Privacy Policy
Nexus Quant is a free, educational, paper-trading market terminal. We collect the minimum needed to run it, never sell your data, and prefer first-party device storage over tracking. This policy explains what we collect and your choices.
Who we are
Nexus Quant is an independent educational project operated from India. It is not a broker, exchange, or registered investment adviser, and is not affiliated with any market-data vendor. Reach us via the contact form on the home page.
What this product is
A simulator running on live public market data. All trading is paper trading with virtual currency — no real money, no real orders, not investment advice. Data is labelled by provenance (LIVE / DELAYED / MODELED / SIM / DEMO).
Data we collect
- Account (optional) — if you sign in with Google, Firebase Authentication gives us your name, email and profile image, used for your league identity and access role.
- Guest mode — anonymous; you get a random callsign and we collect no personal information.
- Paper-trading data — your virtual trades, cash, portfolio and equity, stored on your device and (for signed-in users) under
users/{your-id}in Firestore. - Contact form — the name, email and message you submit.
- Visitor count — a one-way salted hash of your IP + browser, used only to count unique devices. We do not store your raw IP or user-agent.
- Usage analytics — Vercel Web Analytics and Speed Insights, which are cookieless and aggregate (no cross-site tracking).
- AI copilot — prompts you send are processed by Google's Gemini API to generate a reply. You may supply your own API key, which is stored only on your device and never sent to us.
- Device storage — functional
localStorageplus one consent cookie (see the Cookie Policy).
How we use it
To run the terminal, maintain league identity and leaderboards, respond to your messages, protect the service from abuse, and measure aggregate product usage. We do not sell your data or use it for advertising.
Who processes it (sub-processors)
Google (Firebase Authentication, Firestore, Gemini), Vercel (hosting + analytics) and Resend (transactional email). Market-data sources — Yahoo Finance, Finnhub, Binance, Digitraffic and FRED — receive only the symbols or regions you query, never your identity.
Retention
Account and paper-trading data persist until you ask us to delete them or remove your account. Contact messages are kept for support. Visitor data exists only as anonymous aggregate counters.
Your rights
Subject to the India DPDP Act 2023 (and the GDPR where it applies) you may request access, correction, deletion, or withdrawal of consent. Contact us to exercise these; deleting a league account removes its users/{your-id} record.
Security
Firestore uses default-deny rules with owner-only writes and admin-gated reads; secrets stay server-side. Because the platform holds no real money, there is no financial settlement risk — but no online service can be guaranteed perfectly secure.
Children
The service is not directed to anyone under 18. Please do not use it if you are below the age of majority in your jurisdiction.
International transfers
We operate from India and rely on the sub-processors above, whose infrastructure may be located outside your country. Using the service, you consent to such processing.
Changes
We may update this policy; the date above changes when we do, and material changes are surfaced in-app.