Privacy Policy
Version [1.5] · effective from [date]. Part of the Terms of Use.
In short
- Your conversations with the analyst are sent to our AI provider (Claude by Anthropic) so that it can answer, and we keep them for 90 days.
- What you create is kept until you delete it: marks, lists and alerts.
- We do not sell personal information, show ads, or track you across sites. There are no advertising or analytics cookies. We count how the Service is used on our own server, to improve it, and nobody else sees the counts.
- You can ask to see, correct, export or delete your data at dormordechai589@gmail.com. Some of it you can delete yourself, on screen.
- Information about your financial activity is sensitive, and we treat it that way.
1. Who is responsible for your data
The controller is Dor Mordechai, a private individual in Israel. Contact: dormordechai589@gmail.com.
2. What we collect, why, on what legal basis, and for how long
For each kind of information: what it is, why we need it, the legal basis we rely on (under the GDPR and the UK GDPR), and how long we keep it.
2.1 Your account
- Your email address and your Google account ID. When you sign in with Google,
Google verifies the sign-in and tells us exactly two things: your email
address and the identifier of your Google account. Not your name, your photo,
your contacts or anything else — we ask Google only for "openid" and "email".
We do not keep any Google token.
- Why: to create and run your account, and to recognise you when you come back.
- Legal basis: necessary to perform our contract with you.
- How long: as long as your account exists.
- Or your email address and a password. If you sign up with an email address instead, we keep the address and your password — the password only as a one-way hash that we cannot read. We confirm the address before the account exists, by emailing it a code and a link through our email provider (section 4). The same is kept for an account made earlier with a password. Same purpose, basis and period.
- The emails about your account: the code and the link that confirm your address,
a link to choose a new password if you ask for one, or a note that the address
already has an account.
- Why: to confirm the address is yours, and to keep the account secure.
- Legal basis: necessary to perform our contract with you, and our legitimate interest in security.
- How long: our server keeps no copy of these emails; a code or a link is held in its memory for 30 minutes and then forgotten. [How long the email provider keeps a sent message].
- Your sign-in session: a random token in a cookie, and on our server the token
with the time it was created and last used.
- Why: to keep you signed in. Legal basis: contract.
- How long: 90 days, or until you sign out.
- A device ID: a random number your browser keeps, so that each screen has its
own conversation and the analyst acts on the chart you are looking at. On our
server it is linked to your account.
- Why: to run the Service across your devices, and to count the cost of a question against the right account. Legal basis: contract, and our legitimate interest in controlling costs.
- How long: as long as your account exists.
- The record of what you agreed to. When you sign up we record the version of
each document you agreed to, your age confirmation, your choice in the
marketing box (including that you left it empty), the time, and your IP address
at that moment.
- Why: to be able to prove what you agreed to, and when.
- Legal basis: our legal obligation to be able to demonstrate consent, and our legitimate interest in proving the terms of our contract.
- How long: as long as your account exists, and 7 years after it is closed.
- While you are signing up, between Google's answer and the boxes, your email address and Google account ID are held in our server's memory only, for up to 30 minutes — or, if you sign up with an email address, the address and the password's hash, until the address is confirmed and the boxes are ticked. If you leave without ticking the boxes, nothing about you is stored.
2.2 What you create
- Marks, lines and notes on charts (yours and the analyst's), watchlists and
folders, alerts (with their price and note), and display preferences for
each device.
- Why: to show you your work on every device. Legal basis: contract.
- How long: until you delete them, or your account.
- When you delete a mark, a short note that it was deleted (its ID only) is kept for 7 days, so your other devices delete it too.
- The history of alerts that fired, including the text of the notification.
- Why: so that an alert is not sent twice. Legal basis: contract.
- How long: 12 months.
- "Moments" from learning mode: which topic was shown, on which chart, and a
picture of it.
- Why: to show you "what we covered". Legal basis: contract.
- How long: until you delete them; the oldest go when the number kept passes a limit.
This information can reveal your financial interests. A watchlist shows which stocks you follow, a mark shows what you think of a stock, and an alert shows a price that matters to you. So we treat it as sensitive: access is limited, it is never used for marketing, and it goes nowhere beyond what section 4 lists.
2.3 Your conversations with the analyst
- What: what you write, what the analyst answers, and what its tools returned to it, including chart data. The conversation is kept as a transcript on our server.
- Why:
- so the conversation can continue;
- to support you when you contact us;
- to find faults and abuse;
- to be able to show what was said, if there is a dispute;
- to improve the quality of answers — for example, to examine a wrong answer and fix what caused it. This does not include training AI models.
