Privacy

Last updated 10 August 2026

What we collect, why we have it, and who else it reaches. Short, because we collect little.

What we collect

  • Your email address, and (if you sign in with Google, Microsoft or Apple) the name and avatar that provider gives us. Nothing else from those accounts.
  • A username, if you set one, and when you last set it: a username can be changed once a year, and that date is how we know when yours may change again.
  • Which avatar you picked. Not an image: either the name of one of eight patterns, or a note to use the photo your identity provider already gave us. You cannot upload a picture here, so we never hold one.
  • Your portfolio: the symbols you hold, quantities, cost basis if you enter it, and any notes you write.
  • Questions you ask the assistant, and its answers, together with the token counts and cost of each: that is how usage limits are enforced.
  • Session records: the time, your IP address and your browser’s user agent, so you can see and revoke active sign-ins.
  • Billing records, if you subscribe: which plan, its status and renewal date, and an identifier issued by Paddle.
  • Which companies you have used the valuation tool on, on the free plan: that is how the lifetime allowance is counted, and it is why an unlocked company stays unlocked.
  • Your email address if you join the waitlist, before you have an account at all, along with which page you asked from. Kept only until you are invited or until you ask us to remove it.

We never see your card details. They go directly to our payment provider and are never sent to, or stored on, our systems.

Why we have it

To sign you in, to show you your portfolio, to answer your questions, to enforce the limits of your plan, to take payment, and to keep the service running and secure. That is the whole list. We do not build advertising profiles, and we do not sell or share personal information for advertising.

Sessions and cookies

Signing in sets one cookie, __Host-il_session, holding an opaque random token. The token itself is not stored (only its SHA-256 hash), so a copy of our database is not a set of usable sessions. Two short-lived cookies are used during sign-in to prevent cross-site request forgery.

Those are the only cookies we set, and they are strictly necessary ones. We set no advertising cookie of our own anywhere on this site, and we do no cross-site profiling. Google’s advertising tag does set cookies of its own, on the two pages named below and on no others. That is what the notice at the foot of those pages is asking about, if you are in the EEA, the UK or Switzerland.

We do measure how the site is used, and it is worth being exact about how. When a page loads, this site tells our own servers which page it was, whether the site that sent you was a search engine or a social one, and the campaign name written in the link if you arrived from an advertisement. That goes to no third party. It is added to an hourly total and nothing else is kept: no cookie, no identifier for your device, and no record of your individual visit for anything to be traced back to. Your IP address is used only to stop the endpoint being flooded and is then discarded rather than stored. Because it is a counter and not a record, we can tell you how many times a page was opened and we genuinely cannot tell you how many people opened it.

If a page breaks in your browser, the error message, the stack trace, the path you were on and your browser’s user-agent string are sent to our own servers so we can fix it. That report goes to no third party, and your IP address is used only to stop the endpoint being flooded and is then discarded rather than stored.

Four third-party scripts exist, and none of them is loaded site-wide: each loads solely on the page that needs it. Settings → Billing loads Paddle’s checkout library, because that page is where a payment is completed and the payment form is theirs, not ours. That is also why we never see your card. Paddle may set cookies of its own on that page for fraud prevention and to remember a checkout in progress; those are described in Paddle’s own privacy notice. The sign-in and sign-up forms load Cloudflare Turnstile, which checks that a form is being submitted by a person rather than a script. It is what stops the sign-in form being used to send mail to strangers.

The home page and the page shown after you ask for access load Google’s advertising tag, and only those two. If you reached us by clicking one of our advertisements, that link carries a click identifier, and the tag stores it in a cookie on this site so that Google can be told the advertisement led to a signup. That is the whole of what it is for: it lets us see which advertisements are worth paying for. Google may use what it collects for its own advertising purposes, as described in its privacy policy, and it sets cookies of its own to do so. The tag is not asked to record your visit the way the counter above does, and it never sees a page inside the product.

