Skip to main content

Legal

Privacy Policy

Version 2026-09-06 · Last updated

Interim version — under counsel review.

This Privacy Policy is complete and in force as written, but has not yet been reviewed by counsel. Items shown in [brackets] are placeholders awaiting confirmation. Questions: legal@pythiaresearch.org.

This policy explains what Pythia Research (“Pythia”, “we”) collects when you use pythiaresearch.org and the application, why, who else sees it, how long we keep it, and the choices you have. The controller is [ENTITY — legal name and address].

1. What we collect

  • Account: email, name, avatar and the identifier your sign-in provider gives us (Google or GitHub, and Microsoft or Apple where enabled), or a one-time email code if you sign up by email. Your plan, trial and billing status, and a Stripe customer id.
  • Consent record: which version of the Terms you accepted and when.
  • What you create: watchlists, notes, theses, saved screens, saved charts and models, dashboard layouts, interests you pick at sign-up, and any manual portfolio positions (shares, cost basis, purchase date).
  • Brokerage data (only if you connect a brokerage): positions, balances and account identifiers synced read-only through SnapTrade. The SnapTrade secret that authorises the sync is stored encrypted.
  • AI conversations: your prompts, the assistant’s replies, and a short “memory” of facts you tell it (for example your investing style), which you can review and clear in AI settings. Each AI call also records the model used, token counts and estimated cost for your allowance.
  • Usage telemetry: product events such as a page viewed, a company opened, a screen run, with the surface it happened on and a session id. Used for ranking what to show you and for product analytics. Not sold, not shared with ad networks.
  • Session security records: for each sign-in, the browser, operating system, IP address and the approximate city and country derived from it, plus when the session was last seen or revoked. Shown to you in Security settings and used to enforce per-plan device limits.
  • Billing: handled by Stripe. Card numbers never reach our servers.
  • Support and feedback: what you send us by email or through the feedback form.

2. Why we use it (and the legal bases)

  • To provide the Service you signed up for — contract.
  • To personalise what you see: dashboard, feed, watchlist nudges, and the research context given to the AI assistant — contract and, for AI personalisation, your settings (see §4).
  • To bill you and keep accounting records — contract and legal obligation.
  • To keep the Service secure: session limits, abuse and bot detection, rate limiting — legitimate interests.
  • To send transactional email (receipts, payment problems, security notices) — contract; and product email (weekly digest, new reports, reminders) — your preferences, changeable any time in Notification settings or from the link in every email.
  • To improve the product with aggregate analytics and error reports — legitimate interests.

3. What we do not do

  • We do not sell or share your personal data for advertising, and we run no ad trackers.
  • We do not give your prompts or conversations to anyone except the AI provider that answers them.
  • We never see your brokerage password and can never trade or move money.
  • We do not make automated decisions with legal effect about you.

4. AI features and personalisation

When you use the assistant, generate an insight, or ask for a report section, your prompt and the research context assembled for it are sent to the AI provider that runs the selected model. Personalisation is on by default: with it on, that context can include your watchlist, your stated interests, and — if you have a portfolio — your holdings and their weights, so answers can refer to what you own. Turn it off in AI settings and prompts are sent without that personal context. Providers process prompts under their API terms and do not use them to train models. If you bring your own API key, your prompts go directly to that provider under your own agreement with them.

5. Who else processes your data

We use the following providers. Each receives only what its row says, and each is bound by a data-processing agreement or equivalent terms.

  • Supabase Database, authentication, file storage. Receives: All account data, content you create, session security records.
  • Vercel Application hosting, edge network, cookieless web analytics. Receives: Request metadata (IP address, user agent, pages visited); analytics are aggregate and set no cookies.
  • Stripe Payments, subscriptions, invoices. Receives: Name, email, billing address, payment method (card numbers never reach our servers). When you start a trial, subscribe, or buy AI credits.
  • Resend Email delivery. Receives: Email address, name, the content of emails we send you.
  • Sentry Error monitoring and performance tracing. Receives: Error reports and a sampled fraction of sessions replayed with all text masked and media blocked; email addresses and secrets are scrubbed before sending.
  • Vercel AI Gateway and the model providers it routes to (Anthropic, OpenAI, Google, xAI, as listed in the model picker) AI assistant, Pythia Insight narratives, AI report sections. Receives: The prompts you submit and the research context assembled for them (scores, financials, your watchlist or portfolio weights when personalisation is on). When you use an AI feature; providers process prompts under their API data terms and do not train on them.
  • SnapTrade Read-only brokerage connections. Receives: Your brokerage login is entered on SnapTrade, never on Pythia; we receive positions, balances and account identifiers. Only if you connect a brokerage account.
  • Upstash Rate limiting. Receives: Short-lived request counters keyed by IP address or account id.
  • Cloudflare Turnstile Bot protection at sign-up. Receives: Browser signals used to tell people from scripts. When the sign-up challenge is switched on.

