QVL Models

Privacy Policy

QVL Models, Inc. (“QVL Models,” “QVL,” “we,” “us,” or “our”) respects your privacy and is committed to handling personal information responsibly.

This Privacy Policy explains how we collect, use, disclose, protect, retain, and otherwise process personal information when you use QVL websites, web applications, mobile applications, QVL Models, QVL Education, QVL Copilot, portfolio tools, brokerage-connected features, backtesting, analytics, and other products and services that link to this Privacy Policy (collectively, the “Services”).

QVL Models operates a technology platform that provides proprietary market intelligence, market-specific trading models, portfolio tools, education, analytics, research, backtesting, and AI-assisted functionality. QVL’s proprietary volatility-intelligence engine powers multiple retail-facing models and related tools available through the Services.

This Privacy Policy does not replace the privacy policies of third parties such as your broker, bank, payment processor, device provider, or financial-account connection provider.

1. Personal Information We Collect

The information we collect depends on the Services you use and the features you choose to enable.

Account and Profile Information

When you create or maintain a QVL account, we may collect information such as:

  • name;
  • email address;
  • telephone number, if provided;
  • country or region;
  • display name;
  • time zone;
  • language or locale preferences;
  • account creation date;
  • account status;
  • subscription and model-access information;
  • notification preferences; and
  • other information you choose to provide through your profile.

Passwords are protected using cryptographic password hashing. QVL does not store your password in readable form.

Identity, Eligibility, and Onboarding Information

Depending on the Services you use, we may collect or process information relating to:

  • email verification;
  • identity-verification status;
  • country or jurisdiction;
  • onboarding status;
  • QVL account approval status;
  • eligibility or regulatory attestations;
  • accreditation or investor-status information, where applicable;
  • acceptance of legal agreements, disclosures, or risk acknowledgements; and
  • related verification records.

Where a third-party provider performs verification, that provider may collect additional information directly from you under its own privacy policy. QVL may receive verification results, status information, and information needed to complete onboarding. Identity verification through Plaid is described in Section 7.

Authentication and Security Information

We collect information necessary to authenticate users and protect QVL accounts and systems, including:

  • login and logout activity;
  • account sessions;
  • IP addresses;
  • browser and device information;
  • user-agent information;
  • failed authentication attempts;
  • security and fraud signals;
  • multi-factor authentication activity;
  • registered authentication devices;
  • device or installation identifiers; and
  • authentication-method status.

Connected Brokerage and Investment Account Information

If you choose to connect a brokerage or investment account, QVL may receive and process information made available through the connection provider, which may include:

  • brokerage or financial-institution name;
  • provider and account identifiers;
  • connection status;
  • authorization status;
  • account type or subtype;
  • account name or mask;
  • account currency;
  • holdings and positions;
  • quantities;
  • cost basis;
  • market values;
  • cash balances;
  • buying power;
  • transaction or activity history;
  • order and fill information;
  • account and position metadata;
  • synchronization timestamps;
  • data-freshness information; and
  • provider-issued access credentials or tokens necessary to maintain the connection.

The information available to QVL depends on the provider, financial institution, account type, and permissions you authorize.

QVL currently uses providers including Plaid and SnapTrade for supported connected-account functionality.

QVL Model, Portfolio, and Trading Information

When you use QVL Models or portfolio features, we may collect or generate information such as:

  • model subscriptions;
  • models selected or followed;
  • signals delivered to your account;
  • model configuration;
  • allocation settings;
  • paper-portfolio information;
  • live-portfolio configuration;
  • modeled trades;
  • staged trades;
  • user trade approvals;
  • order status;
  • execution information;
  • fills;
  • trade history;
  • strategy activity;
  • portfolio activity;
  • net asset value and performance history;
  • risk metrics;
  • portfolio exposure;
  • benchmark comparisons;
  • reconciliation information;
  • signal alerts; and
  • related analytics.

QVL distinguishes between data generated within the QVL platform and data received from external brokerage or investment accounts.

QVL Education Information

When you use QVL Education, we may collect information such as:

  • enrollment status;
  • lesson activity;
  • progress;
  • completed lessons or tasks;
  • quiz or assessment activity;
  • educational preferences; and
  • education-related notification settings.

