pyvar.com is a product of Fibtec Limited, a company registered in England and Wales under company number 07098379, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ (“Fibtec”, “we”, “us”). This policy explains what personal data pyvar.com collects, why, and what your rights are. Fibtec is the data controller for your account data.
1. What pyvar.com actually stores about a computation
pyvar.com is a deterministic risk-computation engine, not an AI product — results are produced by a Numba-JIT-compiled Monte Carlo/statistical kernel running on our own infrastructure, never by sending your data to a third-party AI model. This matters for what's below, because it means there's nothing beyond what's described here that touches your computation inputs.
A request to compute a risk metric (e.g. Value-at-Risk) typically includes a portfolio value, a series of historical returns (plain numbers — no instrument names, tickers, or counterparty identities are part of this API), and parameters like confidence level and horizon. The historical-returns series itself is used only in memory, for the single computation that needs it, and is never written to a database or object store. What we do keep, as a permanent audit record (see §4), is the job's metadata: your account identifier, the scalar parameters you submitted (portfolio value, confidence level, horizon, simulation count), and the resulting risk metrics — not the raw return series that produced them.
2. Personal data we collect about your account
pyvar.com has one kind of account — there's no separate organisation/company concept, no name, and no physical address collected anywhere in sign-up:
- Your email address — your account identity. Any email address is accepted, including personal ones (no password required to sign up, and no payment card either).
- Authentication data — pyvar.com uses no password at all. Access is via a signed JSON Web Token (JWT) issued after email verification or Google Sign-In (see §3). We hold a per-account identifier used to validate that token, not a password of any kind.
- Billing and usage information, only if you upgrade to a paid tier — see §6.
3. Google Sign-In — what it shares, and what it doesn't
If you choose “Continue with Google”, Google shares your email address and whether Google considers it verified, which we use to either create a new pyvar.com account or sign you into an existing one matched by that email address. Unlike some other Fibtec products, Google Sign-In on pyvar.com can create a brand-new account directly — it isn't restricted to linking an account that already exists, because pyvar.com has no domain-matching or organisation-membership rule for Google to conflict with.
We request only the standard, minimal Google identity scope (your email address and whether it's verified) — nothing about your contacts, files, or any other Google data. Google's own ID token is verified entirely on our servers; it is never forwarded to any third party.
4. How long computation and account records are kept
The job audit record described in §1 (account identifier, submitted parameters, resulting metrics — never the raw return series) is retained indefinitely as a compliance audit trail, consistent with standard practice for regulatory risk-computation records, and is never deleted programmatically.
The full computed result (the complete loss-distribution output, not just the summary metrics stored in the audit record) is kept in object storage for a bounded period — currently up to 90 days in our standard environment, and up to 365 days where a longer compliance-retention window applies — after which it is deleted automatically. The summary metrics in the audit record above are unaffected by this deletion.
5. No AI processing of your computation data
To be explicit, since pyvar.com is also distributed as Claude Code plugins and an MCP server: when you choose to call pyvar.com's API through Claude Code or Claude.ai, whatever you type into Claude is a conversation between you and Anthropic, governed by Anthropic's own privacy terms — pyvar.com only ever sees the resulting API call, exactly as if you'd made it yourself with curl. pyvar.com's own backend never sends your portfolio data, return series, or computed results to Anthropic or any other AI provider; our compute kernel is not an AI model.
6. Payment data
If you upgrade to a paid tier, payment is handled entirely by Stripe, our payment processor. We never see or store your card number, expiry date, or security code — Stripe's own hosted checkout collects this directly. We only ever store the resulting tier, the amount charged, and a reference to the transaction, so we can show you your own billing history.
7. Cookies and tracking
pyvar.com does not use cookies, and we do not run any analytics or advertising tracking — no Google Analytics, no advertising pixels. Your session token (JWT) is kept in your browser's local storage, used only to authenticate your own API calls back to pyvar.com — never for tracking, profiling, or advertising, and never read by anyone but your own browser.
8. Your rights, and how to exercise them
pyvar.com does not currently offer self-service account deletion through the product itself. If you want your account data deleted, contact us at info@pyvar.com and we will action the request.
Under UK GDPR you have the right to access, correct, or request erasure of your personal data, to object to or restrict our processing of it, and to data portability; the same email address is the way to exercise any of these rights, and if you're not satisfied with our response you have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
9. Where your data is hosted, and who else sees it
pyvar.com's infrastructure runs entirely in Amazon Web Services' Ireland (eu-west-1) region — your data does not leave the EU/UK by virtue of our own hosting. (A separate, unconditional CloudFront/WAF edge layer exists in AWS's us-east-1 region purely for routing and security filtering — it holds no origin for your data and never stores anything.) Where we use other companies to help run the service (our “sub-processors”), here's the full list and what each one sees:
| Sub-processor | What they see | Where |
|---|---|---|
| Amazon Web Services | All application data (hosting, database, object storage); also sends account-verification emails via Amazon SES | Ireland (eu-west-1) |
| Stripe | Payment card details, billing contact info (paid tiers only) | See Stripe's own privacy policy |
| Sentry | Application error diagnostics (stack traces, request metadata) for debugging — configured not to include request content by default | See Sentry's own privacy policy |
| Google (optional sign-in only) | Nothing — this flows the other way: Google shares your email address with us, we don't share anything with Google | See Google's own privacy policy |
10. Changes to this policy
We may update this policy from time to time, and for material changes, we'll make reasonable efforts to notify account holders directly.
11. Contact us
Privacy rights and data requests: info@pyvar.com
Fibtec Limited
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