- Legal basis: contract, to answer you; our legitimate interests in security, in fixing faults, in the quality of the Service and in defending legal claims — and you can object to these (section 6).
- How long: 90 days from the last message in the conversation, or until you ask us to delete it, whichever comes first.
- Temporary files the analyst creates during a conversation are deleted when it ends.
- Who reads it: Claude by Anthropic, to answer (section 4); and us, only for the purposes above. We do not use your conversations to train AI models, and any such use would need your separate, explicit consent.
2.4 How the analyst adapts its explanations
- Your knowledge level in each of three subjects (charts, markets, the economy), from a short questionnaire or from the conversation.
- Up to 7 short lines the analyst notes about how to explain to you — for example, "prefers short answers" — plus up to 10 lines it has noticed once and keeps without using yet. These lines contain no stock names and no numbers: the system refuses to store a line that does.
- Why: so the analyst explains at a pace that suits you. Legal basis: contract (it is a feature of the Service), and our legitimate interest in answers that are understood.
- How long: until you delete them. A line that has not come up for 30 days stops being used.
- You can see and delete the lines, and change your level, in the "Your analyst" tab.
- This changes how much is explained, never what is measured: the numbers are the same at every level.
2.5 Fault reports and feature requests
- When the analyst hits a fault in the app, it files a technical report: which
tool, what was sent and what came back. Your question is not stored as a field
in it, but the description the analyst writes may mention what you asked.
- Why: to fix the fault. Legal basis: our legitimate interest in a working Service. How long: until it is fixed, and 12 months after.
- Feature requests, from the form or from a conversation, are kept with what you
asked for.
- Why: to decide what to build. Legal basis: legitimate interest. How long: until it is handled, and 12 months after.
2.6 Running the Service
- The cost of each question: the model, the tokens and the cost, with your
account, device and conversation IDs — without the question and without the
answer.
- Why: the quota and keeping costs under control. Legal basis: contract (the quota) and legitimate interest. How long: 24 months.
- Your weekly allowance: the plan your account is on, any allowance set for your
account alone, and which of the allowance's warnings (75%, 80%, and each percent
from 90%) you have already been shown this week, so the same one is not repeated
on your other devices.
- Why: the weekly allowance. Legal basis: contract. How long: the plan as long as the account exists; the warnings 35 days.
- How the Service is used. We count, on our own server, how the Service is used:
- from what we already keep for the purposes in this section and the ones above: when you signed up; when you asked the analyst, how often, what it cost, how long the answer took and whether it failed; how many questions each conversation had, and whether one is open right now; whether the analyst drew on the chart for you; whether you reached an allowance warning; the fault reports and requests filed; and how many alerts (and how many of them are armed or have fired), lists, marks and notification devices you have — never which instrument, which price or what they say;
- and five things kept only for this: the days you opened the Service (the date, not the time) and the kind of device you opened it on — phone, tablet or computer, read from the description your browser sends with every request; which parts of the Service you used on a day, from a fixed list of eight — charts (moving to another instrument or timeframe), lists, the market screens, the economic calendar, news, alerts, drawing and lessons — the part's name only, never which instrument, which price, how many times or when in the day; the campaign link you arrived from, if you came through one of ours — its source and campaign name, from a fixed list we set, and no advertising-network click identifiers; and which of the analyst's tools each question used — their names only, not what they were asked or what they answered. Nothing is stored on your device for any of this.
- Your knowledge level (section 2.4) is counted only as a total across all accounts, never per account. So are the days, the device kind, the parts you used and the campaign link: we see how many accounts did something, never which account did what.
- Why: to understand how the Service is used and where it fails people, and to decide its plans and its prices. Legal basis: our legitimate interest in improving the Service and in running it. You can object (section 6), and you can switch it off yourself, in the account menu ("Count my use"): your account is then left out of every count, and the days, the device kind, the parts used, the source and the tool names kept for you are deleted.
- Who sees it: only us. No third-party analytics: the counting runs on our own server, and nothing about it is sent to anyone.
- How long: the days, the device kind and the parts used, 12 months; the source, as long as your account exists; the tool names, 24 months, with the cost of the question. Some counts identify nobody — how many visits our home page had from each source on a day, how many sign-ups were started and how many were finished, and how many times a question to the analyst waited because the server was full, for how long in total, and how many idle conversations were paused to make room — and are not personal information.
- Your IP address is used to limit the rate of requests, and is held only in our server's memory, for minutes. It is not stored in our database — except in the record of what you agreed to (section 2.1).
- Your email address, when you sign up or ask for a new password, is likewise used to limit how many emails go to it — so that nobody can use our forms to flood an inbox. It is held only in our server's memory, for at most a day.
