Last updated 4 October 2026.

This is a business tool, and almost everything in it is business information.

What we hold about you personally is your work contact details, what you did on the site, and the records your work here produced. We do not sell any of it, we do not advertise, and nothing here is shared with anybody for their own purposes.

Who we are

US-MTNS operates this site for broker-dealers, issuers and their clients in the US medium-term note market. Write to admin@us-mtns.com about anything on this page.

What we hold, and why

The four kinds, in the order they matter to you.

Your account

Your name, work email address, any other addresses you tell us you send from, the firm you belong to, what you are allowed to do here, and the versions of our disclaimer you have accepted and when. Bonds you bookmark, and the notification preferences you set.

Your password is stored as a bcrypt hash, never as text. Nobody here can read it, and a reset replaces the hash rather than recovering anything.

What you did here

A compliance audit trail: your address, what was done, and when — signing in, granting or removing somebody's access, arming a venue kill switch, setting a deal's price, sharing a document outside your firm. It exists so that a firm can answer "who did this", including about us.

A record of pages opened: the page, the section, your address and firm if you were signed in, the session the visit belonged to, an external link you arrived from, whether the browser looked like a phone or a robot, how long the page took, and whether you were turned away for not being signed in.

Two things about that record are worth being exact about. The session is recorded even when you are not signed in, which means the pages of one anonymous visit are linked to each other, though not to a name. And a visit made while an administrator is signed in as you is marked as such — see below. It is how we know which parts of the site are used, and it is ours alone: see the cookie policy for why there is no analytics service.

Faults. When something breaks, we keep the error, the page it happened on, and the address and firm of the person it happened to — enough to go and ask you about it, which is usually how it gets fixed.

Your work

Deals, orders, trades, hedges, prices, offering documents and the firms on either side of them. These are business records rather than personal data, but your address is on the ones you made: an order says who entered it, a price says who set it, an approval says who approved it. That attribution is the point of the record and it is not removable from it.

Questions you type into the Ask box on the help page, with the page you asked from and the answer you were given. They are grouped by question rather than by person — six people asking the same thing is one record — and your address is kept on the ones you asked, so that we can come back to you when the honest answer is "we have not built that yet". Someone not signed in is counted without being named.

Email you send us

If your desk forwards reoffer prices to us, we keep the sender, the subject, the time, and an excerpt of the message — enough to show you why a price was or was not applied. Documents attached to those emails are stored as documents. If you write to admin@us-mtns.com, we keep the correspondence.

Who else sees it

Nobody for their own purposes. These are the services that hold or process some of it in order to run this one, and they are named because a notice that says "third-party service providers" tells you nothing.

ServiceWhat reaches it
HerokuHosting. Every request passes through it.
MongoDB AtlasThe database: everything described above.
Amazon S3Offering documents and prelims, including ones your firm uploads or shares.
RedisShort-lived counters used to stop password-guessing and scraping. Keyed by network address, and for password resets by the address being reset. Minutes to a day.
Anthropic (Claude)Price lists you paste or email in, and questions you type into the Ask box on the help page, are sent to be read. We send no account records with them. If it is unavailable the site falls back to its own parser.
Our mail hostEmail we send you — invitations, password resets, offering documents.
SlackOperational alerts to us when something breaks. A fault alert can name the page and the person it happened to.

We are also the operator of the service that files public offering documents, and of the database of public SEC holdings filings this site looks bonds up in. Documents you ask us to file reach the first; the second is only ever read, by CUSIP, and nothing about you or your firm is sent to either.

How long we keep it

What the site actually does, rather than a rule we would like to have. Three of these are enforced by the database itself, which is why they are exact.

ThisLasts
Your session100 hours. See the cookie policy.
The record of pages opened400 days, then deleted automatically.
Questions typed into the Ask box365 days after the last time anybody asked that question, then deleted automatically. A question still being asked stays.
Fault reportsKept. Clearing one from our admin pages marks it as dealt with; it does not delete it.
Reoffer emails your desk sends usKept, with the rest of the pricing record.
The compliance audit trailNo fixed end. It goes back to March 2023. It is the record a firm relies on to answer who did what, and shortening it would defeat it.
Your accountAs long as it exists. Switching an account off keeps the record; deleting one removes it.
Deals, orders and tradesKept. They are the market's record of what was done, and they carry the address of whoever did it.
Your choices

Said plainly, because a notice that lists controls you do not have is worse than one that names who holds them: there is no settings page on this site. Your password is yours to change; everything else about your account is changed by your firm's organisation manager or by us, when you ask.

Two things worth saying plainly

An administrator here can sign in as you, to see what you see when something is wrong with your account. Starting it is recorded in the audit trail every time, naming the administrator and your account, and so is stopping it. You are not notified at the time.

And one part of that we would rather you heard from us: in between, the site has become you. An action taken while an administrator is signed in as you is recorded against your address, not theirs — so a row in your firm's activity log is evidence of an account, not proof of a person. The record of pages opened does mark those visits. We are telling you all of this because the alternative is a support tool nobody was told about.

Children. This site is for people doing their jobs at financial firms. It is not for anybody under 18 and we do not knowingly hold anything about one.

Changes, and what this does not cover

If what we collect changes, this page changes, and the date at the top moves with it.

This is a notice about what we hold and what we do with it. It is not a statement of rights under any particular country's data-protection law, and it does not describe a lawful basis, a transfer mechanism, or a complaints procedure to a regulator. If you need those answers for your firm, write to us and ask.

© US-MTNs Incv2026.461