The Holy Grail Research Lab is operated by Vint Hill Designs, a sole proprietorship based in Warrenton, Virginia, USA. This Privacy Policy explains how we collect, use, and protect your information when you use the Platform.
Account information: When you register, we collect your email address and a hashed (encrypted) version of your password. We never store your password in plain text.
Usage data: We store the content you create on the Platform — your chart annotations, drawing tool data, and session preferences. This data is tied to your account and visible only to you.
Payment information: Payments are processed by Stripe. We store only a Stripe Customer ID and subscription status in our database. We never see, store, or have access to your credit card number, expiration date, or CVV.
Tip payments: If you make a tip payment, we record the amount and date for our own records. No card details are stored by us.
Log data: Our server may log standard access information (IP address, browser type, pages visited) for security and debugging purposes.
We do not use your information for advertising. We do not sell, rent, or share your personal data with third parties for marketing purposes.
Stripe: Payment processing is handled by Stripe, Inc. When you subscribe or tip, you are interacting with Stripe's secure checkout. Stripe's privacy policy applies to information you provide during payment. See stripe.com/privacy.
Market data: Chart data is sourced from Yahoo Finance via the yfinance library. No personal information is shared with Yahoo Finance.
Hosting: The Platform is hosted on Railway. Server infrastructure data is subject to Railway's privacy policy.
We retain your account data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law or for fraud prevention.
Your annotations and drawings are deleted automatically when your account is deleted.
We take reasonable measures to protect your information, including password hashing, HTTPS encryption, and secure session management. However, no method of transmission over the internet is 100% secure.
You have the right to:
To exercise any of these rights, please contact us through the Contact page.
The Platform uses a single session cookie to keep you logged in. This cookie is essential for the Platform to function and does not track you across other websites. No advertising or analytics cookies are used.
The Platform is not intended for users under the age of 18. We do not knowingly collect personal information from minors.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Continued use of the Platform after changes are posted constitutes acceptance of the revised policy.
Questions about this Privacy Policy? Visit our Contact page.