Privacy Policy

Last updated: July 27, 2026

Who this policy covers

This policy covers the EmidLabs website (emidlabs.com), the Console (console.emidlabs.com) and its underlying API, the Backtesting API, the strategy execution engine behind it, and the EmidLabs Backtest MCP server that lets AI agents call EmidLabs on your behalf (together, the "Services").

Who is responsible for your data

EmidLabs is currently operated by Samuel Lucas Lima Emidio, as an individual, pending formal incorporation of a registered legal entity. Once incorporated, this policy will be updated to name that entity as the data controller in Samuel's place.

For any question about this policy or your data, contact privacy@emidlabs.com.

Data we collect

Account & authentication

We use Firebase Authentication. When you create an account we store your email address, display name, and the Firebase user ID tied to your login.

Billing

Payments are handled by Stripe Checkout. Your card details are entered directly on Stripe's hosted page and never reach EmidLabs' servers. We store your Stripe customer ID and a record of each transaction — amount, currency, execution units purchased, and status.

API keys & account activity

Each API key you generate is stored with its name, environment, per-service usage allocations, and when it was last used. We also keep an internal activity log tied to your account (e.g. a key was created, a backtest was submitted) for support and abuse investigation.

Website analytics

Browsing emidlabs.com sends standard usage analytics (pages visited, approximate location, device type) to Google Analytics.

Waitlist

If you join the waitlist on the website, your email address is submitted directly to Formspree, our third-party form processor — we do not separately store a copy.

MCP server (AI agent integrations)

When an AI agent calls the EmidLabs Backtest MCP server on your behalf, your EmidLabs API key is passed as an argument to that call and used only in memory, for the duration of that single request, to authenticate against the Backtesting API — the MCP server never logs, stores, or caches it. The MCP server also applies a lightweight, IP-based rate limit purely to prevent abuse of the service itself; the requesting IP address is held in memory only for that purpose and is not persisted or logged.

What we deliberately do not collect

  • We do not store your IP address in any account or backtest record.
  • Card numbers never reach our servers — Stripe handles them end to end.
  • The Console app does not use tracking cookies, session replay, or similar tools.
  • We do not use an error-tracking service that could capture request contents.

Who we share data with

The providers below process data on our behalf ("sub-processors"):

  • Firebase / Google — authentication.
  • Stripe — payment processing.
  • Google Analytics — website usage analytics.
  • Formspree — the waitlist form.
Historical market data (OHLCV) used by the backtesting engine is sourced from Coinbase's public market data. This is market data, not your personal data — nothing about you or your account is sent to Coinbase.

International data transfers

Firebase, Stripe, Google Analytics, and Formspree are US-headquartered providers. Using the Services means some of your data may be processed outside Brazil, under those providers' own safeguards.

How long we keep data

We keep account and billing data for as long as your account is active, plus whatever period is legally required afterward (e.g. billing records for tax purposes). Data tied to a deleted account is removed except where we're legally required to retain it.

Your rights

Under Brazil's LGPD (and equivalent rights if you're in the EU under GDPR), you can request access to, correction of, or deletion of your data, ask for a portable copy of it, or withdraw consent, by emailing privacy@emidlabs.com.

Security

All Services are served over HTTPS. API keys are never written to application logs. Payment data is handled entirely by Stripe, not by our own infrastructure.

Children

The Services are not directed at anyone under 18.

Changes to this policy

If this policy changes, we'll update the "last updated" date above. Material changes will be flagged to existing account holders.