gammagrid Open app →

Privacy Policy

Last updated: 12 September 2026

GammaGrid is a small, independent project. This policy describes what the hosted service at app.gammagrid.io stores about you, why, and what you can do about it. It is written to be read rather than to be survived, and it says what actually happens in the software — every item below can be checked against the source code, which is public.

Who is responsible

The GammaGrid service ("GammaGrid", "we") decides what personal data is collected here and why, and is the controller for it.

GammaGrid is currently operated by an individual and does not yet trade through a registered company. The operator's formal identity and registered details will be published in this section as soon as that changes. Until then, every request under this policy reaches a person at hello@gammagrid.io, and that address is monitored.

What we store, and why

Only what the service needs to work. There is no advertising, no profiling and no third party buying anything from us.

What Why Where it comes from
Email addressIdentifies your account and is how we reach you about the serviceYour Google or GitHub sign-in
Sign-in provider and its account identifierLets you sign back in as the same personYour Google or GitHub sign-in
A sign-in cookie (gg_session)Keeps you signed in between visitsCreated by us when you sign in
Your watchlist — the tickers you addIt is the product: we collect option chains for the symbols people are watchingYou
Contracts you pinKeeps your pinned list between visitsYou
The dates you opened the appCounted so we know how many people use the service. A date per personYour visits
Which tab you opened, and whenSo we can see which parts of the tool are worth the work and which nobody opens. The tab's name and the time — Screener, 19:40 — and nothing about what you looked at there: not the ticker, not the contract, not what you typed. Recorded when you MOVE between tabs, so it is a handful of rows per visit rather than a running logYour visits
Tickers you asked for but could not addShows us which symbols people want when they hit the free limitYou
Which site linked you here, and the campaign tag on that link, if anySo we know which of the things we write actually reaches people. We keep the site's name onlyreddit.com — never the full address, because a full one can carry someone else's search termsYour browser, once, when you first sign in
Which of our emails you were sent, and whether you opened the app through the link in oneSo we know whether an email was worth sending at all, and stop sending the kind that nobody opens. The email's tag and the time — digest-2026-09, 19:40 — nothing about what you did once inside; and the list of who a sent email went to, so a delivery hiccup never sends it to the same person twiceYour visits, when the address carries the tag from one of our emails; our own send log
Your browser's timezone and languageA rough idea of where in the world people are asking for this. Europe/Berlin — a continent, not a placeYour browser
Feedback you send through the formSo we can read it and fix thingsYou

We do not store your name, your payment details (the service takes no payments), your IP address in the application, your broker, your positions, or anything about trades you make. GammaGrid has no connection to any broker and cannot see your account anywhere.

That promise about your IP address is worth being specific about, because the row above says we note roughly where in the world you are. We do not look your location up from your IP. The software can see that address and does not read it; what it reads is the timezone your browser announces on its own, which is how the charts already show you times in your own day. It says Europe/Berlin and nothing narrower, a VPN or a holiday changes it, and it is kept as one word next to your account.

Your Google or GitHub password never reaches us. Signing in happens on their side; we receive only the email address and an identifier.

Why we are allowed to store it

pinned contracts and the sign-in cookie. Without these there is no service. (In GDPR terms: performance of a contract, Article 6(1)(b).)

keeping it working and free of abuse — the per-day visit count, which tabs get opened, and the record of tickers people asked for. These are counted, not profiled: they tell us that the Screener is opened twice as often as the IV surface, which decides what gets built next. They do not tell us what any individual was doing — the tab's name and the time are recorded, never the ticker, the contract or anything you typed — and nothing here is used to make a decision about you. (Article 6(1)(f).)

views, fixed bugs, things worth knowing about GammaGrid. We send these through Postmark (see the table below); every one carries a one-click unsubscribe, and the same promise as always: that address is used for nothing else, and is never sold or shared. Until 11 September 2026 this section read differently — it said there was no mailing list and no newsletter provider, which was true until this feature existed.

