Skip to content
Constellation
Terms of UsePrivacy Policy
Back to website

Legal · data transparency

Privacy Policy

This policy explains what personal information Constellation handles across the website and account services, plus the safeguards required before the one-button Alpaca Paper connection is released.

Effective and last updated · 15 August 2026

1. Who we are

Constellation is the controller of personal information used to provide the constellation.trade website, Constellation account, macOS application, Observatory, and related customer services. Constellation is operated from the United Kingdom.

For privacy questions or requests, email support@constellation.trade.

This policy does not govern information that Alpaca, Stripe, Apple, or another provider collects as an independent controller under its own terms and privacy notice.

2. Information we handle

Account and contact information

Your email address, community username or display name, account identifier, authentication records, account status, and messages you send to support.

Purchase and entitlement information

Your Stripe customer and Checkout Session identifiers, purchase email, amount, currency, payment status and time, product code, refund or dispute status, and the Constellation features your account may access. Stripe handles card and bank details; Constellation does not receive or store your full payment-card number.

Registered Mac and operational information

Your registered Mac identifier, name, machine fingerprint, hardware and operating-system profile, app version and build, connectivity and heartbeat status, selected settings, credential-presence indicators, configuration history, service errors, and security/audit records. Credential-presence indicators say whether a connection exists; they do not contain the credential itself.

Product and community information

Strategies, versions, descriptions, parameters, validation results, installations, votes, publication and moderation state, workspace records, and other content you choose to store or share through product and community features.

Website, relay and support information

IP address, browser and device information, request time, security and diagnostic logs, essential session identifiers, the active Mac you select, relay connection metadata, support correspondence, and information needed to diagnose a fault or prevent abuse.

Alpaca connection and operational responses

This customer flow is not yet enabled. When released, it is expected to process the short-lived OAuth connection state described below, the identity of the Constellation account and registered Mac being connected, and broker/account, market-data, order, position, or trading-status information requested through your connected local engine and displayed in Observatory.

3. Why we use information and our legal bases

PurposeInformationUK GDPR basis
Provide available purchase, account and product features, and the Mac, OAuth and Observatory features once releasedAccount, purchase, Mac, OAuth, configuration and product records relevant to features you usePerformance of our contract with you
Authenticate you and protect users, accounts, payments, Macs, the relay and ServiceAccount, session, IP, device, ownership, audit, connection and diagnostic informationPerformance of our contract and our legitimate interests in security, fraud prevention and service integrity
Operate and improve reliability, compatibility and customer supportVersion, device, error, support and limited operational informationPerformance of our contract and our legitimate interests in maintaining and improving the Service
Process payments, refunds, disputes, accounting and tax recordsPurchase, entitlement and transaction recordsPerformance of our contract and compliance with legal obligations
Operate optional community featuresUsername, strategies, publications, votes, moderation and install recordsPerformance of our contract and our legitimate interests in running a safe, useful community
Comply with law and establish, exercise or defend legal claimsRelevant account, transaction, audit and correspondence recordsLegal obligation and legitimate interests

Where we rely on legitimate interests, we consider whether the use is necessary and balanced against your rights. We do not currently use your Constellation activity for behavioural advertising or sell your personal information.

4. Alpaca OAuth and Keychain

The planned customer flow never asks for your Alpaca password, API key, or API secret. OAuth is not yet enabled for customers. When it is released, you will sign in and approve the connection on Alpaca’s website.

Before release, the connection must bind the browser request, signed-in Constellation account, and registered Mac with short-lived, one-use state. Alpaca will send the hosted backend a temporary authorisation code. The backend will keep Constellation’s client secret server-side while exchanging that code for a Paper-account bearer token with the permissions shown on Alpaca’s consent screen.

The release design is to deliver that token only to the initiating registered Mac through an authenticated, encrypted, one-use handoff; not to store it permanently in Supabase or the hosted Constellation database. The Mac must verify the Paper account, store the token in macOS Keychain, and let the local engine use it as an Authorization: Bearer credential.

These controls are release requirements, not a claim that the unfinished OAuth path is currently available. This policy will be updated if the verified implementation or retention behaviour differs before launch.

5. Data on your Mac

The engine, local AI model, strategy assets, market and decision records, paper-trading ledger, logs, and related runtime data are designed to reside on your Mac. You control that device and its backups.

When you use Observatory away from the Mac, authenticated requests and responses may pass through Cloudflare so the browser can communicate with your registered engine. The relay is a transport boundary; it is not intended as a permanent store for your Alpaca token or local trading database.

