EdgePilot Marketplace Privacy Policy

Effective date and version: August 20, 2026

1. Scope

This Privacy Policy applies to the publicly installable EdgePilot Research plugin and its anonymous Research catalog, recommendation, strategy-download, and historical-backtesting functions. It also applies to account-authenticated EdgePilot Marketplace catalog and strategy-download functions used by the EdgePilot Live client. It does not cover local backtest, paper, exchange-demo, live-trading, order-execution, or exchange-credential processing performed on your device.

2. Who we are

The EdgePilot Marketplace services covered by this Policy are provided by Rivendell Holdings Investment Limited, a company registered in the British Virgin Islands ("Rivendell", "EdgePilot", "we", "us", or "our"). Our company website is www.rivendell.capital. For product, privacy, security, installation, or compatibility matters, contact [email protected]. For corporate matters or formal legal notices, contact [email protected].

3. Information sent to EdgePilot

You do not need an EdgePilot account to use EdgePilot Research. Catalog requests may include search text, locale, asset, venue, category, data-type and risk filters, sort order, result limit, and a requested strategy identifier or version.

Live Marketplace access requires an EdgePilot account and an authenticated session or access token with the required scope. We use the authenticated internal user identifier and authorization scope to approve Live Marketplace requests. An approved Live strategy download is associated with that internal user identifier; the download record and download-specific application logs do not copy your email address, bearer token, refresh token, or account cookie.

A recommendation request may use the version 2 fields you explicitly select: profit style, holding period, principal pain point, maximum-drawdown preference, trading mode, allocation band, instrument universe, and locale. A version 3 request may instead include only explicit strategy concepts, assets, venues, categories, data types, risk or capacity filters, and partial preferences such as profit style, holding period, pain point, drawdown, trading mode, or universe. We process the request and recommendation result only to return the response. We do not persist recommendation requests or results in the application database or write their filters, preferences, search text, or result content to application logs. Recommendation bodies do not contain EdgePilot account credentials or exchange credentials; Live authorization is handled separately from the recommendation body, while Research rejects credentials.

Public requests generate application security and operational logs containing a keyed hash derived from the client IP address, request method, route, status, request identifier, request time, and relevant error or service information. The EdgePilot Research application does not add the public request's User-Agent to these logs. Normal HTTPS handling nevertheless exposes ordinary network metadata, such as IP address, User-Agent, request time, and requested resource, to the service receiving the connection.

For each approved Research or Live strategy ZIP download, we record the download channel, request identifier, strategy identifier and version, time, delivery status, the normalized complete client IP address, and a network quota key. The network quota key is the complete IPv4 address or the normalized IPv6 /64. A Live download record also contains the authenticated internal user identifier; a Research download record does not. People sharing a public IPv4 address, network-address translation service, or IPv6 /64 share the same source-network download allowance.

A request rejected because its download allowance is exhausted does not create a download record. Restricted application logs for that rejection may contain the IPv4 network key or IPv6 /64 network key, the limited quota scope, route, strategy identifier and version, request identifier, and time. These logs do not contain an email address, bearer or refresh token, complete IPv6 client address, or strategy ZIP content.

4. Information not sent to EdgePilot

The Research plugin does not collect or send EdgePilot account cookies, hardware or operating-system machine identifiers, browser fingerprints, persistent local anonymous identifiers, exchange credentials, API keys, runtime-lock metadata, local datasets, imported CSV content, backtest inputs, backtest results, reports, or charts. Its local Dashboard stores only non-identifying preferences such as language and notice state. Temporary local security tokens and process identifiers are not sent to the Marketplace.

5. Local information

Installed strategies and verification records, the runtime and virtual environment, wheel and catalog caches, downloaded or imported market data, processed instrument metadata, backtest inputs, runs, reports, charts, and local Dashboard state are stored on your device in the EdgePilot Research state directory. You control this local information and may remove it with the product's uninstall functions or your file-system tools. EdgePilot cannot remotely access, export, or delete files that remain only on your device.

6. How we use information

We use information received by the Research and Live Marketplace services to provide catalog and recommendation responses, authenticate and authorize Live access, deliver requested packages, enforce source-network and Live-account download allowances, diagnose delivery failures, maintain service reliability, prevent abuse, and comply with applicable law. These services do not provide advertising or payment functionality.

7. Service providers, third parties, and host platforms

Our cloud service and server-side data storage are hosted in Singapore. The Research and Live clients connect to edge-pilot.rivendell.capital for applicable Marketplace services and strategy packages. The Research plugin also connects to EdgePilot-hosted modified NautilusTrader wheels, to files.pythonhosted.org for public Python wheels fixed by the runtime lock, and, when requested by a supported strategy preset, to public Binance Futures sources for historical bars. Each third party processes connections under its own terms and privacy practices.

The AI or coding platform that hosts the plugin may independently process your conversations, tool calls, and plugin-installation information. That processing is controlled by the host platform's policies, not this Policy. We do not make privacy commitments on behalf of OpenAI, Anthropic, Binance, the Python Package Index, or another third party.

8. Retention

Approved strategy-download records are retained for 180 days. Backup copies may remain for up to 30 additional days before rotation. Application logs for rejected download-allowance requests, including an IPv4 address or IPv6 /64 network key, are retained for no more than 14 days under the current deployment configuration. Expired UTC daily and monthly download counter rows are deleted after their period ends.

Other EdgePilot Research application security logs are retained for 14 days under the current deployment configuration and are then rotated out. Anonymous recommendation answers and results are not persisted by the Research application. Information kept only on your device remains until you remove it. A third party may apply its own retention schedule to information it receives.

9. Security

We use administrative and technical safeguards appropriate to the service, including HTTPS transport, restricted application logging, keyed hashing of ordinary public-request IP addresses, trusted-proxy validation, and access controls for download records containing complete IP addresses. No system is completely secure. Do not send credentials, API keys, account details, or other secrets through Research or Marketplace request fields or support email.

10. Your choices and rights

Depending on applicable law, you may have rights to ask whether we hold personal information about you and to request access, correction, deletion, restriction, objection, or a copy. For anonymous Research activity, we may need the approximate client IP address, strategy, and download time to locate a download record; ordinary public-request identifiers remain keyed hashes. For Live Marketplace activity, we may also use the authenticated account to locate applicable records. Send requests or complaints to [email protected]. We may need to verify a request and may retain information where required by law or necessary for security or legal claims. You may also complain to a competent data-protection authority.

11. Age

The EdgePilot Marketplace services covered by this Policy are intended only for users aged 18 or older. We do not knowingly offer them to children.

12. International processing

Using EdgePilot Research or the Live Marketplace may cause information described above to be processed in Singapore and in locations where the applicable host platform, package provider, or market-data provider operates. Those locations may have different data-protection laws from your location.

13. Changes

We may update this Policy when the Research or Live Marketplace service, its data practices, or legal requirements change. We will publish the revised Policy at this URL and change the effective date and version. Material changes will apply prospectively unless applicable law requires otherwise.

14. Contact

Product, privacy, and security enquiries: [email protected].
Corporate matters and formal legal notices: [email protected].

EdgePilot