Legal
Privacy Policy
Last updated · May 5, 2026
1. Overview
We collect only the information needed to operate, secure, and improve the Service. We do not sell your personal information. Where required by law, we honor your right to access, correct, export, and delete the information we hold about you.
If you are located in the European Economic Area, the United Kingdom, Switzerland, or California, additional rights apply to you under the GDPR, UK GDPR, Swiss FADP, or CCPA respectively. See Your rights.
2. Information we collect
Information you provide
- Account information: name, email address, hashed password, and any other profile information you choose to provide.
- Subscription and billing: when you upgrade to a paid plan, our payment processor (Stripe) collects payment-card details. We do not store full card numbers.
- User content: watchlist items, transactions, alert configurations, briefing preferences, notes, and any feedback you submit.
- AI prompts and inputs: the symbols and queries you submit when generating insights or running screeners.
- Brokerage links (optional): if you connect a brokerage account via Plaid, we receive holdings, balances, and transaction history from Plaid for the accounts you authorize.
Information collected automatically
- Usage data: pages visited, features used, AI-insight counts, alert delivery events, and similar telemetry.
- Device and log data: IP address, browser type, operating system, referrer URL, and timestamps of requests.
- Cookies and similar technologies: session cookies for authentication, preference cookies for UI state, and limited analytics cookies. See Cookies and tracking.
Information from third parties
- Market data and news: we receive ticker, quote, news, and fundamentals data from licensed Data Providers. This data is generally not personal to you.
- Brokerage data: through Plaid, we receive account balances, holdings, and transactions you have authorized us to access.
3. How we use information
- Operate the Service: authenticate you, render watchlists, generate AI insights, deliver alerts, and run scheduled briefings.
- Personalize content: tailor briefings, alerts, and recommendations to the tickers and themes you track.
- Bill and account: process payments, prevent fraud, and resolve disputes.
- Communicate: send transactional email (signup, password reset, alert notifications, billing receipts) and, with your consent, occasional product updates.
- Improve the Service: measure aggregate usage, debug errors, and improve relevance of search and AI outputs.
- Comply with law and protect users: enforce our Terms, detect abuse, and respond to lawful requests.
4. AI processing
When you generate an insight, screener result, or briefing, we send relevant context — for example, the ticker symbol, recent fundamentals, news headlines, and grounded passages from public filings — to our AI provider, Anthropic, to produce the AI Output. We do not send your name, email, payment information, or other personal identifiers as part of these requests.
Anthropic processes the request under its enterprise terms, which prohibit the use of customer data to train its general-purpose models. AI Outputs are then stored in your account so they remain visible on subsequent visits.
6. Subprocessors
We use the following categories of subprocessors. The current list is updated as our vendors change.
- Hosting and infrastructure: Dokploy, Hetzner, Cloudflare.
- Database and storage: our PostgreSQL database provider, optional object storage for filing archives.
- Payments: Stripe, Inc. (PCI-compliant card processing).
- Email: Resend (transactional email delivery).
- Authentication: session management is handled in-house; password hashing uses industry-standard algorithms.
- AI: Anthropic PBC (large-language-model inference); Voyage AI (embeddings).
- Market data: Finnhub, Financial Modeling Prep, SEC EDGAR (public filings).
- Brokerage links (optional): Plaid Inc.
- Error and performance monitoring: Sentry, PostHog (events are anonymized where practical).
8. Data retention
We retain personal information for as long as your account is active and for a reasonable period after closure to comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Account information is retained for the life of the account and for up to 12 months after deletion.
- Transaction and billing records are retained for at least 7 years to comply with tax and accounting laws.
- AI Outputs and briefings are retained for the life of the account; you may delete them in your settings.
- Operational logs and security telemetry are retained for up to 90 days.
- Notifications older than 90 days are pruned automatically.
9. Your rights
Depending on where you live, you may have rights to access, correct, port, restrict, or delete the personal information we hold about you, and to object to or withdraw consent for certain processing. You may exercise these rights from your account settings or by contacting us at privacy@einvestmentdashboard.com.
EEA / UK / Switzerland
Under the GDPR, UK GDPR, and FADP you have the right to lodge a complaint with your local supervisory authority. Our legal basis for processing is performance of a contract (to provide the Service) and our legitimate interests (security, fraud prevention, product improvement), subject to your rights and freedoms.
California
California residents have the right to know what personal information we have collected about them, to request deletion, to correct inaccurate information, and to opt out of certain disclosures. We do not sell or "share" personal information as defined under the CCPA.
10. International transfers
We are based in the United States, and our subprocessors may be located in the United States, the European Economic Area, and other countries. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
11. Security
We use a combination of technical and organizational measures to protect personal information, including TLS in transit, encryption at rest for sensitive fields, principle-of-least-privilege access controls, mandatory code review, and regular dependency scanning. No system is perfectly secure; you can help by using a strong unique password and enabling two-factor authentication where available. See our Compliance overview for more.
12. Children's privacy
The Service is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe we may have collected information from a child, please contact us and we will take appropriate steps to remove it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice on the Service before the changes take effect. Continued use of the Service after the effective date of an update constitutes your acceptance.
14. Contact
Questions or requests under this Privacy Policy? Contact our privacy team at privacy@einvestmentdashboard.com.