Backtesting and Strategy Information

When you use QVL backtesting or strategy-development tools, we may process:

  • strategy specifications;
  • market symbols;
  • parameters and assumptions;
  • backtest requests;
  • generated reports;
  • backtest results;
  • performance metrics;
  • benchmark comparisons;
  • cost assumptions;
  • research parameters; and
  • related Copilot conversations where Copilot is used to help construct or explain a backtest.

Billing and Subscription Information

QVL uses third-party payment providers, including Stripe, to process subscription payments.

Payment-card information is entered through Stripe or another applicable payment provider.

QVL does not store your full payment-card number or card security code.

QVL may receive and retain information such as:

  • payment-provider customer identifier;
  • subscription identifier;
  • checkout-session identifier;
  • plan or product purchased;
  • billing status;
  • billing currency;
  • payment status;
  • invoice information; and
  • limited payment-method information supplied by the payment provider.

QVL Copilot Information

When you use QVL Copilot, we may process information including:

  • questions or instructions you submit;
  • Copilot responses;
  • saved conversation history;
  • conversation identifiers;
  • feedback;
  • model or token-usage information;
  • QVL tools used to produce a response;
  • market or research information used to answer your question;
  • permitted QVL model or portfolio context; and
  • redacted operational information used for security, reliability, troubleshooting, and quality monitoring.

More information about QVL Copilot appears in Section 5.

Voice Information

Where QVL Copilot voice functionality is available and you choose to use it, audio may be processed to:

  • recognize or transcribe speech;
  • understand your request;
  • generate a response; and
  • provide synthesized voice output.

Availability of voice features may vary by platform, account, or product release.

Device and Notification Information

If you use QVL mobile applications or enable notifications, we may process:

  • push-notification tokens;
  • device platform;
  • installation identifiers;
  • notification preferences;
  • notification-delivery status;
  • whether a device is authorized for sign-in approval; and
  • information necessary to deliver signal, trade, education, security, account, or Copilot notifications.

Support and Communications

If you contact QVL, we may retain information contained in:

  • support requests;
  • emails;
  • complaints;
  • feedback;
  • account inquiries; and
  • other communications with QVL.

Technical, Security, and Usage Information

We may collect technical and operational information necessary to operate and protect the Services, including:

  • service activity;
  • API requests;
  • timestamps;
  • error information;
  • security events;
  • system-performance information;
  • feature usage;
  • diagnostic information; and
  • audit records.

QVL applies privacy and security controls designed to reduce unnecessary exposure of sensitive financial information in logs and monitoring systems.

2. How We Use Personal Information

We use personal information for purposes including:

  • creating and managing QVL accounts;
  • authenticating users;
  • protecting accounts and systems;
  • verifying identity and eligibility;
  • completing onboarding;
  • providing QVL Models and model subscriptions;
  • delivering model signals, commentary, and notifications;
  • maintaining paper portfolios;
  • maintaining live portfolio functionality;
  • connecting and synchronizing authorized brokerage or investment accounts;
  • displaying holdings and portfolio information;
  • calculating portfolio values, performance, exposure, and risk;
  • staging and processing user-approved transactions;
  • maintaining trade and order history;
  • providing market-data and research tools;
  • providing backtesting;
  • providing QVL Education;
  • providing QVL Copilot;
  • maintaining saved Copilot conversations;
  • providing optional Copilot Memory functionality where enabled;
  • processing subscriptions and payments;
  • providing customer support;
  • sending service-related communications;
  • detecting and preventing fraud, abuse, and unauthorized access;
  • monitoring service reliability and security;
  • investigating errors and incidents;
  • maintaining audit and compliance records;
  • administering QVL subscriptions and accounts;
  • enforcing QVL agreements and platform rules;
  • complying with applicable legal and regulatory requirements; and
  • protecting QVL, our users, and others.

We may also use aggregated, anonymized, or de-identified information for analytics, research, service improvement, and business planning where permitted by law.

3. Connected Brokerage and Investment Accounts

Financial-account information is particularly sensitive, and QVL applies additional controls to connected-account data.

Broker Authentication

When you connect a supported brokerage or investment account, authentication takes place through the financial institution or connection provider.

QVL does not receive or store your brokerage password.

Instead, QVL may receive a provider-issued access credential or token that allows the Services to perform the activities you authorized.

Plaid

Plaid may be used for supported read-only financial or investment-account functionality.

Depending on the applicable connection, QVL may receive information such as holdings, balances, account information, and transaction history.

QVL does not use a Plaid read-only connection to place brokerage orders.

SnapTrade

SnapTrade may be used for supported brokerage connections that permit portfolio synchronization and, where available, trade-capable functionality.

