Privacy Policy
Last updated: September 17, 2026
AlgoThesis is operated by 1232216 B.C. Ltd., 101-1388 Continental St, Vancouver, BC V6Z 0C9, Canada (“AlgoThesis”, “we”, “us”, or “our”). This policy explains the information used by the AlgoThesis website and research application.
1. Information we collect
- Account data: email address, authentication provider, profile name, public-profile preferences, and account timestamps. Passwords are handled and hashed by Supabase; AlgoThesis does not store plaintext passwords.
- Research data: prompts, conversations, generated theses and baskets, selected tickers and weights, saved screens and workflows, Wire drafts and saves, the bull/bear sides you take on Wire stories, tracked-thesis baselines and evidence events, comments, feedback, and files or exports you request.
- Account configuration: plan, onboarding preferences, notification choices, watchlists stored with the Service, bot accounts and hashed bot API credentials, and optional brokerage connection credentials if that restricted integration is enabled.
- Billing data: Stripe customer and subscription identifiers, plan, billing status, and renewal dates. We do not receive or store complete payment-card numbers.
- Technical and security data: IP address, browser and device information, request timestamps, authentication sessions, rate-limit events, and error diagnostics.
- Product events: limited events such as signup, feature use, and completed subscription upgrade. We do not use Google Analytics, Google Ads tags, advertising cookies, or cross-site tracking.
2. How we use information
- Provide, secure, and troubleshoot the research Service.
- Generate cited analysis, baskets, backtests, briefs, and thesis-health updates.
- Save and synchronize research that you ask us to retain.
- Authenticate users, enforce plan limits, prevent fraud and abuse, and revoke compromised credentials.
- Process subscriptions, send transactional or opted-in research email, and provide support.
- Measure aggregate product reliability and usage without advertising profiles.
We do not sell personal information, use your research to trade, or share private theses with other users. Content is public only when you deliberately publish or share it. Your bull/bear sides on Wire stories are private to you by default; when a story shows a crowd split after you’ve sided, that split is aggregate and never attributed to you by name. A side taken before you sign in is timestamped when it merges into your account, not when you tapped it, and is never counted in any public split or record.
3. AI processing and market data
Query text and the market context needed to answer it may be sent to Anthropic Claude or Google Gemini. We do not intentionally include your email, payment details, or authentication credentials in model prompts. AlgoThesis uses server-managed model credentials and does not accept or store personal AI-provider API keys.
Non-personal, non-time-sensitive first-turn queries may be held in a response cache for up to five minutes. Queries containing personal or current-position language bypass that shared cache. Market and company data may come from Databento, SEC EDGAR, Finnhub, Yahoo Finance, and public agencies; those requests normally contain symbols or market parameters rather than your account identity.
4. Service providers
We use these active providers to operate the Service:
- Supabase — authentication, PostgreSQL database, and database backups.
- Vercel — web hosting and privacy-focused product analytics.
- Fly.io — API and worker hosting.
- Stripe — subscription and payment processing.
- Resend — transactional and opted-in research email delivery.
- Sentry — scrubbed application error reporting.
- OpenAI, Anthropic and Google — AI inference. OpenAI and Anthropic write Wire stories from news feeds; Anthropic and Google answer chat and research requests.
- Market and public-data providers — Databento, SEC EDGAR, Finnhub, Yahoo Finance, and relevant public agencies.
- TradingView — embedded price charts. Your browser loads them directly from TradingView, which receives your IP address and browser details.
Where your information is stored. These providers store and process personal information in the United States and other countries outside Canada. While it is there, it is subject to those countries' laws and may be accessed by their courts, law enforcement and national security authorities.
Providers receive only the information required for their role and process it under their own privacy and retention terms.
5. Cookies, analytics, and error reporting
We use strictly necessary authentication and security cookies. Theme and interface preferences may be stored locally in your browser. If you arrive through a tagged campaign link or from another website, a first-party cookie (at_first) stores the campaign labels (UTM source, medium, campaign), the referring site's domain (not the full address) and the page you landed on, for up to 30 days. If you sign up, those values are saved with your account so we can see which channels bring readers; they are also attached to aggregate landing, follow, signup, checkout, or purchase events. We do not retain advertising click IDs such as gclid or fbclid. Vercel Analytics supplies limited aggregate product measurements. We do not load GA4, Google Ads, or a cookie-consent tracker, and we do not set advertising cookies.
Sentry receives error type, stack trace, release, and a scrubbed page path. Before an error leaves the application, user identity, request headers, cookies, query strings, request bodies, extra context, and interaction payloads are removed. Sentry Session Replay is disabled; we do not record browsing sessions or screen contents.
6. Retention
- Account settings and research you save remain until you delete them or delete the account.
- Prompt and output text in internal cost/error logs is stripped after 30 days. The remaining token, cost, model, and reliability metadata is deleted after 180 days.
- Short-lived generalized-response cache entries expire after approximately five minutes and are then deleted.
- Expired sign-in sessions are deleted within a day of expiring.
- If you buy a subscription, we keep a record of the renewal terms you agreed to and the confirmation we emailed for three years, including after you delete your account (without your account link).
- Pseudonymous public-research rate-limit counters are kept for no more than 30 days and are erased immediately when a linked account is deleted.
- Security and infrastructure logs are retained for the limited periods configured by our hosting providers.
- Aggregate statistics that cannot reasonably be linked back to an account may remain.
7. Immediate account deletion
You can permanently delete your account in Settings → Danger Zone by entering the account email and the displayed confirmation phrase. If you have an active Stripe subscription, AlgoThesis cancels it before deleting anything. If cancellation fails, deletion stops and the account remains intact.
On success, authentication and application sessions are revoked and the auth account, profile, private and published research, conversations, drafts, saves, tracking records, comments, preferences, connected credentials, and owned bot accounts and keys are removed from the active production database immediately. Public share links recorded as owned by your account stop resolving. Anonymous or legacy links that were never associated with an account cannot be identified automatically; send the link to privacy@algothesis.ai for removal. The deletion cannot be undone.
Payment processors may retain legally required transaction records, and encrypted service backups can retain isolated copies until they age out under provider backup schedules. Those copies are not available through the live Service. Separate waitlist or marketing submissions that were not linked to an account can be removed through their unsubscribe mechanism or by emailing privacy@algothesis.ai.
8. Your choices and rights
You may:
- Access and update account and profile information in Settings.
- Keep your profile and track record private.
- Delete individual saved research or permanently delete the account.
- Export available thesis and strategy results.
- Unsubscribe from optional email using the link in the message.
- Request access, correction, or deletion assistance by emailing privacy@algothesis.ai.
9. Security
We use HTTPS, row-level database access controls, service-role separation, hashed bot credentials, encrypted connection secrets, bounded sessions, and restricted production access. No system is perfectly secure; contact security@algothesis.ai if you believe an account or credential has been compromised.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect information from children.
11. Changes and contact
We may update this policy as the Service changes. We will update the date above and provide an appropriate notice for material changes. Questions or privacy requests may be sent to privacy@algothesis.ai.
Privacy Officer and complaints. 1232216 B.C. Ltd. has designated a Privacy Officer who is responsible for our compliance with privacy law. Contact: Privacy Officer, 1232216 B.C. Ltd., 101-1388 Continental St, Vancouver, BC V6Z 0C9, Canada, privacy@algothesis.ai. We respond to access and correction requests within 30 days. If you are not satisfied with our response, you can complain to the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca).