Legal
Privacy Policy
What this policy covers
This policy describes how OverfitCheck (“we”, “us”) collects, uses, and protects information you provide when using OverfitCheck at overfitcheck.com. By using the service, you agree to the practices described here.
Information we collect
Account information. When you sign up, we collect your email address and a hashed password (or a Google OAuth token if you sign in with Google). We do not collect payment card numbers. Stripe handles all billing data directly.
Backtest data. When you upload a file for analysis, we receive the trade records in that file: dates, entry/exit prices, profit/loss values, and any metadata columns you include. We also store the computed statistical results (score, test outputs, confidence intervals).
Usage data. We log API requests for error monitoring and rate limiting. Logs include timestamps, IP addresses, and endpoint names. We do not log file contents in application logs.
Payment data. Billing is handled entirely by Stripe. We store your Stripe customer ID to link your account to your purchases. We never see or store card numbers, CVVs, or bank account details.
How we use your information
- To run statistical analysis on your uploaded backtest data and return results
- To manage your account, authenticate you, and enforce plan limits
- To process payments via Stripe
- To send transactional emails (account confirmation, billing receipts). We do not send marketing emails without your explicit consent
- To monitor for errors and maintain service reliability
Your strategy data is never used to train AI models and is never sold to third parties.
Subprocessors
We share data with the following third-party services to operate OverfitCheck:
Data retention
We retain your account and audit data for as long as your account is active. If you delete your account, we will delete your personal data and audit records within 30 days of receiving your deletion request. Anonymized aggregate statistics (not linked to any account) may be retained indefinitely for product improvement.
Stripe retains billing records for legal and tax compliance purposes per their own retention policy.
Your rights
You may request access to, correction of, or deletion of your personal data at any time. To make a request, use the account deletion option in your account settings or email us at support@overfitcheck.com. We will respond within 30 days.
Account deletion requests are honored within 30 days of receipt.
Cookies and local storage
We use Supabase Auth session tokens stored in browser cookies to keep you signed in. We also store a small preference flag in localStorage to remember UI state (such as whether you have dismissed an informational banner). We do not use advertising or tracking cookies.
Security
All data in transit is encrypted via TLS. Data at rest is encrypted by Supabase on AWS. Row-Level Security is enforced on all database tables. You can only access your own data. We do not store raw uploaded files after analysis is complete.
Children
OverfitCheck is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we will delete it promptly.
Changes to this policy
We may update this policy from time to time. We will post the updated policy at this URL with a revised “Last updated” date. Continued use of the service after a policy change constitutes acceptance of the updated policy.
Contact
Questions about this policy: support@overfitcheck.com
Governing law: Washington State, United States.