Capabilities vary depending on the brokerage, account, jurisdiction, and permissions available through SnapTrade.

No Custody or General Withdrawal Authority

Connecting a financial account to QVL does not give QVL custody of your assets.

QVL does not obtain general authority through the connection to withdraw or transfer money out of your brokerage account.

Live Orders Require User Approval

A QVL signal, modeled trade, QVL Copilot response, portfolio calculation, alert, or background process does not by itself authorize a live brokerage order.

QVL is designed so that a live brokerage order requires the applicable explicit user approval before submission.

Broker Is the Source of Truth

Your brokerage or financial institution remains the authoritative source for actual:

  • balances;
  • holdings;
  • cash;
  • orders;
  • fills; and
  • account activity.

QVL information may occasionally differ temporarily because of synchronization timing, external trades, market-data timing, or provider availability.

4. How We Protect Sensitive Financial Information

QVL uses technical, administrative, and organizational safeguards designed to protect personal information based on its sensitivity.

These safeguards include, where appropriate:

  • encryption in transit;
  • encryption of sensitive information at rest;
  • protected encryption-key management;
  • authentication controls;
  • authorization and access controls;
  • service-to-service authentication;
  • monitoring;
  • security logging;
  • audit logging;
  • restricted administrative access;
  • privacy-aware log filtering and redaction; and
  • additional controls for sensitive connected-account information.

Sensitive financial information may be decrypted within authorized QVL systems when necessary to provide a feature you requested, for example:

  • displaying your portfolio;
  • synchronizing holdings;
  • calculating analytics;
  • calculating risk;
  • processing an approved brokerage order; or
  • providing relevant live-portfolio context to QVL Copilot where that use is authorized.

QVL’s ordinary internal administration and customer-support tools are designed to limit access to raw sensitive brokerage information where that information is not necessary for the staff function being performed.

No system of electronic transmission or storage can guarantee absolute security.

5. QVL Copilot and Artificial Intelligence

QVL Copilot is an AI-assisted feature that helps users work with market information, QVL products, portfolio analytics, education, research, backtesting, and other supported functionality.

Information Copilot May Process

Depending on the request and your permissions, QVL Copilot may process:

  • your message;
  • relevant conversation history;
  • QVL model information;
  • market information;
  • public information;
  • QVL educational information;
  • QVL product information;
  • backtesting information;
  • paper-portfolio information; and
  • authorized live-portfolio information.

Live Portfolio Information

Copilot does not receive unrestricted access to all of your connected financial information simply because an account is connected.

Where live portfolio information requires a permission or consent control, QVL checks the applicable authorization before using that information in Copilot.

Where authorized, QVL is designed to provide only information reasonably necessary for the requested task.

Depending on your request, this may include selected information such as:

  • positions;
  • quantities;
  • market values;
  • cost basis;
  • unrealized gains or losses;
  • portfolio allocations;
  • balances;
  • cash; or
  • buying power.

QVL does not provide Copilot with your brokerage password.

AI Service Providers

QVL currently uses Microsoft Azure AI infrastructure, including Microsoft Foundry and related Azure AI services, to support QVL Copilot.

Information processed through these services is subject to QVL’s arrangements with those providers and their applicable enterprise privacy and security terms.

QVL does not intentionally use customer brokerage passwords, provider access credentials, or full brokerage account identifiers as general-purpose AI training data.

Saved Copilot Chats

QVL may save Copilot conversations so that you can access conversation history across supported QVL platforms.

Saved chat history may include:

  • your visible messages;
  • Copilot’s visible responses; and
  • visible result cards, tables, charts, or backtest results associated with the conversation.

Where supported, users may delete saved Copilot chats.

Deleting a saved chat may not immediately remove separate security, audit, de-identified, or redacted operational records that QVL is required or permitted to retain.

Copilot Memory

Where QVL Copilot Memory is enabled, QVL may retain selected information between conversations to make future interactions more useful.

Memory is intended for information such as:

  • user preferences;
  • preferred benchmarks;
  • preferred response style;
  • recurring research preferences; or
  • similar user-specific settings.

QVL’s Memory controls are designed not to intentionally retain the following as persistent preference memories:

  • passwords;
  • authentication secrets;
  • provider access tokens;
  • brokerage account numbers;
  • live account balances; or
  • brokerage holdings.

Where available, QVL may provide controls to review, edit, disable, or delete Copilot Memory.

