Legal

Privacy Policy

This draft is structured more like a production privacy notice than placeholder launch copy, but it should still be reviewed by counsel before production use.

Back
Last updated: April 8, 2026
This draft should be reviewed by a licensed attorney familiar with the privacy laws applicable to your users and aligned with the Terms of Service and Important Disclaimer before production use.

1. Scope of This Policy

This Privacy Policy explains how Stock.Agent collects, uses, stores, discloses, and otherwise processes personal information in connection with our website, applications, newsletters, AI tools, portfolio features, alerts, customer support, and related services (collectively, the "Service").

This Policy should be read together with our Terms of Service and any additional disclosures presented at the point of collection. It should be reviewed by counsel before production launch, especially if you intend to rely on jurisdiction-specific privacy rights language.

2. Information We Collect

We may collect identifiers and account information such as name, email address, username, login session details, authentication provider identifiers, and account preferences. We may also collect billing-related identifiers such as customer IDs, subscription IDs, plan tier, promo code usage, invoice status, and payment processor metadata, but we do not store full payment card numbers unless explicitly stated by a processor-integrated workflow.

We may collect content you submit to the Service, including prompts, portfolio holdings, watchlists, newsletter customization requests, saved reports, notes, AI interactions, support requests, uploaded materials, and other account inputs. We may also collect usage, diagnostics, and device information such as IP address, browser type, cookies, local storage data, session events, logs, crash data, rate-limit events, and security telemetry.

3. How We Use Information

We use personal information to operate, maintain, secure, improve, and support the Service; authenticate users; provide account features; process subscriptions and promotions; generate newsletters, research outputs, and AI responses; deliver alerts and transactional communications; troubleshoot bugs; detect misuse; enforce our terms; analyze product performance; and comply with legal obligations.

We may also use information to personalize outputs, improve workflow quality, evaluate feature adoption, monitor system integrity, investigate suspected abuse, and protect users, our business, data providers, and the public.

4. AI Processing and Automated Features

Some prompts, portfolio inputs, custom requests, and other interactions may be processed by AI or machine-learning systems operated by us or by third-party providers acting on our behalf. AI-generated outputs may be stored to support product functionality, continuity, quality improvement, safety review, memory features, or user-requested history.

Because AI features may involve processing user-submitted content through third-party systems, you should avoid submitting sensitive information unless you are comfortable with that processing and it is necessary for your intended use. If your use case requires special handling of regulated or highly sensitive data, you should obtain legal review before relying on the Service.

5. Cookies, Local Storage, and Similar Technologies

We may use cookies, local storage, SDKs, pixels, and similar technologies for login continuity, user preferences, plan state, analytics, fraud prevention, abuse detection, security monitoring, performance measurement, and feature operation. Some of these technologies may be set or supported by third-party vendors acting on our behalf.

Depending on your jurisdiction, you may have rights to manage certain cookie or tracking preferences. If you implement a consent mechanism, this Policy should be updated to match the live categories and controls presented to users.

6. Sources of Information

We may collect information directly from you, automatically through your use of the Service, from authentication providers, payment processors, market data vendors, customer support interactions, analytics tools, infrastructure providers, security tools, and other service providers that help us operate the platform.

7. When We Share Information

We may share information with vendors and service providers that perform services on our behalf, such as hosting, authentication, AI processing, billing, market data delivery, analytics, logging, customer support, and email delivery. We may also disclose information when required by law, legal process, or governmental request; to protect rights, safety, and security; to investigate misuse; or in connection with a merger, financing, acquisition, bankruptcy, or asset transfer.

We do not sell personal information for cash. If you intend to engage in targeted advertising, data brokerage, or sharing that may be regulated as a "sale" or "sharing" under applicable privacy laws, this Policy should be revised to reflect that before launch.

8. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain business and billing records, support security operations, resolve disputes, enforce agreements, satisfy tax and accounting obligations, and comply with legal requirements.

Retention periods may vary by data category. For example, security logs, job records, billing metadata, and support history may be retained longer than session data or ephemeral workflow inputs where reasonably justified by operational or legal needs.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These may include access controls, authentication measures, logging, alerting, environment restrictions, rate limiting, vendor controls, and other security practices appropriate to our size and risk profile.

No system is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed. You are responsible for protecting your credentials, using secure devices and networks, and notifying us promptly if you believe your account has been compromised.

10. Your Choices and Rights

Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of personal information, and you may have the right to appeal a denied privacy request. You may also manage certain account information directly in the product, unsubscribe from non-essential emails, or request account deletion where available.

If you plan to rely on specific state, national, or regional privacy laws such as the CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, GDPR, or UK GDPR, this section should be reviewed and tailored to those requirements, including identity verification, response timing, appeals, and agent authorization procedures.

11. Children’s Privacy

The Service is not intended for children, and we do not knowingly collect personal information from children under the age where parental consent is required by applicable law. If you believe a child has provided personal information to us without appropriate authorization, contact us so we can investigate and take appropriate steps.

12. International Transfers

If you access the Service from outside the United States, your information may be processed in the United States and other countries where we or our vendors operate. Data protection laws in those locations may differ from those in your jurisdiction.

Where required by law, we may rely on contractual safeguards or other approved transfer mechanisms. If cross-border transfer compliance is material to your business, this section should be finalized with counsel based on your actual vendor stack and data flows.

13. Third-Party Links and Services

The Service may link to or integrate with third-party websites, products, or services. Their privacy practices are governed by their own policies, not this one. We are not responsible for the privacy, security, or content practices of third parties we do not control.

14. Changes to This Policy

We may update this Privacy Policy from time to time as the Service evolves, our practices change, or legal requirements develop. If a change is material, we will provide notice through the Service, by email, or by another reasonable method before the updated Policy becomes effective where required by law.

15. Contact Information

Questions or requests about this Privacy Policy should be sent to: newsletter@stockagent.online.

If you later designate a separate privacy contact, data protection officer, or consumer request contact, update this section so it matches your live compliance process.