- The country you connect from. When you sign in or sign up, we work out the
country of your IP address — from a copy of a geolocation database kept on our own
server (IP Geolocation by DB-IP), or from the network provider
in front of our server — to refuse sign-ins from the countries the Terms list
(section 4). Your address is not sent to anyone for this, and the country is not
stored with your account; a refused attempt is logged by its country code only.
- Why: to comply with sanctions law and with our AI provider's terms. Legal basis: our legal obligation, and our legitimate interest in keeping to our suppliers' terms. How long: not kept.
- Server logs: errors and operations, and which instrument each question was
about, by device and time. Not what you wrote.
- Why: to operate the Service and fix faults. Legal basis: legitimate interest. How long: 30 days.
- Backups: copies of the database, so that it can be restored. How long: 30 days.
2.7 Notifications to your phone or browser
- If you turn on notifications: the subscription address your browser created
(an address at Apple, Google or Mozilla), its keys, and the device's name.
- Why: to send you the notifications you asked for. Legal basis: contract. How long: until you turn notifications off, or the address stops working.
- When the analyst finishes an answer while your screen is closed, we send a notification that the answer is ready, and which instrument it is about. The answer itself is not in the notification; it waits in the panel. The instrument's name can appear on a locked screen. You can turn off this site's notifications in your device's settings.
- A notification's content is encrypted, so the push service carries it but cannot read it. It can still see when a notification is sent, and how long it is.
- We do not send advertising by notification.
2.8 Marketing email — only if you said yes
- If you ticked the box when you signed up, we may email you news about the Service and offers. Legal basis: your consent. You can withdraw it at any time, with the link in every such email or by writing to us; withdrawing does not affect what was done before. How long: until you withdraw.
- Service messages are not marketing, and every account gets them: the code that confirms your address, a link to choose a new password, a change to these documents, the move from the free beta to a paid plan, or a security notice.
2.9 Payments
There are no payments during the beta. If a paid plan opens, card details will go straight to our payment provider and will neither pass through nor be stored on our servers. We would keep only a transaction ID, the amount, the date and the status.
2.10 What we do not do
- We do not sell your personal information, and we do not "share" it for advertising based on your activity across other sites.
- We do not show ads, and we use no advertising or analytics cookies.
- We do not make decisions about you based solely on automated processing that have a legal effect on you or affect you similarly significantly.
- We do not get information about you from anyone else, except the email address and the account ID Google sends when you sign in.
3. Cookies, and what is stored on your device
Cookies. We set three, all our own, and no other site can read them:
tradeapp_sessionkeeps you signed in. Scripts cannot read it, and it is sent only to our site. It lasts 90 days, or until you sign out.tradeapp_oauthexists only while you sign in with Google, to protect the sign-in against forgery. It lasts up to 10 minutes.tradeapp_signupexists only while you sign up, to hold your place between Google, or the email we send you, and the screen with the boxes. It lasts up to 30 minutes.
Storage on your device (the browser's local storage, which stays until it is cleared): the random device ID; your account ID; a copy of your marks and your lists, so that the chart opens quickly and still works when our server does not answer; choices you make on screen (which panels are open, snapping, the sound in learning mode, the list you were last in and its order, whether you have seen the welcome); and short fingerprints of the places in answers that were already shown.
Storage for one tab (cleared when the tab closes): a note that your account was just created, so the welcome opens once.
When you tap a notification, the link it opens is kept briefly in the site's own cache, so the right page opens.
No advertising cookies, no third-party analytics, no tracking across sites, and no third-party scripts or fonts — everything is served from our own site. The counting in section 2.6 runs on our own server and stores nothing on your device. You can switch it off in the account menu ("Count my use").
Why there is no cookie banner. Everything above is there to give you the service you asked for: signing in, staying signed in, protecting the sign-in, having your own work available, and remembering choices you made on screen. We consider all of it strictly necessary, which the law in the EU and the UK does not make subject to consent, and we use nothing else. If you would rather not stay signed in, sign out when you leave, and the session cookie is deleted. If we ever add anything that is not strictly necessary, we will ask you first.
4. Who receives your data
We do not sell personal information, and we do not pass it to advertisers. It goes only where it has to for the Service to work:
- Anthropic PBC (USA), the Claude language model — what you write to the analyst, what is on the chart, what the tools returned, and your explanation level and lines, so that the model can answer. It processes this for us, as our processor, under its [commercial terms and data processing addendum]. United States.
- The web-search provider the analyst uses: when the analyst searches the web (for example, for why a stock moved), the search query is sent to a search provider through Claude by Anthropic. It may contain a company's name or ticker; it is not meant to contain anything that identifies you.
