Privacy Policy
Last updated: 2026-07-13 — the short version: your data stays on our infrastructure.
What we collect. Account data (email, password hash, optional TOTP secrets), product data you create (watchlists, drawings, alerts, workspaces, journal entries), and first-party usage analytics (page views and feature events keyed to a random identifier stored in your browser — not a fingerprint).
Where it lives. On our own servers. Analytics events go to our own database — there is no Google Analytics, no advertising pixel, and no third-party analytics service. Your browser connects to our domain and nothing else.
Third parties we do use. Stripe processes payments (we never see card numbers). Resend delivers transactional email. Server-side, we query market-data vendors and, for some AI features, vendor language models — AI requests are stamped so you can see when a vendor model (rather than our self-hosted one) answered.
Cookies. A session cookie when you sign in, and a deployment-group cookie for canary rollouts. No cross-site tracking cookies.
Your rights. You can delete your account and its data from account settings, or clear the anonymous analytics identifier by clearing site data. Email us for data export requests.
Changes. Material changes to this policy will be announced in the changelog before they take effect.