Privacy
Accounts are optional. If you never open one, this site sets no cookie, loads no tracker, and holds nothing personal about you beyond an ordinary server log line for 14 days. If you open one, we store your email, a password hash, what you choose to save and the feedback you send, and you can export or delete all of it from the ACCOUNT panel. This page says exactly what is kept, why, for how long, and what your rights are.
Last updated 2026-09-25. marketprice.org is operated by qourat. Contact support@qourat.com.
1. The short version
- Who is responsible: qourat, which runs marketprice.org and qourat.com. Contact support@qourat.com.
- No advertising, no analytics, no third party trackers, pixels or fingerprinting. Not now, not with accounts.
- Without an account: no cookie. Your layouts, watchlists, portfolio and alerts stay in your own browser.
- Our web server keeps an ordinary access log for 14 days for security, then deletes it.
- With an account: your email, a password hash, your name, country and how you use the terminal only if you give them, what you choose to save, and feedback you send. Nothing else.
- Export and delete are buttons on the ACCOUNT panel. A closed account’s personal data is deleted at once.
- We do not sell, rent or share personal data, and we never will.
2. If you never open an account
This is true for anyone who never opens an account and never uses the account or feedback forms.
- We hold no email address, no name and no password for you.
- The terminal sets no cookies. It keeps its state in your browser’s local storage, which never leaves your machine and which we cannot read.
- The human check (Google reCAPTCHA) is never loaded, because it loads only on the account and signed-out feedback forms.
- Our server keeps only the access log described below, for 14 days.
- The only personal data we can hold about you is that log line and any email you chose to send us.
3. What stays on your own device
The terminal uses your browser’s local storage. What is in it never leaves your machine and we cannot read it.
- Saved layouts and desks, including the automatic one the terminal restores when you come back.
- Watchlists.
- Portfolio positions and the cost basis you typed.
- Price alerts.
- Small interface preferences, such as the tab a panel was last on.
4. How to delete it
Clear the site data for marketprice.org in your browser settings, or use a private window. That removes everything the terminal kept in your browser, immediately and completely.
Export first if you want to keep it: the layouts dialog exports layouts as JSON and the portfolio exports as JSON or CSV.
5. What our server keeps
The web server writes an ordinary access log line for each request: the time, the IP address, the path, the status code, the size of the response, the referrer and the browser user agent string. This is what any web server writes and it is what lets us see an attack or a broken page.
These logs are kept for 14 days and then deleted. We use them only to keep the service running and secure. We do not build profiles from them, we do not link them to anything, and we do not use them for analytics or advertising.
The legal basis, where the UK and EU rules apply, is our legitimate interest in keeping the service available and secure.
6. No trackers, and the one exception
The terminal loads no analytics script, no advertising script and no social widget. The pages you are reading now load no external font and no external script at all.
One exception is worth naming plainly: the TV function plays video streams published by broadcasters. When you start a channel, your browser connects to that broadcaster and that broadcaster sees your request in the same way any video site would. A few channels that forbid embedding are shown as links that open in a new tab. We do not choose what those sites do, so read their own notices if that matters to you.
7. What an account stores
An account is optional. It stores only the following.
- Your email address. Purpose: to sign you in, to confirm the address is yours and to answer you. Kept while the account exists.
- A hash of your password, never the password itself: scrypt (N 32768, r 8, p 1) with a random 16 byte salt per password. Purpose: to sign you in. Kept while the account exists.
- Your name, your country and how you use the terminal, each only if you choose to give it. Each field has its own delete button on the ACCOUNT panel.
- The layouts you save with SAVE <name> (every open tab with its panels and their options) and the watchlists you copy to the account, so they follow you to another browser. Kept until you delete them or close the account.
- Feedback you send from the terminal, with the account it came from (or the email you give, if you send it signed out). It reaches our inbox at support@qourat.com and the feedback inbox of the site’s admin panel. Only the operator can open the admin panel: it has exactly one login, qourat@gmail.com. Kept for at most two years.
- The time of sign up, of email confirmation and of the last sign in, the sign-in sessions you have open (when each started and was last used), and a short record of account events (sign up, confirmation, password change, an admin disabling or enabling the account). Purpose: security and closing stale accounts.
8. Why we may store it, and for how long
The legal basis for account data, saved layouts and feedback is the contract you enter by opening an account (GDPR and UK GDPR article 6(1)(b)). The basis for the sign-up check and for security records is our legitimate interest in keeping the service free of abuse (article 6(1)(f)).
When you close an account, your email, password hash, profile fields, saved layouts, watchlists, sessions and the feedback sent from it are deleted at once. What is left is a row holding only the account number and its dates, so the admin page can show that an account was closed; that row is deleted after 30 days. A service job checks all of this every hour.
An account whose email is never confirmed is closed after 30 days. An account nobody has signed in to for two years is closed, after a warning email sent 30 days before; signing in keeps it.