- Google, as the sign-in provider: when you sign in with Google, Google knows you signed in to the Service, under Google's own privacy policy. We send Google nothing about what you do in the Service.
- Push services (Apple, Google or Mozilla, depending on your browser): encrypted notifications, so that they reach your device.
- [Email provider, country]: your email address and the messages we send you about your account — the sign-up code and link, a link to choose a new password — so that they reach you. It processes them for us, as our processor.
- netcup GmbH, Germany: everything we store, because our server runs there.
- Authorities: only when the law requires it, and only what it requires.
- A buyer of the business: if the business is transferred, your data may go with it, still under this policy, and we will tell you before it does.
Market-data providers (Intrinio and others) do not receive your identity. Our server asks them for data on its own behalf, and keeps the result in one cache for all users.
5. Transfers between countries
We are based in Israel. The European Commission recognises Israel as giving personal data an adequate level of protection, and so does the United Kingdom, so data can come to us from the EU and the UK without further safeguards.
Some of the providers in section 4 are in other countries — Claude by Anthropic and the push services in the United States, our hosting provider in Germany (inside the European Union), [and our email provider in [country]]. Where personal data of someone in the EU or the UK goes to a country without such recognition, we rely on the safeguards the law provides: the European Commission's standard contractual clauses, with the UK addendum — for Claude by Anthropic, the clauses in its data processing addendum; for any other provider, the same clauses, or the EU–U.S. Data Privacy Framework where that provider is certified under it. You can ask us for a copy of the relevant safeguard at dormordechai589@gmail.com.
6. Your rights
Depending on where you live, the law gives you some or all of these rights. We give all of them to every user, wherever you live:
- Access — a copy of the information we hold about you.
- Correction — of anything that is wrong.
- Deletion:
- marks, lists, alerts, moments and explanation lines: directly on screen;
- your whole account, your conversations and everything else: by writing to dormordechai589@gmail.com. We complete it within one month and confirm in writing.
- Portability — what you created, in a machine-readable format (JSON). Market data is not included, because we are not allowed to redistribute it.
- Objection — to what we do on the basis of our legitimate interests (for example, reading a conversation to fix a fault, or counting how you use the Service — that one you can also switch off yourself, in the account menu). We will stop, unless we have compelling grounds or need it for a legal claim.
- Restriction — asking us to limit what we do with your information while a question about it is being settled.
- Withdrawing consent to marketing email, at any time, with the link in every such email or by writing to us.
- Complaining to the data-protection authority of the country where you live or work, or where you think the infringement happened — in the EU, your national supervisory authority; in the UK, the Information Commission; in Israel, the Privacy Protection Authority. We would like the chance to put things right first, but you do not have to ask us first.
- In California and other US states: we do not sell or share personal information, and do not use it for targeted advertising, so there is nothing to opt out of. The rights to know, to delete and to correct apply to you as above, and we will not treat you differently for using any of them.
How we answer: free of charge, within one month. A complicated request may take up to two months more, and if so we will tell you why within the first month. We may need to confirm that the request is yours, usually by a reply from your account's email address.
What remains after deletion: records the law requires us to keep (accounting and tax), the record of your agreement to the Terms, and the minimum needed to prevent fraud.
7. Security
- All personal information is stored under its own account, and it is tested that one account cannot read another's.
- Google sign-in is checked on our server — Google's signature, the intended recipient, the expiry — and we keep no Google token. Passwords are stored only as a one-way hash, and a new password account is made only once its address is confirmed by a code sent to it. The session cookie cannot be read by scripts.
- Traffic is encrypted. Sign-up, sign-in and questions are rate-limited.
- Each conversation has its own working folder, and the analyst cannot write outside it.
No system is immune, and we cannot promise that a breach will never happen. If a breach is likely to put you at high risk, we will tell you without undue delay, and we will notify the data-protection authorities as the law requires.
8. Sensitive information
In Israel, where we are based, information about a person's financial activity is treated as especially sensitive. Watchlists, alerts and conversations about positions may be such information. So:
- Do not send the analyst account numbers, passwords or details that identify you. It does not need them.
- Please do not share other sensitive information either — about your health, beliefs or the like. The Service has no use for it.
- We do not ask for any of this. What you write, you write by choice.
9. Children
The Service is only for people who are 18 or older, and old enough to enter a contract where they live. It is not directed at children, and we do not knowingly collect information about anyone under 18. If we learn that we have, we delete it.
10. Changes to this policy
A material change will be announced 30 days ahead, by email and in the Service. The next time you sign in, we will ask you to agree where the law requires it, and we keep the version you agreed to.
11. Contact
dormordechai589@gmail.com.