Last updated: September 25, 2026. Version 2026-09-25.
1. Who we are
ECSTI ("ECSTI", "we", "our", "us") provides a platform on which you build and run AI agents that analyse markets, produce written theses, and trade simulated paper portfolios. This policy explains what personal data we process when you use the ECSTI website (ecsti.io) and the ECSTI product, why we process it, who else sees it, and what you can ask us to do about it.
The data controller for that processing is [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. You can reach us about anything in this policy at support@ecsti.io.
We have not appointed a Data Protection Officer; we are not required to. Privacy questions go to the address above and reach a person, not a queue.
2. The short version
- We do not sell your personal data, and we never have.
- Your conversations with an agent are sent to a third-party AI model to generate a response. Section 5 explains exactly which providers, what leaves our systems, and what they may do with it. This is the most significant processing we do, and it is the reason this policy exists in the form it does.
- Your data is stored in the European Union, on infrastructure we run ourselves. Some processing — AI inference in particular — happens in the United States.
- You can ask us to delete your account and everything in it, by email. See section 9, which is honest about how that works today.
- Analytics are opt-in on the website and opt-out in the product. See the Cookie Policy.
3. The personal data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and identity | Your name, email address, profile image, and the Google account identifier we receive when you sign in | Your Google account, at sign-in |
| Public profile | The public handle and display name you choose, used to attribute agents you publish on Discover | You |
| Organisation data | Organisation name, membership, roles, and invitations you send or accept | You and your collaborators |
| Conversation content | The complete text of every message you exchange with the agent builder, including your stated investment preferences, risk appetite, objectives, time horizon, and any free-text you write | You |
| Agent configuration and output | Your agents' strategies, instructions, model choice, every saved revision, generated portraits, and the theses and analyses your agents produce | You, and generated on your behalf |
| Notification settings | The email address we send notifications to, which is your account email address; your Telegram chat identifier if you link Telegram; whether each channel can currently receive notifications, or has stopped because an email bounced permanently, you blocked our Telegram bot, or you unsubscribed; your preferred channel; which kinds of notification you turn on or off on each channel, for all your agents or for a single agent; your briefing timezone and how often you get a briefing (weekly or daily); and a log of what we delivered, on which channel, and when | You; your Google account, for the email address; your browser, for the timezone, unless you set it yourself; and generated on delivery |
| Technical and session data | IP address, browser and device type, operating system, session tokens, and timestamps of your requests | Automatically, when you use the platform |
| Legal acceptance records | The date and version of the Terms of Use and Privacy Policy you accepted, and your cookie choices | Automatically, when you accept |
| Usage analytics | Pages viewed, features used, and performance measurements — only where an analytics provider is enabled for your deployment and, on the website, only if you accept analytics cookies | Automatically, subject to your choice |
| Billing data | A customer identifier from our payment processor, and your subscription status. Card details are handled entirely by the payment processor and never reach our systems | Our payment processor |
| Newsletter data | Your email address and subscription preferences, if you subscribe | You |
We do not ask for and do not want special-category data (health, biometrics, political or religious views, and the rest of Article 9). Please do not put it into an agent conversation.
A note on what you type. The agent builder is a free-text conversation about money. What you write there is as sensitive as anything on this platform, and we treat it that way — but it is genuinely free text, so what ends up in it is partly your choice. Do not paste account numbers, credentials, or other people's personal data into it.
4. Why we use it, and our legal basis
Under the GDPR we must tell you the lawful basis for each purpose. These are ours.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and securing your account, keeping you signed in | Account, identity, session data | Contract — Art. 6(1)(b) |
| Running the agent builder and generating agent output | Conversation content, agent configuration | Contract — Art. 6(1)(b) |
| Running your agents and storing their results | Agent configuration and output | Contract — Art. 6(1)(b) |
| Sending you notifications about your agents, including over Telegram | Notification settings, agent output | Contract — Art. 6(1)(b), part of the service; you can turn each kind off at any time |
| Publishing an agent to Discover under your handle | Public profile, agent configuration and output | Consent — Art. 6(1)(a), given by publishing; withdraw it by unpublishing |
| Keeping the platform available, debugging, and preventing abuse | Technical and session data, error logs | Legitimate interests — Art. 6(1)(f): running a service that works and is not abused |
| Improving the product and understanding how it is used | Usage analytics | Consent — Art. 6(1)(a) on the website; legitimate interests — Art. 6(1)(f) in the product, where you can opt out at any time |
| Sending newsletters and market updates | Newsletter data | Consent — Art. 6(1)(a); unsubscribe at any time |
| Billing and collecting payment | Billing data, account data | Contract — Art. 6(1)(b) |
| Keeping records of legal acceptance, and meeting tax, accounting and other legal duties | Legal acceptance records, billing data | Legal obligation — Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Whatever is relevant to the claim | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override yours. You can object — see section 9 — and we will re-run that balance for your case.
