Draft for a lawyer. This text has not yet been reviewed by a lawyer and is not final. Anything highlighted is a decision still open, including the AI provider and the data provider.

Privacy Policy

Version 1.11 · draft of 2026-10-08

Version [1.5] · effective from [date]. Part of the Terms of Use.

In short

1. Who is responsible for your data

The controller is Dor Mordechai, a private individual in Israel. Contact: dormordechai589@gmail.com.

2. What we collect, why, on what legal basis, and for how long

For each kind of information: what it is, why we need it, the legal basis we rely on (under the GDPR and the UK GDPR), and how long we keep it.

2.1 Your account

2.2 What you create

This information can reveal your financial interests. A watchlist shows which stocks you follow, a mark shows what you think of a stock, and an alert shows a price that matters to you. So we treat it as sensitive: access is limited, it is never used for marketing, and it goes nowhere beyond what section 4 lists.

2.3 Your conversations with the analyst

2.4 How the analyst adapts its explanations

2.5 Fault reports and feature requests

2.6 Running the Service

2.7 Notifications to your phone or browser

2.8 Marketing email — only if you said yes

2.9 Payments

There are no payments during the beta. If a paid plan opens, card details will go straight to our payment provider and will neither pass through nor be stored on our servers. We would keep only a transaction ID, the amount, the date and the status.

2.10 What we do not do

3. Cookies, and what is stored on your device

Cookies. We set three, all our own, and no other site can read them:

Storage on your device (the browser's local storage, which stays until it is cleared): the random device ID; your account ID; a copy of your marks and your lists, so that the chart opens quickly and still works when our server does not answer; choices you make on screen (which panels are open, snapping, the sound in learning mode, the list you were last in and its order, whether you have seen the welcome); and short fingerprints of the places in answers that were already shown.

Storage for one tab (cleared when the tab closes): a note that your account was just created, so the welcome opens once.

When you tap a notification, the link it opens is kept briefly in the site's own cache, so the right page opens.

No advertising cookies, no third-party analytics, no tracking across sites, and no third-party scripts or fonts — everything is served from our own site. The counting in section 2.6 runs on our own server and stores nothing on your device. You can switch it off in the account menu ("Count my use").

Why there is no cookie banner. Everything above is there to give you the service you asked for: signing in, staying signed in, protecting the sign-in, having your own work available, and remembering choices you made on screen. We consider all of it strictly necessary, which the law in the EU and the UK does not make subject to consent, and we use nothing else. If you would rather not stay signed in, sign out when you leave, and the session cookie is deleted. If we ever add anything that is not strictly necessary, we will ask you first.

4. Who receives your data

We do not sell personal information, and we do not pass it to advertisers. It goes only where it has to for the Service to work:

Market-data providers (Intrinio and others) do not receive your identity. Our server asks them for data on its own behalf, and keeps the result in one cache for all users.

5. Transfers between countries

We are based in Israel. The European Commission recognises Israel as giving personal data an adequate level of protection, and so does the United Kingdom, so data can come to us from the EU and the UK without further safeguards.

Some of the providers in section 4 are in other countries — Claude by Anthropic and the push services in the United States, our hosting provider in Germany (inside the European Union), [and our email provider in [country]]. Where personal data of someone in the EU or the UK goes to a country without such recognition, we rely on the safeguards the law provides: the European Commission's standard contractual clauses, with the UK addendum — for Claude by Anthropic, the clauses in its data processing addendum; for any other provider, the same clauses, or the EU–U.S. Data Privacy Framework where that provider is certified under it. You can ask us for a copy of the relevant safeguard at dormordechai589@gmail.com.

6. Your rights

Depending on where you live, the law gives you some or all of these rights. We give all of them to every user, wherever you live:

How we answer: free of charge, within one month. A complicated request may take up to two months more, and if so we will tell you why within the first month. We may need to confirm that the request is yours, usually by a reply from your account's email address.

What remains after deletion: records the law requires us to keep (accounting and tax), the record of your agreement to the Terms, and the minimum needed to prevent fraud.

7. Security

No system is immune, and we cannot promise that a breach will never happen. If a breach is likely to put you at high risk, we will tell you without undue delay, and we will notify the data-protection authorities as the law requires.

8. Sensitive information

In Israel, where we are based, information about a person's financial activity is treated as especially sensitive. Watchlists, alerts and conversations about positions may be such information. So:

9. Children

The Service is only for people who are 18 or older, and old enough to enter a contract where they live. It is not directed at children, and we do not knowingly collect information about anyone under 18. If we learn that we have, we delete it.

10. Changes to this policy

A material change will be announced 30 days ahead, by email and in the Service. The next time you sign in, we will ask you to agree where the law requires it, and we keep the version you agreed to.

11. Contact

dormordechai589@gmail.com.