Privacy policy

What is stored, why it is stored, who else sees it, and how to get rid of it.

Who is responsible

The controller for the data described here is . Questions and requests go to the contact address published on this site.

What is stored

DataWhyRetention
Email addressIdentifies the account, receives the confirmation link, password resets and — if enabled — signal alerts.Until the account is deleted.
Password (hashed)Authentication. Stored as a one-way hash; the plaintext is never written down.Until the account is deleted.
Two-factor secretOnly present if you turn on TOTP two-factor authentication.Until you disable 2FA or delete the account.
Login history — timestamp, IP address, browser user-agent, success or failureLets you see and check access to your own account, and makes unauthorised attempts visible.Until the account is deleted.
Subscription identifiersA Stripe customer and subscription id, so entitlements follow what you have actually paid for.Until the account is deleted; Stripe keeps its own billing records independently.
Trading212 API key (encrypted)Only if you connect a broker. Encrypted at rest with Fernet, read-only, and never used to place orders.Until you disconnect the integration or delete the account.
Watchlist, folders, price alerts, bookmarks and reactionsThe product features themselves.Until the account is deleted.
Chat conversations and messagesSo the analyst chat has history you can search, rename, pin and export.Until you delete the conversation or the account.
Push subscription — endpoint and encryption keysOnly if you allow browser notifications. Required to deliver them to that device.Until you revoke permission or delete the account.
PreferencesTheme, notification toggles and AI preferences.Until the account is deleted.

Cookies and tracking

Advertising measurement is optional and off until you say otherwise. Nothing is placed before you choose, and choosing Reject means the tag is never fetched — not fetched and ignored. You can change your mind at any time in Settings → Privacy.

Strictly necessary storage is used regardless: a login token, your theme and display preferences, and your consent choice itself. These are required for the site to function and are kept in your browser, not on a server.

Who else receives data

  • StripePayment processing and subscription state. Card details go to Stripe directly and are never received or stored by this service.
  • Google AdsAdvertising measurement — only after you accept, and never before. Rejecting means the script is never loaded at all.
  • Email provider (SMTP)Delivers confirmation links, password resets and alerts. Only configured deployments send mail.
  • Market-data providersYahoo Finance, Twelve Data, Stooq, Binance, Kraken and CoinGecko. Queried for symbols and prices; they receive no account information.
  • AnthropicPowers the conversational analyst on deployments with an API key set. Receives the text of your question and the market evidence assembled for it.

Your data is not sold, and it is not shared for anyone else's advertising.

Your rights

You can request access to your data, correction, erasure, a portable copy, or restriction of processing, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time.

In practice: Settings lets you change your email or password, disconnect a broker, revoke sessions, export your conversations, and delete your account. Deleting the account removes your profile, preferences, login history, watchlist, alerts, bookmarks, reactions, notifications, broker credentials, push subscriptions, and all conversations and messages.

Two things deliberately survive deletion, because neither identifies you: published signals, which are market analysis attributed to the AI desk and not to any member, and aggregate model-accuracy statistics. Stripe also retains its own billing records as it is independently required to.

If you are in the EU or UK and think a request has been handled badly, you can complain to your national data-protection authority.

Security

Passwords are stored hashed. Broker API keys are encrypted at rest. Two-factor authentication is available and recommended. No system is immune to compromise, and nothing here should be read as a guarantee against it.