Legal

Privacy policy

How Actumetry collects, uses, shares, and protects personal data.

Effective 31 August 2026 | Version 2026-08-31

Draft for private-alpha preparation. Independent legal review is required before launch.

Who is responsible

Actumetry is operated by Raunak Tanwani, a sole proprietor in India trading as Actumetry, who determines how service data is used. Privacy and data-rights enquiries can be sent to raunak@actumetry.com. A non-residential public service address and final controller notice remain subject to independent legal review before access expands beyond the private alpha.

Data we collect

We process private-alpha application details such as email, country or region, age confirmation, decision style, markets, current review methods, review challenges, and any optional platform, experience, testing-frequency, or feedback-call answers. We also process account identity and verified email, profile and privacy preferences, invitation and legal-acceptance records, trading accounts, strategies, trades, execution events, structured behavioral capture, broker-import records, optional screenshots, feedback, support requests, and operational error records.

We receive data from you, Clerk for authentication, broker or exchange connections you authorize, and the device or browser when an optional usage event or operational error is submitted. We do not ask for broker trading permission when read-only access is available.

X account connection, publishing, and messaging

If the Actumetry owner connects an X account, Actumetry receives the connected account's X user ID, username, display name, granted OAuth scopes, token expiry, and encrypted access and refresh tokens. The owner-controlled X workflow requests only users.read, tweet.read, tweet.write, dm.read, dm.write, media.write, and offline.access. X requires dm.read whenever dm.write is requested. Actumetry never asks for or stores the X password and does not request X email, follows, likes, blocks, mutes, or other engagement permissions.

We use this information to identify and strictly bind the connected account, maintain the owner-authorized connection, stage drafts and media privately, and perform only the exact outbound action an authenticated administrator expressly approved. The Direct Message read scope is not used to collect inbox history; it is requested because X requires it with the write scope. Connecting the account is not itself permission to publish or message. Edits invalidate approval. The integration does not add location data or autonomously post, reply, read or send Direct Messages, follow, like, repost, quote, or otherwise manipulate engagement.

Draft records may include the exact target or recipient ID, text, ordered thread structure, staged media, media descriptions, cryptographic content hashes, approval identity and time, estimated cost, a short-lived release-grant digest and expiry, provider Post or message event IDs, safe failure status, and a non-secret audit trail. The plaintext release grant is not stored. X receives only the approved target, text, media, accessibility metadata, and technical request under X's own terms and privacy policy. Actumetry does not sell X account data or OAuth credentials. They are disclosed only to X, infrastructure providers needed to operate the integration, professional advisers, or authorities where legally required.

Access and refresh tokens are encrypted at rest and retained only while the connection is active. When the owner disconnects X in Actumetry or completes a verified deletion request, Actumetry immediately blocks local use, asks X to revoke the authorization, and deletes locally stored credentials after revocation is confirmed. If X is temporarily unavailable, an encrypted revocation credential may be retained solely to retry revocation; the owner can also revoke the app through X Connected Apps. Staged unpublished media can be deleted by the owner. Limited non-secret approval and publication records are retained only as needed for security, troubleshooting, accounting, and legal obligations under the Retention section.

Questions or deletion requests about the X connection can be sent to raunak@actumetry.com.

Why we use data

  • Provide, secure, troubleshoot, and support the service and your account.
  • Import and reconstruct trades you authorize and calculate requested analytics.
  • Prevent abuse, enforce invitations, preserve audit records, and meet legal duties.
  • Improve product usability using optional, limited product-usage data when you affirmatively enable it.
  • Measure Actumetry's own campaigns using limited public-page and waitlist events only when you separately allow campaign measurement.
  • Send operational messages and product email only under your selected preferences.

Depending on your location and the activity, the legal basis may be performance of the service agreement, compliance with law, legitimate interests in security and service operation, or consent for optional processing. Consent can be withdrawn without affecting earlier lawful processing.

Trading records and evidence

Journal text and trade screenshots are used for your requested product workflow. They are excluded from optional product-usage tracking and summary list responses. Incomplete or inaccurate trading data can change analytical results.

Optional product-usage data

Product-usage tracking, also called telemetry, is off by default. If enabled in account settings, it is limited to approved pages, feature identifiers, durations, navigation paths, counts, app version, and safe request IDs. Passwords, API keys, access tokens, form values, journal text, screenshots, and exact trade data are prohibited fields.

