Who is responsible
Sergio Valle Zarate, México. Contact: hola@rigorscore.com.
What we keep
The files you upload (platform report, optimisation export, equity curve, trades, benchmark, variants) and the SHA-256 hash of each.
What you declare in the form, including the optional description, and the report produced from it.
The IP address the upload came from, to enforce the limit of 10 uploads per hour per address and to stop abuse.
A hash of your report's private token, never the token itself.
When you pay by card: the Stripe checkout session id, the payment date and, for a pack, the hash of the pack's access code.
For a Checkout order, we keep the billing country you declare before payment and, when Stripe provides it, the billing country observed by Stripe. Both are linked to the order to check market availability and reconcile a charge.
Stripe receives your card details, the e-mail address you type on its checkout page (it sends the receipt there) and your card's country, plus the report id and whether you bought one report or the pack. Stripe processes them under its own policy: https://stripe.com/privacy. We never see your card details.
When you redeem an access code: which code unlocked the audit, by its internal id. Codes are stored only as a hash.
When you publish a verification page: its public id and the date.
When you download your report as a PDF or JSON: the SHA-256 hash of that file, so anyone holding it can check at /check that it was not edited. A file checked there is read and discarded, never kept.
When you join the updates list: your e-mail address.
If you create an account: your e-mail address, a scrypt hash of your password (never the password), which reports and access codes are on it, and a hash of each sign-in session. There is no e-mail check yet and we send no e-mail.
To count free previews: which account used each one, when, and the network address it came from. The address is cleared with the rest after 30 days.
For the free first full report: a random identifier of your browser (a cookie named rigor_device, stored by us only as a hash), the SHA-256 of the file, a SHA-256 of your e-mail in its basic form (lower case, without anything after a '+' and, for Gmail, without dots) and the network address, so the same browser, file or inbox gets it only once. The address is cleared after 30 days; the three hashes stay, even if you delete your account and without your e-mail in clear text, so the offer cannot be repeated.
If a shared browser or network holds back that free report and you verify a card for it: Stripe checks the card without charging it, and we keep only a SHA-256 of the fingerprint Stripe gives that card (never its number) and the date, so each card gives one free report. The date goes with your account; the hash stays, like the three above.
For 'Invite a colleague': each account's invite link, and for an account created through someone's link, the date, whether its free first report happened and the hash of its browser identifier, to refuse self-invites. The inviter sees only counts, never who joined. It is deleted with the inviter's account; when the account that joined is deleted, its row keeps only the dates and the outcome under a random id (no e-mail, no browser hash), so the monthly limit still holds.
If you make a recovery key: only its SHA-256 and the date it was made, never the key, which is shown to you once. It is deleted when you use it, when you make a new one or with your account.
If you turn on two-step sign-in: the secret your authenticator app shares (needed to check its codes) and the last code step used, so a code works once. It is deleted when you turn it off, when you use your recovery key or with your account.
If you add a passkey: its credential id, its public key (never the private key, which stays on your device), the name you give it, the site address it was made for, the device's counter and when it was added and last used. It is deleted when you remove it or with your account.
For 'Open sessions' in your account: for each session, a short device label (such as 'Chrome · Windows', never the browser's full string), the network address (an IPv6 address counts as its /64) and when it was last used. It is deleted when the session is signed out or expires, or with your account.
For 'Recent activity' in your account: each sign-in (with or without a code, or with a passkey), each change of password, two-step sign-in, recovery key or passkeys and each session signed out, with its date, the short device label and the network address. We keep the latest 50, and delete them after 90 days and with your account. Separately, when someone types a wrong password for your account: how many tries there were per network and hour, the device label and the time of the last one, never the e-mail or password typed; we keep the latest 20 lines, and delete them after 90 days and with your account. And for each browser you open 'My account' with, the time of its last visit and its label, kept under the hash of its random mark (the same cookie as the free report), only to tell you what happened since; it is deleted after 90 days without a visit or with your account.
To know which of our own links brings visitors: visits to the home and case pages are counted per day, language and link tag (such as ?ref=f4 in a link we posted), with no address; a cookie named rigor_seen holds only today's date so a browser counts once a day. When you arrive from a tagged link, a cookie named rigor_ref keeps only that tag for 30 days, and if you create an account the tag is kept with it until you delete the account.
What we do not keep
We never ask for or store broker or exchange keys, trading account passwords or card details. There is no third-party analytics or advertising on these pages. The only cookies are our own: one that keeps you signed in, one that protects the sign-in forms, one that marks your browser for the free first report, one that remembers which of our links brought you and one with today's date to count a visit once; none tracks you across sites or is shared. Our own access log keeps only a shortened address (the last part of the IP is removed) and never the report link's secret. Our hosting provider may keep its own request logs, with full IP addresses, for its own retention period.
What it is used for
To produce and show your report, to enforce the upload limit, to record a payment or a redeemed code, to show a verification page you chose to publish, and to write to the updates list. We do not sell or share your data and do not use it for advertising.
How long we keep it
Unpaid audits: after 30 days we delete the files, the report, what you declared and the description. The id, the file hashes, the class and the date remain so the record stays checkable.
The upload IP address is deleted in that same clean-up after 30 days, for paid audits too.
Paid audits and your free first full report: kept so you can reopen the report, until you delete them with your account or ask us to delete them.
Verification page: public until you withdraw it from your report or ask us to withdraw it or to delete the audit. If you published it, the clean-up keeps only what that page shows (class, dimension statuses, hashes, dates, trial counts and engine version), so the page and its badge keep working.
Updates list: until you ask to be removed.
Account: until you delete it from your account page or ask us to. Deleting it removes the e-mail, the password hash, the sessions and the list of your reports and codes; the reports follow the rules above unless you choose to delete them too. A sign-in session ends after 30 days or when you sign out.
Who can see it
Only the operator, and the hosting and database providers that store it for us. Stripe sees what it needs to take a card payment. A verification page, only if you publish it, shows the class, the dimensions, the hashes, the date and a fixed notice; never your files, trades, description or token.
The data may be hosted outside your country, on the servers of our hosting provider.
Your rights
Write to hola@rigorscore.com to ask for access to, a copy of, or the deletion of your data. To show the audit is yours, include its private link. Deletion removes everything we hold on that audit: files, report, hashes, class and verification page. To leave the updates list, write from that address. You can delete your account yourself from your account page, and download a copy of what it holds there ('Download my data'). We answer within 30 days.
You can also complain to the data protection authority of your country.
Changes
Changes are posted on this page with a new date.