Market data comes from Financial Modeling Prep, FRED, Federal Reserve Bank of St. Louis, European Central Bank, U.S. Securities and Exchange Commission, Logo.dev, Aswath Damodaran, NYU Stern. None of them receives personal data from us. We may also disclose data when the law requires it, to enforce our Terms, or in a merger or sale of the business, in which case this policy continues to apply.

6. Cookies and similar storage

  • Essential: sign-in cookies set by our authentication provider, and browser storage for your interface preferences and the sign-up acceptance tick.
  • Analytics: Vercel Web Analytics, which is aggregate and sets no cookies.
  • Diagnostics: Sentry error reporting; a small sampled share of sessions is replayed for debugging with all text masked and all media blocked.

The first-visit notice offers Accept and Decline; nothing optional runs until you choose, and Decline leaves only the essential sign-in cookie. Change your choice any time in Privacy settings.

7. How long we keep it

  • Account, content and portfolio data: for as long as your account exists.
  • Billing records: kept by Stripe and in our subscription event log for as long as tax and accounting law requires.
  • Session security records: [RETENTION — set by the retention job (LG-11)].
  • AI usage and cost records: [RETENTION — 13 months proposed, set by the retention job (LG-11)].
  • Usage telemetry and notifications: [RETENTION — set by the retention job (LG-11)].
  • Error reports at Sentry: 90 days. Email delivery logs at Resend: per their retention.
  • After you delete your account, your data is removed from our database at once; backups roll off within 7 days; anonymised aggregates may be kept.

8. Your rights and choices

  • Delete: delete your account from Profile settings. This removes your account and content, cancels any subscription, deletes your Stripe customer record (invoices stay on Stripe as accounting records) and deletes any SnapTrade user so the brokerage authorisation is revoked upstream.
  • Access and portability: download a JSON archive of everything we hold about you from Profile settings (“Export my data”), any time. Prefer email? Write to privacy@pythiaresearch.org and we will send it within 30 days.
  • Correct: edit your profile in Settings, or email us for anything else.
  • Object or restrict: turn off AI personalisation and product email in Settings; for other objections, email us.
  • EU/UK: you also have the right to complain to your supervisory authority. California — Do Not Sell or Share: we do not sell or share personal information as defined by the CCPA. The one optional processing is analytics; declining it in the cookie notice or in Privacy settings is your opt-out. The rights above cover access, deletion and correction, and we will not discriminate for exercising them.

9. Security

Data is encrypted in transit and at rest. Database access is scoped per user by row-level security, and server-owned fields (plan, billing, consent) cannot be changed from the browser. Brokerage secrets are encrypted with a key held outside the database. Two-factor authentication is available to every account. Access to production is limited to the operators, and we rotate our keys on a schedule. No system is perfectly secure; if we learn of a breach affecting you we will notify you without undue delay. Report a vulnerability to security@pythiaresearch.org.

10. Where data is stored

Our database and application run in the United States [REGION — confirm the Supabase region]. If you use the Service from elsewhere, your data is transferred to and processed there, under the safeguards our processors provide (standard contractual clauses where required).

11. Children

The Service is not for anyone under 18 and we do not knowingly collect data from children. If you believe a child has an account, email us and we will delete it.

12. Changes

Material changes are announced by email at least 14 days before they take effect, and the version above changes. Continued use after the effective date is acceptance.

13. Contact

Privacy: privacy@pythiaresearch.org · Legal: legal@pythiaresearch.org · Post: [POSTAL ADDRESS]


Interim version under counsel review; the placeholders above are the open items. See the Terms of Service for usage rules.