Privacy Policy

Version 2026-07-28Effective 28 July 2026

The short version. We collect the minimum needed to run your account: an email address from our identity provider, the watchlist and prompts you configure, and basic technical logs. There is no analytics, no advertising, no tracking, and no third-party request on any page of this site. We do not sell or share your personal information. You can delete your account, and everything tied to it, from inside the app at any time.

1. Who we are

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller of the personal data described in this policy. Contact: [privacy@yourdomain.com]. [If you have an EU/UK establishment or an Art. 27 representative, name it here. If you appoint a DPO, name them here.]

2. What we collect

Category What, specifically Source
Account identity Email address, and an opaque user identifier issued by our identity provider. We do not receive or store your password. Our identity provider (WorkOS), when you sign up or sign in
Service configuration Your watchlist entries, the RSS/Atom feed URLs you subscribe to, your focus prompts, and your preferences. You, in the app
Agreement records Which version of the Terms, Privacy Policy, and Risk Disclosure you accepted, when, plus the IP address and browser user-agent at the moment of acceptance. Automatic, at acceptance
Technical & operational IP address, user-agent, request paths, timestamps, response codes, and error traces in server logs. Rate-limiting counters keyed to your account. Automatic, when you use the Service
Payment [None today. When billing launches: our payment processor handles card data directly and we receive only a customer/subscription identifier and status. Name the processor here and update §5.] Payment processor

We do not collect your positions, holdings, portfolio, account balances, net worth, income, investment objectives, or risk tolerance. The Service does not ask for them and has nowhere to put them. A watchlist is a list of instruments you asked to read about, not a statement of what you own.

We do not collect special-category data, biometric data, or precise geolocation.

3. Why, and on what legal basis

Purpose Data used Legal basis (UK/EU GDPR)
Create and operate your account; deliver the Service Account identity, service configuration Performance of a contract (Art. 6(1)(b))
Steer and filter analysis to the topics you asked for Watchlist, focus prompts Performance of a contract (Art. 6(1)(b))
Security, abuse prevention, rate limiting, debugging Technical & operational Legitimate interests (Art. 6(1)(f)) — running a secure service
Proving you agreed to our terms; defending legal claims Agreement records Legal obligation and legitimate interests (Art. 6(1)(c), (f)) — establishing and defending legal claims
Service and legal notices about your account Email address Performance of a contract (Art. 6(1)(b))

We do not use your data for advertising, profiling with legal effect, or automated decision-making about you.

4. Cookies and tracking

We run no analytics, no advertising, and no tracking of any kind. There are no third-party scripts, pixels, beacons, or embeds on this site. Web fonts are served from our own domain rather than a third-party CDN, specifically so that visiting a page does not disclose your IP address to anyone else.

The only client-side storage we use is what is strictly necessary to keep you signed in — a session established by our identity provider when you log in. Because it is strictly necessary to deliver a service you requested, it does not require consent, and there is no cookie banner. We do not set any optional or non-essential cookie.

Public marketing pages (the home page and these legal pages) set no storage at all and can be read entirely without signing in.

5. Who we share it with

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose it only to the processors below, only for the purposes shown, and only under contracts requiring them to protect it.

Recipient Role What they receive
WorkOS Authentication and account management Email, credentials you supply to them, authentication events
[Render] Application hosting Traffic and server logs (IP, request metadata)
[Neon] Managed database All stored account data, at rest
[Anthropic] AI model provider Prompt content only — see section 6
Tiingo, Twelve Data, Finnhub Market data Instrument symbols only. These are requested by our servers, not your browser, and are not linked to you.

We may also disclose data where required by law, to enforce our Terms, to protect rights or safety, or in connection with a merger or acquisition (in which case this policy continues to apply until you are notified otherwise).

6. What goes to the AI model provider

This deserves its own section because it is the least obvious processing we do.

Do not put confidential, personal, or material non-public information into a focus prompt. Treat a focus prompt as text you are handing to a third-party service.

7. International transfers

Our providers are located in the [United States]. If you are in the UK, EEA, or Switzerland, your data will be transferred outside your jurisdiction. Those transfers rely on [Standard Contractual Clauses / the UK Addendum / an adequacy decision — confirm what each processor's DPA actually uses and name it]. You can request a copy of the safeguards from the contact in section 14.

8. How long we keep it

Deleting your account. Use "Delete account" in Settings. This removes your account row and, by database cascade, your watchlist, focus prompts, preferences, and agreement records, and deprovisions your account at our identity provider. It is immediate and irreversible. The shared analysis graph contains no personal data and is unaffected.

9. Your rights

Subject to applicable law, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, and to receive it in a portable format. Where we rely on legitimate interests, you may object at any time. Where we rely on consent, you may withdraw it without affecting prior processing.

Most of these you can exercise yourself in the app: view and edit your watchlist, feeds and prompts at any time, and delete your account in Settings. For anything else, contact [privacy@yourdomain.com]; we will respond within [30 days]. We will not discriminate against you for exercising a right.

If you are in the UK or EEA you may also complain to your local supervisory authority [e.g. the UK ICO at ico.org.uk].

10. California residents

Under the CCPA/CPRA, in the last 12 months we collected the categories of personal information described in section 2 — identifiers, internet or network activity, and commercial information — for the business purposes in section 3, from the sources listed, and disclosed them to the service providers listed in section 5.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, and we do not do so with the personal information of minors under 16. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" mechanism to offer; we honour Global Privacy Control signals as a matter of course by never engaging in the practices they opt out of. We do not use or disclose sensitive personal information for purposes requiring a right to limit.

You have the right to know, delete, and correct, and to be free from discrimination for exercising those rights. Exercise them via the app or the contact in section 14. You may use an authorised agent; we may require verification.

11. Security

Access to the Service passes through a single authenticated gateway; per-user data is isolated at the database level by row-level security, not only in application code. Authentication is delegated to a specialist provider and we never see your password. Data is encrypted in transit and at rest by our infrastructure providers.

No system is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and the relevant authority where the law requires it.

12. Children

The Service is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

13. Changes

We may update this policy. The version and effective date are at the top. If a change is material we will require you to accept the new version in the app before continuing to use the Service.

14. Contact

[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[privacy@yourdomain.com]