Privacy Policy
What personal data we process, why, how long we keep it, and your rights.
Last updated: July 8, 2026
The Company values your personal data and complies with applicable data-protection laws, including the Korean Personal Information Protection Act (PIPA) and, where applicable, the GDPR. This policy explains what personal data we collect and use, third-party sharing, retention and your rights.
1. Personal data we collect
Account details (email, name, profile image via Clerk), consent records (timestamp, IP, user-agent), payment data (Stripe customer/subscription identifiers — card data is held by Stripe), portfolios and watchlists, referral relationships and a hashed signup IP, API keys (hashed), service access/usage records, paid-plan waitlist sign-ups (email, plan of interest, language), and enterprise sales inquiries (work email, organization, team size, intended use).
2. Purposes of use
We use personal data for member management and authentication, billing/renewal/refunds of paid subscriptions, providing and improving the Service, meeting legal obligations (such as consent evidence), and preventing abuse (such as referral-fraud detection).
3. Legal bases
We process personal data on the bases permitted by applicable law, including performance of a contract, your consent, legal obligations and legitimate interests.
4. Sharing and processors
To provide the Service we engage processors for authentication (Clerk), payments (Stripe), AI processing (Anthropic), hosting/CDN and email. When AI processing is used, personally identifying data is minimized.
5. International transfers
Some processors are located outside your country; where this occurs we apply the safeguards required by law. The details of international transfers will be finalized and disclosed in the pre-launch legal review.
6. Retention and deletion
Personal data is deleted without undue delay once its purpose is achieved or you close your account, except where a legal retention obligation applies. On account deletion, related data is cascade-deleted.
7. Your rights
You may request access, correction, deletion, restriction and portability of your personal data. You can export your data (portability) and delete your account (erasure) directly from your profile page.
8. Cookies
We use the minimum necessary cookies for keeping you signed in, language preference and referral attribution.
9. Security
We apply technical and organizational measures such as access control, transport encryption and IP hashing to process personal data securely.
10. Children
The Service does not target children below the minimum age set by applicable law and does not knowingly collect their personal data.
Jurisdiction-specific notices
Depending on where you reside, the following also applies.
United States (California) users
California residents have the right under the CCPA/CPRA to know the categories of personal data collected, to request deletion, and to opt out of sale/sharing. The Company does not sell personal data.
EU/EEA users
Under the GDPR the Company acts as data controller and states its legal bases; you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority.
Republic of Korea users
Under PIPA the Company discloses the items, purposes, retention period, processing consignment and cross-border transfer of personal data, and you may request access, correction, deletion and suspension of processing.
Where this policy conflicts with mandatory law, that law prevails; cross-border transfer and retention details are finalized in the pre-launch legal review.