Optional campaign measurement

Public-page campaign measurement is off by default and is separate from signed-in product telemetry. If you allow it, Meta Pixel and X Pixel may record base visits on a small allowlist of public product pages, including the application page. When the server creates a new unique waitlist record, Meta Conversions API may receive one server-side Lead event. Separately, after any successful application response, the browser may send X one parameter-free Lead event containing no email or application answers. Because the fixed public response does not reveal duplicate status, repeated accepted submissions can produce multiple X Lead events. Actumetry's unique waitlist records remain the source of truth.

Meta may receive a one-way hash of the submitted email, Actumetry's fixed public URL, IP address, browser user agent, Meta cookie identifiers, event time, and an opaque event ID. X may receive the sanitized Actumetry origin and path, IP and browser information, provider cookie identifiers, and a validated X click ID. Actumetry removes the query and fragment before either browser tag loads and does not retain arbitrary query parameters.

Actumetry prohibits trade records, symbols, prices, balances, broker or account IDs, strategies, journal text, screenshots, direction, outcomes, and P&L from campaign measurement payloads. Meta and X measurement are excluded from sign-in, invitation, and authenticated workspace pages. You can withdraw through “Privacy choices” in the public footer. A supported Global Privacy Control signal is treated as a denial. See the cookie notice for the current browser technologies and duration.

Optional model analysis

A model review runs only when you request it and have configured your own OpenRouter key. Actumetry sends only the information needed for the requested review through a route requiring Zero Data Retention. Journal text, screenshots, identity, exact prices, currency P&L, credentials, and execution notes are excluded. OpenRouter and the selected model provider act as independent service providers under their own terms. Provider availability and practices may change, so review the displayed model and provider before requesting a review.

Who receives data

Data is disclosed only as needed to authentication, hosting, database, object storage, email, broker or exchange, user-selected model providers, and—only after separate permission—Meta and X for Actumetry campaign measurement; professional advisers; or authorities where legally required. Actumetry does not sell personal data or send trading records to advertising providers. The current provider register identifies the categories and launch verification still required.

International transfers

Providers may process data outside your country. Before EEA or UK users are admitted, Actumetry must document the applicable adequacy decision or transfer safeguard, complete any required transfer assessment, and publish the final provider list. This remains a private-alpha launch gate.

Retention

Data is kept only while needed to assess applications, operate the private alpha, provide the account, resolve requests, protect service integrity, and meet legal obligations. Optional product-usage data is retained for 90 days, client error reports for 30 days, sent or terminally failed email-outbox records for 30 days, and the versioned campaign-measurement choice for up to 180 days. Actumetry does not retain a separate copy of the Meta conversion payload after the request and operational log cycle; Meta applies its own terms and retention. X applies its own terms and retention to browser measurement events and provider cookies. Verified deletion requests remove or de-identify eligible application and account data through the documented operator process. Final periods and enforcement for application records, account content, evidence, broker imports, logs, backups, provider copies, and legal holds require operator and counsel approval before broader alpha access.

Your choices and rights

Account settings provide product-usage and email choices, while the public “Privacy choices” control manages campaign measurement. You may also request access/export, deletion, correction, restriction, objection, opt-out, and appeal. Rights vary by location and may have lawful exceptions. Actumetry will verify identity, respond without discrimination, and explain a denial or appeal route where required. EEA and UK users may complain to their supervisory authority; eligible US residents may use applicable state appeal and opt-out rights.

Security and automated decisions

Actumetry requires sign-in and keeps each user's data access separate. It also encrypts stored provider credentials, traces requests using safe identifiers, restricts uploads, and limits optional product-usage data. No system can guarantee absolute security. Report a suspected incident to raunak@actumetry.com. Do not include passwords, access tokens, API secrets, or unnecessary trading records.

Actumetry does not make solely automated decisions that produce legal or similarly significant effects. Analytics and optional model outputs are informational and remain inspectable by the user.

Age, changes, and contact

The service is intended only for people aged 18 or older. We version material changes and require renewed acceptance before continued authenticated use. Users can submit privacy requests from account settings or contact raunak@actumetry.com.