This page is being reviewed and may change.
Privacy Policy
Uncertain (uncertain.fyi)
Effective date: October 8, 2026
Last updated: October 8, 2026
Uncertain is a research digest run by one person, an individual based in Toronto, Ontario, Canada ("I", "me"). This policy explains what information the site collects, why, where it is kept, who else handles it, and what you can do about it.
Please note before signing in: there is not yet a way to contact me or to delete your account (sections 7 and 9). Until there is, don't sign in or connect a broker unless you're comfortable with your account record staying on the site.
The short version:
- You can read the site without signing in. If you do, I don't collect anything about you beyond what every web server logs (see "Server logs").
- If you sign in with Google, I store your Google name, email address, profile-picture link and Google account ID, plus whatever you save on the site.
- If you connect a brokerage account, I store your API keys for it in encrypted form and use them only to read your own account and send the orders you ask for.
- Your information is stored and processed in the United States, not Canada.
- There are no ads, no tracking pixels and no third-party analytics scripts.
1. What I collect
1.1 Everyone, signed in or not: server logs
When your browser requests a page, the web server (nginx) records a standard access-log line:
- your IP address
- the date and time
- the page or file requested
- the referring page, if your browser sends one
- your browser's user-agent string (browser and operating system)
- the response status and size
The site's traffic runs through Cloudflare, so Cloudflare also sees these requests (see section 4).
I use these logs to keep the site running, to spot abuse, and to produce a private traffic report (pages viewed, referrers, rough visitor counts). That report is built on my own server with a log-analysis tool (GoAccess). IP addresses are anonymized in the report itself, but the raw logs contain full IP addresses. The report is password-protected and only I can see it.
The site's API (the part that handles sign-in and portfolios) also writes application logs, which include the request path, time and IP address. Email addresses, tokens, keys and secrets are filtered out of the request details in these logs. The scheduled job that sends queued broker orders (section 2.1) keeps its own log of order numbers, ticker symbols, order statuses and any error message the broker returns.
1.2 If you sign in with Google
Sign-in is through Google only. I ask Google for your basic profile and email address, nothing more (the email and profile scopes). I don't receive your Google password and I don't get access to your Gmail, Drive, contacts or anything else.
I store:
| What | Why |
|---|---|
| Your Google account ID | To recognize you the next time you sign in |
| Your email address | To identify your account |
| Your name | To show you who you're signed in as |
| A link to your Google profile picture | To show your avatar in the header |
| Sign-in sessions (see 1.3) | To keep you signed in |
| Your category filter (which topic categories you chose to see) | So your filter follows you to other devices |
Your name, email and picture link are refreshed from Google each time you sign in.
1.3 Sessions
When you sign in, I create a random session token. Your browser keeps the token in a cookie. The server keeps only a one-way hash of it, so the database alone can't be used to sign in as you. A session lasts 7 days from your last visit. Visiting extends it, and a week without visiting signs you out. Signing out deletes the session.
1.4 Your portfolio
Signed-in users can build a practice portfolio by setting a view on each question. Signed-out visitors don't get a portfolio, and nothing they do on the site is saved on my server (a few display settings stay in their own browser, see section 5). When you save, I store a record of the order:
- when you placed it
- the capital it was sized against (for a practice portfolio, $10,000 of pretend money)
- for each question you took a view on: the question, your probability, the market's consensus probability at that moment, how much you staked, and the dollar amount
- the resulting allocation to each ticker symbol (weight, dollar amount, quantity, price)
Saved orders are never edited or overwritten. Each save adds a new record, so your full history is kept for as long as your account exists. That history is used to show your current holdings, your order history and your profit and loss over time.
1.5 If you connect a brokerage account
Signed-in users can choose to connect their own brokerage account. Right now the only supported broker is Alpaca. To connect, you paste in API keys that you create in your Alpaca dashboard. I store:
- Your API key and secret, encrypted (see section 3)
- whether the account is a paper (simulated) or live account
- the account ID and account status Alpaca reports back
- when the connection was verified
Both paper and live accounts can be connected, and the site can read either. Placing orders in a live (real-money) account is currently switched off; orders can only be sent to paper accounts.
When you use the connection, I also store:
- each order sent to the broker: ticker symbol, buy or sell, dollar amount or quantity, and an order reference
- the broker's updates on each order: status, filled quantity, average fill price, and any message the broker returns
To show your portfolio, the site reads your account's equity, cash, buying power, positions and value history from Alpaca at the moment you view it. These balance and position figures are passed to your browser but not stored in my database.