Some information is deliberately stored in the hosted account database—for example your identity, entitlement, registered-Mac metadata, settings, community content and audit records—so the website can authenticate you, confirm ownership, and provide the Service.

6. Cookies and local storage

We use essential cookies and similar local storage needed to sign you in securely, refresh your session, preserve your selected registered Mac, and remember limited interface state. Without these technologies, authenticated parts of the Service will not work correctly.

Constellation does not currently place advertising cookies or third-party behavioural analytics on the website. Stripe, Alpaca, or another site you visit from Constellation may use cookies under its own policy.

7. Who receives information

We share only what is reasonably needed to operate the Service, comply with law, or protect users:

  • Stripe processes Checkout and payment information. See Stripe’s Privacy Policy.
  • Supabase provides authentication, database, and related account infrastructure. See Supabase’s Privacy Policy.
  • Cloudflare provides network protection and the authenticated browser-to-Mac relay. See Cloudflare’s Privacy Policy.
  • Vercel provides hosting and server-side execution for the website and is intended to host the OAuth callback once released. See Vercel’s Privacy Notice.
  • Alpaca provides the separate Paper account, OAuth authorisation, trading API, and market data. See Alpaca’s disclosures and privacy documents.
  • Professional advisers and authorities may receive information where reasonably necessary for legal, accounting, security, insurance, or regulatory purposes.

We may transfer relevant information as part of a genuine reorganisation, financing, sale, or acquisition, subject to appropriate confidentiality and data-protection safeguards.

8. International transfers

Some providers may process information outside the United Kingdom. Where UK data-protection law treats this as a restricted transfer, we use an applicable UK adequacy regulation or appropriate contractual safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and complete any required transfer assessment.

Contact us if you want more information about the safeguard relevant to your information.

9. How long we keep information

  • OAuth state: not currently collected through a customer-facing OAuth flow. Before release, it must be short-lived and one-use.
  • Alpaca bearer token: not currently collected through a customer-facing OAuth flow. The release design is temporary hosted processing followed by Keychain storage until you disconnect or delete it.
  • Account, registered-Mac, configuration and community records: kept while your account is active and then deleted or anonymised when no longer reasonably needed, subject to backups, security, disputes, and legal obligations.
  • Purchase, tax, refund and accounting records: normally kept for up to six years after the relevant transaction or longer where law or an active dispute requires it.
  • Security, diagnostic and support records: kept only for as long as reasonably needed to resolve the issue, protect the Service, and establish or defend legal claims.

Your local engine database, logs, models, and Keychain items remain on your Mac until you remove them or erase the device. Deleting a web account does not automatically erase independent backups or data held by Alpaca, Stripe, Apple, or another provider under its own retention rules.

10. Your privacy rights

Depending on the circumstances, UK data-protection law may give you the right to:

  • ask for a copy of your personal information;
  • correct incomplete or inaccurate information;
  • ask us to erase information;
  • restrict how information is used;
  • object to processing based on legitimate interests;
  • receive information you provided in a portable format; and
  • withdraw consent where consent is the basis for processing.

These rights can have legal exceptions. Email support@constellation.trade to make a request. We may need to verify your identity and ordinarily respond within one month.

Constellation does not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects.

11. Security

We use measures designed to protect personal information, including authenticated sessions and row-level database controls. Account-to-Mac ownership checks, short-lived one-use OAuth state, server-only application secrets, encrypted device delivery, and macOS Keychain storage are mandatory controls for the unreleased Alpaca connection.

No service can guarantee perfect security. Keep macOS and Constellation updated, protect your Mac login and recovery methods, and contact us promptly if you suspect unauthorised access.

12. Children

The Service is for adults aged 18 or over. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information to the Service.

13. Changes to this policy

We may update this policy when the product, providers, or law changes. We will publish the new version here with its effective date and provide additional notice where a change materially affects your rights or how we use information.

14. Contact and complaints

Controller
Constellation
Privacy contact
support@constellation.trade
Website
constellation.trade
Operating location
United Kingdom

We would appreciate the opportunity to resolve a concern directly. You also have the right to complain to the UK Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint for current contact and complaint options.

On this page

  1. Who we are
  2. Information we handle
  3. Purposes and legal bases
  4. Alpaca OAuth and Keychain
  5. Data on your Mac
  6. Cookies and local storage
  7. Who receives information
  8. International transfers
  9. How long we keep information
  10. Your rights
  11. Security
  12. Children
  13. Changes
  14. Contact and complaints
Constellation

Paper trading only. No performance promises.

TermsPrivacyContact