Who else touches it

Running a service means other companies handle parts of it. These are all of them, and the list is deliberately short:

Provider What it does for us What it sees
SupabaseHandles the Google and GitHub sign-inYour email address and sign-in identifier
netcupHosts the servers and holds the backups, in GermanyEverything stored, at rest
CloudflareServes the gammagrid.io website, and stands in front of the app: every request to app.gammagrid.io passes through its network, which also keeps the app's static files and — for signed-in visitors — ready-made screens close to youThe traffic in transit, including your session cookie on its way to our server; it does not store your account or your email address. A screen is handed out from its cache only after a signature check that names no account. The website's analytics use no cookies and do not identify visitors
SentryTells us when the software breaks — on our servers or in your browser — so it gets fixed rather than reportedThe error itself: which line of our code failed and in which release, and for an error in your browser, the page it happened on and the browser's name and version. Your account number travels with it so we can tell "one person is affected" from "everyone is" — not your email address, and not your IP address. Stored in Frankfurt, Germany
Grafana LabsHolds the service's own operational measurements and the software's log messagesCounts and sizes — how many tickers are being collected, how large the database is, how long a query took, how many people opened each tab — and the messages our software writes about its own work. Totals and averages only: nothing that identifies a person, and no account number. Stored in the EU
PostmarkDelivers the occasional email we send about the product — an owner decides what goes out and to whom, nothing automated per accountYour email address, and the content of that one email. No open or click tracking — we turned it off

Two honest notes about the last two, because "no personal data" is a claim worth qualifying rather than repeating:

something unexpected into an error message. We have turned off the setting that would attach the contents of variables to a report, precisely so that cannot happen by accident, and we do not send your email address at any point. A report from your browser records which requests the page made and which screens it moved between just before the error — not what you typed, and not what you clicked.

query was slow. They are not written to contain personal data and we do not put email addresses in them.

The market-data provider that supplies option chains is not on this list, and deliberately: we ask it about ticker symbols, never about people. It has no way of knowing whose watchlist a symbol came from.

Where any of these process data outside the European Economic Area, they do so under their own published data-processing terms.

How long we keep it

it, or until the service closes. That includes which tabs you opened: it is attached to your account and goes when the account goes.

days at Grafana, after which they are removed by those services and not by us. Neither is a record we keep; both exist to notice a problem while it is still happening.

visit, then it is deleted automatically. Signing out deletes it immediately. We store only a one-way hash of the session token, never the token itself.

removed as new ones are made. This is worth stating plainly: after a deletion, your data can still exist in a backup for up to five days, and then it is gone from those too.

What you can ask for

You can ask us to show you what we hold, correct it, delete it, or send it to you in a portable form. You can object to the counting described above. You can also complain to your national data protection authority if you think we have handled something badly.

How: email hello@gammagrid.io. We will answer within 30 days, and in practice much sooner — the service is small enough that a person reads it.

There is no self-service delete button in the app yet. Until there is, deletion is done by hand on request, which is slower but not less complete.

What deletion does and does not remove

Deleting your account removes your account record, your watchlist, your pinned contracts, your visit dates, which tabs you opened, your ticker requests and your sessions.

Two things survive, and you should know about both:

you wrote "the GLD chart is empty", that sentence remains in our inbox as a bug report with no author. If you want the text itself gone as well, say so in your deletion request and we will remove it.

option prices and open interest — facts about contracts traded on a public exchange, not information about you. Once a symbol has been collected, that history exists independently of who asked for it, and other people are watching the same symbols.

Cookies

One: gg_session, which keeps you signed in. It is strictly necessary — remove it and you are signed out. There are no advertising cookies, no analytics cookies and no third-party trackers in the application.

The gammagrid.io website counts page views through Cloudflare Web Analytics, which works without cookies and without identifying visitors.

The demo pages at app.gammagrid.io/demo show the free list without an account and set no cookie. They count three things, anonymously and without any identifier: that a page was opened, that a view was switched, and that a sign-in button was pressed — totals per minute, nothing about who. If you sign in from a demo page, the sign-in records that you came through the demo, the same way it records a referring website.

Security

Traffic is encrypted in transit. Sign-in tokens are stored as one-way hashes, never in a form that can be replayed. The database is not reachable from the public internet, and backups are held on storage that only the production machine can reach.

GammaGrid is a beta operated by one person. That is not a reason to expect it to be careless, and it is a reason not to store anything here that you would not want to lose — which, given the list above, is nothing you have not already given to a search engine.

Children

The service is not intended for anyone under 16, and we do not knowingly hold data about anyone under 16.

Changes to this policy

We will change this document as the service changes. The date at the top always moves when it does, including for small corrections, so that you can tell whether you have read this version. Every past version exists in the project's version history.

Contact

hello@gammagrid.io