Legal
Privacy policy
Last updated October 2026
A template describing the data this application actually collects. Complete the controller details and the retention schedule with counsel before launch.
What we collect
- Account data: your email address, a bcrypt hash of your password (never the password), an optional display name, and your tier.
- Billing data: a Stripe customer identifier and subscription metadata. Card numbers are held by Stripe and never reach our servers or logs.
- Product data: your watchlist, your alert rules, and any API keys you create (stored as SHA-256 hashes).
- Technical data: server logs containing IP address, user agent and request paths, retained for security and debugging.
What we do not collect
- Brokerage credentials, account numbers, positions or balances. The product never asks for them and has no integration that would use them.
- Third-party advertising or cross-site tracking identifiers.
Why we process it
To provide the service you subscribed to (contractual necessity), to take payment (contractual necessity), to keep the service secure and prevent abuse (legitimate interests), and to meet accounting and tax obligations (legal obligation).
Processors
- Stripe — payments and subscription management.
- Our hosting and managed-database providers — application hosting and storage.
- Our transactional email provider — account and alert email.
Each is bound by a data-processing agreement. Where data is transferred outside your region, standard contractual clauses apply.
Retention
Account and product data are kept while your account exists and for a limited period after closure for accounting purposes. Server logs are retained for a short window. Deleting your account removes your account, watchlist, alert and API-key records; billing records are retained where tax law requires.
Your rights
Depending on where you live, you may have rights to access, correct, export, delete or restrict processing of your personal data, and to object to processing based on legitimate interests. Contact [privacy contact] to exercise them.
Cookies
The application sets one essential cookie: an HTTP-only, signed session token used to keep you logged in. There are no advertising or analytics cookies in this build. Any analytics added later will be privacy-preserving and disclosed here before it ships.