Privacy Policy

Last updated: July 10, 2026

1. What we collect

Account data: your email address (used to sign you in and send service emails) and, if you use Google sign-in, the email Google verifies for you - nothing else from your Google account.
Usage data: the tickers you analyze, your reports, quota usage, and timestamps - the minimum needed to run quotas, history, and abuse prevention. We also keep standard server logs (IP address, requests) for security and rate limiting.
Billing data: handled entirely by Stripe. We never see or store your card number - only your subscription status and a Stripe customer reference.

2. What we don't do

We don't sell your data, run third-party advertising or tracking pixels, or profile you. There are no third-party analytics scripts on this site. We don't ask for - and you should never send us - brokerage credentials or portfolio details; the Service is deliberately impersonal.

3. Cookies

One first-party session cookie keeps you signed in, and one browser preference remembers your light/dark theme. That's the complete list.

4. Service providers

We share the minimum necessary data with the processors that run the Service: Stripe (payments), Resend (transactional email to your address), Anthropic (the AI models that generate analyses - ticker symbols and market data, never your identity), market-data providers (ticker symbols only), and DigitalOcean (hosting, US data center). Each processes data under its own privacy terms.

5. Sharing & visibility

Your reports are private by default. If you create a share link, anyone with that link can read that report (without your identity attached); you can disable a share link at any time. Aggregate, anonymous statistics (e.g. "how many analyses ran this week") may be used to operate and describe the Service.

6. Retention & deletion

We keep your account data and reports while your account is active. Email us to delete your account - we'll remove your account data and reports within 30 days, except records we must keep for legal or billing purposes. Server logs rotate automatically.

7. Security

Passwordless sign-in (no password to steal), HTTPS everywhere, signed session cookies, single-use sign-in links that expire in 15 minutes, and least-privilege infrastructure. No system is perfectly secure - use a mailbox you control and keep it protected.

8. Changes & contact

Material changes will be posted here with an updated date. Questions or deletion requests: signin@parallaxresearch.io.