Memory is distinct from saved chat history.

Operational and Quality Information

QVL may retain limited or redacted Copilot operational information for purposes such as:

  • service reliability;
  • debugging;
  • abuse prevention;
  • security;
  • quality monitoring;
  • investigation of incidents; and
  • improvement of QVL Copilot.

Copilot Does Not Authorize Sensitive Actions

A Copilot response does not, by itself, authorize:

  • a live trade;
  • a transfer of assets;
  • an account-security change;
  • a brokerage-connection change;
  • a subscription purchase or cancellation; or
  • account deletion.

Sensitive actions remain subject to the applicable confirmation, authentication, and authorization controls.

6. Passkeys and Biometric Authentication

QVL may support authentication using passkeys based on WebAuthn.

Passkeys may use your device’s security system, including:

  • Face ID;
  • Touch ID;
  • fingerprint recognition;
  • Windows Hello; or
  • another local device-authentication method.

QVL does not receive or store the facial scan, fingerprint image, biometric template, or other biometric information used by your device to authenticate you.

QVL receives and stores cryptographic information needed to verify the passkey, which may include:

  • credential identifier;
  • public key;
  • signature counter;
  • supported transport information;
  • device type;
  • device label;
  • registration date; and
  • last-use information.

The biometric check itself occurs on your device or through your operating-system/passkey provider.

7. Identity Verification Using Plaid

Why QVL May Use Plaid Identity Verification

QVL may use Plaid Identity Verification (“Plaid IDV”) as part of its account verification process. Plaid is a third-party identity-verification service provider. QVL may use it to confirm that a person creating or using a QVL account is who they claim to be, and to help prevent identity fraud, impersonation, unauthorized account creation, and misuse of QVL accounts.

Plaid IDV is not necessarily available in every QVL product, region, or account type. When QVL’s Plaid Identity Verification process is enabled, you may be asked to complete identity verification through Plaid. Plaid IDV is separate from, and in addition to, Plaid’s connected-account functionality described in Section 3.

Separate Notice and Consent

Plaid IDV is performed with separate notice to you and your separate consent. Before identity verification begins, QVL will inform you that your identity information will be provided to and processed by Plaid for verification purposes. Your general acceptance of this Privacy Policy is not treated as your consent to Plaid IDV. If you do not consent, you may decline to proceed, although QVL may then be unable to provide features or account access that require identity verification.

Information Plaid May Collect or Process

Depending on the verification method and the workflow configured by QVL and Plaid, not every item below is collected in every case.

Identity information

Depending on the verification method, this may include:

  • legal name;
  • date of birth;
  • residential address;
  • telephone number;
  • email address;
  • government-issued identification information; and
  • national identification number or similar identity number, where applicable.

Government identity documents

Plaid may ask you to photograph or upload a government-issued identity document, such as a driver’s licence, passport, provincial or state identification card, or another supported government identity document. The document may contain your photograph, name, date of birth, address, document number, expiration date, and other information printed on or encoded in the document.

Selfie or short video (Selfie Check)

Plaid’s Selfie Check may capture a selfie image or, more commonly, a short video of your face. This is used to:

  • confirm that a real, live person is completing the verification;
  • prevent fraud;
  • compare your face with the photograph on the identity document you submitted, where document verification is used; and
  • perform other identity-verification and fraud-prevention checks enabled for the workflow.

Facial and Biometric Information

Plaid may analyze facial features or facial geometry derived from the photograph on your identity document and from your selfie or video in order to perform identity matching, liveness detection, fraud prevention, and related verification checks. This information may be considered biometric information under applicable law. This analysis is performed by Plaid and its service providers, not by QVL.

Because selfie, video, and facial analysis may involve biometric information, QVL intends to give you a separate biometric notice and ask for your separate consent before this step begins.

Device Authentication vs. Identity Verification

QVL’s use of Face ID, Touch ID, fingerprint authentication, Windows Hello, or passkeys to sign in to QVL is separate from Plaid Identity Verification, and the two must not be confused.

For passkey and device authentication (Section 6):

  • the biometric check happens on your device or through your operating-system or passkey provider;
  • QVL does not receive or store your Face ID image, fingerprint, or underlying device biometric template; and
  • QVL receives and verifies only the cryptographic (WebAuthn public-key) credential associated with your passkey.

