This statement describes how Replicurve handles information when you visit our website, request API access, or call the replication API. It reflects actual system behavior as of the effective date above.
1. Scope
This statement covers the Replicurve marketing site, API, and related support correspondence. Enterprise deployments (on-prem or VPC) may follow separate agreements.
2. What we store
API key records
When we issue an API key, we store a record keyed by the API token, including plan tier, customer or organization name, active status, creation and expiry dates, and optional per-key configuration (monthly limits, overage flags). This file does not contain return series from your API calls.
Usage metering
Each successful POST to /v1/replication or
/v1/offset increments a per-key counter for the current
calendar month. We store only integer counts — not request bodies,
tickers, or output weights. /v1/validate and health checks
are not metered.
Correspondence
Email you send to api@replicurve.com (for example when requesting a key) is retained in our mail system for support and billing purposes.
Web server logs
Our reverse proxy may log standard access metadata: timestamp, client IP address, HTTP method, URL path, response status, and user agent. These logs support security and operations. They do not include request body content by default.
3. What we do not persist from API requests
Return series and other fields in POST bodies are processed
in memory to compute responses. The application does not write request
payloads or response bodies to disk as part of normal operation.
Preset universe names (for example "sp500") may trigger
reads from a local market-data cache of publicly available prices. That
cache is not derived from your custom basket submissions.
4. How we use information
- Authenticate API requests and enforce plan limits.
- Operate, secure, and improve the Service.
- Respond to support and sales inquiries.
- Invoice and administer paid subscriptions.
- Meet legal obligations where required.
We do not sell personal data. We do not use API return series for model training or product analytics.
5. Retention
- Usage counts — retained by calendar month for billing and limit enforcement; older months may be archived or deleted on a rolling basis.
- API key records — retained while the key is active and for a reasonable period afterward for audit and billing.
- Server logs — typically rotated within 90 days unless longer retention is required for an investigation.
- Email — retained per our mail provider’s policy and operational needs.
6. Processors and hosting
The Service runs on infrastructure we operate or contract with (cloud hosting, email, and networking providers). Those providers process data only to deliver the Service on our instructions. A list of subprocessors is available on request for customers who need it for vendor due diligence.
7. International transfers
If you access the Service from outside the country where our servers run, your information may be transferred to and processed in that jurisdiction. We apply appropriate safeguards where required by applicable law.
8. Your rights
Depending on your location (including the EU/UK under GDPR), you may have rights to access, correct, delete, restrict, or object to processing of personal data, and to data portability or to lodge a complaint with a supervisory authority.
To exercise these rights, contact api@replicurve.com. Because we do not retain API payload content, deletion requests generally apply to account metadata, correspondence, and logs — not to return series already discarded after processing.
9. Data Processing Agreement
Customers who need a Data Processing Agreement (DPA) for GDPR or similar regimes may request our standard template at api@replicurve.com. Paid plans and enterprise agreements can incorporate the DPA by reference.
10. Security
API access requires bearer tokens over HTTPS. Keys should be stored as secrets in your environment. We apply reasonable technical and organizational measures appropriate to the nature of the data we hold. No method of transmission or storage is completely secure.
11. Changes
We may update this statement when our practices change. The effective date at the top will be revised accordingly. Material changes will be communicated where practicable.
12. Contact
Privacy and data-processing questions: api@replicurve.com. See also our Terms of Service.