- Your username, password verifier and sessions exist so the account you created can be signed into
- Your positions, scenarios and value history exist so the ledger you chose to use can show you your own numbers
- Your Stripe customer id and plan status exist so a subscription you bought actually unlocks
The whole list fits on one page.
That is the point.
GioModel collects the smallest amount of data that lets an account work. There are no analytics scripts, no advertising trackers, no third-party pixels and no data sold to anyone. This page lists every category stored, why it is stored, how long it stays, and how to get rid of it. Last updated: 7 August 2026.
What is stored, and why
This list is the database schema in plain words. If a field is not named here, it is not held.
- 01Your username
Stored twice — once as you typed it and once normalised for uniqueness. It is the only identifier an account has. No email address, real name, phone number or address is collected at registration.
- 02A password verifier, never your password
Your password is never stored and never written to a log. What is stored is a PBKDF2 verifier derived from your password with a per-account random salt and a server-side secret pepper, plus the iteration count used. It cannot be turned back into your password, and the owner cannot read it.
- 03Hashed session tokens
Signing in creates a session. Only a hash of the session token is stored, alongside its creation and expiry times, so a copy of the database does not let anyone impersonate you. Expired sessions are deleted, and changing your password invalidates every existing session at once.
- 04Your saved positions
If you use the position ledger: the ticker, the number of shares and the entry price for each position you enter. This is the most sensitive thing in the database and it is shared with nobody — not Stripe, not the data provider, not anyone else.
- 05Named scenarios and daily value history
Up to five named what-if scenarios you save, each a set of positions, and one portfolio-value point per completed trading session — total value, cost basis and position count — so the ledger can show history over time.
- 06Your Stripe customer id
If you subscribe, the site stores the Stripe customer identifier that links your GioModel account to your Stripe record, plus which plan is active and when it was granted. That is all the billing data held here. Card numbers, expiry dates and billing addresses live with Stripe and never reach GioModel.
- 07Basic account housekeeping
Registration date, last sign-in time, whether the account is disabled, and short-lived rate-limit counters that block password-guessing. Rate-limit records are keyed and time-windowed, not kept as a browsing history.
Why it is lawful to hold
- Rate-limit counters and the sign-in timestamp exist to stop password guessing and abuse
- Salting, peppering and token hashing exist so a stolen database is not a stolen set of accounts
- An admin action log records owner actions on accounts, so changes are traceable
- Stripe keeps payment and tax records for the periods its own obligations require
- GioModel holds no card data, so there is nothing here to retain for a payments regulator
- Nothing is collected for marketing, profiling, or automated decisions about you
Who else is involved
Three third parties touch this site. None of them receives your saved positions.
- 01Stripe — payment processing
Checkout, card storage, renewals and the cancellation portal all run on Stripe. Card details go from your browser to Stripe directly and never pass through GioModel. Stripe receives what it needs to charge you and your GioModel username as a reference; it does not receive your positions, scenarios or value history.
- 02Cloudflare — hosting and database
The site, its API and its database run on Cloudflare infrastructure, so Cloudflare processes the data described above as the host and sees the connection metadata any web host sees. It is a processor acting on instructions, not a party allowed to use your data for its own ends.
- 03Nasdaq — market data
Prices and historical sessions come from Nasdaq. Data flows one way, into the models. Nasdaq is sent nothing about you: not your username, not your positions, not the fact that you looked at a particular ticker.
There is one cookie and it is a session cookie. It is first-party, set only after you sign in, and marked HttpOnly, Secure and SameSite=Lax — meaning scripts cannot read it, it only travels over HTTPS, and it is not sent along on cross-site requests. It holds a session token and nothing else. It expires on its own and is cleared when you sign out. There are no advertising cookies, no analytics cookies, and no third-party cookies, which is why this site has no consent banner to click through.
How long it is kept
- 01While your account exists
Username, password verifier, positions, scenarios, value history and plan status are kept for as long as the account does. They are not archived elsewhere.
- 02Sessions and rate limits expire on their own
Session rows carry an expiry and are deleted once past it or when you sign out. Rate-limit counters live inside short windows and roll over.
- 03When you ask for deletion
The account record is removed and everything keyed to it — positions, scenarios, history, sessions and the Stripe customer link — goes with it. What remains afterwards is whatever Stripe must keep as a record of payments already made, which is governed by Stripe and by tax law rather than by GioModel.
Your rights, and how to use them
ACCESS
Ask for a copy of everything held about your account. You will get the username, registration and last-login times, your saved positions and scenarios, your value history and your plan status. The password verifier and session hashes are secrets, not personal content, and are described rather than handed over.
CORRECTION
Positions, scenarios and your password are editable by you at any time inside the Portfolio page. If something else is wrong, email and it will be fixed.
DELETION
Ask by email and the account is deleted. Positions, scenarios, value history, sessions and the Stripe customer link are removed with it, because they are tied to the account record. Cancel billing first, or ask for both in the same message.
EXPORT
Your positions and scenarios can be sent to you as plain machine-readable files. Ask by email.
To exercise any of these, email giovanni.alex@gmail.com from a message that identifies your username. Expect a reply within a few business days. There is no charge, and no form to fill in. See the contact page for what else that address covers.
The owner can see registration dates, last sign-in times, position counts and plan status. That is the administrative view: a list of usernames with how many positions each holds and when the account was created. The owner cannot see your password, because only a one-way verifier exists, and cannot see your session tokens, because only their hashes are stored. GioModel is operated personally by Giovanni Alexander in Canada, and he is the only person with access to this data.