Privacy Policy

Your data, handled with restraint.

Last updated September 30, 2026. This is a plain-language policy for what Echelon collects today. Accounts are open; no paid plan is open to the public yet. We will review this policy with counsel and update it here before any paid plan opens.

What we collect

If you join the waitlist, we collect your email address, an optional referral code if you arrived from an invite link, and, if you tap one of the “I'm a” buttons, which of three broad groups you identify with (student, professional analyst, or managing your own portfolio). We do not use advertising trackers or advertising cookies, and we never sell or rent your data.

When you join the waitlist or create an account, we record that you confirmed you are 18 or older, and the date of that confirmation. Echelon is for adults. We do not ask for your date of birth, and we do not store your age.

If you create an account, we also keep:

  • your email address and, if you set one, your password. The password passes over HTTPS to our authentication provider (Supabase), which stores it only as a one-way hash. We never store the password itself.
  • your plan and its dates: free, trial, or paid, and when a trial or term starts and ends. If you pay, we keep the customer and subscription identifiers Stripe returns (see Stripe below).
  • your group selection, your referral code, and whether you verified an academic .edu address and for which school. An academic address is optional. Give us one and we can apply academic pricing; it is never required to create an account or to use Echelon.
  • your learning record: the answers and written justifications you submit, their scores and the feedback on them, practice attempts, skill progress, XP, streaks, placement results, Season membership, any credential you earn, and any course an instructor enrolls you in. This is what makes grading, review, and your record work.
  • if you are granted extra time on a timed assessment, the time allowance and a short note about it.
  • any feedback you send us from inside the product, with the page you sent it from.
  • a note of which reminder emails we have sent you (trial and streak reminders), so we never send the same one twice, and whether you turned the streak reminder off.

We collect the minimum needed to run the product.

We do use one third-party analytics service: Vercel Web Analytics, which counts page views and referrers. It runs on every page of this site, including this one. It is cookieless and does not build a profile of you across other websites — but it is a third party, so we name it rather than claim we use none.

We also run first-party product metrics. When you use the site we log the event name (for example “lesson opened”); the page path, with anything identifying removed; a random session id that is discarded when the tab closes; your group selection, if you made one; and a few small context tags. When you are signed in, the event also carries your account's internal id, so we can measure progress per account. It never carries your email address. These events set no cookies, they stay on our own servers, and anything that looks like personal data is rejected before it is stored.

Echelon also keeps a small amount of data in your browser's local storage. It stays on your device, is never sold or shared, and persists between visits until you clear your browser data — so we would rather list it than describe ourselves as storing nothing. Every key is prefixed echelon: and they cover: your group selection; your lesson progress and XP; your practice and review history; your watchlist; the daily challenge you answered; your haptics preference; and a first-visit timestamp (echelon:first_touch), which exists only to measure how long a new visitor takes to reach their first piece of graded feedback. None of it is an advertising identifier. Clearing your browser data removes all of it.

How we use it

To run your account and grade your work; to send the emails the service needs (sign-in links, password resets, and trial and billing notices); to send product email you can turn off, such as early-access news and the streak reminder, each with a one-click way to stop; to attribute referrals; and to measure and improve the product. We do not sell or rent your data, and we do not share it except with the service providers below who process it on our behalf.

Legal bases (where GDPR applies): your consent when you join the waitlist, performance of our agreement with you when you have an account, and our legitimate interest in operating and improving the product.

Who processes it

We use a small set of processors, each only for its stated purpose:

  • Supabase — runs sign-in and stores the waitlist, account, and learning-record data.
  • Resend — sends confirmation and update emails.
  • Vercel — hosts the site, serves requests, and provides Web Analytics (page-view and referrer counts).
  • Anthropic — powers the AI mentor and the grader. When you submit an answer for grading or ask a question about a filing, the text you wrote is sent to Anthropic's API to produce the explanation or feedback you see back. We send the text of your answer or question and the lesson context it belongs to; we do not send your email address or account identifiers with it. Anthropic processes it to return a response and does not use it to train their models.
  • OpenAI — an alternative model provider, used only when configured. Echelon's AI layer can route the same answer or question text to OpenAI's API instead of Anthropic's when an OpenAI key is set for the deployment; the same rule applies — the text of your answer or question and its lesson context, never your email address or account identifiers. When no OpenAI key is configured, nothing is sent to OpenAI.
  • Upstash — holds our rate limits. To stop abuse, we count requests per IP address over short windows (minutes to a day). Those counters — your IP address as a key and a request count — are stored in Upstash Redis and expire with the window; nothing else about you is stored there.
  • Stripe — processes payments. No paid plan is open to the public yet. When one is, your card details are entered on Stripe infrastructure and are never stored on our servers; what we keep is the customer and subscription identifier Stripe returns, your plan, and its status, because that is what tells the site what your account can open.
  • TradingView — some market charts on Echelon, including the tiles on the Terminal, are TradingView's own widgets, loaded in a frame from TradingView's servers. When one loads, your browser connects to TradingView directly, so TradingView receives your IP address and standard browser information and may set its own cookies under its own privacy policy. We send TradingView nothing about you or your account.

If no AI key is configured, these features fail closed — the lesson still grades on its deterministic checks and nothing is sent anywhere.

Do Not Track

Some browsers send a Do Not Track signal. Echelon does not track you across other websites and does not let advertising networks do so, so there is no cross-site tracking for the signal to switch off, and the site behaves the same whether or not the signal is sent. The TradingView frames described above follow TradingView's own policy.

Retention & your rights

We keep waitlist data until you ask us to delete it or the waitlist closes. We keep account data, including your learning record, for as long as your account is open. Ask us to delete your account from the address on it and, within 30 days, we delete the account and everything listed above that is tied to it, and ask Stripe to delete your customer record; Stripe keeps the payment records the law requires it to keep. Rate-limit counters expire on their own within a day. Product metrics that were never tied to an account carry no name or email and are kept to measure the product. Our hosting provider keeps server logs for a limited period under its own retention settings.

You can request access to, correction of, or deletion of your data — and opt out of emails — at any time by emailing hello@echelonterminal.com. Depending on where you live, you may have rights under the GDPR, UK GDPR, or CCPA/CPRA; we honor those requests regardless of location.

Data security & children

Data is stored with reputable providers and transmitted over HTTPS. No method is perfectly secure, but we collect little and guard it accordingly. You must be 18 or older to join the waitlist or to create an account. Echelon is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that a user is under 18, we close the account and delete the data. This matches section 8 of the terms.

Contact

Questions or requests: hello@echelonterminal.com. We will update this page as the product grows and note the revision date above.

The terms that govern your use of Echelon are at /terms, and the plain-language summary of what Echelon is and is not is at /disclosures.

Educational use only — not investment advice.