Privacy Policy
last updated 23 Aug 2026 · questions: support@mail.quants.sh
This explains what CLR3 Ventures collects when you use quants.sh, why, and how data moves through the service. The short version: we keep what is needed to run your account and bill you; your code, private keys, provider credentials and trading data stay on your machine. Browser prompts and agent transcript events pass through our control plane while they are relayed to and from that machine.
[01]What we collect
- Account: name, email address, a hash of your password, two-factor settings, notification preferences, editor preferences.
- Billing: plan, its status, your wallet and AI-credit balances and statement, your deposit code, and the public keys and signatures of SOL deposits you send us. We never hold your private keys and never see a card, because we accept none.
- Transactions balance: your deposit memo, deposits observed on-chain (signature, amount, sender address) and the running balance.
- Machine metadata: machine size, status, public IP, box software version, resource usage samples (CPU, memory, disk, network totals) and container names.
- Workspace metadata: project names, image tags and digests, session start/stop times and exit reasons, agent thread titles, and approval decisions. Not the content of your files or threads.
- Security log: sign-ins, password and 2FA changes, key changes, with IP address and browser family.
- Support email you send to support@mail.quants.sh.
[02]What stays on your machine
Your source code, built images, persistent agent transcript files, the transaction ledger, private keys your software uses, provider credentials, and anything else in the filesystem live on your dedicated machine. We do not copy those files to our systems. Feed traffic passes through the private channel on your machine and is not logged by us beyond per-session counts used for safeguards and billing.
The agent pane connects through the quants.sh control plane. Our API and WebSocket endpoints terminate the browser connection and relay prompt and transcript events in plaintext at the application layer to and from the agent on your machine. TLS protects those connections in transit, but this is not end-to-end encryption from our infrastructure and the control plane can technically access the relayed content while processing it. We do not use prompt or transcript content to train models, intentionally write it to application logs, or intentionally retain it after relay.
[03]How we use it
To provide the service (provision and operate the machine, route feeds, bill you, notify you), to keep it secure (rate limiting, abuse detection, the security log), to support you when you ask, and to meet legal obligations. We do not sell data and we do not use your data to train models.
[05]Retention
Account and billing records are kept while the account exists and for 7 years after for tax and accounting purposes. Security logs are kept 12 months. Usage samples are kept 7 days on the machine and 30 days in the control plane. Your machine and its contents are kept while your account exists (see the Terms, section 8) and destroyed when the account is deleted.
[06]Security
Passwords are hashed with Argon2id. Secrets we must store (recovery codes, certificates) are encrypted at rest. Control-plane traffic to your machine uses mutual TLS with per-machine certificates. Two-factor authentication is available and required for sensitive actions when enabled. Staff access to production is limited, logged and used only for operating the service.
[07]Your rights
You can view and change your profile, preferences and keys in Settings, download your projects from the workspace or over SSH, and delete your account yourself. Email us to request a copy of the data we hold about you, to correct it, or to have it erased where we are not required to keep it. We answer within 30 days. Residents of the EU/EEA and UK have the rights set out in the GDPR; Canadian residents, those under PIPEDA.
[09]Changes and contact
If this policy changes materially we email you before the change takes effect. Questions or requests: support@mail.quants.sh.