Privacy Policy
Last updated: March 27, 2026
1. Information We Collect
We collect only the information necessary to provide and improve the Service:
- Account information — email address and password (hashed) when you create an account via Supabase Auth.
- Usage data — number of analyses performed (stored as a count in our database) to enforce free-tier limits.
- Payment information — Stripe manages all payment data. We store only your Stripe Customer ID. We never see or store your full card details.
- IP addresses — used temporarily for anonymous rate limiting via Upstash Redis. Not stored long-term or linked to personal profiles.
2. How We Use Your Information
- To authenticate you and manage your account
- To enforce usage limits and process premium subscriptions
- To improve the quality and accuracy of the Service
- We do not sell, rent, or share your personal data with third parties for marketing purposes
3. Third-Party Services
We use the following third-party services, each governed by their own privacy policies:
- Supabase — authentication and database
- Stripe — payment processing
- Upstash Redis — caching and rate limiting
- Google Gemini (via Google AI) — AI text generation (ticker and financial metrics are sent; no personal user data is included in prompts)
- Financial Modeling Prep — financial data provider
- Vercel — hosting and edge infrastructure
4. Data Retention
Account data is retained for as long as your account remains active. You may request deletion of your account and associated data by contacting us. Anonymous rate-limit data (IP-based) expires automatically after 30 days.
5. Cookies & Local Storage
We use browser cookies and local storage solely for authentication session management (Supabase Auth tokens). We do not use tracking cookies or third-party advertising cookies.
6. Security
We implement industry-standard security practices including encrypted connections (HTTPS), hashed passwords, and access-controlled databases. However, no system is 100% secure, and we cannot guarantee the absolute security of your data.
7. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or delete your personal data. To exercise these rights, contact us via the information below.
8. Changes to This Policy
We may update this Privacy Policy periodically. The “Last updated” date at the top reflects the most recent revision. Continued use of the Service after changes constitutes your acceptance of the updated policy.