Your keys are never sent back to your browser. The site only shows the last four characters so you can tell which key is connected.
API keys are financial credentials: anyone holding them can trade in that account. So connecting is a separate, express consent. The connect form says what connecting means and links to this policy and to the Terms.
1.6 Stored in your browser (not on my server)
See section 5.
1.7 What I don't collect
- No payment information. The site is free and takes no payments.
- No advertising identifiers, tracking pixels or third-party analytics scripts.
- Nothing from people who aren't signed in, apart from server logs.
- Nothing I know of from anyone under 18. The site is not meant for them, and signing in requires you to be 18 or older (Terms, section 6). There's no age check, so if you believe someone under 18 has signed in, tell me once a contact address is published and I'll delete their account.
2. Why I use it
I use your information only to:
- run the site and keep you signed in
- save and show your portfolio, order history and performance
- send orders to your connected broker when you ask, and keep track of what happened to them (see 2.1)
- keep the site secure and spot abuse
- understand, in aggregate, which pages people read
- meet legal obligations
I won't use your information for any other purpose without asking you first. I don't sell your information, rent it, share it for advertising, or use it to build marketing profiles.
2.1 Orders that continue after you leave
When you save a portfolio with a connected broker, some orders may have to wait. For example, buys wait until sells finish, or until the market opens. A scheduled job on my server checks in with your broker during market hours to send those queued orders and record their results, even if you have closed the site. It only ever continues orders you already submitted. It never starts new ones.
2.2 Consent
The sign-in menu says that signing in means you agree to this policy, and links to it. That is your consent to the collection described above. Connecting a broker is a separate, express consent: the connect form says so and links here. You can withdraw consent for the broker connection at any time by disconnecting it in Settings. Withdrawing consent to the rest means closing your account, which isn't possible yet (section 7).
3. Where it's stored and how it's protected
- The site's database is a single file on a server I rent from Vultr, in a data centre in the United States.
- Before each update to the site's server software, a copy of the database is saved on the same server so the update can be undone if it goes wrong. The 20 most recent copies are kept and older ones are deleted automatically. Copies are not edited afterwards, so a copy can still hold information you have since changed or removed, including your broker keys (still encrypted) after you disconnect, until that copy is deleted. Copies are kept by count, not by age, so how long that takes depends on how often the site is updated.
- Broker keys are encrypted at rest with Rails' built-in encryption. One application-wide key encrypts every user's credentials. The encryption key is kept apart from the database, so a copy of the database alone doesn't reveal your keys. But because the server has to use your keys to talk to your broker, it can decrypt them. That means I, as the operator, technically could too, although I don't look at them and they're only used for your own account.
- Session tokens are stored only as one-way hashes.
- All traffic to the site is encrypted in transit (HTTPS).
Outside Canada. The server is in the United States, and every service provider in section 4 is a US company (Cloudflare also runs servers worldwide). So your information is stored and processed outside Canada. While it is there it is subject to the laws of that country, and courts, law enforcement and national-security authorities there may be able to access it.
Breaches. No system is perfectly secure. If a breach of your personal information creates a real risk of significant harm, I'll notify you (at the email address on your account) and the Office of the Privacy Commissioner of Canada as soon as feasible, as PIPEDA requires, and I keep a record of every breach.
4. Who else handles your information
| Provider | What they do | What they see |
|---|---|---|
| Sign-in | That you signed in to Uncertain. Your browser also loads your profile picture straight from Google's servers. Google's privacy policy applies. | |
| Alpaca (only if you connect it) | Your brokerage | The orders the site sends using your keys, and the requests that read your account. Your relationship with Alpaca is governed by your own agreement with them. |
| Cloudflare | Network and security proxy in front of the site | Every request to the site, including your IP address. Cloudflare may set its own security cookies. |
| Vultr | Hosts the server and the database, in the United States | Stores the data described here on their hardware |
| Anthropic | Its AI model, Claude, writes the daily research updates and helps me maintain the site's code and server | The research runs use public sources only. When Claude helps maintain the server it can read the database and logs stored there, which include account details. It can't read the encryption key, so it can't decrypt broker keys. |
| GitHub | Hosts the code and runs deployments | Code only. No user data or database copies pass through it. |
Each provider handles what it sees under its own terms and privacy policy, which I don't control. I don't share your information with anyone else unless the law requires it (for example a valid court order), or it's needed to protect the site, its users or me from fraud or harm.
