De Nederlandse vertaling is in voorbereiding. Tot die tijd is de Engelse versie hieronder leidend.
Privacy Policy
Last updated: 25 September 2026
1. Data controller
Next Step L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates — [email protected].
This policy applies to the website cubrik.ai, the Cubrik web application and the Cubrik mobile application. For users located in the European Economic Area, the United Kingdom or Switzerland, we apply the principles of the GDPR / UK GDPR.
2. What Cubrik does with your money — nothing
Cubrik holds no funds, takes no custody of any asset, and is not a broker. It has no trading account of its own, simulated or otherwise: it drafts strategies, tests them against historical market data, and runs agents that report to you — and that act only through a service of your own that you connected and allowed them to use.
You may connect your own accounts and tools to Cubrik through an MCP connector — your broker's, your exchange's, or one you run yourself. When you do, you authorise that service directly, in its own screen, and we store the access token it issues so that your agent can use it. That token is the only credential of yours we ever hold: never a password, and never your card details. You choose which of the connected service's tools your agent may use; none of them are available to it until you switch them on, and you can disconnect at any moment, which deletes the token there and then rather than thirty days later.
Where money moves as a result, it moves on the connected service, under the agreement you have with that service and on instructions you approved. Cubrik never touches it.
3. Data we collect
Account data: your e-mail address, and the display name and form of address you choose. There are no passwords. You sign in with a single-use code we e-mail you, or with Sign in with Apple or Sign in with Google; where you use one of those, we receive the e-mail address you agreed to share and, if the provider sends it, your name.
Billing data: the plan you subscribe to, payment history, and country and tax identifier where applicable. Plans are bought on our website, never inside the mobile application. Card details are collected and processed directly by our payment provider; we never see or store them.
Configuration data: the strategies you write, the instructions you give your agents, their triggers and their limits, the standing instruction you may set for the chat, and your preferences.
Agent activity: what your agents did on each run — the market data they read, the tools they called, what they did or were refused on a service you connected, and the reports they wrote. This is what the run history and your notifications are built from.
Analyses: where you analyse a service you connected, the trades read from it and the figures computed from them.
Connector data: for each connector you add — the name you gave it, the address of the server, and the access token that server issued, which is encrypted before it is written and is never shown again: not to you, not to our support, not in our administration tools. We also keep the list of tools that server offers, which of them you enabled, and a line for each call your agent makes through it — which connector, which tool, when, and whether it worked. What the call contained is not recorded: those are your trading instructions, and one copy of them is enough.
Conversations: what you write to the agent, the files and images you attach to a message, and what it replies.
AI consent: in the mobile application, whether you allowed your data to be sent to the artificial intelligence service it names (section 5), the version of that notice you agreed to and when — and when you withdrew it, if you did.
Technical data: IP address and the approximate country, city and time zone derived from it, device and browser type, timestamps, session identifiers. The approximate location is shown back to you in your list of sessions so that you can recognise a sign-in that is not yours; it comes from the network address of the request and never from your device's location services, which the Service does not use and does not ask for.
Mobile notifications: if you turn them on, the notification token your device issues, so that an alert can reach that device.
Messages we send you: a record of the transactional e-mails sent to you — the recipient, the kind of message and the time. The content of a message carrying a one-time code is never stored.
Support: the content of your exchanges with our support team.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Service: answering you in the chat, running your agents and your backtests, producing your analyses | Performance of the contract |
| Sending your data to an artificial intelligence service from the mobile application | Your consent, asked in the application before anything is sent and withdrawable at any time in Settings |
| Billing, accounting | Legal obligation / contract |
| Security, fraud and abuse prevention | Legitimate interest |
| Support and service communications | Contract / legitimate interest |
| Improving the Service (aggregated statistics) | Legitimate interest |
| Marketing e-mails | Consent (withdrawable at any time) |
5. Processors and recipients
We share data only with the providers needed to operate the Service. Those that process your data on our behalf are bound by contract to use it only to provide their service to us, and to protect it to a standard at least equal to this policy:
- Amazon Web Services (Frankfurt, eu-central-1): hosting and transactional e-mail.
