Privacy
Last updated 30 August 2026
Stratify runs options backtests. This page says exactly what is kept, for how long, and what leaves the server. It describes the software in this repository rather than a category of service.
What we collect when you sign in
- Your Google account's subject identifier — a stable, opaque id. This is what identifies your account, not your email, so changing your address does not move or lose it.
- Your email address, display name and avatar URL, as Google reports them. The email is used to identify the account to you and to contact you about the service.
- Nothing else. We request the `openid email profile` scopes only, so we cannot read your mail, files, calendar or contacts even if we wanted to.
What we collect when you use it
- A hash of each API key. Keys are hashed with scrypt and a server-side pepper before storage, so a key cannot be recovered from our database — including by us. That is why a key is shown once and never again.
- If you connect an application — ChatGPT, Claude, Gemini or anything else that signs in through OAuth — a hash of the tokens issued to it, the name it registered under, and when it last connected. Hashed the same way as an API key, and deleted when you disconnect it.
- Per-call metering: CPU-seconds and the number of option prices returned.
- A call log: which tool you called, the arguments you sent, whether it succeeded, and the reason if it was refused.
- Your backtest specifications and their results, so your reports keep working.
- A peppered hash of your IP address at signup, used to throttle bulk account creation. The raw address is never written down.
What we never collect
- Your conversations. Stratify is an MCP server: it receives the tool arguments your client sends and nothing of the discussion around them.
- Payment card details. Nothing on this site takes a card.
- Analytics, advertising or tracking of any kind. There is no third-party script on this website. The only cookies are your sign-in session and a ten-minute cookie used to complete the Google handshake.
How long it is kept
- Usage records, the call log, and the bodies of your specifications and results: 30 days, then deleted or replaced with a tombstone. Report links keep resolving afterwards and say the content was purged on schedule.
- Signup records: 7 days.
- Your account, and the hash of each key: until you ask us to delete them.
- A shortlist of strategies you chose to keep: until you remove it. It is small, it is the durable artefact, and a shortlist that silently forgets things is worse than none.
Who it is shared with
- Nobody. Your specifications, results and reports are private to your account and are not sold, licensed, syndicated or used to train anything.
- Google sees that you signed in, because you signed in with Google. It does not see what you do here.
- We will disclose data if a valid legal order compels it, and we will tell you unless we are forbidden from doing so.
Your control
- Disconnect any connected application from your dashboard. Access ends immediately, including any refresh token it holds — it cannot quietly mint itself a new session afterwards.
- Revoke any API key at any time from your dashboard; it stops working immediately.
- Sign out to invalidate your browser session server-side, not just locally.
- Ask us to delete your account and everything attached to it. Write to the address below and it will be done.
- Ask for a copy of what we hold about you and we will send it.
Where it lives
- On servers we operate. Market data and account records are not replicated to third-party platforms.
- Transport is HTTPS throughout. Session cookies are http-only, secure, and not readable by any script.
Contact
Questions, corrections, or a deletion request. Write to 1406srinath@gmail.com, or use the feedback tool inside the product — it reaches the same place and carries the context of what you were doing.