5. Cookies and browser storage
Cookies
| Name | Set by | Purpose | Lasts |
|---|---|---|---|
session_token |
uncertain.fyi (first-party) | Keeps you signed in. Only set after you sign in. HttpOnly (page scripts can't read it), Secure, SameSite=Lax. | 7 days from your last visit, or until you sign out |
_uncertain_api_omniauth |
uncertain.fyi, when you sign in | Protects the Google sign-in round trip from forgery. Holds no personal information. | Until you close your browser |
Cloudflare cookies (e.g. __cf_bm) |
Cloudflare | Bot and abuse protection, if Cloudflare decides to set them | Set by Cloudflare, typically short |
Local storage. The site also saves a few small items in your browser's local storage. These never leave your device unless noted.
| Key | Purpose |
|---|---|
session-hint |
A copy of your name, email, profile-picture link, user ID and the questions you hold a view on, so a newly opened tab can show you as signed in right away. It holds no password or token, and it's cleared when you sign out or your session ends. |
topic-categories |
The categories you filtered to (also saved to your account if you're signed in) |
portfolio-open |
Whether the portfolio panel was open or closed |
theme |
Light or dark theme, if you picked one |
There are no advertising or cross-site tracking cookies. You can clear cookies and local storage in your browser settings at any time. If you do, you'll be signed out and lose your display preferences.
6. How long I keep it
| Data | Kept for |
|---|---|
| Account details (Google ID, email, name, picture link, category filter) | As long as your account exists. Account deletion isn't available yet (section 7). |
| Sessions | Until sign-out, or 7 days after your last visit. Signing out deletes the session at once. Expired sessions can't be used, and a daily job deletes them. |
| Portfolio orders and history | As long as your account exists |
| Broker keys | Until you disconnect the broker. Disconnecting deletes them from the live database immediately. Database copies made before then may still hold them, encrypted (section 3). |
| Records of orders sent to a broker and their updates | As long as your account exists. They are kept after you disconnect, so your history stays accurate. |
| Web server logs | Deleted by the server's standard log rotation, currently after about two weeks |
| Scheduled-job logs | Up to 30 days. A daily job rotates and deletes them. |
| Application logs | Kept in the server's system journal, which is trimmed by size, not age, so they may be kept longer than 30 days. I intend to cap them at 30 days. |
| Traffic report | Rebuilt every hour from the web server logs still kept. It contains no full IP addresses. |
| Database copies (section 3) | The 20 most recent are kept, however old they are |
7. Your rights
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you can:
- Access the personal information I hold about you
- Correct it if it's inaccurate
- Withdraw consent, for example by disconnecting your broker or closing your account
- Complain to me, and if you're not satisfied, to the Office of the Privacy Commissioner of Canada
There is no contact address yet. These requests need a way to reach me, and there isn't one. Until a contact email is published here, you can't make an access, correction or deletion request, and I can't promise a response time. Once it is published, I'll answer requests within 30 days, as PIPEDA requires. You can complain to the Office of the Privacy Commissioner of Canada at any time.
Wherever you live, I'll handle requests the same way once the contact address exists. Your local privacy laws may give you further rights, and you can complain to your local data protection authority.
Deleting your account
- Disconnect a broker: you can do this yourself in Settings. It deletes your stored keys immediately. Before disconnecting, the site cancels any of your orders that are still waiting to be sent or still open at the broker.
- Sign out: deletes your current session.
- Delete your account: not available yet. There is no delete button and no contact address to ask through. Until one exists, your account, saved filter, portfolio and order history, and broker-order records stay on the site.
When deletion is available, it will remove your account and everything linked to it from the live database. Database copies made before then (section 3) will still hold it until they are deleted. Deleting your data from Uncertain won't affect anything held by Alpaca or Google. Orders already sent to your broker stay in your brokerage account and records.
8. Changes to this policy
If I change this policy, I'll update the "Last updated" date above. If a change is significant (for example, collecting a new kind of information or using it for a new purpose), I'll put a notice on the site before it takes effect, and ask for your consent again where the law requires it.
9. Contact
I'm the person responsible for privacy at Uncertain (PIPEDA's "accountable individual"), based in Toronto, Ontario, Canada. There is no contact email yet. One will be published here. Until then you can't reach me through the site, and the rights in section 7 that need a request can't be exercised.