For Plaid Identity Verification (this Section 7):

  • you may intentionally provide a selfie or short video to Plaid;
  • Plaid may perform liveness detection;
  • Plaid may compare your selfie or video with the photograph on your identity document; and
  • Plaid may process facial or biometric information for identity verification and fraud prevention.

These are separate processes. Plaid’s facial verification is not part of QVL’s passkey system.

Verification Results

Plaid may produce verification outputs such as:

  • verification status;
  • pass, fail, or review results;
  • document-verification results;
  • selfie and liveness results;
  • identity-match results;
  • fraud or risk indicators; and
  • related verification metadata.

QVL does not necessarily receive or store every raw field or output that Plaid generates.

What Plaid Processes

Plaid performs the identity-verification processing, including document checks, selfie and liveness checks, and facial matching. Plaid’s retention of information is separate from QVL’s. Plaid may retain and process information in accordance with its agreements with QVL, its applicable privacy disclosures, configured retention or redaction settings, and applicable law. You can review Plaid’s practices in Plaid’s privacy information at plaid.com/legal.

What QVL Intends to Retain

QVL’s intended production architecture is designed so that QVL does not retain the following in its own systems:

  • images of your government identity document;
  • selfie images or selfie videos;
  • facial geometry or biometric templates;
  • national identification numbers, including Social Security Numbers or Social Insurance Numbers where applicable; and
  • full raw Plaid Identity Verification responses.

QVL may retain limited information needed to operate and demonstrate the verification process, such as whether verification was completed, the verification status or outcome, a Plaid verification-session identifier, timestamps, a limited reason or status code, the number of verification attempts, and records of the notice and consent you were shown.

QVL retains verification-related information in accordance with its applicable retention requirements, legal obligations, security requirements, and approved records-retention practices, as further described in Section 13.

Your Privacy Rights and Choices

You may decline or stop identity verification before it is completed, although QVL may then be unable to provide features or account access that require it.

Depending on where you live, you may have rights to request access to, correction of, or deletion of personal information, to withdraw consent where applicable, or to exercise other applicable privacy rights, as described in Section 14. To make a request, contact privacy@qvlmodels.com. For information that Plaid processes on QVL’s behalf, QVL may coordinate with Plaid as appropriate to fulfil an applicable request.

Requests may be subject to identity verification, applicable legal exceptions, fraud-prevention requirements, regulatory obligations, and permitted retention requirements. QVL and Plaid may be legally required or permitted to retain certain information, so deletion cannot be guaranteed in every case.

Availability

Plaid Identity Verification is not available to all users. Its availability remains subject to QVL completing its technical, security, legal, and Plaid production-readiness checks. We will update this Privacy Policy if our identity-verification practices change.

8. Payments and Subscriptions

QVL uses third-party payment providers, including Stripe, for supported subscription purchases and billing.

Payment information is generally entered into a payment-provider-hosted interface rather than directly into QVL systems.

QVL may use payment and subscription information to:

  • activate subscriptions;
  • determine model or feature access;
  • manage plan status;
  • process renewals;
  • provide invoices;
  • manage cancellations;
  • handle billing-related support; and
  • prevent billing fraud or abuse.

QVL does not store your full payment-card number or card security code.

Payment providers process payment information under their own terms and privacy policies.

9. How We Disclose Personal Information

QVL may disclose personal information to service providers and other parties where reasonably necessary to operate the Services, fulfill your requests, protect QVL or our users, or comply with law.

These parties may include:

Microsoft and Azure Service Providers

For cloud computing, databases, storage, networking, encryption-key services, AI processing, search, speech, security, and related infrastructure.

Plaid and SnapTrade

For connected financial-account functionality, identity verification (including, where enabled and with your separate consent, Plaid Identity Verification described in Section 7), synchronization, and supported brokerage features.

Stripe and Other Payment Providers

For subscription billing, checkout, invoices, payment-method management, and related payment services.

Email and Communication Providers

QVL uses third-party providers, including Resend, to send account, verification, security, subscription, model, and service communications.

Push-Notification Providers

QVL uses push-delivery infrastructure including Expo and the applicable mobile-platform notification services to deliver notifications to supported devices.

Error and Security Monitoring Providers

QVL may use service providers such as Sentry for error and reliability monitoring.

QVL configures monitoring systems with controls designed to reduce unnecessary transmission of sensitive personal or financial information.

Market, Research, and Information Providers

QVL uses external data and research services to obtain information such as:

  • market prices;
  • market history;
  • fundamentals;
  • news;
  • options information; and
  • other financial-market information.

