Privacy Policy
We collect what we need to operate the website and your account, provide requested research features, process configured billing, and send messages you request or explicitly opt into. We do not sell personal information. Signed-in users can download a machine-readable copy of their personal data and schedule or cancel account deletion from Account & Security. Use the contact in §12 for other rights requests.
§1Who we are
StockMarketAgent.ai ("we", "us", "the Service") refers to this website and its operator. The operator's approved legal name, registered address, and governing jurisdiction have not yet been supplied for publication. Paid commercial launch is blocked until those details and this policy are approved. References to "you" mean any visitor or registered user. Privacy requests can be sent to the contact in §12 in the meantime.
§2Information we collect
Account information
- Email address, display name, and password hash.
- If you choose an external sign-in provider: the provider name, a protected reference to the provider-issued account identifier, profile and verified-email claims the provider returns, connection and last-used times, and relay-email status where applicable. We do not receive your password for that provider.
- Subscription tier, billing status, and invoice history (where applicable).
- Account preferences, saved watchlists, and private report notes.
Usage information
- Security and server-log data needed to operate and protect the Service, such as IP address, request time, route, and device or browser information.
- After you select “Allow analytics,” privacy-limited page views, typed product interactions, and performance measurements described in the analytics consent prompt.
Guest watchlists
If you use a watchlist while signed out, only the ticker symbols are stored in this browser. That device-only record expires 30 days after its last change and is removed if you clear site data. On sign-in, successful entries are added to your account; existing account entries and notes are preserved, and entries that cannot be added remain on the device until they expire or you remove them.
What we do not collect
- Brokerage credentials and brokerage account numbers.
- Payment card numbers (handled exclusively by our PCI-compliant processor).
§3How we use your information
- To provide account, research, watchlist, annotation, and configured billing features you request.
- To authenticate you, connect or disconnect sign-in methods, prevent duplicate or unauthorized account linking, investigate abuse, and process provider account-security or revocation notices.
- To send account-security and service messages, and the weekly digest only after the applicable opt-in and confirmation steps.
- To measure and improve product reliability after optional analytics consent, and to detect abuse and prevent fraud.
- To meet our legal and tax obligations.
We do not target advertising on the basis of your reading history.
§4Legal basis & retention
Where the GDPR or UK GDPR applies, we rely on contract performance (delivering the Service you requested), legitimate interests (security, abuse prevention, and service reliability), and consent (marketing emails and optional product analytics). Account and billing records are retained while needed to provide the Service and afterward only for applicable legal, security, backup, tax, and dispute-handling obligations. Contact us for the retention rule applicable to a particular record.
Short-lived external sign-in attempts and handoff records expire and are pruned. A connected-provider identity is retained while it remains linked to your account, subject to security, deletion, and legal retention requirements. Disconnecting it removes the local sign-in method; provider-side authorization records are governed by that provider and may also need to be removed in its account settings.
§5Sharing & processors
Data may be processed by services configured for hosting and operations, transactional email (Cloudflare Email Sending and Resend), payment processing (Stripe), and—only after you opt in—product analytics (Plausible and PostHog). Provider availability and deployment configuration can vary; provider credentials are not evidence that a provider is active. We never sell personal information, and we do not share watchlists or reading history with brokerage firms, issuers, or advertisers. The production subprocessor list, processing agreements, and regions must be verified before commercial launch and are available on request once approved.
When you choose external sign-in, the enabled provider—Google, Apple, LinkedIn, Microsoft, or X—receives the minimum login request data needed for its OAuth or OpenID Connect flow and returns the identity claims you authorize. Depending on the service and applicable law, that provider may act as an independent controller for its account service and as a recipient or processor for the login exchange. Its own terms and privacy policy also apply. Provider credentials and one-time codes are handled server-side and are not exposed to browser JavaScript.
§6Cookies
We use strictly-necessary storage for authentication, security, language preference, and recording your privacy choice. Optional analytics are off unless you select “Allow analytics.” You can turn them off again in Preferences; doing so stops collection and resets the analytics client. When you are signed in, we also mirror that versioned choice to your account so confirmed subscription, report, export, and email-delivery outcomes can honor the same withdrawal; queued provider exports recheck the choice before delivery. We do not use third-party advertising cookies, automatic DOM capture, or session replay, and analytics page URLs omit query strings and fragments.
§7Your rights
Depending on your jurisdiction you may have the right to: access a copy of your data, correct inaccurate data, delete your account, restrict or object to processing, port your data, and withdraw consent. Contact us at the address in §12 to exercise any of these rights. We respond within the period required by applicable law.
§8Security
We use TLS in transit, one-way password hashing, access controls, and operational logging. Session and token security controls are described by the product behavior actually available to your account. No system is perfectly secure; if a breach affects your data, we will notify you and relevant authorities as required by applicable law.
§9International transfers
Processing locations depend on the production hosting and providers that are actually configured. We do not promise a user-selected data region. Production processing regions and any required transfer safeguards must be documented and approved before commercial launch.
§10Children
The Service is not directed to anyone under 18. We do not knowingly collect data from minors; if you believe we have, contact us and we will delete it.
§11Changes
We may update this Policy from time to time. The current version and date will be published here. We will provide any additional notice or renewed consent required by applicable law before a change takes effect.
§12Contact
Privacy enquiries: [email protected]
The approved operator name and postal address are pending the external legal-entity review described in §1 and must be added before paid commercial launch.