Privacy & Cookies Policy
Last updated: 7 September 2026
Controller
Thorben Spanka is the data controller. Contact: hello@criticalquant.com. The postal address is available in the Legal Notice.
Your CriticalQuant account
You can browse the game preview without an account. If you create an account, we process your chosen username, a password hash, account creation and update dates, account status, and sign-in tokens. Your password is transmitted over HTTPS and stored as a hash, not as readable text. The current form does not ask for an email address; an email supplied through the account service may also be held with that account.
We use this information to create and operate the account you request, sign you in, and let you manage or delete it. The legal basis is performing the account service you request (Article 6(1)(b) GDPR). A username and password are required to create an account; providing them is voluntary. Creating an account does not subscribe you to a newsletter.
The full fund game is in development. The current browser preview does not save game runs to your account. The former Labs have been retired.
Game updates by email
If you request game updates, we use your email address and your subscription and confirmation records to send development news about the CriticalQuant fund game. This is separate from a CriticalQuant account. The legal basis is your consent (Article 6(1)(a) GDPR). Providing your email is voluntary; without it we cannot send you updates.
If you submit this form after following a tagged CriticalQuant link, we also send its channel and campaign labels to Brevo with your signup. This helps us understand which posts bring people to the game. This feature does not set cookies or store an identifier in your browser.
We use Brevo to process the signup and send the confirmation email. Confirming its link completes your subscription. Brevo processes the email address, consent information and technical information needed to deliver the messages and operate the form. It records delivery and confirmation-link events so we can verify and manage your subscription. See Brevo’s privacy information.
You can withdraw your consent through the unsubscribe link in an update or by contacting hello@criticalquant.com. We use your address for updates while you remain subscribed. Information needed to record consent, respect an unsubscribe request or resolve a legal claim may be retained for those purposes. You can request access or deletion using the same contact address.
Sign-in storage and security
The account page uses browser local storage named cq_account_pass_v1 for account state, including a guest-state record before sign-in. After sign-in, cq_auth_token_v1 holds your sign-in token. The server also sets the cq_session sign-in cookie, marked Secure, HttpOnly and SameSite=Lax. This storage supports account access; it is not used for advertising.
Server sign-in sessions and the cookie expire after 90 days. Browser local storage has no automatic expiry; signing out, deleting your account or clearing this site's browser data removes the local sign-in information. An expired token no longer authorizes account access even if a copy remains in browser storage. Signing out revokes the account's server sessions.
For abuse prevention, the server uses your network address to derive short-window attempt counters. Account-security processing relies on our legitimate interest in protecting the service and its users (Article 6(1)(f) GDPR). Website hosting also involves technical requests and access logs, which can include network addresses, request times, requested paths and browser information.
Feedback and contact
If you voluntarily send feedback or contact us, we process the information you provide to answer your request and improve the service. Existing feedback records contain the submitted answers, requested topic, a record identifier and receipt time; abuse-prevention hashes are held separately. Do not include confidential employer information, private code or financial-account details.
The basis is our legitimate interest in responding to enquiries and improving the service (Article 6(1)(f) GDPR), or Article 6(1)(b) where your message concerns your requested account service. We do not use these messages to make automated decisions with legal or similarly significant effects.
Providers and international processing
Hostinger supplies website hosting and business email and processes information needed to operate those services. Its published Data Processing Addendum describes subprocessors and safeguards, including standard contractual clauses for applicable international transfers. The location of hosting alone does not determine every support or subprocessor location. Contact us for information about the safeguards applicable to your data.
When you follow an external link, such as a link to a social platform, that provider receives the request and applies its own privacy terms. We do not embed social-platform feeds on the game landing page.
How long information is kept
Account records remain while your account is maintained. You can delete your account in the account menu or request deletion by email. The account deletion function removes your user record and associated sign-in sessions from the active database. Expiry of a sign-in token is not itself deletion of the account.
Contact and feedback information is retained while needed to resolve the enquiry or evaluate the submitted feedback, and longer only where needed to meet a legal obligation or establish, exercise or defend legal claims. Security counters are periodically removed after their short operating windows. Technical logs and hosting backup copies have separate provider retention and deletion processes; active-account deletion is not a promise that every backup copy disappears instantly. Contact us for a data-access or deletion request covering those copies.
Your rights
You may request access, correction, erasure, restriction and, where applicable, portability by emailing hello@criticalquant.com. You may object to processing based on legitimate interests on grounds relating to your situation. Where processing relies on consent, you may withdraw that consent without affecting earlier lawful processing. We may need information sufficient to verify that the request concerns your own account.
You may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority. The account service does not make automated decisions with legal or similarly significant effects.
Cookies and measurement
The game landing page and our own error page do not use advertising or analytics cookies. Account storage is described above. Any former Labs progress retained in your browser can be removed by clearing this site’s browser data.
For the market-making article and free starter, links tagged with the campaign x_spread_20260906 enable first-party daily aggregate counts: article loaded, demo link clicked, demo loaded, controls used, explanation opened and download clicked. Each event is attempted at most once per page load. These counts help us understand which explanations are useful; they do not identify unique people, prove task completion or track return visits.
The measurement endpoint stores only the fixed campaign, UTC date and event totals, with operator tests kept in a separate QA group. It does not store IP addresses, user agents, account identifiers, raw URLs or individual event records. It sets no cookies and uses no persistent browser storage. Do Not Track and Global Privacy Control disable these requests. Counts older than 30 days are removed on the next accepted event; an inactive campaign's remaining aggregate file is deleted at campaign closeout. Hostinger's technical access logs are separate from these counters.