Where QVL Copilot or another feature performs an external information lookup, QVL seeks to provide only information reasonably necessary to perform the request.

QVL does not intentionally provide these market-data providers with brokerage passwords or provider access credentials.

Professional Advisers and Business Service Providers

We may disclose information to:

  • lawyers;
  • accountants;
  • auditors;
  • consultants;
  • cybersecurity specialists;
  • insurance providers; or
  • other professional service providers

where reasonably necessary and subject to applicable confidentiality obligations.

Legal and Safety Requirements

QVL may disclose information where we reasonably believe disclosure is necessary to:

  • comply with applicable law;
  • respond to a lawful court order or government request;
  • meet a regulatory obligation;
  • investigate fraud or security incidents;
  • protect the rights, property, or safety of QVL, our users, or others; or
  • establish, exercise, or defend legal claims.

Corporate Transactions

Information may be transferred or disclosed in connection with:

  • financing;
  • merger;
  • acquisition;
  • corporate restructuring;
  • sale of assets; or
  • similar corporate transaction,

subject to applicable privacy requirements.

At Your Direction

We may disclose information where you direct or authorize us to do so.

10. QVL Does Not Sell Personal Information

QVL does not sell personal information as part of its business model.

QVL’s business model is based on QVL products, subscriptions, model access, education, technology, and related Services.

QVL also does not share personal information for cross-context behavioral advertising as part of its current business model.

QVL does not provide connected brokerage information to third parties for those third parties’ independent advertising purposes.

If QVL’s practices materially change in the future, we will update this Privacy Policy and provide any notices or choices required by applicable law.

11. Cookies, Local Storage, and Similar Technologies

QVL websites and applications may use cookies, local storage, and similar technologies for purposes including:

  • authentication;
  • maintaining sessions;
  • security;
  • remembering preferences;
  • storing interface settings;
  • maintaining application state;
  • preventing fraud or abuse; and
  • providing requested functionality.

Some information, such as certain interface, layout, or theme preferences, may be stored locally on your device rather than associated with your QVL account.

QVL does not currently use personal information for cross-context behavioral advertising.

If QVL introduces optional analytics, advertising, or other non-essential tracking technologies that require consent or an opt-out under applicable law, QVL will provide the applicable notice and controls.

Browser and device settings may also allow you to control certain cookies or local-storage technologies, although disabling required technologies may prevent portions of the Services from functioning properly.

12. Security

QVL maintains safeguards designed to protect personal information against:

  • unauthorized access;
  • misuse;
  • loss;
  • alteration;
  • disclosure; and
  • destruction.

Our safeguards vary based on the sensitivity and nature of the information and may include:

  • encryption;
  • credential protection;
  • access controls;
  • authentication;
  • multi-factor authentication;
  • passkeys;
  • network controls;
  • secure key management;
  • administrative permissions;
  • monitoring;
  • audit trails;
  • security testing;
  • privacy-aware logging;
  • backups; and
  • incident-response processes.

Access to personal information by QVL personnel is restricted according to business need and system permissions.

Although QVL takes security seriously, no Internet-based or electronic system can guarantee absolute security.

You are responsible for maintaining the confidentiality of your account credentials and for notifying QVL if you believe your account has been compromised.

13. Data Retention and Deletion

QVL retains personal information for only as long as reasonably necessary for the purpose for which it was collected and for legitimate business, security, legal, accounting, tax, regulatory, and dispute-resolution requirements.

Retention periods vary depending on the type of information.

For example:

  • account and profile information may be retained while your QVL account remains active;
  • financial-account information may be retained while necessary to maintain the connection, provide portfolio functionality, support historical records, or meet legal obligations;
  • model and trading records may be retained for audit, account-history, security, legal, or regulatory purposes;
  • billing records may be retained for accounting, taxation, dispute, and legal purposes;
  • saved Copilot chats may remain until deleted or otherwise removed under QVL retention procedures;
  • Copilot Memory information is subject to separate controls and retention rules;
  • security and audit records may be retained longer than ordinary application data;
  • backtest reports and related artifacts may have their own retention periods; and
  • information may remain temporarily in backups after deletion from active systems.

Certain information may be retained longer where required by:

  • law;
  • regulation;
  • contractual obligation;
  • investigation;
  • litigation hold;
  • fraud prevention;
  • security requirement; or
  • dispute resolution.

