies
Measuring the engine or search results in aggregate Quant: analysis results. Gaia: the result counts recorded with each search Both (f) legitimate interest — figures computed across users, never reported per person. Quant's Chat transcripts are not used for this.
Complying with law, and establishing, exercising or defending legal claims Any of the above Both (c) and (f)

We do not use your data for advertising, profiling with legal effect, or automated decisions about you other than each Service's own metering. We do not sell it.

7. Who receives it

  • Auth0 (Okta) — identity and login for both Services.
  • Stripe — subscriptions and payment for both Services; holds card data we never see.
  • MotherDuck — operates the databases in which every record above is stored (see Section 8 on where that data is held).
  • Anthropic — receives Quant's AI Chat context in Section 5 to generate each answer. Not used by Gaia.
  • Google Cloud — hosts both Services and their logs.
  • An IP-geolocation lookup service — receives your IP address at sign-in to derive country, region and city. Quant uses ipinfo.io for this.
  • Market-data providers (Alpha Vantage, Twelve Data, Yahoo Finance) — receive the instrument symbol Quant requests, never your identity.

Some of these providers are in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.

8. Where your data is stored

Both Services — Quant and Gaia — run on Google Cloud in the European Union (region europe-west1, Belgium), and the logs they write stay there. Your authentication data — the account record our identity provider, Auth0, keeps for your login — is stored within the EU. The records listed in Sections 2 and 3, however, are stored in databases operated for us by MotherDuck, a third-party provider, and we do not control the country or region in which MotherDuck holds them. We therefore cannot guarantee that this data is stored within the EU or the EEA. Where it is held or accessed outside the EEA, the transfer rests on the safeguards in Section 7 — the EU–US Data Privacy Framework where the provider is certified, otherwise Standard Contractual Clauses — and you may ask us, at the address in Section 1, which applies at any given time. Card data is held by Stripe under its own arrangements and never reaches us.

9. How long we keep it

Until you delete your account. Neither Service runs a routine that expires, thins out or archives stored records on its own — every record above is kept for as long as your account exists, because reopening an old analysis, journal entry or search is a feature, not a bug. Erasing it is in your hands.

  • Deleting your Quant account cancels any running Stripe subscription with immediate effect first; then deletes every row in every table in Section 2 keyed to your user id, checked against the database's own catalogue; then deletes your Auth0 identity — in that order, so a failure at any step leaves your login in place to try again rather than an account that has gone while its data or its subscription has not. Your Stripe customer record and invoices are not deleted by us; Stripe holds them as billing records for as long as Swedish accounting law requires.
  • Deleting your Gaia account is done on request to the address in Section 1; we remove every record in Section 3 keyed to your account and confirm to you when it is done.

10. Your rights

Under the GDPR you may ask us for access to your data, for correction, for erasure, for restriction, for a portable copy, and you may object to processing based on our legitimate interests. Erasure is available from within Quant (account deletion). For anything else, or for a Gaia account, write to us at the address in Section 1; we answer within one month. You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or to the supervisory authority of your own EU country.

11. Children

Neither Service is directed at anyone under 18, and we do not knowingly hold data about them.

12. Changes

We will post any change here with a new version and effective date. A change that narrows your rights or widens what we collect takes effect only after notice within the relevant Service.