Privacy Policy

Epic Apex Trader

Last updated: 2026-07-24


1. Overview

This Privacy Policy describes how an Epic Apex Trader deployment (“Apex”, “we”) may collect, use, and store information when you use the desk and APIs.

Because Apex can be self-hosted, the deploying operator is the data controller for that instance.

2. Information we collect

Account data

Trading configuration (BYOK)

Trading and wallet activity

Technical data

We do not intentionally collect government ID, biometric data, or full payment card numbers inside Apex. Card payments, if any, are processed by the operator’s payment processor under that processor’s privacy policy.

3. How we use information

4. Multi-tenant isolation

Signed-in users’ portfolio, wallet, journal, and credentials are stored separately. Operators must not use user keys except to operate the service for that user.

5. Sharing

We do not sell personal data. Data may be shared with:

6. Retention

Account and trading records are retained while your account is active and as needed for security and audit. Logs are rotated according to operator policy. You may request deletion of account data from the operator; some records may be retained where required by law or fraud prevention.

7. Security

8. Local storage

The desk may store a JWT access token in browser local storage for session continuity. Clear it via Sign out.

9. Children

Epic Apex Trader is not directed to children under 18 (or the age of majority in your jurisdiction).

10. International users

Data may be processed where the operator hosts infrastructure. You are responsible for ensuring use is lawful where you live.

11. Your choices

12. Changes

Updates will be posted to this document and/or the repository. Continued use constitutes acceptance.

13. Contact

Contact the instance operator or open a private security report via the project’s private repository.