Legal

Privacy Policy

How Aruan Research Limited collects, uses and protects personal data, and the rights you have over it under Nigerian, European, UK and US state law.

Version 2.1
Effective 1 September 2026
Supersedes 1.4, 12 March 2026

01

Who we are

Aruan Research Limited, Lagos, Nigeria, is the data controller for personal data processed through this service. For the purposes of the UK GDPR and EU GDPR we have appointed a representative; contact details are in section 12. Our data protection officer can be reached at [email protected].

02

What we collect

  • Account data — name, email, sex, stated knowledge level, password hash.
  • Usage data — tickers analysed, assumptions set, tabs opened, exports produced.
  • Conversation data — questions put to the AI analyst and the replies returned.
  • Technical data — IP address, device and browser, session timestamps.
  • Billing data — plan, transaction references. Card details are handled by our payment processor and never reach our servers.

03

Why we process it

We process account and billing data to perform our contract with you; usage and technical data on the basis of our legitimate interests in securing, operating and improving the service; and any optional marketing on the basis of your consent, which you may withdraw at any time. Where we rely on legitimate interests we have assessed that they are not overridden by your rights, and you may object as described in section 8.

04

AI processing

Questions you put to the AI analyst, together with the quantitative output of the model you are viewing, are sent to a third-party large language model provider to generate a reply. We do not send your name, email or billing details. Our provider is contractually prohibited from using this content to train its models, and retains it only transiently for abuse monitoring.

No automated decision producing a legal or similarly significant effect on you is made through the service.

05

Who we share it with

We share personal data with processors acting on our instructions: cloud hosting, market-data providers, our large language model provider, our payment processor, our email provider, and error and analytics tooling. We do not sell personal data, and we do not share it for cross-context behavioural advertising. We may disclose data where required by law or to establish or defend legal claims.

06

International transfers

We are established in Nigeria and use suppliers in the European Economic Area, the United Kingdom and the United States. Transfers out of the EEA and UK are made under the European Commission’s standard contractual clauses and the UK addendum, supplemented where necessary by additional technical measures. Transfers under the Nigeria Data Protection Act are made to jurisdictions we have assessed as providing adequate protection, or on the basis of your consent.

07

How long we keep it

Account data is kept while your account is open and for 24 months after closure. Conversation data is kept for 12 months. Billing records are kept for 6 years to meet tax and accounting obligations. Technical logs are kept for 90 days. Where we no longer need data we delete or irreversibly anonymise it.

08

Your rights

Subject to the law that applies to you, you may request access to your personal data, correction, deletion, restriction or portability; object to processing based on legitimate interests; and withdraw consent. Residents of California, Colorado, Connecticut, Virginia and other US states with comprehensive privacy laws may additionally opt out of sale or sharing, request a list of categories disclosed, and appeal a refused request.

Write to [email protected]. We respond within 30 days, or one month where the GDPR applies, and we will not treat you differently for exercising a right.

09

Cookies

We set strictly necessary cookies for authentication, session integrity and security. We do not use advertising cookies. Where analytics cookies are used in the EEA or UK they are set only with your consent, which you may change at any time through the cookie settings link in the footer.

10

Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, one-time-password verification at registration, rate limiting and brute-force detection on authentication, least-privilege access for staff, and logging of administrative actions. No system is perfectly secure, and we will notify you and the relevant authority of a qualifying breach within the periods the applicable law requires.

11

Children

The service is not directed to anyone under 18 and we do not knowingly collect their personal data. If you believe a minor has registered, contact [email protected] and we will delete the account.

12

Complaints

If you are dissatisfied with how we have handled your personal data, please contact our data protection officer first. You also have the right to complain to the Nigeria Data Protection Commission, to the Information Commissioner’s Office in the United Kingdom, or to the supervisory authority of your EU member state of residence.