5. AI models and your conversations
This section describes the processing most people would not expect, so it gets its own heading rather than a line in a table.
What is sent. When you talk to the agent builder, we send the AI provider the conversation history for that thread, the instructions that tell the model how to behave, and the current configuration of the agent you are building. When one of your agents runs, we send the model that agent's instructions and the market data it is reasoning over. Your name, email address, and account identifiers are not included in the request — but the conversation itself contains whatever you have written into it, and for this product that generally means your investment preferences, your risk appetite, and your objectives.
Which providers. Model inference runs on:
- Amazon Web Services (AWS Bedrock), in the AWS
us-east-2region. Most models we offer — including the Anthropic, OpenAI, DeepSeek and Meta families — are served to us through Bedrock. AWS is the processor; the underlying model developers do not receive your data through this route. - Google (Gemini API), for the Gemini model family and for generating agent portraits.
What they may do with it. Both providers process this data as our service providers, under terms that prohibit using it to train their foundation models. Neither retains the content of your conversations for their own purposes.
We do not train models on your data. Not our own, not anyone else's.
No automated decisions with legal effect. Agent output is research and simulated trading. It is not a decision about you, and it does not determine your access to anything. The trades agents make are simulated: they happen in paper portfolios, no real money moves, and no order reaches a real broker or exchange. You decide what to do with what an agent produces. Article 22 GDPR — the right not to be subject to solely automated decisions with legal or similarly significant effects — is therefore not engaged.
6. Who we share it with
We do not sell personal data and we do not share it for advertising. We share it with the service providers below, each of which processes it only on our instructions and for the purpose named.
| Recipient | What they process | Where |
|---|---|---|
| Google Cloud | Hosting for the product, our application servers, and our database | European Union (europe-west1, Belgium) |
| Amazon Web Services | AI inference on conversation and agent content (Bedrock) | United States (us-east-2) |
| AI inference (Gemini API), portrait generation, and sign-in via Google OAuth | United States | |
| Telegram | Delivering agent notifications to your Telegram account, if you link one. Telegram receives your chat identifier and the text of the notification | International |
| Resend | Delivering email notifications, including briefings. Resend receives your email address, the subject and content of each email, an unsubscribe link, and an internal identifier for your account. It tells us when an email to you bounces or is reported as spam; after a permanent bounce or a spam report, we stop emailing that address | European Union (eu-west-1, Ireland) |
| Vercel | Hosting and performance measurement for the ecsti.io website | United States and global edge network |
| Financial Modeling Prep | Market and company data that agents reason over. We send ticker symbols and similar market queries — no personal data | United States |
| Payment processor | Subscription billing and payment card handling, once paid plans are live | United States |
| Analytics and error-monitoring providers | Usage analytics and error diagnostics, only where enabled for a given deployment, and on the website only with your consent. See the Cookie Policy | Varies by provider |
We run our own logging and monitoring inside our own cluster, so ordinary application logs are not sent to a third party.
We will also disclose personal data where we are legally required to, and where it is necessary to establish or defend legal claims or to protect the rights and safety of ECSTI or its users. If we are ever compelled to hand over your data, we will tell you unless we are legally prohibited from doing so.
If we are involved in a merger, acquisition, or sale of assets, your data may transfer to the acquirer. We will tell you before it does, and this policy will continue to apply until you are given notice of a new one.
7. Sending data outside the EU
Your data is stored in the European Union. Some of the providers in section 6 — AWS, Google, Vercel, Telegram — process data in the United States or internationally.
For those transfers we rely on:
- the EU Commission's adequacy decision for the EU–US Data Privacy Framework, where the provider is certified under it; and otherwise
- the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c), together with technical measures including encryption in transit and at rest.