When information is no longer required, QVL takes reasonable steps to delete, anonymize, or otherwise securely dispose of it.

Account Deletion Requests

You may request deletion of your QVL account by contacting QVL through the privacy or support channels identified below.

Deletion of an account does not necessarily require QVL to delete information that we are legally permitted or required to retain.

Brokerage Disconnection

Disconnecting a brokerage or investment account stops future use of that connection subject to applicable provider and system processes.

Certain previously received records may continue to be retained where necessary for:

  • historical portfolio records;
  • security;
  • reconciliation;
  • audit;
  • legal requirements; or
  • other legitimate purposes described in this Policy.

14. Your Privacy Rights and Choices

Depending on where you live and the law applicable to QVL, you may have rights relating to your personal information.

These may include rights to:

  • request access to personal information;
  • request correction of inaccurate information;
  • request deletion where applicable;
  • obtain information about how personal information is used or disclosed;
  • withdraw consent where consent is the applicable legal basis;
  • manage certain privacy preferences;
  • object to or opt out of certain processing where required by law;
  • request portability where applicable; and
  • complain to QVL or an applicable privacy regulator.

You may also have product controls that allow you to:

  • update profile information;
  • disconnect brokerage accounts;
  • manage notification settings;
  • remove registered passkeys;
  • manage authorized devices;
  • delete saved Copilot conversations;
  • manage Copilot Memory where available; and
  • manage live-portfolio Copilot permissions where applicable.

To exercise a privacy right, contact:

privacy@qvlmodels.com

We may need to verify your identity before fulfilling a request.

Certain rights are subject to legal exceptions.

Withdrawing consent for a particular feature may mean QVL can no longer provide that feature.

Canadian Users

Where Canadian privacy law applies, you may have rights including the ability to:

  • request access to personal information QVL holds about you;
  • understand how that information has been used or disclosed;
  • challenge its accuracy or completeness;
  • request corrections;
  • withdraw consent, subject to legal or contractual restrictions; and
  • raise a complaint concerning QVL’s handling of personal information.

Applicable federal or provincial privacy laws may provide additional or different rights depending on your location and circumstances.

If you are dissatisfied with QVL’s response, you may have the right to contact the Office of the Privacy Commissioner of Canada or another applicable privacy authority.

United States Users

Depending on your state of residence and whether the applicable law applies to QVL, you may have additional rights such as:

  • access;
  • correction;
  • deletion;
  • portability;
  • disclosure of categories of personal information collected or disclosed;
  • opting out of certain sales or sharing;
  • limiting certain uses of sensitive personal information;
  • appealing certain privacy-request decisions; and
  • non-discrimination for exercising applicable privacy rights.

Because U.S. privacy laws differ by state, the availability and scope of these rights may vary.

15. International Processing and Data Transfers

QVL and its service providers may process personal information in more than one country.

Information may be processed or stored in Canada, the United States, or other jurisdictions where QVL or its service providers operate.

For example, portions of QVL’s cloud, AI, security, communication, financial-connection, and payment infrastructure may operate outside your province, state, or country of residence.

When personal information is processed in another jurisdiction, it may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement authorities, regulatory bodies, or national-security authorities where legally required.

QVL remains responsible for personal information under its control and uses contractual, technical, administrative, and organizational safeguards intended to protect information processed by service providers.

16. Children's Privacy

The QVL Services are intended for adults.

QVL does not knowingly offer the Services to anyone under 18 years of age.

If we learn that personal information was collected from a person under 18 in circumstances where it should not have been collected, we will take appropriate steps to address the information.

17. Changes to This Privacy Policy and Contact Information

QVL may update this Privacy Policy as our Services, technology, service providers, business practices, or legal obligations change.

When we update the Policy, we will update the version and effective date shown at the beginning.

If a change is material, we may provide additional notice through:

  • the QVL website;
  • the QVL application;
  • email;
  • an in-product notification; or
  • another appropriate method.

Where required, we may ask you to review or accept an updated Privacy Policy before continuing to use particular Services.

QVL maintains version information and records of acceptance of applicable legal agreements where appropriate.

Privacy Contact

Questions, concerns, complaints, and privacy requests may be directed to:

Privacy Officer
QVL Models, Inc.
375 University Avenue, Unit 101, Suite 1111
Toronto, Ontario M5G 2J5
Canada
Email: privacy@qvlmodels.com

For general account or support questions, you may also use QVL’s applicable customer-support channel.