Effective date: July 21, 2026 · Version 2026-07-21
Simulated paper trading only. Educational — not financial advice. No real money, no real orders. Simulated results do not represent real trading.
1. Who we are
FinSim (“Obsidian Market Replay”) is operated by Andrew Lang, doing business as Obsidian Metrics, a sole proprietorship based in Pennsylvania, USA (“Obsidian Metrics,” “we,”
“us”). This Privacy Policy explains what FinSim stores and how your data is handled. It is part of
the FinSim Terms of Service.
2. What FinSim itself stores
An anonymous user ID. A one-way, HMAC-derived identifier computed from your community
email. FinSim does not intentionally store your email address in its own application database — only
this derived ID is written to the simulator database.
Your simulated sandbox. Your paper cash, positions, working orders, options book, and
trade log, stored as a data blob keyed to your anonymous ID, with a last-updated timestamp. Every
value in it is simulated and has no real-world worth.
A session cookie. A signed, httponly cookie that carries your anonymous user ID, an
encoded (base64) copy of your email, your access tier, and an expiry of about 12 hours. It is signed
by the server so it cannot be tampered with, and it is not readable by page scripts. It is used only
to keep you signed in and to route you to your own sandbox.
Terms acceptance. A record that you accepted the Terms of Service, with the version and a
timestamp, keyed to your anonymous ID.
FinSim does not use third-party advertising or analytics trackers, and does not sell your data.
3. What third parties store
Supabase (authentication and database) holds your community account identity: your email,
a password hash, and your tier. Sign-in, email verification, and password reset happen through
Supabase; FinSim never stores or sees your password.
Skool / payment processor. If you subscribe, the community platform (Skool) and/or the
payment processor hold your billing data under their own privacy terms. FinSim never sees or stores
your card details.
4. Isolation and access
Your sandbox is isolated to your account and enforced on the server. Other members cannot see it,
and there is no administrative surface inside FinSim that exposes one member’s data to another. The
public competition tracker exposes only two demonstration bots — never the owner’s private research
environment and never any member’s sandbox. The public no-login demo and leaderboard contain only
simulated, anonymized data.
5. Data retention and deletion
We keep your sandbox while your account is active. On account termination or a deletion request,
we delete your FinSim sandbox data within a reasonable period, except any records we are required to
keep by law. To request deletion, contact us at andylang5989@gmail.com. Requests about your community account
identity (email, password) are handled through Supabase / the community platform.
6. Cookies
FinSim uses a single strictly-necessary session cookie, described in Section 2. It is required to
keep you signed in; there are no optional or advertising cookies.
7. Children
FinSim is not directed to children and requires you to be at least 18 years old.
8. Changes and contact
We may update this Policy; material changes will be noticed in-product or by email. Questions or
privacy requests: andylang5989@gmail.com.