You can ask us for a copy of the safeguards we rely on for any specific transfer, at support@ecsti.io.
8. How long we keep it
| Data | Retention |
|---|---|
| Account, identity, and public profile | For as long as your account exists, then deleted within 30 days of account closure |
| Unpublished draft agents and their conversations | 30 days after you last touch them, then deleted automatically |
| Published agents, their revisions and their output | For as long as your account exists, or until you delete the agent |
| Conversation content on a published agent | For as long as the agent exists |
| Sessions | Until the session expires or you sign out |
| Telegram link tokens | Until redeemed or expired, typically within minutes |
| Notification delivery records (Telegram and email) | 90 days, then deleted automatically |
| Record of the notice that an agent's instant trades are simulated: which agent, your account, and when you first turned them on | Indefinitely, even after the agent is deleted. Our automatic deletion of notification records skips it on purpose, so the notice is never sent to you twice for the same agent |
| Technical and application logs | Up to 90 days |
| Legal acceptance records | For as long as your account exists, plus 6 years afterwards, as evidence of the agreement between us |
| Billing and tax records | 7 years, or whatever the applicable tax law requires |
| Newsletter subscription | Until you unsubscribe |
Where we say "deleted", we mean deleted from our live systems. Encrypted backups roll off on their own schedule, and a deleted record can persist in a backup for up to 35 days after it leaves the live database.
9. Your rights
If the GDPR applies to you, you have the right to:
- access the personal data we hold about you, and get a copy of it;
- rectify it, if it is wrong or incomplete;
- erase it ("the right to be forgotten"), in the circumstances Article 17 allows;
- restrict our processing of it, while a dispute about it is resolved;
- port it — receive the data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible;
- object to processing we base on legitimate interests, including profiling;
- withdraw consent at any time, where we rely on consent. Withdrawing it does not affect processing we did before you withdrew it; and
- complain to a supervisory authority — see section 13.
How to exercise them, honestly stated. Email support@ecsti.io. We will respond within one month, and will tell you if we need to extend that by up to two further months, as Article 12(3) permits. We will not charge you, unless a request is manifestly unfounded or excessive.
About account deletion specifically. A "delete account" control appears in your account settings, but it is not currently connected on our side — pressing it will not delete your account, and we would rather say so here than let you believe otherwise. Until that is finished, account deletion and erasure run through the email address above, as a manual process we complete within 30 days. That covers your data across every system named in section 6, not just the account record. Your right to erasure is unaffected; only the self-service route is missing, and it is being built.
You can already, without contacting us: change your name and profile image, change your public handle, delete individual agents and their conversations, link and unlink Telegram, and turn analytics off.
10. Cookies and analytics
We use strictly necessary cookies to keep you signed in — these cannot be turned off without breaking sign-in.
On the ecsti.io website, analytics cookies are set only if you accept them in the cookie banner, and you can change that choice at any time from the footer. In the ECSTI product, analytics are on by default and you can turn them off at any time under Settings → Legal → "Cookie preferences".
The Cookie Policy lists each cookie, what it does, and how to control it.
11. How we protect it
Personal data is encrypted in transit and at rest. Access to production systems is restricted to the people who need it, over authenticated and audited paths. Secrets are held in a managed secret store rather than in configuration or code. Our database is not reachable from the public internet. We keep dependencies patched and monitor for anomalies.
None of this makes a system perfectly secure, and we will not claim it does. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where Article 33 requires it, and we will notify you directly where the breach is likely to result in a high risk to your rights.
12. Children
ECSTI is not for anyone under 18. We do not knowingly collect personal data from children, and if we learn that we have, we will delete it. If you believe a child has given us their data, write to support@ecsti.io.
13. Changes, and how to complain
Changes. We will update this policy as the product changes. The date and version at the top always reflect the current text. When a change is material, we will not rely on you noticing it: we will ask you to accept the revised policy the next time you sign in, and record that acceptance.
Complaints. If you think we have handled your data badly, tell us first — support@ecsti.io — and we will try to put it right. You also have the right to complain directly to the data protection authority in the EU or EEA country where you live, where you work, or where you believe the problem occurred. That right does not depend on you raising it with us first.
14. Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]