Last updated 18 September 2026
For an account: your email address, a salted password hash (never the password), the plan you are on, when you logged in last, and a log of plan changes. For payments (when enabled): the transaction reference from our payment provider — never card numbers, which we do not see.
Our web server keeps standard access logs (IP address, page, time, browser) for 14 days for security and to count visitors. Visitor counts on our side are aggregated from those logs; the address is hashed in memory and not stored with the counts. We use no advertising trackers and no third-party analytics scripts.
We email you about your account (invitations, approvals, password resets, membership expiry) through Resend, which processes the address to deliver the message. We do not send marketing email unless you ask for it.
The service runs on a server in New York, USA. Email is delivered from the EU/US infrastructure of Resend.
Write to invest@apexgdi.com from your account address to see, correct or delete what we hold about you. Deleting the account removes the record; access logs expire on their own.
One cookie, set when you log in, that identifies your session. Nothing else.