Privacy Policy
Last updated 2 August 2026
These terms are a working draft prepared for launch. They have not been reviewed by counsel. Have a lawyer review them before you take live payments.
What we collect
- Your email address. Required to create an account and to send you sign-in links.
- Sign-in records. For each session we store the time, your IP address and your browser's user-agent string, so you can recognise unfamiliar activity and so we can rate-limit abuse.
- Google account identifier, if you choose to sign in with Google. We request only your email address and basic profile.
- Subscription and payment records — plan, status, renewal date, invoice amounts and their outcome.
- API usage counts, if you use the API, to enforce your plan's daily limit.
- Watchlists you choose to create.
What we deliberately do not collect
- No password. Sign-in is by emailed link or Google, so there is no password for us to store or for a breach to leak.
- No card details. Payments are handled entirely by Stripe. Card numbers never touch our servers.
- No brokerage credentials, holdings, or portfolio data. We do not connect to your broker and cannot see what you own.
- No advertising trackers or third-party analytics cookies.
Cookies
We set one essential cookie, sp_session, which identifies your signed-in
session. It is HttpOnly, Secure, SameSite=Lax,
and expires after 30 days. A short-lived sp_oauth_state cookie is used
during Google sign-in to protect against cross-site request forgery, and is discarded
immediately afterwards. We use no advertising or analytics cookies, so there is
nothing to consent to or opt out of.
Who we share data with
We do not sell your data, ever. We share the minimum necessary with a small number of processors:
- Cloudflare — hosting, and the databases holding your account.
- Stripe — payment processing. Stripe receives your email and holds your payment method under its own privacy policy.
- Resend — delivers sign-in emails.
- Brevo — delivers the newsletter, if you are subscribed to it.
- Google — only if you choose Google sign-in.
How long we keep it
Account data is kept while your account exists. Sign-in tokens expire after 15 minutes and sessions after 30 days. Payment records are retained for as long as tax and accounting law requires, typically seven years, even after an account closes.
Your rights
You may ask us to show you the data we hold about you, correct it, delete your account and its data, or export it. Email support@stockpilot-ai.com and we will respond within 30 days. Deleting your account does not delete payment records we are legally required to keep.
If you are in the EEA or UK, our lawful bases are contract (running your account), legitimate interest (security and abuse prevention) and consent (the newsletter, which every email lets you unsubscribe from in one click). If you are in California, we do not sell or share personal information as those terms are defined by the CCPA.
Security
Traffic is encrypted in transit. Sign-in tokens and API keys are stored only as SHA-256 hashes, so their plaintext cannot be recovered from our database. Sessions are server-side and can be revoked instantly. No system is perfectly secure, and we cannot guarantee absolute security.
Children
The Service is not directed at anyone under 18 and we do not knowingly collect their data.
Changes and contact
We will notify you by email of material changes. Questions: support@stockpilot-ai.com.