A sign-in session lasts 30 days from sign in, or until you sign out; its record is deleted when it ends. A confirmation link works for 48 hours and its record is deleted within 7 days of use or expiry. Failed sign-in and sign-up attempts are counted per hashed network address and per hashed email for rate limits, never with the address itself, and the counts are deleted after 2 days. The record of account events is kept one year.
9. Traffic counts on the admin page
The admin page shows how many times a day the terminal was opened, split into the terminal itself, the instrument pages (/i/...) and the function pages (/f/...), and how many different visitors that was each day. Nothing is counted per person or per account, and no address is linked to an account.
The different-visitor count uses a keyed hash of the network address. The key is random, is replaced every day, and is deleted with that day’s hashes when the day ends, so the count cannot follow anyone from one day to the next or be turned back into an address. Only the daily totals are kept, for about 13 months.
10. Email verification and our own mail server
When you open an account we send one message with a link to confirm the address (you can ask for it again from the ACCOUNT panel). Later we send only what you ask for: a copy of feedback you send while signed in with a confirmed address, an answer to your feedback, and the one warning before a two-year inactivity close. Everything is plain text from no-reply@qourat.com through our own mail server on the same machine as the site. No mailing service, newsletter tool or marketing list is involved.
Saving layouts and watchlists to the account needs a confirmed address. Until then SAVE keeps them in your browser.
11. The human check on sign up and sign in
To keep bots out, the sign-up form, the sign-in form and the feedback form when you are signed out use Google reCAPTCHA v3, the score-based version with no puzzle. When one of those forms is on screen, your browser loads Google’s script and sends Google information about your device and how you interact with the page, and Google processes it under its own privacy policy (https://policies.google.com/privacy) and terms of service (https://policies.google.com/terms). Our server then asks Google whether the check passed.
The script is loaded only when one of those forms is opened, never on the terminal otherwise. Google’s floating badge is hidden; the notice Google asks for is printed under each of those forms instead.
12. Cookies
We set at most two cookies, both strictly necessary for something you asked for, so neither needs a consent banner and neither has any advertising or tracking purpose.
Google’s reCAPTCHA script can set its own cookies, and only on the forms named above. No other cookie is set by us or by anyone else.
- mp_session: keeps you signed in. Set when you sign in or sign up; lasts 30 days or until you sign out. HttpOnly (page scripts cannot read it), Secure (sent only over HTTPS), SameSite=Lax. It holds a random value; our server keeps only a hash of it.
- mp_csrf: a random form token that stops other sites from sending forms in your name. Set only when you use the sign-up, sign-in, confirmation or signed-out feedback forms; deleted when you close the browser. HttpOnly, Secure, SameSite=Strict.
13. Deletion and export
The ACCOUNT panel has an export button, which downloads everything the account holds as one JSON file (your details, saved layouts, watchlists, feedback, your open sessions and the account events), and a delete button, which asks for your password and deletes the account as described above.
If you prefer, or cannot sign in, write to support@qourat.com from the account’s address and we do it for you within 30 days.
14. Where the server is, and who else sees anything
The server is in New York, in the United States. If you are outside the United States your request, and any account data, is processed there.
Our hosting provider necessarily handles the traffic that reaches the server and acts as our processor. Google sees the forms that carry the human check, as described above. Beyond that, no one: we use no processor for analytics, marketing or support ticketing, and account data never leaves our server.
The data providers listed on the disclaimer page see requests from our server, not from you. Your browser does not talk to them.
15. Email you send us
If you write to support@qourat.com we keep that message and our reply so we can answer you and keep a record of the issue. We delete it when it is no longer needed, and at the latest after two years.
16. Your rights, in plain words
Under the EU and UK General Data Protection Regulation (GDPR and UK GDPR), the California Consumer Privacy Act (CCPA, as amended by the CPRA) and similar laws elsewhere, you have rights over personal data a company holds about you. Write to support@qourat.com to use any of them; we answer within 30 days (45 under the CCPA).
- Access: ask what we hold about you and get a copy.
- Correction: ask us to fix anything wrong. You can edit or delete every profile field yourself on the ACCOUNT panel.
- Deletion: ask us to delete what we hold. Your browser storage is yours to clear at any time.
- Objection and restriction: ask us to stop or limit any processing that is not needed to run the service securely.
- Portability: get your data as a file you can take elsewhere. The ACCOUNT panel exports the account as JSON, and the terminal exports your layouts and your portfolio.
- No sale and no sharing: we have never sold or shared personal information, and we do not use it for targeted advertising. There is nothing to opt out of, and you will not be treated differently for using any right.
- No automated decision making about you happens on this site. The forecasts are about markets, not about people.
- Complaint: you can complain to your data protection authority, in the UK the Information Commissioner’s Office. We would rather you wrote to us first.
17. Children
The terminal is not directed at children. We knowingly collect nothing from anyone under 16, and accounts are not open to them: the sign-up form asks you to confirm you are 16 or older. If you believe a child has opened an account or written to us, tell us and we will delete it.
18. Changes, and how to reach us
If this changes, the date at the top of this page changes with it and the change is described here before it takes effect. We will not start collecting personal data quietly.
Privacy questions: support@qourat.com.