Nyquist
What we collect, why, who processes it and how long it stays. Last updated 6 September 2026.
Nyquist is a pre-incorporation project operated by its founder. Until a legal entity is formed, the founder is the data controller for the data described here. Company details will be published on the Company page upon incorporation.
Nyquist (“we”) operates the Nyquist platform and the websites at
app.nyquist.pro, demo.nyquist.pro, research.nyquist.pro and
discovery.nyquist.pro (together, the “Service”). This policy explains what personal data we
collect, why, and what you can do about it. It applies to visitors, people who request access, and
account holders. Questions go to contact@nyquist.pro.
We are a business-to-business service for investment funds and other professional organisations. We do not offer the Service to consumers.
When you request access or register we collect your e-mail address, name, firm and role. When you sign in we record the time, IP address and browser identifier of the session for security. If you write to us, we keep the correspondence.
Portfolios, positions, trades, watchlists, documents and other data you upload or enter are processed only to deliver the features you use — risk and stress calculations, agent debates, reports. We do not sell this data, we do not share it with other customers, and we do not use it to train models.
Our servers log each request (path, status, timing, IP address, browser identifier). Before a log line is written, a redaction filter masks e-mail addresses, tokens, phone numbers, passwords and API keys that might appear in it.
We measure website traffic with three tools, none of which sets a cookie. Cloudflare Web Analytics is a JavaScript beacon that counts page views and load times in aggregate, without identifiers. Umami is analytics software we run ourselves on the same Azure server as the platform: page views, referrers and clicks on our pages, and that data never leaves our infrastructure. PostHog (EU region) is product analytics — which pages and features are used, and in what order. PostHog keeps a random identifier in your browser’s local storage so that page views from the same browser can be joined into one visit; it is not linked to your name or e-mail, it does not follow you across other sites, and session recording is switched off. Signed-in platform users may be identified to PostHog by an internal account number only — never by name or e-mail.
Signed-in users receive a session token so the platform knows who you are. Your theme choice and the PostHog analytics identifier are kept in your browser’s local storage. We set no advertising or third-party tracking cookies.
Where the GDPR applies, our legal bases are performance of a contract (providing the Service), legitimate interests (security, product improvement, responding to you) and legal obligation.
Agent debates and other language-model features send a prompt to a third-party inference provider — NVIDIA NIM or OpenRouter. The prompt contains what the request needs: the ticker or question you asked, and the slices of your data the agents were asked to reason about. Your account credentials and vendor keys are never included. We do not train models on customer data; the provider processes the prompt under its own terms to return a completion.
We use the following third parties to run the Service. Each processes data only as needed for the purpose listed.
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, databases, encrypted backups | EU (Sweden Central) |
| Resend | Transactional e-mail (access confirmations, invitations, notices) | United States |
| Cloudflare | Web Analytics beacon (cookieless page-view counts) | United States (global edge) |
| Umami (self-hosted) | Website analytics on our own server — first party; data stays on the Azure host above | EU (Sweden Central) |
| PostHog | Product analytics (page and feature usage; local-storage identifier) | EU (Frankfurt) |
| NVIDIA NIM / OpenRouter | Language-model inference for agent features (prompts only) | United States |
We will update this list before adding a subprocessor that handles customer data.
You can act on your data directly from your account or by writing to us:
GET /api/auth/me/export).POST /api/auth/account/delete); everyone can ask for deletion by e-mail.Requests go to contact@nyquist.pro with the subject “Data protection”. We may ask you to confirm the request from the e-mail address on the account.
All traffic is encrypted in transit (TLS with HSTS). Passwords are stored as bcrypt hashes and, at registration and sign-in, checked against known-breach lists using a privacy-preserving lookup. Administrator accounts use two-factor authentication. Vendor keys you store with us are encrypted at rest per user. Every data lookup is scoped to the owning account, and the application connects to the database under a role that cannot bypass row-level access policies. Sensitive operations are written to a tamper-evident audit chain whose integrity can be verified. The full picture is on the Security page.
No system is perfectly secure. If you believe you have found a vulnerability, please tell us at contact@nyquist.pro.
We will change this policy as the Service changes and update the date at the top of this page. Account holders are notified of material changes by e-mail.
Data controller and data-protection contact: Nyquist (a pre-incorporation project operated by its founder — see “Who we are”), contact@nyquist.pro. Company details are on the Company page.