Privacy Policy

Last Updated: July 30, 2026

1. Introduction

At JCurve Technologies ("JCurve", "we", "our", or "us"), we are committed to safeguarding the privacy and security of your personal data and institutional research content. This Privacy Policy describes how we collect, use, store, and protect your information across our multi-tenant equity research platform.

2. Information We Collect

We collect information to provide, maintain, and secure our services:

  • Account & Profile Information: Full name, institutional email address, organization name, team assignments, password hashes, and assigned license roles.
  • Uploaded Documents & Workspace Data: Financial reports, PDF document uploads, research notes, saved snippets, and custom project metadata.
  • Usage & Telemetry Data: Token usage events, query activity, search interaction logs, IP addresses, browser types, and OpenTelemetry trace IDs (trace_id / message_id) end-to-end.
  • Payment & Billing Data: License purchase history, seat assignments, invoice records, and billing contact details (processed via PCI-compliant payment partners).

3. How We Use Your Information

We process data for the following legitimate business purposes:

  • To power the agentic chat experience, vector retrieval, and numeric verification engine.
  • To enforce organization license seat limits and LLM token quota allocations.
  • To log audit trail events for organization managers and enterprise security compliance.
  • To monitor platform performance, resolve system errors, and maintain security infrastructure.

4. Data Isolation & LLM Training Policies

OUR ZERO-TRAINING GUARANTEE: We do NOT sell your data, uploaded financial reports, or proprietary research queries to third parties. We do NOT train foundation AI models on your organization's data.

All document chunks, vector embeddings (Pinecone/pgvector), chat histories (MongoDB), and operational databases (PostgreSQL) are strictly partitioned by tenant ID (org_id). All external AI provider integrations operate under enterprise agreements with zero data-retention for model training.

5. Sub-Processors & Infrastructure Partners

We partner with enterprise-grade cloud providers to run our services. Key sub-processors include:

  • AI Foundation Providers: OpenAI, Anthropic, Cohere, Voyage AI (accessed via strict enterprise strategy adapters with token tracking middleware).
  • Vector & Database Hosting: Pinecone, MongoDB Atlas, AWS / Managed PostgreSQL.
  • Document Processing: JCurve Document Service (dedicated Go microservice for SEC EDGAR & BSE PDF extraction).

6. Data Security & Retention

Data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. We retain account data for as long as your organization maintains an active subscription. Upon workspace termination or project deletion, associated vector embeddings and temporary staging files are purged in accordance with our data retention schedule.

7. Your Rights & Controls

Depending on your jurisdiction (e.g., GDPR, CCPA), you have the right to:

  • Request access to or export of your account data and project snippets.
  • Request correction or deletion of personal account records.
  • Manage organization member roles and data access via Organization Admin settings.

8. Contact Information

For privacy inquiries, data subject access requests, or security inquiries, please contact our Data Protection Officer at privacy@jcurveiq.com.