Privacy Policy

Last updated: 18 November 2025

1. Introduction

Arclay Group Ltd ("Arclay Group", "we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use Quill Ledger (the "Service").

2. Data Controller

For the purposes of UK data protection law, Arclay Group Ltd is the data controller of your personal data processed in connection with the Service.

If you have questions about this Privacy Policy or how we handle your data, you can contact us at support@quillledger.com.

3. Information We Collect

3.1 Information You Provide

  • Account Data: When you register, we collect your email address, username, and a salted and hashed password.
  • Profile Data: Information you choose to provide during onboarding or in your settings, such as age range, country, investment style, and financial goals.
  • Manual Portfolio Data: Assets you add manually, including ticker symbols, quantities, purchase prices, and notes.
  • Forum and Community Content: Posts, comments, messages, and other content you submit to community features.

3.2 Linked Broker and Data Integrations

When you connect accounts from third-party providers (such as Trading212, Interactive Brokers, or future supported brokers), we may receive:

  • Holdings and positions;
  • Transaction history;
  • Cash balances;
  • Account identifiers required to fetch data.

Broker API keys, access tokens, and similar secrets are encrypted at rest using industry-standard encryption.

3.3 Automatically Collected Information

  • Usage Data: Information about how you interact with the Service, such as pages viewed, features used, and general usage patterns.
  • Device and Log Data: IP address, browser type, operating system, device identifiers, and timestamps.
  • Cookies and Local Storage: We use essential cookies and/or similar technologies to keep you logged in, remember preferences, and protect your account. We do not use third-party advertising or tracking cookies.

4. How We Use Your Information

We process your personal data on the following legal bases: performance of our contract with you, our legitimate interests in operating and improving the Service, and compliance with legal obligations.

We use your data to:

  • Operate, maintain, and provide the Service and your Quill Ledger account;
  • Fetch, analyse, and display your portfolio and financial data;
  • Generate AI-assisted insights based on your profile and portfolio;
  • Process subscription payments via Stripe;
  • Monitor and improve the security, performance, and usability of the Service;
  • Communicate with you about updates, security alerts, and support;
  • Comply with applicable laws and regulations.

5. Sharing of Your Information

We do not sell your personal data. We only share your information with third parties where necessary to operate the Service, or where required by law.

5.1 Service Providers

We use trusted third parties to help us operate Quill Ledger, including:

  • Render: hosting and infrastructure provider for the application and database;
  • Stripe: payment processor for subscription billing;
  • OpenAI: AI model provider used to generate insights; we use their zero-retention API configuration;
  • EOD Historical Data and yFinance: market data providers for quotes and enrichment;
  • Other future brokers and data providers you choose to connect.

These service providers only process your data on our instructions and under appropriate contractual safeguards.

5.2 Legal and Compliance

We may disclose your information if required to do so by law or in response to valid legal requests, including to regulators, law enforcement, or courts.

6. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Service. After you delete your account:

  • Your personal profile and portfolio data are removed from our production systems within approximately 30 days;
  • Backups may retain data for up to an additional 30 days before being overwritten;
  • Forum content may be anonymised rather than deleted, so that discussions remain readable;
  • Aggregated or anonymised data that does not identify you may be retained for analytics and service improvement.

7. Your Rights

Under UK data protection law, you have the following rights:

  • Right of Access: To request a copy of the personal data we hold about you.
  • Right to Rectification: To have inaccurate or incomplete data corrected. You can edit much of your data in your account settings.
  • Right to Erasure: To request deletion of your personal data in certain circumstances, for example by using the "Delete Account" function.
  • Right to Restrict Processing: To request that we limit how we use your data in specific situations.
  • Right to Data Portability: To request your data in a structured, commonly used format.
  • Right to Object: To object to certain types of processing carried out on the basis of our legitimate interests.

You can exercise these rights by contacting us at support@quillledger.com. We may need to verify your identity before responding.

8. International Data Transfers

Your information may be transferred to, and processed in, countries outside the UK, including where some of our service providers are located (for example, hosting or AI providers). When we transfer data internationally, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms to ensure your data remains protected.

9. Security

We take appropriate technical and organisational measures to protect your personal data, including encryption at rest and in transit, strict access controls, and secure development practices. However, no system can be completely secure, and we cannot guarantee absolute security.

More detail is provided on our dedicated Security page.

10. Children

The Service is intended for users aged 18 and over. We do not knowingly collect or process personal data of children. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you, for example by email or a notice within the Service. The "Last updated" date at the top of this page will indicate when the Policy was last revised.

12. Contact and Complaints

If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us at:

Email: support@quillledger.com

If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).