Privacy Policy
Last updated: July 12, 2026
AlgoThesis is operated by 1232216 B.C. Ltd. (“AlgoThesis”, “we”, “us”, or “our”). This policy explains the information used by the AlgoThesis website and research application.
1. Information we collect
- Account data: email address, authentication provider, profile name, public-profile preferences, and account timestamps. Passwords are handled and hashed by Supabase; AlgoThesis does not store plaintext passwords.
- Research data: prompts, conversations, generated theses and baskets, selected tickers and weights, saved screens and workflows, Wire drafts and saves, tracked-thesis baselines and evidence events, comments, feedback, and files or exports you request.
- Account configuration: plan, onboarding preferences, notification choices, watchlists stored with the Service, bot accounts and hashed bot API credentials, and optional brokerage connection credentials if that restricted integration is enabled.
- Billing data: Stripe customer and subscription identifiers, plan, billing status, and renewal dates. We do not receive or store complete payment-card numbers.
- Technical and security data: IP address, browser and device information, request timestamps, authentication sessions, rate-limit events, and error diagnostics.
- Product events: limited events such as signup, feature use, and completed subscription upgrade. We do not use Google Analytics, Google Ads tags, advertising cookies, or cross-site tracking.
2. How we use information
- Provide, secure, and troubleshoot the research Service.
- Generate cited analysis, baskets, backtests, briefs, and thesis-health updates.
- Save and synchronize research that you ask us to retain.
- Authenticate users, enforce plan limits, prevent fraud and abuse, and revoke compromised credentials.
- Process subscriptions, send transactional or opted-in research email, and provide support.
- Measure aggregate product reliability and usage without advertising profiles.
We do not sell personal information, use your research to trade, or share private theses with other users. Content is public only when you deliberately publish or share it.
3. AI processing and market data
Query text and the market context needed to answer it may be sent to Anthropic Claude or Google Gemini. We do not intentionally include your email, payment details, or authentication credentials in model prompts. AlgoThesis uses server-managed model credentials and does not accept or store personal AI-provider API keys.
Non-personal, non-time-sensitive first-turn queries may be held in a response cache for up to five minutes. Queries containing personal or current-position language bypass that shared cache. Market and company data may come from Databento, SEC EDGAR, Finnhub, Yahoo Finance, and public agencies; those requests normally contain symbols or market parameters rather than your account identity.
4. Service providers
We use these active providers to operate the Service:
- Supabase — authentication, PostgreSQL database, and database backups.
- Vercel — web hosting and privacy-focused product analytics.
- Fly.io — API and worker hosting.
- Stripe — subscription and payment processing.
- Resend — transactional and opted-in research email delivery.
- Sentry — scrubbed application error reporting.
- Anthropic and Google — AI inference.
- Market and public-data providers — Databento, SEC EDGAR, Finnhub, Yahoo Finance, and relevant public agencies.
Providers receive only the information required for their role and process it under their own privacy and retention terms.
5. Cookies, analytics, and error reporting
We use strictly necessary authentication and security cookies. Theme and interface preferences may be stored locally in your browser. Vercel Analytics supplies limited aggregate product measurements. We do not load GA4, Google Ads, or a cookie-consent tracker, and we do not set advertising cookies.
Sentry receives error type, stack trace, release, and a scrubbed page path. Before an error leaves the application, user identity, request headers, cookies, query strings, request bodies, extra context, and interaction payloads are removed. Sentry Session Replay is disabled; we do not record browsing sessions or screen contents.
6. Retention
- Account settings and research you save remain until you delete them or delete the account.
- Prompt and output text in internal cost/error logs is stripped after 30 days. The remaining token, cost, model, and reliability metadata is deleted after 180 days.
- Short-lived generalized-response cache entries expire after approximately five minutes.
- Pseudonymous public-research rate-limit counters are kept for no more than 30 days and are erased immediately when a linked account is deleted.
- Security and infrastructure logs are retained for the limited periods configured by our hosting providers.
- Aggregate statistics that cannot reasonably be linked back to an account may remain.
7. Immediate account deletion
You can permanently delete your account in Settings → Danger Zone by entering the account email and the displayed confirmation phrase. If you have an active Stripe subscription, AlgoThesis cancels it before deleting anything. If cancellation fails, deletion stops and the account remains intact.
On success, authentication and application sessions are revoked and the auth account, profile, private and published research, conversations, drafts, saves, tracking records, comments, preferences, connected credentials, and owned bot accounts and keys are removed from the active production database immediately. Public share links recorded as owned by your account stop resolving. Anonymous or legacy links that were never associated with an account cannot be identified automatically; send the link to privacy@algothesis.ai for removal. The deletion cannot be undone.
Payment processors may retain legally required transaction records, and encrypted service backups can retain isolated copies until they age out under provider backup schedules. Those copies are not available through the live Service. Separate waitlist or marketing submissions that were not linked to an account can be removed through their unsubscribe mechanism or by emailing privacy@algothesis.ai.
8. Your choices and rights
You may:
- Access and update account and profile information in Settings.
- Keep your profile and track record private.
- Delete individual saved research or permanently delete the account.
- Export available thesis and strategy results.
- Unsubscribe from optional email using the link in the message.
- Request access, correction, or deletion assistance by emailing privacy@algothesis.ai.
9. Security
We use HTTPS, row-level database access controls, service-role separation, hashed bot credentials, encrypted connection secrets, bounded sessions, and restricted production access. No system is perfectly secure; contact security@algothesis.ai if you believe an account or credential has been compromised.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect information from children.
11. Changes and contact
We may update this policy as the Service changes. We will update the date above and provide an appropriate notice for material changes. Questions or privacy requests may be sent to privacy@algothesis.ai.