๐Ÿฆ‰ OwlScore

Privacy Policy

Last updated: [DATE]

[LEGAL ENTITY NAME] ("OwlScore," "we," "us") operates the OwlScore website and Service. This policy describes what personal data we collect, how we use it, and your choices.

1. Data we collect

We do not collect brokerage account credentials, portfolio holdings, or financial account information โ€” OwlScore does not link to brokerage accounts (see Disclaimer ยง2).

2. How we use data

3. Data sharing (subprocessors)

We share data with the following categories of service providers, solely to operate the Service:

| Provider | Purpose | Data shared | |---|---|---| | Supabase | Database, authentication | Account data, usage data | | Stripe | Payment processing | Billing data (Stripe is PCI-compliant; we never see full card numbers) | | Resend | Transactional email | Email address | | Anthropic | LLM-powered scanner and research memos | Your natural-language query text; ticker context (not your identity) | | [Tiingo / FMP / Alpha Vantage] | Market data | None of your personal data โ€” this is inbound market data only | | Plausible / Umami | Privacy-friendly analytics | Aggregate, non-personally-identifying usage data | | Vercel | Hosting | Standard request logs (IP address, for security/abuse purposes) |

We do not sell your personal data. We do not share individual watchlists or query history with any third party except as listed above or as required by law.

4. Cookies and tracking

We use only essential cookies for authentication (session management via Supabase Auth). Our analytics provider does not use cookies or cross-site tracking.

5. Data retention

We retain account data for as long as your account is active, plus [12 months] after closure for legal/accounting purposes, unless you request earlier deletion (see ยง6). Aggregate/anonymized usage data may be retained indefinitely.

6. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise these rights, contact [CONTACT EMAIL]. We will respond within [30 days] (or the timeframe required by applicable law, e.g., GDPR/CCPA).

7. Children's privacy

The Service is not directed to individuals under 18. We do not knowingly collect data from anyone under 18.

8. Security

We use industry-standard measures (encryption in transit, access controls via Supabase Row Level Security) to protect your data, but no system is perfectly secure. Notify us at [CONTACT EMAIL] if you believe your account has been compromised.

9. International data transfers

[Placeholder โ€” fill in if serving users outside the hosting region, e.g., Vercel/Supabase data-residency details and any required transfer mechanism (SCCs, etc.).]

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified via email or in-app notice.

11. Contact

Questions about this policy or your data: [CONTACT EMAIL].