On the page shown after you ask for access, that tag is also given a scrambled form of the address you just typed. Most advertisement clicks now come from inside a phone app, where the click identifier above cannot be matched to anything on its own, so without this we cannot tell which advertisements actually work. What is sent is a SHA-256 hash: a one-way fingerprint that cannot be turned back into your address. Google compares it against its own accounts to see whether the advertisement it showed led here. The address itself is never put in a web link, never appears in this page’s address bar, and never leaves your browser for this purpose; only the fingerprint does. If you did not arrive from one of our advertisements there is nothing for it to match, and if your browser declines to compute it the page carries on without.

If you are in the EEA, the UK or Switzerland, that tag stores nothing until you say so. It starts in a mode where advertising storage, personalisation and measurement are all switched off, and it is only turned on if you press Accept on the notice at the foot of the page. Pressing Reject leaves it switched off and costs you nothing else on this site. Your answer is remembered in your own browser, not on our servers, so clearing this site’s data makes the notice appear again and lets you answer differently.

If you reached us from one of our advertisements on Reddit, the same two pages load Reddit’s advertising pixel instead of Google’s tag, and they load it only for you: a visitor who arrived any other way never loads it. We can tell from the link, which carries Reddit’s own click identifier and names Reddit as the source. It does the same job for Reddit that the tag above does for Google, including storing the click identifier in a cookie on this site and, on the page shown after you ask for access, being given the same one-way fingerprint of your address rather than the address itself. Reddit may use what it collects for its own advertising purposes, as described in its privacy policy. In the EEA, the UK and Switzerland it is not loaded at all until you press Accept on the notice; there is no “off” mode for it, so refusing means it never runs.

None of these four is loaded on your portfolio, on any stock page, or on any other page once you are signed in.

What other users can see

If you post a comment, other users see the username you chose, the avatar you picked, and which plan you are on (from the first paid tier upwards). That last one is a deliberate disclosure and it is the only thing on this list you did not type: a badge beside your name says that you subscribe, though never what you paid or when.

Nothing else reaches another user. In particular nothing about your portfolio does: not which companies you hold, not whether you hold the one being discussed, and nothing computed from either. A feature that showed the last of those was built and then removed for exactly this reason.

Your email address is never shown to another user, in any circumstance. That is why posting requires a username: there is no fallback that could show an address instead.

Who else sees it

We use these processors, each for one job:

  • Amazon Web Services: hosting and databases (United States), and email delivery for sign-in links.
  • Anthropic, or AWS Bedrock: the assistant. When you ask a question, the question and the relevant part of the page or portfolio you are looking at are sent to the model provider so it can answer. Do not put anything in a question you would not want sent there.
  • marketstack: quotes and price history. It receives symbols, never anything identifying you.
  • Paddle (Paddle.com Market Ltd): subscriptions. Paddle is more than a processor here: as merchant of record it is the seller, so it collects your payment details and billing address in its own right and as its own controller, not on our behalf. It gives us back an identifier, a plan and a status, never your card. Its handling of what it collects is governed by Paddle’s own privacy notice.

Public filing data comes from the SEC and from official statistical agencies. Those are sources we read, not parties we send anything to.

We may disclose information if legally required to. We will tell you when we are permitted to.

How long we keep it

  • Account and portfolio data: until you delete your account.
  • Assistant conversations: until you delete them, or your account.
  • Expired and revoked sessions: cleared automatically.
  • Sign-in links: 15 minutes, then unusable.
  • Billing records: kept as long as tax and accounting law requires, even after an account is closed.
  • Waitlist entries: until you are invited, or until you ask us to remove yours.
  • Valuation-tool history on the free plan: until you delete your account.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it and close your account. Depending on where you live you may also have the right to object to or restrict certain processing, to data portability, and to complain to a data protection authority. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.

Email support@investailor.com and we will respond within 30 days.

Security

Traffic is encrypted in transit. Session tokens are stored only as hashes. Credentials are held as encrypted secrets that only the production cluster can decrypt. Internal services are not reachable from the internet. No system is perfectly secure, and we will tell affected users promptly if there is a breach that puts their data at risk.

Children

The service is not intended for anyone under 18, and we do not knowingly collect their data.

International transfers

We operate in the United States, so if you are elsewhere your data is processed there, under appropriate safeguards for transfers out of your region.

Changes

If we change this policy materially we will say so before it takes effect. Contact: support@investailor.com, Investailor.

Privacy · Investailor