Controller: Illuminum AB · org.nr 559359-4343 · VAT SE559359434301 · Västra Ågatan 22, 753 09 Uppsala, Sweden
Effective date: 23 August 2026 Version: 2026-08-23.1
This is the company-level policy for Illuminum AB, the controller behind both Quant and Gaia (each, a "Service"; together, the "Services"). It distils what the two products' own privacy policies had in common — who we are, your rights, how long we keep things, who else sees your data — into one place, and then states plainly, product by product, what each Service actually stores. Each product's own Terms of Service still governs your use of that product and is the more specific document where the two ever appear to differ; write to us and we will correct whichever text is wrong.
Illuminum AB is the controller of the personal data processed through Quant and Gaia — the applications, websites and APIs that make up each Service. Contact: david.jirout@illuminum.se, or the postal address above. Where a Service offers a control for a right below (account deletion, profile edits), you may use it directly instead of writing to us.
Quant stores what you do in it and what you say to it. The list below is complete.
Most of these records also carry your name and email address beside your user id, so that they remain attributable if the identity record is later removed.
Payment card data never reaches us. It is entered on, and held by, Stripe. Market data is not personal data and is not stored against you: price bars are cached per server instance and never joined to your account.
Gaia stores your account and session details together with what you search for. The list below is complete.
Both Services record, in the records above, when a session or search session starts; that a sign-in occurred, including where it was made through a social login connection via our identity provider, Auth0; the type of device used (mobile or desktop); the operating system; and the city and country resolved from the visitor's IP address at the time. This is the same underlying pattern in both products even though the two databases hold it in differently-shaped tables — a single login records row per login for Quant, a session/profile row per event for Gaia.
When you ask Quant's AI Chat a question, the following is sent to Anthropic (our model provider) to generate the answer: your question and the earlier turns of the same conversation; the analysis on screen as computed under your Trade Settings — verdict, score, levels and every signal's current reading — and the instrument's recent price history; and, where you have saved it, your My Strategy text. Your Trade Settings themselves (the ATR preset, which signals are enabled) are not sent, only the analysis computed under them; your news sources are not sent; and your recorded holdings and transactions are not sent — the Chat is told only, where an EXIT stop message is shown, that a recorded holding exists, and it is instructed not to compute or discuss what any level would realise for you. Your name and email are not sent with the question. Anthropic processes this on our instruction as a processor; we do not use Anthropic's consumer products for it. Gaia has no equivalent chat feature.
| Purpose | Records | Service | Basis (GDPR art. 6(1)) |
|---|---|---|---|
| Operating the Service you asked for — sign-in, your settings, your analyses/searches, reopening your own history | Quant: account and profile, analysis requests, analysis results, notes, recorded trades, favourites, AI Chat transcripts. Gaia: login records, nature-data searches, image searches, map-layer searches, relationship searches, searches in progress, cached results | Both | (b) contract |
| Metering and billing the plan | Quant: account and profile (allowance counters, Stripe id), allowance records. Gaia: login records (free-searches and sessions counts, Stripe id, subscription) | Both | (b) contract |
| Keeping a record of the risk/no-advice notice you accepted, and of what Quant showed you | analysis requests (notice version, time), analysis results | Quant | (f) legitimate interest — evidencing what was shown and accepted, which also protects you against a notice being changed after the fact |
| Securing accounts and the Service, including any sanctions or jurisdiction check at sign-in | Quant: login records (IP, geo, device). Gaia: login records (country, city, device) | Both | (f) legitimate interest; (c) legal obligation where a sanctions/eligibility check applies |
| Measuring the engine or search results in aggregate | Quant: analysis results. Gaia: the result counts recorded with each search | Both | (f) legitimate interest — figures computed across users, never reported per person. Quant's Chat transcripts are not used for this. |
| Complying with law, and establishing, exercising or defending legal claims | Any of the above | Both | (c) and (f) |
We do not use your data for advertising, profiling with legal effect, or automated decisions about you other than each Service's own metering. We do not sell it.
Some of these providers are in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.
Both Services — Quant and Gaia — run on Google Cloud in the European Union (region europe-west1, Belgium), and the logs they write stay there. Your authentication data — the account record our identity provider, Auth0, keeps for your login — is stored within the EU. The records listed in Sections 2 and 3, however, are stored in databases operated for us by MotherDuck, a third-party provider, and we do not control the country or region in which MotherDuck holds them. We therefore cannot guarantee that this data is stored within the EU or the EEA. Where it is held or accessed outside the EEA, the transfer rests on the safeguards in Section 7 — the EU–US Data Privacy Framework where the provider is certified, otherwise Standard Contractual Clauses — and you may ask us, at the address in Section 1, which applies at any given time. Card data is held by Stripe under its own arrangements and never reaches us.
Until you delete your account. Neither Service runs a routine that expires, thins out or archives stored records on its own — every record above is kept for as long as your account exists, because reopening an old analysis, journal entry or search is a feature, not a bug. Erasing it is in your hands.
Under the GDPR you may ask us for access to your data, for correction, for erasure, for restriction, for a portable copy, and you may object to processing based on our legitimate interests. Erasure is available from within Quant (account deletion). For anything else, or for a Gaia account, write to us at the address in Section 1; we answer within one month. You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or to the supervisory authority of your own EU country.
Neither Service is directed at anyone under 18, and we do not knowingly hold data about them.
We will post any change here with a new version and effective date. A change that narrows your rights or widens what we collect takes effect only after notice within the relevant Service.