- Artificial intelligence. The answers in the chat, the work of your agents and the written part of your analyses are produced by artificial intelligence models. The model receives what a request needs: your messages and the files you attach, the name or form of address you asked to be called by, your standing instruction, the strategies and agents concerned, and what the agent read from a service you connected. It uses it to produce the answer.
- Amazon Bedrock, the artificial intelligence service of Amazon Web Services, which we use inside our own AWS account in the European Union. It is the service the mobile application uses by default. Your data is not shared with anyone else — the company that made the model included — and it is not used to train any model. AWS may keep it for a limited time to detect abuse, under its own terms.
- Some of the models the web application offers, its default model among them, are run by other artificial intelligence providers. A request to one of them, or a strategy you ask to have scored, is processed by the provider that serves it, under its own terms.
- In the mobile application, nothing is sent to an artificial intelligence service until you have been told which one and have allowed it. You can withdraw that permission at any time in Settings, under AI data sharing; doing so also pauses your running agents, since their work is your data going to the same service.
- MongoDB Atlas (Frankfurt): the database in which the data described above is stored.
- Cloudflare: serves the website and the applications and terminates the connection; it processes request metadata, including your IP address.
- Payment provider (Stripe): processes subscriptions bought on our website.
- Apple: where you turn on notifications, your device token and the notification pass through Apple's Push Notification service. Where you use Sign in with Apple, Apple tells us the address you chose to share.
- Google: where you use Sign in with Google, Google tells us your e-mail address and your name.
- The services you connect yourself: where you add a connector, the requests your agent makes go to that server and what it returns comes back to us. That service is not our subcontractor — it is yours, under the terms you accepted with it. We do not choose it, we do not control which tools it offers, and we cannot see what it does with a request once it has one.
We use no advertising, analytics, attribution or crash-reporting service, and we set no cookie that is not strictly necessary to keep you signed in. We do not sell your data and we do not share it for anyone else's purposes. We may disclose data to authorities where the law requires it.
6. International transfers
Our providers may be located outside your country, notably in the United States and the United Arab Emirates. A request to a model run by another artificial intelligence provider is processed in that provider's country, which can be outside the European Union. For data of persons located in the EEA, the United Kingdom or Switzerland, we rely on the European Commission's standard contractual clauses or an equivalent mechanism.
7. Retention periods
- Account, configuration and conversations: for the duration of the relationship, then 30 days after closure.
- Agent run logs and analyses: 24 months, then anonymised.
- AI consent record: for the duration of the relationship, then 30 days after closure.
- Record of e-mails sent to you: 12 months.
- Billing: 10 years (accounting obligations).
- Technical and security logs: 12 months.
- Connector access tokens: until you disconnect that connector or close your account, whichever comes first — deleted immediately in either case, not after a delay.
- Sessions: expire within 7 days of their last use.
8. Your rights
You may access your data, rectify it, erase it, request its portability, restrict or object to its processing, and withdraw your consent. In the mobile application, you can withdraw your consent to sending your data to an artificial intelligence service at any time in Settings, under AI data sharing. You can delete your account, and everything listed above with it, from inside the application at any time — Settings, then Delete account. Other requests go to [email protected] and are answered within 30 days. You may lodge a complaint with the data protection authority of your country of residence.
9. Security
Encryption in transit (TLS) and at rest, secret isolation, least-privilege access control, access logging, encrypted backups.
A connector's access token is encrypted with a key of its own before it is written, and that key is itself stored encrypted, apart from the database holding the token. It is never written to a log, never returned by any of our interfaces and never visible in our administration tools. No system is infallible; in the event of a breach affecting your data, we will notify you within the timeframes the law requires.
10. Minors
The Service is not available to anyone under 18, or under the age of majority where they live. We do not knowingly collect data relating to them.
11. Changes
Any material change will be notified by e-mail or in the application.
Laatst bijgewerkt: 25 September 2026